System monitoring method and related device
By conducting preliminary statistics on the transaction feature data of the third-party system and adjusting the dynamic alarm threshold, combined with the LSTM algorithm to optimize the alarm rules, the problems of low monitoring efficiency and frequent false alarms in the existing technology are solved, and efficient and accurate system monitoring is achieved.
Patent Information
- Application Number
- CN202511025958.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-10-17
AI Technical Summary
Existing technologies are unable to efficiently and accurately monitor the status of a large number of third-party systems, resulting in high labor costs and frequent false alarms, and are unable to meet the monitoring needs of Internet systems.
By regularly acquiring transaction feature data from third-party systems, performing preliminary statistical processing, adjusting alarm thresholds based on dynamic alarm threshold update strategies, and optimizing alarm rules with the LSTM algorithm, accurate determination of system alarm information can be achieved.
It achieves real-time and efficient monitoring of third-party systems, reduces false alarm information, reduces monitoring costs, and improves the effectiveness and accuracy of alarms.
Smart Images

Figure CN120803858A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and particularly relates to a system monitoring method and related device. BACKGROUND
[0002] For a financial Internet system which needs to interact with a large number of third-party systems, monitoring the system state is the key to ensuring the normal operation of the system. As the number of third-party systems continues to increase with the expansion of Internet business, higher requirements are put forward for the monitoring system of the Internet. At the same time, due to the limitation of labor cost, it is often impossible to invest all the limited manpower into system monitoring. Therefore, how to realize efficient and accurate monitoring of the system state has become a problem to be solved. SUMMARY
[0003] In view of the above problems, the present application provides a system monitoring method and related device to realize the purpose of improving monitoring efficiency and reducing manual work. The specific scheme is as follows:
[0004] The first aspect of the present application provides a system monitoring method, comprising:
[0005] acquiring transaction feature data of a third-party system at a regular time;
[0006] performing preliminary statistical processing on the transaction feature data to obtain statistical data of an alarm element;
[0007] processing the corresponding statistical data based on each alarm threshold update rule indicated by an alarm threshold update strategy to obtain an alarm threshold of each alarm element;
[0008] determining system alarm information based on a comparison result of the current statistical data of each alarm element and the corresponding alarm threshold.
[0009] In a possible implementation, the alarm element includes a transaction volume, the statistical data of the transaction volume includes an average transaction volume in the same collection period within a first statistical duration, and processing the corresponding statistical data based on each alarm threshold update rule indicated by the alarm threshold update strategy to obtain an alarm threshold of each alarm element includes:
[0010] multiplying each average transaction volume and a corresponding weight coefficient to obtain an adjustment value of each average transaction volume;
[0011] Superimpose each of the adjustment values to obtain a transaction volume alarm threshold, the sum of all weight coefficients is greater than 1 and less than the first coefficient value, two adjacent average transaction volumes in time, the first weight coefficient is less than the second weight coefficient, the first weight coefficient corresponds to the first average transaction volume, the second weight coefficient corresponds to the second average transaction volume, and the first average transaction volume is earlier than the second average transaction volume.
[0012] In a possible implementation, the alarm elements include a success rate, the statistical data of the success rate includes an average transaction success rate in a second statistical duration, each alarm threshold updating rule indicated by the alarm threshold updating strategy processes corresponding statistical data to obtain an alarm threshold of each of the alarm elements, and the alarm threshold of each of the alarm elements includes:
[0013] According to a success rate interval range in which the average transaction success rate is located, a success rate adjustment value is determined;
[0014] The average transaction success rate is subtracted by the success rate adjustment value to obtain a success rate alarm threshold.
[0015] In a possible implementation, the alarm elements include a response time, the statistical data of the response time includes an average response time in a third statistical duration, each alarm threshold updating rule indicated by the alarm threshold updating strategy processes corresponding statistical data to obtain an alarm threshold of each of the alarm elements, and the alarm threshold of each of the alarm elements includes:
[0016] The average response time is multiplied by a loose coefficient to obtain a response loose value;
[0017] The smaller of the response loose value and a response fixed value is taken as a response time alarm threshold.
