Attribution analysis method and device based on artificial intelligence, computer equipment and medium
By employing an AI-based attribution analysis approach, and utilizing data perception, collection, processing, and interactive intelligent agents combined with a large language model, the inefficiency and inaccuracy of existing root cause analysis methods are addressed. This enables rapid and accurate fault location, thereby improving the operational efficiency and stability of cloud-native systems.
Patent Information
- Application Number
- CN202510808085.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-10-28
Smart Images

Figure CN120851187A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology and can be applied to fields such as fintech and healthcare, particularly to attribution analysis methods, devices, computer equipment, and storage media based on artificial intelligence. Background Technology
[0002] In cloud-native architectures of medium to large enterprises in sectors such as finance and healthcare, system complexity increases significantly, and operations and maintenance face the challenge of correlating massive amounts of heterogeneous data (such as metrics, logs, and tracing data). Existing root cause analysis (RCA) methods heavily rely on manual switching between multiple monitoring systems to view data, which is inefficient and prone to errors. Traditional automated tools, due to insufficient analytical depth, struggle to handle complex and unknown faults, resulting in time-consuming and inaccurate fault localization. These limitations directly threaten the high availability and stability of the system, especially in the financial sector, where they may lead to financial losses or compliance risks.
[0003] Specifically, traditional root cause analysis methods are typically based on static rules or shallow correlation analysis, lacking adaptability to dynamic and complex scenarios. For example, in payment and settlement systems in the financial sector, if transaction delays or decreased success rates occur, traditional methods may attribute the cause solely to a single monitoring metric (such as database CPU utilization) or simple log keyword matching, ignoring the deep dependencies between microservice call chains or the potential impact of external dependencies (such as third-party payment gateways). This analytical approach struggles to accurately pinpoint the root cause; for instance, it might attribute a failure to local database overload when the actual root cause is a timeout in downstream risk control services due to rate limiting from external data sources.
[0004] Similar issues exist in the healthcare field. Taking hospital electronic medical record systems as an example, when slow system response or partial malfunction occurs, traditional RCA methods may only focus on the single indicator of high server memory usage, neglecting the complex interactions between different modules in a microservice architecture. For instance, data transmission anomalies may occur between the image upload module and the medical record storage module, or the impact of external systems such as the stability of medical insurance interfaces on the overall system may be overlooked. Such analytical biases not only prolong fault recovery time but may also lead to ineffective repair operations due to misjudgments, further exacerbating system risks. In a medical setting, this could result in patients not receiving timely diagnostic information, delaying treatment.
[0005] Therefore, there is an urgent need for a root cause analysis technology that can quickly and accurately locate the root cause, thereby improving the operational efficiency and stability of cloud-native systems. Summary of the Invention
[0006] The purpose of this application is to propose an attribution analysis method, apparatus, computer device, and storage medium based on artificial intelligence, so as to solve the technical problems of low efficiency and poor accuracy of existing root cause analysis methods.
[0007] Firstly, an attribution analysis method based on artificial intelligence is provided, including:
[0008] When an alarm notification corresponding to the target system is detected by a preset data-sensing intelligent agent, the data-sensing intelligent agent is used to parse the alarm notification to obtain the corresponding key entity information.
[0009] Based on a preset data acquisition intelligent agent, associated data corresponding to the key entity information is collected;
[0010] Based on a preset data processing intelligent agent, the associated data is fused to obtain a corresponding comprehensive dataset.
[0011] Based on a preset data interaction intelligent agent, a target prompt text corresponding to the comprehensive dataset is constructed;
[0012] Based on a pre-defined large language model, the comprehensive dataset is subjected to association analysis and intelligent reasoning processing according to the target prompt text to generate corresponding root cause analysis results.
[0013] Output the attribution analysis results.
[0014] Secondly, an attribution analysis device based on artificial intelligence is provided, comprising:
[0015] The parsing module is used to parse the alarm notification corresponding to the target system based on the data sensing agent when the alarm notification is detected by the preset data sensing agent to obtain the corresponding key entity information.
[0016] The data acquisition module is used to collect associated data corresponding to the key entity information based on a preset data acquisition intelligent agent;
[0017] The fusion module is used to perform data fusion processing on the associated data based on a preset data processing intelligent agent to obtain a corresponding comprehensive dataset.
[0018] The construction module is used to construct target prompt text corresponding to the comprehensive dataset based on a preset data interaction intelligent agent;
[0019] The processing module is used to perform correlation analysis and intelligent reasoning on the comprehensive dataset based on the preset large language model and the target prompt text, and generate corresponding root cause analysis results.
[0020] The output module is used to output the attribution analysis results.
[0021] Thirdly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described artificial intelligence-based attribution analysis method.
[0022] Fourthly, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the steps of the aforementioned artificial intelligence-based attribution analysis method.
[0023] In the aforementioned scheme implemented by the AI-based attribution analysis method, device, computer equipment, and storage medium, when an alarm notification corresponding to the target system is detected by a preset data-sensing agent, the data-sensing agent first parses the alarm notification to obtain the corresponding key entity information; then, a preset data-acquisition agent collects associated data corresponding to the key entity information; subsequently, a preset data-processing agent performs data fusion processing on the associated data to obtain a corresponding comprehensive dataset; next, a preset data-interaction agent constructs a target prompt text corresponding to the comprehensive dataset; further, based on a preset large language model, association analysis and intelligent reasoning processing are performed on the comprehensive dataset according to the target prompt text to generate corresponding root cause analysis results; finally, the attribution analysis results are output. When an alarm notification corresponding to the target system is detected, this application uses a data-aware intelligent agent to parse the alarm notification and obtain key entity information. Then, a data-acquisition intelligent agent collects associated data corresponding to the key entity information. Subsequently, a data-processing intelligent agent performs data fusion processing on the associated data to obtain a comprehensive dataset. Then, a target prompt text corresponding to the comprehensive dataset is constructed based on the data-interaction intelligent agent. Based on the use of a large language model, association analysis and intelligent reasoning processing are performed on the comprehensive dataset according to the target prompt text to generate corresponding root cause analysis results. Finally, the attribution analysis results are output. In this way, by combining multiple intelligent agents and a large language model, this application can achieve end-to-end automation of anomaly detection and attribution analysis result generation, significantly reducing manual intervention, effectively improving the processing efficiency of attribution analysis, and improving the accuracy of the generated attribution analysis results. Attached Figure Description
[0024] To more clearly illustrate the solutions in this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is an exemplary system architecture diagram to which this application can be applied;
[0026] Figure 2 This is a flowchart of an embodiment of the artificial intelligence-based attribution analysis method according to this application;
[0027] Figure 3 This is a schematic diagram of the structure of an embodiment of the artificial intelligence-based attribution analysis device according to this application;
[0028] Figure 4 This is a schematic diagram of the structure of one embodiment of the computer device according to this application. Detailed Implementation
[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein in the specification of the application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings of this application, are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings of this application are used to distinguish different objects, not to describe a particular order.
