Multi-index joint alarm method, device, equipment and medium
By constructing an indicator correlation graph and generating correlation subgraphs, and determining alarms based on the current indicator abnormality value, the problems of accuracy, recall rate, and detection time in traditional monitoring systems are solved, efficient multi-indicator joint alarms are achieved, and labor costs are reduced.
Patent Information
- Application Number
- CN202410339271.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-22
- Publication Date
- 2025-09-23
AI Technical Summary
Traditional single-indicator monitoring systems are difficult to simultaneously meet the requirements of high accuracy, recall rate, and low detection time. Multi-indicator monitoring solutions rely on manual rule construction, which is costly and difficult to handle a large number of indicators.
By constructing an indicator association graph, using historical alarm data to calculate the joint information entropy of edge weights, deleting low-threshold edges to generate an associated subgraph, and combining the current indicator abnormality value to determine the alarm, manual intervention is reduced.
It improves the accuracy and recall rate of alarms, shortens the discovery time, and reduces the labor cost of multi-indicator alarms. It is suitable for monitoring systems with a large number of indicators.
Smart Images

Figure CN120689985A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and more particularly to a multi-indicator joint alarm method, apparatus, device, and medium. Background Art
[0002] Traditional monitoring systems primarily rely on monitoring a single metric to generate alerts. However, this single-metric-based alerting approach has limitations and often struggles to simultaneously achieve high accuracy, recall, and detection time. To overcome the limitations of single-metric monitoring, some vendors have adopted multi-metric monitoring solutions. Currently, multi-metric monitoring solutions primarily rely on the experience of domain experts to manually construct multiple judgment rules based on single metrics. Alerts are triggered only when multiple single-metric rules simultaneously meet specific conditions. However, this approach is labor-intensive. Furthermore, in large-scale monitoring systems with a vast number of metrics, it is difficult for humans alone to handle all possible combinations of single-metric rules.
[0003] Therefore, a new multi-index joint alarm method is needed. Summary of the Invention
[0004] The embodiments of the present disclosure describe a multi-indicator joint alarm method, apparatus, device, and medium.
[0005] According to a first aspect, a multi-indicator joint alarm method is provided, comprising:
[0006] Based on historical alarm data corresponding to multiple indicators, an indicator association graph is constructed, wherein the indicator association graph includes multiple nodes and edges between the nodes, the multiple nodes respectively corresponding to the multiple indicators, the edges are determined based on whether there are alarms between the indicators corresponding to the connected nodes in a predetermined historical time interval, and the edge weights of the edges indicate a joint information entropy determined based on the number of alarms of the indicators corresponding to the connected nodes in the historical time interval; based on the data distribution of the edge weights of the edges included in the indicator association graph, a first threshold is determined, and edges in the indicator association graph having edge weights greater than the first threshold are deleted to obtain multiple association subgraphs;
[0007] Obtain the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in the current time window respectively, and determine the node weights of the nodes included in each associated subgraph based on the indicator abnormality degree values; determine the current subgraph abnormality degree values of each associated subgraph based on the node weights and the edge weights, and determine whether to issue alarms corresponding to each associated subgraph based on the current subgraph abnormality degree values.
[0008] According to a second aspect, a multi-indicator joint alarm device is provided, comprising:
[0009] The graph generating unit is configured to construct an indicator association graph based on historical alarm data corresponding to a plurality of indicators, wherein the indicator association graph includes a plurality of nodes and edges between the nodes, the plurality of nodes respectively corresponding to the plurality of indicators, the edges being determined based on whether there are alarms between the indicators corresponding to the connected nodes in a predetermined historical time interval, and the edge weights of the edges indicating a joint information entropy determined based on the number of alarms of the indicators corresponding to the connected nodes in the historical time interval; determining a first threshold value based on a data distribution of the edge weights of the edges included in the indicator association graph, deleting edges in the indicator association graph having edge weights greater than the first threshold value, and obtaining a plurality of association subgraphs;
[0010] The alarm unit is configured to respectively obtain the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in the current time window, and determine the node weights of the nodes included in each associated subgraph based on the indicator abnormality degree values; determine the current subgraph abnormality degree values of each associated subgraph based on the node weights and the edge weights, and determine whether to issue alarms corresponding to each associated subgraph based on the current subgraph abnormality degree values.
[0011] According to a third aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the method of the first aspect.