[0018] In a possible implementation, the system monitoring method further includes:
[0019] The system performance indicators of the third-party system are monitored, and when an increase rate of the system performance indicators exceeds an increase rate threshold, it is determined whether a transaction growth amount of the third-party system exceeds a growth amount threshold;
[0020] When it is determined that the transaction growth amount exceeds the growth amount threshold, corresponding alarm information is sent.
[0021] In a possible implementation, the comparison result of the current statistical data of each of the alarm elements and the corresponding alarm threshold determines system alarm information, and the system alarm information includes:
[0022] If the current transaction volume exceeds the transaction volume alarm threshold and the current transaction success rate is lower than the success rate alarm threshold, or if the current transaction volume exceeds the transaction volume alarm threshold and the current transaction response time exceeds the response time alarm threshold, the system alarm information is determined.
[0023] In a possible implementation, the transaction feature data includes a result identifier of success or failure of each transaction, a transaction start time and a transaction end time, the preliminary statistical processing of the transaction feature data includes obtaining statistical data of alarm elements, and the preliminary statistical processing includes:
[0024] determining transaction volume statistical data based on the total number of the result identifiers;
[0025] determining response time statistical data based on the transaction start time and the transaction end time;
[0026] determining success rate statistical data based on the total number of the result identifiers and the number of the result identifiers representing transaction success.
[0027] The second aspect of the present application provides a system monitoring device, including:
[0028] a feature data acquisition module configured to acquire transaction feature data of a third-party system at a regular time;
[0029] a feature data statistical module configured to perform preliminary statistical processing on the transaction feature data to obtain statistical data of alarm elements;
[0030] an alarm threshold updating module configured to perform processing on corresponding statistical data based on each alarm threshold updating rule indicated by an alarm threshold updating strategy to obtain an alarm threshold of each of the alarm elements; and
[0031] an alarm information determination module configured to determine system alarm information based on a comparison result of current statistical data of each of the alarm elements and a corresponding alarm threshold.
[0032] The third aspect of the present application provides a computer program product, including computer readable instructions, when the computer readable instructions run on an electronic device, the electronic device implements the system monitoring method of the first aspect or any implementation manner of the first aspect.
[0033] The fourth aspect of the present application provides an electronic device, including at least one processor and a memory connected with the processor, wherein:
[0034] the memory is configured to store a computer program;
[0035] The processor is configured to execute the computer program to enable the electronic device to implement the system monitoring method of the first aspect or any implementation manner of the first aspect.
[0036] The fifth aspect of the present application provides a computer storage medium, which carries one or more computer programs, and when the one or more computer programs are executed by an electronic device, the electronic device can implement the system monitoring method of the first aspect or any implementation manner of the first aspect.
[0037] Through the above technical solution, the system monitoring method provided by the present application acquires the transaction feature data of the third-party system in a timely manner. Through preliminary statistical processing of the transaction feature data, the statistical data of the alarm elements is obtained. Then, based on each alarm threshold updating rule indicated by the alarm threshold updating strategy, the corresponding statistical data is processed to obtain the alarm threshold of each alarm element. Finally, based on the comparison result of the current statistical data of each alarm element and the corresponding updated alarm threshold, the system alarm information is determined. Through real-time monitoring of the third-party system, the system monitoring method dynamically adjusts the alarm threshold with the change of the transaction information, without manual intervention, so that the alarm accuracy is significantly improved, and the system monitoring cost is significantly reduced. At the same time, the number of invalid and false alarm information can be effectively reduced, and the effectiveness of the alarm is effectively improved. BRIEF DESCRIPTION OF DRAWINGS
[0038] The above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the original and elements are not necessarily drawn according to the scale.
[0039] Figure 1 An architecture diagram of a system monitoring system provided by the present application;
[0040] Figure 2 A flowchart of a system monitoring method provided by the present application;
[0041] Figure 3 A program fragment of transaction data collection provided by the present application;
[0042] Figure 4 A program fragment of alarm threshold updating based on a long short-term memory network provided by the present application;
[0043] Figure 5 A structure diagram of a system monitoring device provided by the present application;
[0044] Figure 6 A structure diagram of an electronic device provided by the present application. DETAILED DESCRIPTION
[0045] The following describes the embodiments of the present application in conjunction with the accompanying drawings. The terms used in the implementation methods of the present application are only used to explain the specific embodiments of the present application and are not intended to limit the present application.
