Alarm processing method and related equipment
By acquiring alarm configuration information and automatically determining the handling strategy for alarm events, the problem of existing alarm systems being unable to handle alarms automatically is solved, realizing automated processing and interception of alarm events, and improving the stability and efficiency of the system.
Patent Information
- Application Number
- CN202410599147.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-13
- Publication Date
- 2025-11-14
AI Technical Summary
Existing alarm systems can only issue alarms but cannot process them automatically, causing maintenance personnel to spend a lot of time and energy, resulting in low processing efficiency and failing to meet the need for rapid response.
By acquiring alarm configuration information edited according to different business needs, including alarm interception and processing configurations, the system automatically determines whether alarm events need to be intercepted and generates processing strategies to achieve automated processing and interception of alarm events.
It automates alarm handling, reduces manual intervention, and improves system stability, reliability, and efficiency.
Smart Images

Figure CN120956579A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, specifically to an alarm processing method and related equipment. Background Technology
[0002] With the development of technology, understanding the status of infrastructure and systems is crucial for ensuring service reliability and stability. Therefore, alarm systems have emerged to address and resolve various issues that may arise within the system. However, existing alarm systems only have the function of issuing alarms, requiring maintenance personnel to spend a significant amount of time and effort processing each alarm individually. This is not only inefficient but also fails to meet the need for rapid response. Summary of the Invention
[0003] This application provides an alarm processing method and related equipment. The related equipment may include an alarm processing device, electronic equipment, computer-readable storage medium, and computer program product, which can improve the efficiency of alarm processing.
[0004] This application provides an alarm processing method, including:
[0005] Obtain alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information.
[0006] When an alarm event is detected in the system, the target service to which the alarm event belongs is obtained, and the target alarm module to which the target service belongs, as well as the target processing tool information required to process the target alarm type corresponding to the target alarm module, are determined according to the alarm processing configuration information.
[0007] Based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, determine whether the current alarm event needs to be intercepted, and obtain the interception determination result;
[0008] Based on the target processing tool information and the interception determination result, a target alarm processing strategy corresponding to the alarm event is generated, and the alarm event is processed based on the target alarm processing strategy.
[0009] Accordingly, embodiments of this application provide an alarm processing device, including:
[0010] The first acquisition unit is used to acquire alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information.
[0011] The second acquisition unit is used to acquire the target service to which the alarm event belongs when an alarm event is detected in the system, and to determine the target alarm module to which the target service belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module according to the alarm processing configuration information.
[0012] The interception unit is used to determine whether the current alarm event needs to be intercepted based on the processing threshold in the alarm interception configuration information and the number of historical alarms corresponding to the alarm event, and to obtain an interception determination result;
[0013] The processing unit is configured to generate a target alarm processing strategy corresponding to the alarm event based on the target processing tool information and the interception determination result, and process the alarm event based on the target alarm processing strategy.
[0014] Optionally, in some embodiments of this application, the second acquisition unit may be specifically used to acquire the target service to which the alarm event belongs, and determine the target alarm module to which the target service belongs based on the alarm processing configuration information; determine whether the target alarm module is in a blocking period based on the alarm configuration information; if the target alarm module is in a blocking period, suspend alarm processing; if the target alarm module is not in a blocking period, detect whether the device corresponding to the alarm event is disabled through a scheduling check operation, and obtain the detection result; if the detection result shows that the device is in a disabled state, no alarm processing is performed; if the detection result shows that the device is not in a disabled state, determine the target processing tool information required to process the target alarm type corresponding to the target alarm module based on the alarm processing configuration information.
[0015] Optionally, in some embodiments of this application, the second acquisition unit may include a first acquisition subunit and a sending subunit, as follows:
[0016] The first acquisition subunit is used to acquire the target service to which the alarm event belongs when an alarm event is detected in the system, and to determine the target alarm module to which the target service belongs and the target alarm type corresponding to the target alarm module according to the alarm processing configuration information.