[0012] According to a fourth aspect, an electronic device is provided, comprising a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method of the first aspect is implemented.
[0013] According to embodiments of the present disclosure, a multi-indicator joint alarm method, apparatus, device, and medium are provided. First, an indicator association graph can be constructed based on historical alarm data corresponding to multiple indicators. The indicator association graph includes multiple nodes and edges between the nodes. The multiple nodes correspond to multiple indicators, and the edges are determined based on whether the indicators corresponding to the connected nodes all have alarms within a predetermined historical time interval. The edge weights of the edges indicate the joint information entropy determined based on the number of alarms for the indicators corresponding to the connected nodes within the historical time interval. Next, a first threshold is determined based on the data distribution of the edge weights included in the indicator association graph, and edges in the indicator association graph with edge weights greater than the first threshold are deleted, resulting in multiple association subgraphs. Then, the indicator anomaly level value of the indicator corresponding to the node included in each association subgraph in the current time window can be obtained. Based on the indicator anomaly level value, the node weight of the node included in each association subgraph is determined. Based on the node weight and edge weight, the current subgraph anomaly level value of each association subgraph is determined. Based on the current subgraph anomaly level value, it is determined whether to issue an alarm for each association subgraph. This method can reduce the labor cost of multi-indicator alarm while improving the accuracy and recall rate of alarms and shortening the detection time. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 A schematic diagram showing a monitoring scheme based on a single indicator is shown;
[0015] Figure 2 A schematic diagram of a multi-indicator joint alarm method according to an embodiment of the present disclosure is shown;
[0016] Figure 3 A schematic diagram of a multi-indicator joint alarm method according to an embodiment of the present disclosure is shown;
[0017] Figure 4 A schematic diagram showing an indicator association diagram according to an embodiment of the present disclosure is shown;
[0018] Figure 5 A schematic diagram showing an associated subgraph according to an embodiment of the present disclosure is shown;
[0019] Figure 6 A schematic block diagram of a multi-indicator joint alarm device according to an embodiment of the present disclosure is shown;
[0020] Figure 7 A schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure is shown;
[0021] Figure 8 A schematic diagram of the structure of a storage medium suitable for implementing the embodiments of the present disclosure is shown. DETAILED DESCRIPTION
[0022] The technical solutions provided in this specification are further described in detail below in conjunction with the accompanying drawings and embodiments. It will be understood that the specific embodiments described herein are merely for explaining the relevant inventions and are not intended to limit the inventions. It should also be noted that, for ease of description, only the portions relevant to the relevant inventions are shown in the accompanying drawings. It should be noted that, unless there is a conflict, the embodiments of the present disclosure and the features therein may be combined with each other.
[0023] In the description of the implementations of the present disclosure, the term "including" and similar terms should be understood as open inclusion, i.e., "including but not limited to." The term "based on" should be understood as "based at least in part on." The term "one / an implementation" or "the implementation" should be understood as "at least one / an implementation." The term "some implementations" should be understood as "at least some implementations." Other explicit and implicit definitions may be included below.
[0024] As mentioned above, traditional monitoring systems mainly rely on monitoring a single indicator to generate alarms. Figure 1 A schematic diagram of a monitoring solution based on a single indicator is shown. Figure 1 In the example shown, for example, alarms can be issued based on different single indicators. For example, Alert (A) can be issued based on the abnormality level of indicator A, and Alert (B) or Alert (C) can be issued based on the abnormality level of indicator B or C. However, this alarm method that relies on a single indicator has the following problems: it is usually difficult to achieve good accuracy, recall rate, and detection time at the same time. For example, the instantaneous fluctuation of a specific single indicator does not necessarily mean that there is a problem with the monitored data. It may just be a normal spike in the monitored data. If an alarm is issued immediately, it is easy to cause a false alarm. However, if the alarm for the spike of the indicator is delayed and the alarm is issued only after the abnormal trend is confirmed, it may lead to a prolonged fault detection time, or even a missed fault call, thereby reducing the recall rate.
[0025] Therefore, to overcome the limitations of single-metric monitoring solutions, some manufacturers have adopted multi-metric monitoring solutions. Currently, multi-metric monitoring solutions primarily rely on the experience of domain experts to manually construct multiple judgment rules based on single metrics. Alerts are triggered only when multiple single-metric rules simultaneously meet specific conditions. However, this solution also has the following problems: First, manually combining multiple single-metric rules is labor-intensive. Second, for monitoring systems with a large number of metrics, it is difficult to manually configure all possible combinations of single-metric rules.