[0046] The embodiments of the present application are described below in conjunction with the accompanying drawings. Those skilled in the art will appreciate that, with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0047] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0048] See also Figure 1 , Figure 1 FIG2 shows a schematic diagram of the architecture of a system monitoring system, which may include a terminal 100 and a third-party system 200 .
[0049] Among them, a system monitoring application can be installed on the terminal 100. The above application and web page can provide an interface. The terminal 100 can receive relevant parameters input by the user on the system monitoring interface and monitor transactions of the third-party system 200 based on the parameters.
[0050] Next describe Figure 1 The product form of the mid-terminal 100;
[0051] The terminal 100 in the embodiment of the present application may be a mobile phone, a tablet computer, a laptop computer, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), etc., and the embodiment of the present application does not impose any limitation on this.
[0052] The terminal 100 can include a radio frequency unit, a memory, an input unit, a display unit, a camera (optional), an audio circuit (optional), a speaker (optional), a microphone (optional), a headphone jack (optional), a processor, an external interface, a power supply, and the like. It will be understood by those skilled in the art that the above components are merely examples and do not constitute a limitation on the terminal or the multifunctional device, and more or fewer components can be included, or some components can be combined or different components can be included.
[0053] The input unit can be used to receive inputted digital or character information, and to generate key signal input related to user settings and function control of the portable multifunctional device. Specifically, the input unit can include a touch screen (optional) and / or other input devices. Specifically, the other input devices can include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control buttons, on / off buttons, and the like), trackballs, mice, joysticks, and the like.
[0054] The input device can receive inputted data and the like.
[0055] The display unit can be used to display information inputted by a user or information provided to a user, various menus of the terminal, an interactive interface, file display, and / or playing of any kind of multimedia file. In the embodiments of the present application, the display unit can be used to display an interface of system monitoring, processing results, and the like.
[0056] The memory can be used to store software codes related to the system monitoring method, and the processor can execute the steps of the system monitoring method, and can also dispatch other units (such as the input unit and the display unit) to realize corresponding functions.
[0057] The radio frequency unit (optional) can be used to receive and send signals in the process of receiving or transmitting information or calls.
[0058] In the embodiments of the present application, the radio frequency unit can receive data of the third party system 200.
[0059] It should be understood that the radio frequency unit is optional, and can be replaced by other communication interfaces, for example, can be a network interface.
[0060] The terminal 100 further includes a power supply (such as a battery) for supplying power to each component.
[0061] The terminal 100 further includes an external interface, which can be a standard Micro USB interface, or can be a multi-pin connector, and can be used to connect the terminal 100 with other devices for communication, or can be used to connect a charger to charge the terminal 100.
[0062] Currently, there are two main monitoring methods for complex Internet systems: white list monitoring method and general monitoring method.
[0063] White list monitoring method: screening out third-party systems with large transaction volume, high sensitivity, and involving core business scenarios, configuring alarm rules one by one, using white list management mechanism, and manually adding, adjusting, and deleting alarm rules.
[0064] General monitoring method: configuring uniform alarm rules for all systems, and constantly adjusting alarm thresholds according to business development.
[0065] The white list monitoring method requires manual maintenance of alarm rules, which increases labor costs and cannot monitor systems outside the white list in real time, with limited monitoring range. The difficulty of general monitoring lies in setting appropriate alarm thresholds: due to the uneven quality of massive third-party system services, if the threshold is set strictly, a large number of false alarms will be generated; if the threshold is set loosely, timely and effective monitoring cannot be achieved; even if the threshold is set reasonably, the accuracy of monitoring is greatly reduced. In addition, adaptive monitoring algorithms based on ARIMA, neural networks, etc. have large computational complexity and are mainly applied to single system monitoring, with poor applicability in multi-system monitoring scenarios.
[0066] To solve the above problems, the embodiment of the present application provides a system monitoring method. The system monitoring method of the embodiment of the present application will be described in detail below with reference to the accompanying drawings.
[0067] Referring to Figure 2 , Figure 2 The flow of the system monitoring method provided by the embodiment of the present application is shown in Figure 2 The system monitoring method provided by the embodiment of the present application can include steps 201 to 204, which will be described in detail below.
[0068] 201, acquire transaction feature data of the third-party system regularly.