[0030] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0031] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.
[0032] like Figure 1As shown, system architecture 100 may include terminal device 101, network 102, and server 103. Terminal device 101 may be a laptop 1011, tablet 1012, or mobile phone 1013. Network 102 is used as a medium to provide a communication link between terminal device 101 and server 103. Network 102 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0033] Users can use terminal device 101 to interact with server 103 via network 102 to receive or send messages, etc. Various communication client applications can be installed on terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social media platform software, etc.
[0034] Terminal device 101 can be various electronic devices with a display screen and support web browsing. In addition to laptops 1011, tablets 1012, or mobile phones 1013, terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 player (Moving Picture Experts Group Audio Layer IV), a laptop computer, and a desktop computer, etc.
[0035] Server 103 can be a server that provides various services, such as a backend server that provides support for the pages displayed on terminal device 101.
[0036] It should be noted that the AI-based attribution analysis method provided in this application embodiment is generally executed by a server / terminal device, and correspondingly, the AI-based attribution analysis device is generally located in the server / terminal device.
[0037] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0038] Continue to refer Figure 2This document illustrates a flowchart of an embodiment of the AI-based attribution analysis method according to this application. The order of steps in the flowchart can be changed, and some steps can be omitted, depending on different requirements. The AI-based attribution analysis method provided in this application can be applied to any scenario requiring attribution analysis, and thus can be applied to products in these scenarios, such as attribution analysis scenarios in the financial and medical fields. The AI-based attribution analysis method includes the following steps:
[0039] Step S201: When an alarm notification corresponding to the target system is detected by a preset data sensing agent, the alarm notification is parsed based on the data sensing agent to obtain the corresponding key entity information.
[0040] In this embodiment, the artificial intelligence-based attribution analysis method operates on electronic devices (e.g., Figure 1 The server / terminal device shown can receive alarm notifications via wired or wireless connection. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra-wideband) connections, and other currently known or future known wireless connection methods. The specific implementing entity of this application is an attribution analysis system, which can be simply referred to as the system. This system is an observable automated root cause analysis system that combines a large language model with the Dify workflow engine.
[0041] The system achieves workflow automation and agent collaboration based on Dify: Dify serves as the core automation orchestration platform and agent management center in this application, and its key roles include:
[0042] 1. Workflow Definition and Execution: Provides an interface for designing root cause analysis workflows, and the Dify engine reliably drives the automated execution of the process.
[0043] 2. Agent Management and Scheduling: Create, configure, and manage a series of dedicated agents as workflow execution units to collaboratively complete tasks: 2.1 Anomaly Detection and Triggering Agent (i.e., data-aware intelligent agent): Listen for alarms, capture abnormal signals, and parse key entity information. 2.2 Multi-Source Data Acquisition Agent (i.e., data acquisition intelligent agent): Based on trigger information and standard labels, this agent calls the standardized interface provided by the MCP (Model Context Protocol) service (MCP is the core platform for model-service interaction). The MCP is responsible for handling the complex interaction logic with backend heterogeneous data sources (covering SkyWalking tracing system, Prometheus metric system, log system, event system, CMDB, etc.), achieving accurate and automated extraction of necessary context data (link, metric, log, event, configuration, topology, etc.). 2.3 Data Preprocessing and Fusion Agent (i.e., data processing intelligent agent): Clean, transform, align, and structurally aggregate heterogeneous data to construct a comprehensive analysis dataset (which can be simply referred to as a comprehensive dataset). 2.4 LLM Interaction Agent (i.e., data interaction agent): Constructs high-quality prompts, submits the fused data and analysis instructions to the large language model, and processes the returned results.
[0044] Furthermore, the target system mentioned above can be an application service system, infrastructure system, database system, middleware system, logging system, monitoring system, etc. When the data-aware intelligent agent detects an alarm notification corresponding to the target system, it parses the alarm content (such as service name and abnormal indicators) and extracts the corresponding key entity information (such as instance ID and time range).
[0045] Furthermore, this application can be applied to attribution analysis scenarios in the financial and healthcare sectors. For example, in the financial insurance sector, a relevant scenario for financial enterprises could be: payment transaction delays and decreased success rates. Problem subject: The core payment system of an insurance company (microservice architecture, Kubernetes cluster deployment). User requirements: Ensure 24 / 7 high availability, with a transaction success rate ≥99.99%. Attribution analysis scenario: Phenomenon: Within a certain period, the payment transaction success rate plummeted from 99.99% to 98.5%, leading to a surge in user complaints.
[0046] In the healthcare field, a relevant scenario for medical enterprises is: slow response times in electronic medical record (EMR) systems. The primary issue is the hospital's HIS system (microservice-based, containerized, and deployed in a hybrid cloud). User requirements include ensuring a doctor's response time of less than 1 second to avoid delays in diagnosis and treatment. The root cause analysis scenario is as follows: During peak morning hours (8:00-9:00), the average response time of the EMR system surges from 0.8 seconds to 5.2 seconds, resulting in a 30% decrease in outpatient efficiency.
[0047] Step S202: Based on the preset data acquisition intelligent agent, collect the associated data corresponding to the key entity information.
[0048] In this embodiment, the specific implementation process of the above-mentioned data acquisition intelligent agent collecting associated data corresponding to the key entity information will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0049] Step S203: Based on the preset data processing intelligent agent, perform data fusion processing on the associated data to obtain the corresponding comprehensive dataset.