[0026] In order to solve the above technical problems, the embodiments of the present disclosure provide a multi-indicator joint alarm method. Figure 2FIG. 1 shows a schematic diagram of a multi-index joint alarm method according to an embodiment of the present disclosure. Figure 2 As shown, in some embodiments, for example, historical alarm data corresponding to multiple indicators can be obtained to construct an indicator association graph of multiple indicators. The indicator association graph may include multiple nodes and edges between nodes, wherein multiple nodes can correspond to multiple indicators respectively, and the edges can be determined based on whether there are alarms between the indicators corresponding to the connected nodes in a predetermined historical time interval, and the edge weights of the edges can indicate the joint information entropy determined based on the number of alarms in the historical time interval according to the indicators corresponding to the connected nodes. Then, a first threshold can be determined based on the data distribution of the edge weights, and the edges in the indicator association graph with edge weights greater than the first threshold can be deleted, thereby obtaining multiple associated subgraphs. For example Figure 2 In the example shown, after deleting the edges whose edge weights are lower than the first threshold, four associated subgraphs are obtained. Thereafter, the node weights of the nodes included in each associated subgraph can be determined based on the indicator abnormality values of the indicators corresponding to the nodes included in each associated subgraph in the current time window, and the indicator abnormality values can be used to determine the node weights of the nodes included in each associated subgraph; the current subgraph abnormality values of each associated subgraph can be determined based on the node weights and the edge weights, and whether to issue alarms corresponding to each associated subgraph can be determined based on the current subgraph abnormality values. For example, Figure 2 In the example shown, for example, the nodes corresponding to metrics A, B, and C form a connected subgraph G1. This allows the abnormality values of metrics A, B, and C to be obtained and used to determine the node weights of their corresponding nodes. The current abnormality value of G1 is determined based on the node weights and edge weights of the nodes included in G1. Furthermore, based on this current abnormality value of the subgraph, it is determined whether to issue an alarm corresponding to G1.
[0027] The advantages of this method are: on the one hand, it can simultaneously improve the accuracy and recall rate of alarms and reduce the time to discovery through multi-indicator joint alarms, solving the problem of difficulty in achieving the above three simultaneously. On the other hand, it constructs a multi-indicator indicator association graph and divides the association subgraph through the historical alarm data of multiple indicators. Based on the current abnormality value of the corresponding indicator of the node in the association subgraph, it determines the multi-indicator joint alarm corresponding to the association subgraph, without manually setting rules or rule combinations based on single alarm indicators, which greatly reduces the labor cost of multi-indicator alarms. Furthermore, it is also convenient for joint alarms for a large number of indicators.
[0028] The detailed process of this method is further described below.
[0029] Figure 3 FIG. 1 shows a flow chart of a multi-index joint alarm method according to an embodiment of the present disclosure. Figure 3 As shown, the method comprises at least the following steps:
[0030] Step S201: construct an indicator association graph based on historical alarm data corresponding to multiple indicators, wherein the indicator association graph includes multiple nodes and edges between the nodes, wherein the multiple nodes correspond to the multiple indicators respectively, and the edges are determined based on whether there are alarms between the indicators corresponding to the connected nodes in a predetermined historical time interval, and the edge weights of the edges indicate a joint information entropy determined based on the number of alarms of the indicators corresponding to the connected nodes in the historical time interval; determine a first threshold value based on the data distribution of the edge weights of the edges included in the indicator association graph, and delete the edges in the indicator association graph whose edge weights are greater than the first threshold value to obtain multiple association subgraphs;
[0031] Step S303, respectively obtain the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in the current time window, and determine the node weights of the nodes included in each associated subgraph based on the indicator abnormality degree values; determine the current subgraph abnormality degree values of each associated subgraph based on the node weights and the edge weights, and determine whether to issue alarms corresponding to each associated subgraph based on the current subgraph abnormality degree values.