[0069] Specifically, the acquisition of transaction feature data between the third-party system can refer to the program fragment shown in Figure 3 The aspect dependency can be introduced in the pom file:
[0070] <dependency>
[0071] <groupid>org.springframeWork.boot< / groupid>
[0072] <artifactid>spring-boot-starter-aop< / artifactid>
[0073] < / dependency>
[0074] The system number, transaction area, transaction success flag, transaction start time, and transaction end time are acquired through the aspect method.
[0075] Where, @Aspect is the annotation of AspectJ framework (Spring AOP underlying dependency to achieve), declare this is a "aspect", to encapsulate the general logic (such as here the log collection), can be applied to multiple target methods. @Component is the Spring annotation, give the class to the Spring container management, let the aspect can be normally loaded, executed.
[0076] The expression in @Pointcut is the AspectJ pointcut expression, to accurately match the method to be intercepted, that is, specify which business method executes, will enter the logic of this aspect.
[0077] joinPoint.proceed(args) is the key to trigger the target method to execute, which is equivalent to let the originally executed business method (such as the method of a certain service) run here. If the args (input parameter) is modified, it will also be brought into the modified value.
[0078] try-catch: wrap proceed, capture the exception when the target method executes. If the method runs normally, successFlag = "Y" (mark "transaction success"); if the exception is thrown, go to catch, record the error log, and successFlag = "N" (mark "transaction failure").
[0079] Finally, through the pre-acquisition of systemId (system number), areaName (transaction area), the successFlag (success / failure mark) obtained after execution, and the calculated time-consuming (endTime - startTime), spell into a JSON format string, output through watchLogger.info.
[0080] It can be understood that the skilled in the art can also use other ways to obtain transaction characteristic data, which will not be described here.
[0081] 202, the transaction characteristic data is preliminarily statistically processed to obtain the statistical data of the alarm element.
[0082] Specifically, on the basis of the preliminary transaction characteristic data, each transaction characteristic data needs to be processed correspondingly, and then the statistical data of the alarm elements are obtained. The alarm elements can include: transaction volume, success rate, response time, etc. For example, the statistical data of the transaction volume can be determined based on the total number of result identifiers, i.e., the transaction volume is obtained by counting the number of result identifiers. Based on the transaction start time and the transaction end time, the statistical data of the response time of each transaction is determined. Based on the total number of result identifiers and the number of result identifiers representing transaction success, the statistical data of the success rate is determined.
[0083] Each of the above statistical data can be statistical data within a statistical period (such as one hour, one day, etc.). The specific statistical length of the statistical data can be adjusted and selected by those skilled in the art according to the needs of the statistics, which is not limited here.
[0084] 203, based on the alarm threshold update strategy indicated by each alarm threshold update rule, the corresponding statistical data is processed to obtain the alarm threshold of each alarm element.
[0085] Specifically, taking the alarm elements including: transaction volume, success rate and response time as an example:
[0086] The statistical data of the transaction volume includes: the average transaction volume in the same collection period within the first statistical length, and the determination process of the transaction volume alarm threshold includes:
[0087] Each average transaction volume is multiplied by the corresponding weight coefficient to obtain an adjustment value of each average transaction volume.
[0088] Each adjustment value is superimposed to obtain the transaction volume alarm threshold, the sum of all weight coefficients is greater than 1 and less than the first coefficient value, the first weight coefficient is less than the second weight coefficient, the first weight coefficient corresponds to the first average transaction volume, the second weight coefficient corresponds to the second average transaction volume, and the first average transaction volume is earlier than the second average transaction volume.
[0089] For example, the collection frequency of the transaction characteristic data of system A is 1 hour once, and the transaction volume of system A at time t is monitored. Considering that t is in the kth hour, the average transaction volume of the same period k in the last i days is C tk-1 , C tk-2 ...C tk-i , the alarm threshold update rule is:
[0090]
[0091] is a weight coefficient, generally speaking, the closer the time, the greater the weight, considering the transaction periodicity, the weight coefficient of the same period of week, month and year can be increased as appropriate, s1 is a transaction volume threshold relaxation coefficient, it is recommended that the value of s1 be set to 1.3 or more to avoid frequent false alarms.
[0092] The statistical data of the success rate includes: the average transaction success rate in the second statistical duration, and the determination process of the success rate alarm threshold, including:
[0093] According to the success rate interval range in which the average transaction success rate is located, a success rate adjustment value is determined. The average transaction success rate is subtracted by the success rate adjustment value to obtain the success rate alarm threshold.