[0050] In this embodiment, the specific implementation process of the above-mentioned data fusion processing of the associated data based on the preset data processing intelligent agent to obtain the corresponding comprehensive dataset will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0051] Step S204: Construct target prompt text corresponding to the comprehensive dataset based on the preset data interaction intelligent agent.
[0052] In this embodiment, the specific implementation process of constructing the target prompt text corresponding to the comprehensive dataset based on the preset data interaction intelligent agent will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0053] Step S205: Based on the preset large language model, perform association analysis and intelligent reasoning processing on the comprehensive dataset according to the target prompt text to generate corresponding root cause analysis results.
[0054] In this embodiment, the processing steps for association analysis and intelligent reasoning of the comprehensive dataset based on the Large Language Model (LLM, specifically DeepSeek) and the target prompt text include: The Large Language Model (DeepSeek) serves as the core engine for intelligent analysis in this application, primarily performing the following analysis and reasoning tasks:
[0055] 1. Data Understanding: Deep semantic parsing of modal observable data.
[0056] Leveraging the inherent natural language processing and understanding capabilities of large language models, deep semantic parsing and key information extraction are performed on fused structured data (such as distributed tracing and performance metrics) and semi-structured / unstructured data (such as system logs and event records).
[0057] 2. Association Discovery: Intelligent identification of anomalies and potential associations across data sources.
[0058] Leveraging the pattern recognition and semantic understanding capabilities of a large language model, this system proactively detects and identifies statistically significant or semantically relevant anomalous patterns and potential associations across different data types (e.g., log events, metric fluctuations, link anomalies). It can effectively identify and confirm complex relationships across data domains, such as the relationship between specific events and performance metric degradation, or anomalous links and their corresponding metric / log evidence chains.
[0059] 3. Causal inference: Logical reasoning that integrates system topology information.
[0060] It integrates topology and service dependency information provided by the Configuration Management Database (CMDB) and the SkyWalking distributed tracing system. A large language model serves as the inference engine, performing logical deduction based on discovered anomalies and system dependencies. It analyzes potential fault propagation paths and causal chains layer by layer. For example, if an application in a Kubernetes pod experiences high latency, it correlates with system load, CPU usage, and operating system anomaly logs of the corresponding Kubernetes host machine to ultimately find the underlying cause.
[0061] 4. Causal relationship and transmission path analysis: precise root cause tracing and scope of impact definition.
[0062] We employ large language models to perform deep reasoning analysis, precisely identifying the propagation path of fault events within the system topology. By combining multi-dimensional information such as time series, dependencies, and anomaly severity, we systematically trace the root cause of faults and assess the potential impact of faults based on service dependency graphs, thereby obtaining the final attribution analysis results.
[0063] Step S206: Output the attribution analysis results.
[0064] In this embodiment, the specific implementation process of outputting the attribution analysis results will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0065] When an alarm notification corresponding to the target system is detected, this application uses a data-aware intelligent agent to parse the alarm notification and obtain key entity information. Then, a data-acquisition intelligent agent collects associated data corresponding to the key entity information. Subsequently, a data-processing intelligent agent performs data fusion processing on the associated data to obtain a comprehensive dataset. Then, a target prompt text corresponding to the comprehensive dataset is constructed based on the data-interaction intelligent agent. Based on the use of a large language model, association analysis and intelligent reasoning processing are performed on the comprehensive dataset according to the target prompt text to generate corresponding root cause analysis results. Finally, the attribution analysis results are output. In this way, by combining multiple intelligent agents and a large language model, this application can achieve end-to-end automation of anomaly detection and attribution analysis result generation, significantly reducing manual intervention, effectively improving the processing efficiency of attribution analysis, and improving the accuracy of the generated attribution analysis results.
[0066] In some alternative implementations, step S202 includes the following steps:
[0067] Obtain the preset tag system.
[0068] In this embodiment, the aforementioned tagging system is a globally unified tagging system pre-built according to actual business needs. The tagging system may include: defining and implementing a set of standard tags covering key dimensions such as data centers, applications, instances, environments, tracking IDs, and infrastructure (e.g., Pods, virtual machines); all observable data must be injected with the corresponding tags. This standardized tagging system provides a foundation for cross-data source association.
[0069] The system also establishes observability data standardization: by mandating a unified data model for structured processing of tracking, metrics, logs, and event data from the access systems, semantic consistency is ensured. Furthermore, the system maintains a comprehensive Configuration Management Database (CMDB) to store IT assets, applications, middleware, service configurations, dependencies, and change history, ensuring that CMDB configuration items (CI) and observable data use the same standard tagging system for identification and association. In addition, observable data standardization and the tagging system provide the foundation for subsequent multi-source data association, while the CMDB platform provides topological and dependency information for causal inference.
[0070] Based on the labeling system, a designated standard label corresponding to the key entity information is determined.
[0071] In this embodiment, the aforementioned tagging system defines and implements standard tags covering key dimensions such as data centers, applications, instances, and environments, and all observable data is injected with corresponding tags, providing a foundation for cross-data source association. Specifically, the specified standard tags matching the aforementioned key entity information can be determined by querying the tagging system.
[0072] The data acquisition agent invokes the standardized interface corresponding to the specified service.
[0073] In this embodiment, the aforementioned standardized interface is specifically the MCP (Model Context Protocol) service, which is a standardized interface provided by a specified service. MCP is the core platform for interaction between the model and the service. MCP is responsible for handling the complex interaction logic with backend heterogeneous data sources (including SkyWalking tracing system, Prometheus metrics system, log system, event system, CMDB, etc.), and realizing the accurate and automated extraction of necessary context data (link, metrics, logs, events, configuration, topology, etc.).
[0074] Based on the key entity information and the specified standard label, the standardized interface is used to perform corresponding data query processing on the preset heterogeneous data source to obtain the corresponding heterogeneous data.
[0075] In this embodiment, the specific implementation process of using the standardized interface to perform corresponding data query processing on the preset heterogeneous data source based on the key entity information and the specified standard label to obtain the corresponding heterogeneous data will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0076] The heterogeneous data is used as the associated data.