[0032] First, in step S301, an indicator association graph is constructed based on the historical alarm data corresponding to multiple indicators, and the indicator association graph includes multiple nodes and edges between nodes. Among them, multiple nodes can correspond to multiple indicators respectively, and the edges can be determined based on whether there are alarms between the indicators corresponding to the connected nodes in a predetermined historical time interval, and the edge weights of the edges can indicate the joint information entropy determined based on the number of alarms of the indicators corresponding to the connected nodes within the historical time interval. In this step, an undirected graph can be constructed as an indicator association graph based on multiple indicators and the historical alarm data corresponding to the multiple indicators. In different embodiments, multiple indicators for different businesses or for different purposes can be obtained, and this specification does not limit this. In different embodiments, the specific methods of obtaining historical alarm data corresponding to multiple indicators may also be different.
[0033] Multiple nodes in the indicator association graph represent multiple indicators. Based on the historical alarm data, whether the indicators represented by each node correspond to the alarm within a predetermined historical time interval, it can be determined whether there is an edge between each node. Figure 4 In the indicator association graph shown, if both indicator J and indicator K have alarms in the above historical time interval, it is determined that there is a connecting edge, or simply an edge, between the node corresponding to indicator J and the node corresponding to indicator K. The weight of the edge can be the joint information entropy determined based on the number of alarms in the historical time interval for the indicators corresponding to the nodes connected by the edge. For example Figure 4In the example shown, the weight of the edge between the node corresponding to indicator J and the node corresponding to indicator K can be the joint information entropy H(J, K) determined based on the number of alarms for indicator J and indicator K in the historical time interval. In different embodiments, the specific method of determining the joint information entropy between indicators can be different. In one embodiment, the joint information entropy between indicators can be expressed as the following formula:
[0034] H(X, Y) = -∑ X ∑ Y P(x,y)logP(x,y) (1)
[0035] in,
[0036]
[0037] Where X and Y represent indicators, x and y represent values indicating whether the indicator is in alarm, P() represents the probability distribution function, cnt(X) represents the number of alarms for indicator X in a specific time interval, cnt(Y) represents the number of alarms for indicator Y in a specific time interval, and cnt(X) represents the number of times indicators X and Y simultaneously in alarm in a specific time interval.
[0038] After obtaining multiple text features, a first threshold can be determined based on the data distribution of the edge weights of the edges included in the indicator association graph, and edges with edge weights greater than the first threshold are deleted from the indicator association graph to obtain multiple association subgraphs. For example, Figure 5 In the example shown, you can Figure 4 In the indicator association graph shown, edges with edge weights lower than a first threshold are deleted to obtain multiple association subgraphs G1, G2, G3, and G4.
[0039] In different embodiments, the specific method of determining the first threshold value may vary. In one embodiment, a first exponential function may be fitted based on the data distribution of the edge weights of the edges included in the indicator association graph; the first function value is set, and the first threshold value is determined based on the first function value and the first exponential function. In a specific embodiment, the fitted first exponential function can be expressed as: F(x) = a·e bx -1, where F(x) represents the edge weight distribution probability, a and b are calculation coefficients, x is the edge weight value, and e is a natural constant. Determining the first threshold by fitting the function can facilitate determining the first threshold based on the actual distribution of edge weights. This allows for more accurate segmentation of the relationship index graph from the indicator association graph based on the first threshold.
[0040] Then, in step S303, the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in the current time window are obtained respectively, and the node weights of the nodes included in each associated subgraph are determined based on the indicator abnormality degree values. In this step, the obtained indicator abnormality degree values are used to indicate whether the current value or state of the corresponding indicator is abnormal. In different embodiments, the specific method of obtaining the indicator abnormality degree value may be different, and this specification does not limit this. For convenience of calculation, in one embodiment, the indicator abnormality degree value may be a normalized indicator abnormality degree value. In one embodiment, the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in multiple time periods within the current time window may also be obtained respectively, and the node weights of the nodes included in each associated subgraph in multiple time periods are determined based on the indicator abnormality degree values.
[0041] After determining the node weights, the current subgraph abnormality degree values of each associated subgraph can be determined based on the node weights and the edge weights. In different embodiments, the specific methods for determining the current subgraph abnormality degree values may be different. In the above embodiment of determining the node weights of the nodes included in each associated subgraph in multiple time periods, the multiple time period abnormality degree values corresponding to each associated subgraph in the multiple time periods can be determined based on the edge weights of the edges included in each associated subgraph and the node weights of the included nodes in the multiple time periods; the current subgraph abnormality degree values of each associated subgraph can be determined based on the multiple time period abnormality degree values corresponding to each associated subgraph in the multiple time periods. In a specific embodiment, the current subgraph abnormality degree values of each associated subgraph can be determined based on the weighted average of the multiple time period abnormality degree values corresponding to each associated subgraph in the multiple time periods. In the above manner, the current subgraph abnormality degree can be determined more accurately.