[0094] For example, the average transaction success rate R of system A in the past week is calculated A-avg The alarm threshold updating rule is:
[0095]
[0096] Wherein, R A-new represents the success rate alarm threshold obtained at the current time.
[0097] The statistical data of the response time includes: the average response time in the third statistical duration, and the determination process of the response time alarm threshold, including:
[0098] The average response time is multiplied by the relaxation coefficient to obtain a response relaxation value. The smaller of the response relaxation value and the response fixed value is taken as the response time alarm threshold.
[0099] For example, the average response time T of system A in the past week is calculated A-avg The alarm threshold updating rule is:
[0100]
[0101] Wherein, s2 is the average response time threshold relaxation coefficient, usually s2 is set to 1.3 or more to avoid frequent false alarms.
[0102] It can be understood that those skilled in the art can adjust the reference standard of each alarm threshold as needed, which will not be repeated here.
[0103] 204, based on the comparison result of the current statistical data of each alarm element and the corresponding alarm threshold, the system alarm information is determined.
[0104] Specifically, for example, if the current transaction volume exceeds the transaction volume alarm threshold and the current transaction success rate is lower than the success rate alarm threshold, or if the current transaction volume exceeds the transaction volume alarm threshold and the current transaction response time exceeds the response time alarm threshold, the system alarm information is determined.
[0105] For example, if the transaction volume of any system B exceeds C kn-new and the success rate is lower than R kn-new or the response time is higher than T kn-new , the adaptive alarm information is allowed to be sent to the third-party system through alarm filtering rule verification. Wherein C kn-new , R kn-new , T kn-new represent the alarm filtering rule update threshold in the time range [k-1, k).
[0106] The system monitoring method can monitor a large number of third-party systems in real time, and the alarm parameters are adaptively adjusted with business data without manual intervention, so that the monitoring accuracy is significantly increased and the monitoring cost is significantly reduced. The present application avoids a large number of invalid false alarms by setting alarm filtering rules and alarm bottom rules, reduces the harassment of associated parties, and greatly improves the alarm effectiveness.
[0107] In some embodiments, to achieve more accurate and reliable monitoring of the third-party system and timely detection of abnormal conditions of the system, the system performance indicators of the third-party system are monitored, and when the rising rate of the system performance indicators exceeds the rising rate threshold, it is determined whether the transaction growth of the third-party system exceeds the growth threshold. And when it is determined that the transaction growth exceeds the growth threshold, the corresponding alarm information is sent.
[0108] Specifically, by conducting stress testing on the third-party Internet system, when any indicator such as CPU, memory, IO, etc. of the system rises by 3%, the increased transaction volume C max is taken as the alarm bottom threshold. If the transaction volume of any system exceeds C max , the alarm information is immediately sent to the Internet system operation and maintenance personnel through the alarm bottom rule verification, and the emergency disposal work is carried out through automatic flow limiting means to avoid the impact on normal transactions.
[0109] In other embodiments, to realize reliable and accurate updating of each alarm threshold described above, the threshold updating process of step 203 can be realized by LSTM (Long Short-Term Memory, Long Short-Term Memory Network) during execution. Referring to Figure 4 , for the average transaction volume, average transaction success rate, and average response time data of a plurality of third-party systems in the past X days, based on the LSTM algorithm, the transaction volume filtering threshold C kn-new (k=0, 1..., 23), the transaction success rate filtering threshold R kn-new (k=0, 1..., 23), and the average response time filtering threshold T kn-new。
[0110] Wherein,Figure 4 The process of the LSTM model from data preprocessing, model construction, model training, and model prediction is recorded in the code shown in the middle:
[0111] In the data and processing stage: initializing the normalizer, mapping the data to the [0, 1] interval, which helps to improve the model training effect. Normalize the transaction volume data, first fit the data distribution and then convert. Adjust the dimension to [sequence length, batch size, input feature number]. Realize cleaning and converting the original data to adapt to the model input requirements.
[0112] In the model construction stage: determine the network layer composition (LSTM layer + linear layer) and the forward propagation method of data in the model, so that the model can learn the sequence data rule.