[0077] In this embodiment, after obtaining the aforementioned heterogeneous data, it can be further structured according to a unified data model. For example, a unified field format (such as timestamp, service name, instance ID, etc.) can be defined to ensure semantic consistency between data from different sources. The data is then collected and converted into a standard format through a data access layer (such as Kafka or Fluentd) to obtain the aforementioned associated data, which is then stored in a data lake or data warehouse.
[0078] This application obtains a preset tag system; determines a specified standard tag corresponding to the key entity information based on the tag system; then, based on the data acquisition agent, calls a standardized interface corresponding to a specified service; subsequently, based on the key entity information and the specified standard tag, uses the standardized interface to perform corresponding data query processing on a preset heterogeneous data source to obtain corresponding heterogeneous data; and finally, uses the heterogeneous data as the associated data. This application, by using a tag system to determine the specified standard tag corresponding to the key entity information, then calling a standardized interface corresponding to a specified service based on the data acquisition agent, and then using the standardized interface to perform corresponding data query processing on a preset heterogeneous data source based on the key entity information and the specified standard tag, can efficiently and accurately collect associated data corresponding to the key entity information, improving the efficiency of associated data acquisition and ensuring the accuracy, standardization, and completeness of the obtained associated data.
[0079] In some optional implementations of this embodiment, the heterogeneous data source includes at least a preset tracing system, a metrics system, a log system, an event system, and a configuration management database; the step of using the standardized interface to perform corresponding data query processing on the preset heterogeneous data source based on the key entity information and the specified standard tags to obtain the corresponding heterogeneous data includes the following steps:
[0080] Based on the standardized interface, the link tracing system performs data query processing corresponding to the key entity information and the specified standard label to obtain the corresponding link data.
[0081] In this embodiment, the aforementioned link tracing system is specifically the SkyWalking link tracing system. The link tracing system can be automatically queried based on the specified standard tags and metadata (key entity information) by calling the standardized interface of the MCP service, and the extracted first relevant data (such as distributed link tracing data) will be used as the link data.
[0082] Based on the standardized interface, the indicator system is used to perform data query processing corresponding to the key entity information and the specified standard label to obtain the corresponding indicator data.
[0083] In this embodiment, the aforementioned indicator system is specifically the Prometheus indicator system. The indicator system can be automatically queried using a standardized interface based on the specified standard labels and key entity information, and the extracted second relevant data (such as CPU and memory usage) can be used as the aforementioned indicator data.
[0084] Based on the standardized interface, the log system performs data query processing corresponding to the key entity information and the specified standard tags to obtain the corresponding log data.
[0085] In this embodiment, the aforementioned logging system is specifically an ELK logging system. The logging system can be automatically queried using a standardized interface based on the specified standard tags and key entity information, and the extracted third-party related data (such as application logs and system logs) can be used as the aforementioned log data.
[0086] Based on the standardized interface, the event system performs data query processing corresponding to the key entity information and the specified standard tags to obtain the corresponding event data.
[0087] In this embodiment, the event system can be automatically queried using a standardized interface based on the specified standard tags and key entity information, and the extracted fourth related data (such as alarm events and deployment events) can be used as the event data.
[0088] Based on the standardized interface, the configuration management database is queried for data corresponding to the key entity information and the specified standard tags to obtain the corresponding configuration data.
[0089] In this embodiment, the configuration management database (CMDB) can be automatically queried using a standardized interface based on the specified standard tags and key entity information, and the extracted fifth related data (such as configuration information and topology data) can be used as the configuration data.
[0090] The heterogeneous data is obtained by integrating and processing the link data, the indicator data, the log data, the event data, and the configuration data.
[0091] In this embodiment, the corresponding integrated data can be obtained by integrating the above-mentioned link data, indicator data, log data, event data and configuration data, and the integrated data can be used as the above-mentioned heterogeneous data.
[0092] This application utilizes standardized interfaces to perform data querying on the link tracing system, the metrics system, the log system, the event system, and the configuration management database, respectively, to obtain corresponding link data, metrics data, log data, event data, and configuration data. Then, it integrates these link data, metrics data, log data, event data, and configuration data to obtain the heterogeneous data. By using standardized interfaces, this application can accurately and automatically extract link data, metrics data, log data, event data, and configuration data associated with key entity information and specified standard tags from the link tracing system, metrics system, log system, event system, and configuration management database. Furthermore, by integrating the extracted link data, metrics data, log data, event data, and configuration data, the required heterogeneous data is obtained, effectively ensuring the completeness and accuracy of the obtained heterogeneous data.
[0093] In some optional implementations, step S203 includes the following steps:
[0094] The data processing agent performs data cleaning on the associated data to obtain the corresponding first processed data.
[0095] In this embodiment, the data cleaning process includes: missing value handling: identifying and filling in (mean / median / mode) or deleting missing data. Outlier detection: removing outliers using statistical methods (such as Z-score, IQR) or visualization. Deduplication: deleting duplicate records and retaining unique identifiers or key fields. In the financial field, the aforementioned related data may include claims data, such as claims amount, claims conditions, and customer risk data. In the healthcare field, the aforementioned related data may include medical data, such as personal health records, prescriptions, and examination reports.
[0096] The first processed data is subjected to data transformation processing to obtain the corresponding second processed data.
[0097] In this embodiment, the data transformation process includes: Format standardization: unifying timestamps, units, encoding (e.g., UTF-8), and classification labels (One-Hot encoding). Normalization / scaling: applying Min-Max or Z-Score standardization to numerical data. Discretization: binning continuous variables (e.g., age segmentation) to fit certain analytical models.
[0098] The second processed data is then aligned to obtain the corresponding third processed data.
[0099] In this embodiment, the data alignment process includes: Time alignment: resampling or interpolating time-series data at a fixed frequency (e.g., hourly). Spatial alignment: unifying geographic coordinate systems (e.g., WGS84) or grid partitioning. Semantic alignment: unifying concepts from multiple data sources (e.g., "car" and "vehicle") through ontology or keyword mapping.
[0100] The third processed data is subjected to structured aggregation processing to obtain the corresponding fourth processed data.
[0101] In this embodiment, the above-mentioned structured aggregation process includes: Feature fusion: merging multi-source features through concatenation, weighted averaging, or deep learning (such as Autoencoder). Relationship modeling: constructing a knowledge graph or association matrix to preserve the topological relationships between data. Hierarchical aggregation: generating summary statistics according to business logic hierarchies (such as user → group → market).