[0042] In another embodiment, for a first subgraph included in the multiple associated subgraphs, the current subgraph abnormality level of the first subgraph can be determined based on the sum of the associated abnormality values of all nodes included in the first subgraph, wherein the associated abnormality value is determined based on the weight of the node and the sum of the products of the edge weights of all edges connected to the node. In this way, the current subgraph abnormality level can be further measured in a convenient manner.
[0043] In a specific embodiment, the subgraph abnormality degree value can also be expressed as the following formula:
[0044]
[0045] in,
[0046] S ti =∑ v∈V , e∈E n v·e -de (4)
[0047] Among them, W represents the abnormality value of the subgraph, S t represents the abnormality degree value of the time period ti, v represents the subgraph node, V represents the subgraph node set, e represents the edge of the subgraph, V represents the edge set of the subgraph, n v represents the node weight, de represents the edge weight, l represents the number of time periods, and i represents the time period sequence number.
[0048] After determining the current subgraph abnormality level value, it can be determined whether to issue an alarm corresponding to each associated subgraph according to the subgraph abnormality level value. In different embodiments, the specific method of determining whether to issue an alarm corresponding to each associated subgraph according to the current subgraph abnormality level value may be different. In one embodiment, the second threshold corresponding to each subgraph can be determined according to the historical subgraph abnormality level value of each associated subgraph, and whether to issue an alarm corresponding to each associated subgraph can be determined according to whether the current subgraph abnormality level value of each subgraph exceeds the second threshold. In a specific embodiment, the second threshold can be determined in the following manner: fitting a second exponential function corresponding to each subgraph according to the historical subgraph abnormality level value of each associated subgraph; setting the second function value corresponding to each subgraph, and determining the second threshold corresponding to each subgraph according to the second function value and the second exponential function. By determining the second threshold by fitting the function, the second threshold can be determined according to the actual distribution of the subgraph abnormality level values in history, so that an alarm can be issued more accurately based on the second threshold.
[0049] In a specific embodiment, the fitted second exponential function can be expressed as: F(x)=e a-bx , where F(x) represents the distribution probability of the subgraph abnormality value, a and b are calculation coefficients, x is the subgraph abnormality value, and e is a natural constant.
[0050] Figure 6 A schematic block diagram of a multi-index joint alarm device according to an embodiment of the present disclosure is shown. The device is used to perform the following Figure 3 As shown in the method. Figure 6 As shown, the apparatus 600 includes:
[0051] The graph generating unit 601 is configured to construct an indicator association graph based on historical alarm data corresponding to a plurality of indicators, wherein the indicator association graph includes a plurality of nodes and edges between the nodes, wherein the plurality of nodes correspond to the plurality of indicators respectively, and the edges are determined based on whether the indicators corresponding to the connected nodes all have alarms in a predetermined historical time interval, and the edge weights of the edges represent a joint information entropy determined based on the number of alarms of the indicators corresponding to the connected nodes in the historical time interval; determine a first threshold value based on the data distribution of the edge weights of the edges included in the indicator association graph, and delete edges in the indicator association graph having edge weights greater than the first threshold value to obtain a plurality of association subgraphs;
[0052] The alarm unit 602 is configured to respectively obtain the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in the current time window, and determine the node weights of the nodes included in each associated subgraph based on the indicator abnormality degree values; determine the current subgraph abnormality degree values of each associated subgraph based on the node weights and the edge weights, and determine whether to issue an alarm corresponding to each associated subgraph based on the current subgraph abnormality degree values.
[0053] The embodiment of the present disclosure also provides an electronic device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the following is achieved: Figure 3 The method shown.
[0054] You can also refer to the following Figure 7 , which shows a structural diagram of an electronic device 700 suitable for implementing the embodiments of the present application. Figure 7 The electronic device 700 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.