[0113] In the model training stage: through multiple iterations, use the training data to let the model learn the data rule. In each iteration, take the input-target pair, calculate the loss through forward propagation, calculate the gradient through back propagation, and update the parameters through the optimizer, gradually reducing the prediction error.
[0114] In the model prediction stage: first set the model to evaluation mode and close the gradient calculation. Starting from the end of the training data, roll forward to predict multiple steps, and finally inverse normalize the prediction results to the original data order to facilitate interpretation.
[0115] In specific use, the above various statistical data of the third-party system can be input into the trained model to update the various alarm thresholds.
[0116] As a specific application of the above embodiment, the statistical results of the various statistical data of the multiple systems are shown in the following table:
[0117]
[0118] The following table shows the various alarm thresholds of the third-party system with system identification 1:
[0119]
[0120] The following table shows the alarm thresholds of multiple third-party systems processed by the LSTM model:
[0121]
[0122] The system monitoring method does not need manual configuration of alarm rules, is simple and more accurate in calculation, effectively avoids false alarms caused by occasional abnormalities of third-party systems based on the LSTM algorithm combined with alarm filtering rules, and greatly improves the effectiveness of alarms. The performance of abnormal third-party systems that may affect the normal operation of the system is monitored, and automatic flow limiting and other means are taken to avoid risks and ensure the smooth operation of the system.
[0123] The above introduces a system monitoring method provided by the embodiment of the application, and the following introduces a device for executing the system monitoring method.
[0124] Please refer to Figure 5 , Figure 5 The structure diagram of a system monitoring device provided by the embodiment of the application. As shown in Figure 5 , the system monitoring device comprises:
[0125] The feature data acquisition module 501 is configured to acquire transaction feature data of the third-party system regularly.
[0126] The feature data statistical module 502 is configured to perform preliminary statistical processing on the transaction feature data to obtain statistical data of alarm elements.
[0127] The alarm threshold updating module 503 is configured to process the corresponding statistical data based on each alarm threshold updating rule indicated by the alarm threshold updating strategy to obtain the alarm threshold of each alarm element. And,
[0128] The alarm information determination module 504 is configured to determine the system alarm information based on the comparison result of the current statistical data of each alarm element and the corresponding alarm threshold.
[0129] In a possible implementation, the alarm elements include transaction volume, the statistical data of the transaction volume includes average transaction volume in the same collection period within the first statistical duration, and the process in which the alarm threshold updating module 503 processes the corresponding statistical data based on each alarm threshold updating rule indicated by the alarm threshold updating strategy to obtain the alarm threshold of each alarm element includes:
[0130] Each average transaction volume is multiplied by the corresponding weight coefficient to obtain an adjustment value of each average transaction volume.
[0131] The adjustment values are superimposed to obtain the transaction volume alarm threshold, the sum of all weight coefficients is greater than 1 and less than the first coefficient value, the first weight coefficient is less than the second weight coefficient, the first weight coefficient corresponds to the first average transaction volume, the second weight coefficient corresponds to the second average transaction volume, and the first average transaction volume is earlier than the second average transaction volume.
[0132] In a possible implementation, the alarm element includes a success rate, the statistical data of the success rate includes an average transaction success rate in a second statistical duration, and the process of obtaining the alarm threshold of each alarm element by the alarm threshold updating module 503 based on each alarm threshold updating rule indicated by the alarm threshold updating strategy and processing the corresponding statistical data includes:
[0133] determining a success rate adjustment value according to the success rate interval range in which the average transaction success rate is located;
[0134] subtracting the success rate adjustment value from the average transaction success rate to obtain the success rate alarm threshold.
[0135] In a possible implementation, the alarm element includes a response time, the statistical data of the response time includes an average response time in a third statistical duration, and the process of obtaining the alarm threshold of each alarm element by the alarm threshold updating module 503 based on each alarm threshold updating rule indicated by the alarm threshold updating strategy and processing the corresponding statistical data includes:
[0136] multiplying the average response time by a loose coefficient to obtain a response loose value;
[0137] taking the smaller one of the response loose value and a response fixed value as the response time alarm threshold.
[0138] In a possible implementation, the system further includes a system performance monitoring module configured to monitor a system performance indicator of the third-party system, and determine whether a transaction growth amount of the third-party system exceeds a growth amount threshold when an upward rate of the system performance indicator exceeds an upward rate threshold.