[0102] The fourth processed data is used as the comprehensive dataset.
[0103] In this embodiment, the generated comprehensive dataset can be stored in a structured format or a database table, accompanied by metadata descriptions (field meanings, conversion rules). Furthermore, the data lineage related to the comprehensive dataset is intelligently recorded throughout the process to ensure traceability.
[0104] This application utilizes a data processing intelligent agent to perform data cleaning, data transformation, data alignment, and structured aggregation on associated data. This enables efficient and accurate data fusion processing of associated data across multiple dimensions, effectively improving the data accuracy of the generated comprehensive dataset.
[0105] In some alternative implementations, step S204 includes the following steps:
[0106] The data interaction agent performs data analysis on the comprehensive dataset to extract key data from it.
[0107] In this embodiment, firstly, the core objective of root cause analysis is clarified. For example, is it to analyze the root cause of increased service response time or to locate the specific source of system failure? Then, the expected results are set: clearly define what results are desired from the large model, such as root causes, chains of evidence, and remediation suggestions. Next, by carefully examining the comprehensive dataset transmitted by the data processing agent, including link data, indicator data, log data, event data, and configuration data, key information points are extracted from the comprehensive dataset to obtain the aforementioned key data, such as the specific values of abnormal indicators, the content of error logs, and the time consumption in link tracing.
[0108] Obtain the preset prompt text construction strategy.
[0109] In this embodiment, the strategy for constructing the aforementioned prompt text includes: building a framework for the prompt text, including an introduction, a data presentation section, and a problem guidance section. Specifically, the introduction includes: providing background information in concise and clear language, explaining the current problem or anomaly. For example: "The response time of service A has increased significantly, and its root cause needs to be analyzed." The data presentation section includes: presenting the extracted key information to the large model in a structured manner. This can be organized according to data type or chronological order to ensure the information is clear and easy to understand. For example: "Link tracing data shows that the Span1 latency reached 500ms, far exceeding the normal level." "Indicator data shows that the CPU utilization of the instance where service A is located reached 90%, close to full load." "Multiple database connection timeout errors were found in the log data, with specific error codes XXXX." The problem guidance section includes: clearly stating the task that the large language model needs to complete, and the expected output format. For example: "Based on the above data, please analyze the root cause of the increased response time of service A, and provide a detailed chain of evidence and remediation suggestions. Please return the results in JSON format, including the following fields: root cause, chain of evidence, and remediation suggestions."
[0110] Based on the aforementioned prompt text construction strategy, the key data is processed to generate a corresponding first prompt text.
[0111] In this embodiment, based on the strategy content of the above-mentioned prompt text construction strategy, the above-mentioned key data can be processed to construct matching prompt text, and the generated text can be used as the above-mentioned first prompt text.
[0112] The first prompt text is optimized to obtain the corresponding second prompt text.
[0113] In this embodiment, the above expression optimization process includes: using clear and concise language: avoiding the use of vague or ambiguous words to ensure that the large model can accurately understand the instructions. Maintaining logical coherence: ensuring that the various parts of the Prompt are logically coherent and that the information is presented in an orderly manner, facilitating reasoning and analysis by the large model. Example guidance: if possible, a simplified example can be provided to illustrate the expected output format and content, helping the large language model better understand the task requirements.
[0114] The second prompt text is verified based on a preset verification strategy.
[0115] In this embodiment, the verification process includes: checking whether the generated second prompt text covers all key data and whether the instruction is clear, and generating a corresponding verification result. If the second prompt text is found to cover all key data and the instruction is clear, the second prompt text is determined to pass verification; otherwise, the second prompt text is determined to fail verification.
[0116] If the second prompt text passes verification, then the second prompt text will be used as the target prompt text.
[0117] In this embodiment, if the second prompt text passes verification, it is directly used as the final target prompt text. Alternatively, if the second prompt text fails verification, it can be further adjusted and optimized based on the returned verification results, such as adding more details or adjusting the question guidance method, until a target prompt text that meets the construction requirements is obtained.
[0118] This application utilizes a data interaction intelligent agent to perform data analysis on a comprehensive dataset to extract key data. Then, based on a prompt text construction strategy, prompts are constructed from this key data to obtain a first prompt text. The first prompt text is further optimized to obtain a second prompt text. Subsequently, when the second prompt text passes verification using a validation strategy, it is used as the final target prompt text. Through this prompt text construction process, a high-quality, highly accurate target prompt text can be automatically and efficiently constructed. This facilitates the effective guidance of the DaDa language model in root cause analysis and returns expected attribution analysis results, thus ensuring the accuracy of the generated attribution analysis results.
[0119] In some optional implementations of this embodiment, step S206 includes the following steps:
[0120] Obtain the preset report generation strategy.
[0121] In this embodiment, the above-mentioned report generation strategy includes the design and formatting of root cause analysis report templates. Specifically, 1) the design of root cause analysis report templates includes: Framework definition: designing a report template containing the following modules: Problem phenomenon: objectively describing the abnormal behavior (e.g., "API response time suddenly increased by 50%"). Deduction process: displaying the analysis path in the form of a logic tree or flowchart (e.g., "first check the request volume → locate the slow query → associate with missing index"). Evidence chain: attaching key data fragments (e.g., log fragments, monitoring chart screenshots), statistical test results (e.g., p-value) or model confidence level. Root cause inference: clearly stating the conclusion (e.g., "the root cause is a full table scan due to a lack of indexes in the database"), and marking the confidence level (high / medium / low). Remediation plan: explaining the operation step by step (e.g., "create index statement + execute command"), and estimating the scope of impact (e.g., "expected to reduce query time by 90%"). Improvement suggestions: long-term optimization measures (e.g., "introduce automatic index suggestion tool"). 2) Formatting includes: Multi-turn dialogue fine-tuning: Guiding the data interaction agent to fill in the content according to the above root cause analysis report template, requiring clear point division and avoiding the piling up of technical jargon. Dynamic content embedding: Inserting root cause analysis results (such as abnormal time windows, resource consumption data) into the root cause analysis report template through variables to ensure real-time performance. Visualization assistance: Calling relevant plugins to generate simple charts (such as line charts comparing indicators before and after repair) and embedding them into the report text of the root cause analysis report.