[0055] like Figure 7As shown, the electronic device 700 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 701. The above-mentioned processing device 701 can be a general-purpose processor, a digital signal processor (DSP), a microprocessor or a microcontroller, and may further include an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. In RAM 703, various programs and data required for the operation of the electronic device 700 are also stored. The processing device 701, ROM 702 and RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0056] Typically, the following devices may be connected to the I / O interface 705: an input device 706 including, for example, a touch screen, a touchpad, a keyboard, a mouse, etc.; an output device 707 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 708 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 709. The communication device 709 may allow the electronic device 700 to communicate with other devices wirelessly or by wire to exchange data. Figure 7 The electronic device 700 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 7 Each block shown in the figure may represent one device, or may represent multiple devices as needed.
[0057] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 709, or installed from the storage device 708, or installed from the ROM 702. When the computer program is executed by the processing device 701, the above-mentioned functions defined in the multi-indicator joint alarm method provided in the embodiment of the present application are executed.
[0058] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed in a computer, the computer is caused to execute the following steps provided in the present disclosure: Figure 3 A multi-indicator joint alarm method is shown in . Figure 8 A schematic diagram of a storage medium for implementing an embodiment of the present application. Figure 8 As shown, the storage medium 800 can be a non-transitory computer-readable storage medium for storing non-transitory computer-executable instructions 801. When the non-transitory computer-executable instructions 801 are executed by the processor, a multi-indicator joint alarm method provided in an embodiment of the present application can be implemented. For example, when the non-transitory computer-executable instructions 801 are executed by the processor, one or more steps in a multi-indicator joint alarm method provided in an embodiment of the present application can be executed. For example, the storage medium 800 can be applied to the above-mentioned electronic device. For example, the storage medium 800 may include a memory in the electronic device. For the description of the storage medium 800, reference can be made to the description of the memory in the embodiment of the electronic device, and the repeated parts will not be repeated here. The specific functions and technical effects of the storage medium 800 can be referred to the description of a multi-indicator joint alarm method provided in an embodiment of the present application, and will not be repeated here.
[0059] It should be noted that the computer-readable medium of the embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a memory card of a smart phone, a storage component of a tablet computer, a portable computer disk, a hard disk of a personal computer, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or device. In the embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries a computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0060] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more programs, and when the one or more programs are executed by the server, the electronic device implements a multi-indicator joint alarm method provided in an embodiment of the present application.
[0061] Computer program code for performing the operations of the embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0062] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of the systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram may represent a module, program segment, or portion of code, which contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the boxes may occur in an order different from that marked in the accompanying drawings. For example, two boxes shown in succession may actually be executed substantially in parallel, or they may sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, as well as the combination of boxes in the block diagram and / or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or may be implemented using a combination of dedicated hardware and computer instructions. The units involved in the embodiments described in the present disclosure may be implemented using software or hardware. The name of the unit does not, in some cases, constitute a limitation on the unit itself. The functions described above in this document may be performed at least in part by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0063] The various embodiments in this specification are described in a progressive manner. Similar portions between the various embodiments can be referenced to each other, and each embodiment focuses on the differences between the other embodiments. In particular, the storage medium and computing device embodiments are described briefly because they are generally similar to the method embodiments. For relevant portions, refer to the description of the method embodiments.
[0064] The above description is only a preferred embodiment of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned disclosed concepts. For example, the above-mentioned features are replaced with (but not limited to) technical features with similar functions disclosed in the present disclosure to form a technical solution. In addition, although the operations are described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination.
[0065] The above specific implementation methods further describe in detail the purpose, technical solutions and beneficial effects of the embodiments of the present invention. Although the subject matter has been described in a language specific to structural features and / or method logical actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims. It should be understood that the above are only specific implementation methods of the embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made on the basis of the technical solution of the present invention should be included in the scope of protection of the present invention.
Claims
1. A multi-index joint alarm method, comprising: Based on historical alarm data corresponding to multiple indicators, an indicator association graph is constructed, wherein the indicator association graph includes multiple nodes and edges between the nodes, the multiple nodes respectively corresponding to the multiple indicators, the edges are determined based on whether there are alarms between the indicators corresponding to the connected nodes in a predetermined historical time interval, and the edge weights of the edges indicate a joint information entropy determined based on the number of alarms of the indicators corresponding to the connected nodes in the historical time interval; based on the data distribution of the edge weights of the edges included in the indicator association graph, a first threshold is determined, and edges in the indicator association graph having edge weights greater than the first threshold are deleted to obtain multiple association subgraphs; Obtain the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in the current time window respectively, and determine the node weights of the nodes included in each associated subgraph based on the indicator abnormality degree values; determine the current subgraph abnormality degree values of each associated subgraph based on the node weights and the edge weights, and determine whether to issue alarms corresponding to each associated subgraph based on the current subgraph abnormality degree values.