[0139] When it is determined that the transaction growth amount exceeds the growth amount threshold, the corresponding alarm information is sent.
[0140] In a possible implementation, the process of determining the system alarm information by the alarm information determining module 504 based on a comparison result of the current statistical data of each alarm element and the corresponding alarm threshold includes:
[0141] If the current transaction amount exceeds the transaction amount alarm threshold and the current transaction success rate is lower than the success rate alarm threshold, or if the current transaction amount exceeds the transaction amount alarm threshold and the current transaction response time exceeds the response time alarm threshold, the system alarm information is determined.
[0142] In a possible implementation, the transaction characteristic data includes a result identifier of success or failure of each transaction, a transaction start time and a transaction end time, and the process of performing preliminary statistical processing on the transaction characteristic data by the characteristic data statistical module 502 to obtain the statistical data of the alarm element includes:
[0143] determining the statistical data of the transaction amount based on the total number of the result identifiers.
[0144] Based on the transaction start time and the transaction end time, statistical data of a response time is determined.
[0145] Based on the total number of result identifiers and the number of result identifiers representing a successful transaction, statistical data of a success rate is determined.
[0146] The embodiments of the present application also provide an electronic device. Referring to FIG. 1, Figure 6 which shows a structural schematic diagram suitable for implementing the electronic device in the embodiments of the present application. The electronic device in the embodiments of the present application can include, but is not limited to, a fixed terminal such as a mobile phone, a notebook computer, a PDA (Personal Digital Assistant), a PAD (Tablet Personal Computer), a desktop computer, and the like. Figure 6 The electronic device shown is merely an example, and should not bring any limitation to the functions and use range of the embodiments of the present application.
[0147] As shown in FIG. 2, Figure 6 the electronic device can include a processing device (for example, a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 602 or loaded from a storage device 608 into a random access memory (RAM) 603. In a state where the electronic device is powered on, the RAM 603 also stores various programs and data required for operation of the electronic device. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0148] Generally, the following devices can be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, and the like; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; a storage device 608 including, for example, a memory card, a hard disk, and the like; and a communication device 609. The communication device 609 can allow the electronic device to communicate with other devices wirelessly or by wire to exchange data. Although Figure 6 The electronic device with various devices is shown, but it should be understood that it is not required to implement or have all the shown devices. More or fewer devices can be alternatively implemented or provided.
[0149] The embodiments of the present application also provide a computer program product including computer readable instructions, which, when running on an electronic device, cause the electronic device to implement any one of the system monitoring methods provided by the embodiments of the present application.
[0150] The embodiment of the present application further provides a computer readable storage medium, the storage medium carries one or more computer programs, when the one or more computer programs are executed by an electronic device, the electronic device can realize any system monitoring method provided by the embodiment of the present application.
[0151] In addition, it should be noted that the above-described apparatus embodiments are merely illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment. In addition, the connection relationship between the modules in the apparatus embodiments provided by the present application indicates that there is a communication connection between them, which can be implemented as one or more communication buses or signal lines.
[0152] Through the above description of the embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and necessary general hardware, and of course can also be realized by special hardware including special integrated circuits, special CPUs, special memories, special components, etc. Generally, functions completed by computer programs can be easily realized by corresponding hardware, and the specific hardware structure for realizing the same function can also be various, such as analog circuit, digital circuit or special circuit, etc. However, for the present application, software program implementation is a better embodiment. Based on this understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a readable storage medium, such as a computer floppy disk, U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk, etc., including a plurality of instructions to make a computer device (which can be a personal computer, training device, or network device, etc.) execute the methods described in various embodiments of the present application.
[0153] In the above embodiments, all or part can be realized by software, hardware, firmware or any combination thereof. When realized by software, it can be realized in the form of a computer program product in whole or in part.
[0154] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from one website, computer, training device or data center to another website, computer, training device or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be stored by the computer or a data storage device such as a training device, a data center, etc. integrated with one or more available media sets. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)), etc.
Claims
1. A system monitoring method, characterized in that: include: Regularly obtain transaction feature data from third-party systems; Performing preliminary statistical processing on the transaction characteristic data to obtain statistical data of alarm elements; Processing corresponding statistical data based on each alarm threshold update rule indicated by the alarm threshold update strategy to obtain an alarm threshold for each of the alarm elements; Based on the comparison result of the current statistical data of each alarm element and the corresponding alarm threshold, the system alarm information is determined.