[0122] Based on the report generation strategy, the data interaction agent is used to format the root cause analysis results to obtain the corresponding root cause analysis report.
[0123] In this embodiment, based on the strategy content of the above-mentioned report generation strategy, the above-mentioned data interaction agent can be guided to format the root cause analysis results, thereby generating a corresponding root cause analysis report.
[0124] Get the preset report output method.
[0125] In this embodiment, there is no specific limitation on the selection of the above report output method. For example, any one of the following methods can be selected: email sending, interface display, pop-up reminder, etc.
[0126] Based on the aforementioned report output method, the root cause analysis report is processed for output.
[0127] In this embodiment, the output processing of the root cause analysis report can be completed according to the selected report output method.
[0128] This application obtains a preset report generation strategy; then, based on the report generation strategy, uses the data interaction agent to format the root cause analysis results to obtain a corresponding root cause analysis report; subsequently, it obtains a preset report output method; and then, based on the report output method, it outputs the root cause analysis report. After generating root cause analysis results based on a preset large language model, this application automatically formats the root cause analysis results using the data interaction agent based on the report generation strategy to obtain a root cause analysis report, thereby improving the efficiency of root cause analysis report generation. Furthermore, it intelligently outputs the root cause analysis report based on the obtained report output method, thereby improving the intelligence of the output of attribution analysis results.
[0129] In some optional implementations of this embodiment, after step S206, the electronic device may further perform the following steps:
[0130] Call the preset feedback channel.
[0131] In this embodiment, the system provides a user feedback channel, allowing development and operations engineers to evaluate the accuracy of the automated root cause analysis results. This feedback drives workflow and agent optimization, supplements and improves related monitoring data, forming a continuous improvement intelligent operations and maintenance closed loop.
[0132] The configuration of the aforementioned feedback channels is not specifically limited. For example, the following feedback entry points can be provided on the report page related to the root cause analysis report display: Rating system: Five-star rating (1-5 stars) for quick evaluation of accuracy. Text box: Open-ended questions (e.g., "Which step of reasoning was the least clear?") to collect qualitative opinions. Tag categorization: Pre-set tags (e.g., "Missing data," "Logical jumps," "Impractical suggestions") for users to quickly select.
[0133] Evaluation information is collected and processed based on the feedback channels and root cause analysis.
[0134] In this embodiment, all evaluation information related to the completed root cause analysis can be collected in real time through the aforementioned feedback channels. The evaluation information collection process is anonymized to ensure user feedback data is desensitized and to avoid privacy risks. Simultaneously, the feedback batch corresponding to each Agent optimization is recorded, enabling traceable continuous improvement.
[0135] Extract target evaluation information that meets preset screening conditions from the evaluation information.
[0136] In this embodiment, the aforementioned preset screening condition can be a specified time period. Specific evaluation information within the specified time period can be extracted from the aforementioned evaluation information and used as the target evaluation information. The selection of the specified time period is not specifically limited and can be set according to actual business needs; for example, it can be set to the past year. Furthermore, by performing data analysis and processing only on the target evaluation information that meets the preset screening condition, and then performing optimization processing on the agent, it is unnecessary to perform data analysis on all evaluation information corresponding to root cause analysis, thereby effectively improving the optimization processing efficiency of the agent.
[0137] Based on the target evaluation information, the corresponding agent optimization process is performed.
[0138] In this embodiment, the aforementioned intelligent agent may include a data perception intelligent agent, a data acquisition intelligent agent, a data processing intelligent agent, and a data interaction intelligent agent. The process of optimizing the intelligent agent based on target evaluation information includes: 1) Problem classification: Archive feedback (target evaluation information) by type (model misjudgment, data delay, ambiguous description). 2) Prioritization: Determine the optimization order based on feedback frequency and severity (e.g., false alarms leading to production accidents). 3) Iterative training: Data augmentation: Add negative cases to the training set and fine-tune the reasoning logic of the large language model. Rule supplementation: Add regular expressions or constraints for common misjudgment scenarios (e.g., "network jitter falsely reported as service failure"). Process correction: Adjust the evidence chain weight allocation strategy (e.g., increase the priority of key logs). 4) Effect verification and notification: A / B testing: Conduct double-blind evaluation of the reports before and after optimization and statistically analyze the percentage increase in accuracy. Transparent notification: Push improvement reports to users via email or system announcements (e.g., "Recent root cause analysis accuracy improved by 15%").
[0139] This application automatically collects evaluation information corresponding to root cause analysis based on the use of feedback channels, extracts target evaluation information that meets preset screening conditions from the evaluation information, and then performs corresponding agent optimization processing based on the use of target evaluation information. This helps to improve the accuracy and intelligence of each agent in subsequent data processing related to root cause analysis, thereby helping to improve the accuracy of attribution analysis.
[0140] In some alternative implementations, the user information obtained is subject to user consent and complies with relevant laws and policies.
[0141] Furthermore, any software tools or components not belonging to our company that appear in the embodiments of this application are merely illustrative examples and do not represent actual use.
[0142] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0143] It should be emphasized that, to further ensure the privacy and security of the above attribution analysis results, the attribution analysis results can also be stored in a blockchain node.
[0144] The blockchain referred to in this application is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include an underlying blockchain platform, a platform product service layer, and an application service layer.
[0145] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) refers to the theories, methods, technologies, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0146] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware with computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When executed, the program can include the processes of the embodiments of the above methods. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).
[0147] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0148] Further reference Figure 3 As a response to the above Figure 2 To implement the method shown, this application provides an embodiment of an attribution analysis device based on artificial intelligence, which is similar to... Figure 2 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.
[0149] like Figure 3 As shown, the artificial intelligence-based attribution analysis device 300 described in this embodiment includes: a parsing module 301, a data acquisition module 302, a fusion module 303, a construction module 304, a processing module 305, and an output module 306. Wherein:
[0150] The parsing module 301 is used to parse the alarm notification based on the data sensing agent when the alarm notification corresponding to the target system is detected by the preset data sensing agent, and obtain the corresponding key entity information.