2. The method according to claim 1, wherein Determining a first threshold according to data distribution of edge weights of edges included in the indicator association graph includes: fitting a first exponential function according to the data distribution of edge weights of edges included in the indicator association graph; A first function value is set, and a first threshold is determined according to the first function value and a first exponential function.
3. The method according to claim 1, wherein Determining whether to issue alarms corresponding to respective associated subgraphs according to the current subgraph abnormality level value includes: According to the historical subgraph abnormality degree values of each associated subgraph, the second threshold value corresponding to each subgraph is determined, and according to whether the current subgraph abnormality degree value of each subgraph exceeds the second threshold value, it is determined whether to issue an alarm corresponding to each associated subgraph.
4. The method according to claim 3, wherein: Determining, based on the historical subgraph abnormality degree values of the associated subgraphs, second thresholds corresponding to the subgraphs, respectively, includes: According to the historical subgraph abnormality degree values of each associated subgraph, fitting the second exponential function corresponding to each subgraph; A second function value corresponding to each subgraph is set, and a second threshold corresponding to each subgraph is determined according to the second function value and a second exponential function.
5. The method according to claim 1, wherein Obtaining the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in the current time window respectively, and determining the node weights of the nodes included in each associated subgraph according to the indicator abnormality degree values, including: Obtaining indicator abnormality values of indicators corresponding to nodes included in each associated subgraph in multiple time periods within the current time window, and determining node weights of the nodes included in each associated subgraph in the multiple time periods according to the indicator abnormality values; Determining the current subgraph abnormality value of each associated subgraph according to the node weight and the edge weight includes: Determine, based on the edge weights of the edges included in each associated subgraph and the node weights of the nodes included in the multiple time periods, the multiple time period abnormality degree values corresponding to each associated subgraph in the multiple time periods; According to the multiple time period abnormality degree values corresponding to the multiple time periods of each associated subgraph, the current subgraph abnormality degree value of each associated subgraph is determined.
6. The method according to claim 5, wherein: Determining the current subgraph abnormality value of each associated subgraph according to the multiple time period abnormality values corresponding to each associated subgraph in the multiple time periods includes: The current sub-graph abnormality value of each associated sub-graph is determined according to a weighted average of the abnormality values of multiple time periods corresponding to each associated sub-graph in the multiple time periods.
7. The method according to claim 1, wherein Determining the current subgraph abnormality value of each associated subgraph according to the node weight and the edge weight includes: For a first subgraph included in the multiple associated subgraphs, determine the current subgraph anomaly degree value of the first subgraph based on the sum of the associated anomaly values of all nodes included in the first subgraph, wherein the associated anomaly value is determined based on the weight of the node and the sum of the products of the edge weights of all edges connected to the node.
8. A multi-indicator joint alarm device, comprising: The graph generating unit is configured to construct an indicator association graph based on historical alarm data corresponding to a plurality of indicators, wherein the indicator association graph includes a plurality of nodes and edges between the nodes, the plurality of nodes respectively corresponding to the plurality of indicators, the edges being determined based on whether there are alarms between the indicators corresponding to the connected nodes in a predetermined historical time interval, and the edge weights of the edges indicating a joint information entropy determined based on the number of alarms of the indicators corresponding to the connected nodes in the historical time interval; determining a first threshold value based on a data distribution of the edge weights of the edges included in the indicator association graph, deleting edges in the indicator association graph having edge weights greater than the first threshold value, and obtaining a plurality of association subgraphs; The alarm unit is configured to respectively obtain the indicator abnormality degree values of the indicators corresponding to the nodes included in each associated subgraph in the current time window, and determine the node weights of the nodes included in each associated subgraph based on the indicator abnormality degree values; determine the current subgraph abnormality degree values of each associated subgraph based on the node weights and the edge weights, and determine whether to issue alarms corresponding to each associated subgraph based on the current subgraph abnormality degree values.
9. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method according to any one of claims 1 to 7.
10. An electronic device comprising a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method according to any one of claims 1 to 7 is implemented.