2. The system monitoring method according to claim 1, characterized in that: The alarm element includes: transaction volume, and the statistical data of the transaction volume includes: average transaction volume in the same collection period within the first statistical time period. Each alarm threshold update rule indicated by the alarm threshold update strategy is processed on the corresponding statistical data to obtain the alarm threshold of each alarm element, including: Multiplying each of the average transaction volumes by the corresponding weight coefficient to obtain an adjustment value for each of the average transaction volumes; Each of the adjustment values is superimposed to obtain a trading volume alarm threshold, the sum of all weight coefficients is greater than 1 and less than the first coefficient value, for two temporally adjacent average trading volumes, the first weight coefficient is less than the second weight coefficient, the first weight coefficient corresponds to the first average trading volume, the second weight coefficient corresponds to the second average trading volume, and the first average trading volume is earlier than the second average trading volume.
3. The system monitoring method according to claim 1, wherein: The alarm element includes a success rate, and the statistical data of the success rate includes an average transaction success rate within a second statistical period. Each alarm threshold update rule indicated by the alarm threshold update strategy is processed on the corresponding statistical data to obtain an alarm threshold for each alarm element, including: Determining a success rate adjustment value based on a success rate interval within which the average transaction success rate falls; The success rate adjustment value is subtracted from the average transaction success rate to obtain a success rate alarm threshold.
4. The system monitoring method according to claim 1, wherein: The alarm element includes a response time, and the statistical data of the response time includes an average response time within a third statistical time period. Each alarm threshold update rule indicated by the alarm threshold update policy is processed on the corresponding statistical data to obtain an alarm threshold for each of the alarm elements, including: Multiplying the average response time by a relaxation coefficient to obtain a response relaxation value; The smaller one of the response loose value and the response fixed value is used as the response time alarm threshold.
5. The system monitoring method according to claim 1, wherein: Also includes: monitoring a system performance indicator of the third-party system, and determining whether a transaction growth amount of the third-party system exceeds a growth amount threshold when an increase rate of the system performance indicator exceeds an increase rate threshold; When it is determined that the transaction growth amount exceeds the growth amount threshold, a corresponding alarm message is sent.
6. The system monitoring method according to claim 1, characterized in that: The determining of system alarm information based on a comparison result of the current statistical data of each alarm element with the corresponding alarm threshold includes: If the current transaction volume exceeds the transaction volume alarm threshold and the current transaction success rate is lower than the success rate alarm threshold, or if the current transaction volume exceeds the transaction volume alarm threshold and the current transaction response time exceeds the response time alarm threshold, the system alarm information is determined.
7. The system monitoring method according to any one of claims 1 to 6, characterized in that: The transaction characteristic data includes the result identification of each transaction success or failure, the transaction start time, and the transaction end time. The preliminary statistical processing of the transaction characteristic data to obtain statistical data of alarm elements includes: Determining statistical data of transaction volume based on the total number of result identifiers; Determining statistical data of response time based on the transaction start time and the transaction end time; Based on the total number of result identifiers and the number of result identifiers indicating successful transactions, statistical data of the success rate is determined.
8. A system monitoring device, characterized in that: include: Feature data acquisition module, used to periodically acquire transaction feature data from third-party systems; A feature data statistics module is used to perform preliminary statistical processing on the transaction feature data to obtain statistical data of alarm elements; An alarm threshold updating module is used to process corresponding statistical data based on each alarm threshold updating rule indicated by the alarm threshold updating strategy to obtain an alarm threshold for each of the alarm elements; as well as, The alarm information determination module is used to determine system alarm information based on the comparison result of the current statistical data of each alarm element and the corresponding alarm threshold.
9. An electronic device, characterized in that: comprising at least one processor and a memory connected to the processor, wherein: The memory is used to store computer programs; The processor is configured to execute the computer program so as to enable the electronic device to implement the system monitoring method according to any one of claims 1 to 7.
10. A computer storage medium, characterized in that The storage medium carries one or more computer programs, and when the one or more computer programs are executed by an electronic device, the electronic device can implement the system monitoring method according to any one of claims 1 to 7.