[0151] The acquisition module 302 is used to acquire associated data corresponding to the key entity information based on a preset data acquisition intelligent agent;
[0152] The fusion module 303 is used to perform data fusion processing on the associated data based on a preset data processing intelligent agent to obtain a corresponding comprehensive dataset;
[0153] Construction module 304 is used to construct target prompt text corresponding to the comprehensive dataset based on a preset data interaction intelligent agent;
[0154] Processing module 305 is used to perform association analysis and intelligent reasoning processing on the comprehensive dataset based on the target prompt text according to a preset large language model, and generate corresponding root cause analysis results;
[0155] Output module 306 is used to output the attribution analysis results.
[0156] In some optional implementations of this embodiment, the acquisition module 302 includes:
[0157] The first acquisition submodule is used to acquire the preset tag system;
[0158] The first determining submodule is used to determine the specified standard label corresponding to the key entity information based on the label system;
[0159] The calling submodule is used to call the standardized interface corresponding to the specified service based on the data acquisition agent;
[0160] The query submodule is used to perform corresponding data query processing on the preset heterogeneous data source based on the key entity information and the specified standard label, using the standardized interface to obtain the corresponding heterogeneous data.
[0161] The second determining submodule is used to treat the heterogeneous data as the associated data.
[0162] In some optional implementations of this embodiment, the heterogeneous data source includes at least a preset link tracing system, indicator system, log system, event system, and configuration management database; the query submodule includes:
[0163] The first query unit is used to perform data query processing on the link tracing system based on the standardized interface to obtain the corresponding link data, which corresponds to the key entity information and the specified standard label.
[0164] The second query unit is used to perform data query processing on the indicator system based on the standardized interface, corresponding to the key entity information and the specified standard label, to obtain the corresponding indicator data.
[0165] The third query unit is used to perform data query processing on the log system based on the standardized interface to obtain the corresponding log data, which corresponds to the key entity information and the specified standard label.
[0166] The fourth query unit is used to perform data query processing on the event system based on the standardized interface to obtain the corresponding event data, which corresponds to the key entity information and the specified standard label.
[0167] The fifth query unit is used to perform data query processing on the configuration management database based on the standardized interface to obtain the corresponding configuration data, which corresponds to the key entity information and the specified standard label.
[0168] The integration unit is used to integrate the link data, the indicator data, the log data, the event data, and the configuration data to obtain the heterogeneous data.
[0169] In some optional implementations of this embodiment, the fusion module 303 includes:
[0170] The first processing submodule is used to perform data cleaning processing on the associated data based on the data processing intelligent agent to obtain the corresponding first processed data.
[0171] The second processing submodule is used to perform data conversion processing on the first processed data to obtain the corresponding second processed data;
[0172] The third processing submodule is used to perform data alignment processing on the second processed data to obtain the corresponding third processed data;
[0173] The fourth processing submodule is used to perform structured aggregation processing on the third processing data to obtain the corresponding fourth processing data;
[0174] The third determining submodule is used to use the fourth processed data as the comprehensive dataset.
[0175] In some optional implementations of this embodiment, the construction module 304 includes:
[0176] The analysis submodule is used to perform data analysis on the comprehensive dataset based on the data interaction agent, so as to extract key data from the comprehensive dataset;
[0177] The second acquisition submodule is used to acquire the preset prompt text construction strategy;
[0178] A construction submodule is used to perform prompt construction processing on the key data based on the prompt text construction strategy to obtain the corresponding first prompt text;
[0179] The optimization submodule is used to optimize the expression of the first prompt text to obtain the corresponding second prompt text.
[0180] The verification submodule is used to perform verification processing on the second prompt text based on a preset verification strategy;
[0181] The fourth determining submodule is used to use the second prompt text as the target prompt text if the second prompt text passes verification.
[0182] In some optional implementations of this embodiment, the output module 306 includes:
[0183] The third acquisition submodule is used to acquire the preset report generation strategy;
[0184] The formatting submodule is used to format the root cause analysis results using the data interaction agent based on the report generation strategy, so as to obtain the corresponding root cause analysis report.
[0185] The fourth acquisition submodule is used to acquire the preset report output method;
[0186] The output submodule is used to process the root cause analysis report based on the report output method.
[0187] In some optional implementations of this embodiment, the artificial intelligence-based attribution analysis device further includes:
[0188] The calling module is used to invoke preset feedback channels;
[0189] The collection module is used to collect evaluation information corresponding to root cause analysis based on the feedback channels;
[0190] The extraction module is used to extract target evaluation information that meets preset screening conditions from the evaluation information;
[0191] The optimization module is used to perform corresponding agent optimization processing based on the target evaluation information.
[0192] To address the aforementioned technical problems, embodiments of this application also provide a computer device. Please refer to [link / reference needed]. Figure 4 , Figure 4 This is a basic structural block diagram of the computer device in this embodiment.
[0193] The computer device 4 includes a memory 41, a processor 42, and a network interface 43 that are interconnected via a system bus. It should be noted that only the computer device 4 with components 41-43 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the computer device described here is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0194] The computer device can be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device can interact with the user via a keyboard, mouse, remote control, touchpad, or voice control.
[0195] The memory 41 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 41 may be an internal storage unit of the computer device 4, such as the hard disk or memory of the computer device 4. In other embodiments, the memory 41 may also be an external storage device of the computer device 4, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 4. Of course, the memory 41 may also include both the internal storage unit and its external storage device of the computer device 4. In this embodiment, the memory 41 is typically used to store the operating system and various application software installed on the computer device 4, such as computer-readable instructions for attribution analysis methods based on artificial intelligence. In addition, the memory 41 can also be used to temporarily store various types of data that have been output or will be output.
[0196] In some embodiments, the processor 42 may be a central processing unit (CPU), controller, microcontroller, microprocessor, or other data processing chip. The processor 42 is typically used to control the overall operation of the computer device 4. In this embodiment, the processor 42 is used to execute computer-readable instructions stored in the memory 41 or to process data, for example, to execute computer-readable instructions for the artificial intelligence-based attribution analysis method.
[0197] The network interface 43 may include a wireless network interface or a wired network interface, which is typically used to establish communication connections between the computer device 4 and other electronic devices.
[0198] This application also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the artificial intelligence-based attribution analysis method described above.
[0199] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0200] Obviously, the embodiments described above are only some embodiments of this application, not all embodiments. The accompanying drawings show preferred embodiments of this application, but do not limit the patent scope of this application. This application can be implemented in many different forms; rather, the purpose of providing these embodiments is to provide a more thorough and comprehensive understanding of the disclosure of this application. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this application's specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the scope of patent protection of this application.
Claims
1. An attribution analysis method based on artificial intelligence, characterized in that, Includes the following steps: When an alarm notification corresponding to the target system is detected by a preset data-sensing intelligent agent, the data-sensing intelligent agent is used to parse the alarm notification to obtain the corresponding key entity information. Based on a preset data acquisition intelligent agent, associated data corresponding to the key entity information is collected; Based on a preset data processing intelligent agent, the associated data is fused to obtain a corresponding comprehensive dataset. Based on a preset data interaction intelligent agent, a target prompt text corresponding to the comprehensive dataset is constructed; Based on a pre-defined large language model, the comprehensive dataset is subjected to association analysis and intelligent reasoning processing according to the target prompt text to generate corresponding root cause analysis results. Output the attribution analysis results.
2. The attribution analysis method based on artificial intelligence according to claim 1, characterized in that, The step of collecting associated data corresponding to the key entity information based on the preset data acquisition intelligent agent specifically includes: Obtain the preset tag system; Based on the labeling system, a designated standard label corresponding to the key entity information is determined; Based on the data acquisition intelligent agent, the standardized interface corresponding to the specified service is invoked; Based on the key entity information and the specified standard label, the standardized interface is used to perform corresponding data query processing on the preset heterogeneous data source to obtain the corresponding heterogeneous data. The heterogeneous data is used as the associated data.
3. The attribution analysis method based on artificial intelligence according to claim 2, characterized in that, The heterogeneous data source includes at least a preset tracing system, a metrics system, a log system, an event system, and a configuration management database; the step of using the standardized interface to perform corresponding data query processing on the preset heterogeneous data source based on the key entity information and the specified standard tags to obtain the corresponding heterogeneous data specifically includes: Based on the standardized interface, the link tracing system performs data query processing corresponding to the key entity information and the specified standard label to obtain the corresponding link data. Based on the standardized interface, the indicator system is processed to perform data querying corresponding to the key entity information and the specified standard label to obtain the corresponding indicator data. Based on the standardized interface, the log system performs data query processing corresponding to the key entity information and the specified standard tags to obtain the corresponding log data. Based on the standardized interface, the event system performs data query processing corresponding to the key entity information and the specified standard label to obtain the corresponding event data. Based on the standardized interface, the configuration management database is queried for data corresponding to the key entity information and the specified standard tags to obtain the corresponding configuration data. The heterogeneous data is obtained by integrating and processing the link data, the indicator data, the log data, the event data, and the configuration data.
4. The attribution analysis method based on artificial intelligence according to claim 1, characterized in that, The step of performing data fusion processing on the associated data based on a preset data processing intelligent agent to obtain a corresponding comprehensive dataset specifically includes: Based on the data processing intelligent agent, the associated data is cleaned to obtain the corresponding first processed data; The first processed data is subjected to data transformation processing to obtain the corresponding second processed data; The second processed data is aligned to obtain the corresponding third processed data; The third processed data is subjected to structured aggregation processing to obtain the corresponding fourth processed data; The fourth processed data is used as the comprehensive dataset.
5. The attribution analysis method based on artificial intelligence according to claim 1, characterized in that, The step of constructing the target prompt text corresponding to the comprehensive dataset based on the preset data interaction intelligent agent specifically includes: The data interaction agent performs data analysis on the comprehensive dataset to extract key data from the comprehensive dataset. Obtain the preset prompt text construction strategy; Based on the aforementioned prompt text construction strategy, the key data is processed to construct prompts, resulting in the corresponding first prompt text. The first prompt text is optimized to obtain the corresponding second prompt text; The second prompt text is verified based on a preset verification strategy; If the second prompt text passes verification, then the second prompt text will be used as the target prompt text.
6. The attribution analysis method based on artificial intelligence according to claim 1, characterized in that, The step of outputting the attribution analysis results specifically includes: Obtain the preset report generation strategy; Based on the report generation strategy, the data interaction agent is used to format the root cause analysis results to obtain the corresponding root cause analysis report. Obtain the preset report output method; Based on the aforementioned report output method, the root cause analysis report is processed for output.
7. The attribution analysis method based on artificial intelligence according to claim 1, characterized in that, After the step of outputting the attribution analysis results, the method further includes: Call the preset feedback channel; Based on the feedback channels, the corresponding evaluation information is collected and processed through root cause analysis. Extract target evaluation information that meets preset screening conditions from the evaluation information; Based on the target evaluation information, the corresponding agent optimization process is performed.
8. An attribution analysis device based on artificial intelligence, characterized in that, include: The parsing module is used to parse the alarm notification corresponding to the target system based on the data sensing agent when the alarm notification is detected by the preset data sensing agent to obtain the corresponding key entity information. The data acquisition module is used to collect associated data corresponding to the key entity information based on a preset data acquisition intelligent agent; The fusion module is used to perform data fusion processing on the associated data based on a preset data processing intelligent agent to obtain a corresponding comprehensive dataset. The construction module is used to construct target prompt text corresponding to the comprehensive dataset based on a preset data interaction intelligent agent; The processing module is used to perform correlation analysis and intelligent reasoning on the comprehensive dataset based on the preset large language model and the target prompt text, and generate corresponding root cause analysis results. The output module is used to output the attribution analysis results.
9. A computer device, characterized in that, The method includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the attribution analysis method based on artificial intelligence as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the attribution analysis method based on artificial intelligence as described in any one of claims 1 to 7.
Citation Information
Cited By
Associated data tracking cascade deletion method based on large model agent
CN121501811A
A method for tracking and cascading deletion of associated data based on a large model agent
CN121501811B
Payment method, device, equipment, medium and program product
CN121526599A
Alarm prompt template optimization method, electronic equipment, medium and product
CN121882007A
A manufacturing-oriented multi-agent collaborative attribution analysis method
CN122490467A