[0017] The sending subunit is used to send the alarm event to the callback result processor for event processing if it is determined that the target alarm type includes a fault alarm type;
[0018] If it is determined that the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event can be obtained, the alarm event and the preset analysis result are sent to the callback result processor for event processing.
[0019] If it is determined that the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event cannot be obtained, the target processing tool information required to process the target alarm type corresponding to the target alarm module is determined according to the alarm processing configuration information.
[0020] Optionally, in some embodiments of this application, the second acquisition unit may further include a filtering subunit and a query subunit, as follows:
[0021] The filtering subunit is used to filter out events that do not need to be processed from the alarm events when an alarm event is detected in the system, and update the alarm events based on the filtering results.
[0022] The query subunit is used to query the alarm storage information corresponding to the alarm event and end the alarm event that is determined to be non-existent based on the alarm storage information.
[0023] Optionally, in some embodiments of this application, the processing unit may be specifically used to perform an interception operation on the alarm event if it is determined based on the interception determination result that the alarm event needs to be intercepted; if it is determined based on the interception determination result that the alarm event does not need to be intercepted, generate a target alarm processing strategy corresponding to the alarm event based on the target processing tool information, and process the alarm event based on the target alarm processing strategy.
[0024] Optionally, in some embodiments of this application, the processing unit may be specifically used to generate a target alarm processing strategy corresponding to the alarm event based on the target processing tool information if the script determines that the intercepted alarm event has been recovered, and process the alarm event based on the target alarm processing strategy.
[0025] Optionally, in some embodiments of this application, the first acquisition unit may be specifically used to display an alarm configuration management interface, which includes alarm modules belonging to different services and alarm rules corresponding to different services. The alarm rules include one or more alarm types corresponding to the alarm module and processing tools required to process each alarm type.
[0026] Optionally, in some embodiments of this application, the first acquisition unit may be specifically used to pop up an alarm configuration management sub-interface corresponding to the specific service on the alarm configuration management interface when a hover operation for a specific service is detected on the alarm configuration management interface. The alarm configuration management sub-interface includes one or more alarm types corresponding to the specific service, as well as processing tools required to process each alarm type.
[0027] Optionally, in some embodiments of this application, the processing unit may be specifically used to store the target alarm processing strategy corresponding to the alarm event and asynchronously send the target alarm processing strategy corresponding to the alarm event to the user.
[0028] Optionally, in some embodiments of this application, the processing unit may be specifically used to display an alarm data analysis interface based on the alarm configuration information and the target alarm processing strategy corresponding to the alarm event. The alarm data analysis interface includes at least one of the following charts: an access overview chart, including the number of alarm modules and alarm rules accessed by different service groups; an alarm analysis quantity trend chart, including the number of alarm analyses performed by different services at different times; an alarm interception ratio trend chart, including the alarm interception situation generated by different services at different times; and a feature alarm interception ratio trend chart, including the alarm interception situation generated by different service features at different times.
[0029] This application also provides a computer-readable storage medium storing a computer program thereon, wherein the computer program, when executed by a processor, implements the steps in the alarm processing method provided in this application.
[0030] Furthermore, this application also provides a computer program product, including a computer program or instructions, which, when executed by a processor, implement the steps in the alarm processing method provided in this application.
[0031] This application provides an alarm processing method and related equipment. It can acquire alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information. When an alarm event is detected in the system, the target business to which the alarm event belongs is acquired, and the target alarm module to which the target business belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module are determined according to the alarm processing configuration information. Based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, it is determined whether the current alarm event needs to be intercepted, and an interception determination result is obtained. Based on the target processing tool information and the interception determination result, a target alarm processing strategy corresponding to the alarm event is generated, and the alarm event is processed based on the target alarm processing strategy. This application combines real-time detection, automated decision-making, and automatic interception technologies to achieve automated processing and interception of cluster alarms in the existing network, reducing the need for manual intervention and improving the stability, reliability, and efficiency of the system. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0033] Figure 1 This is a schematic diagram of a scenario for the alarm processing method provided in the embodiments of this application;
[0034] Figure 2 This is a first flowchart of the alarm processing method provided in the embodiments of this application;
[0035] Figure 3 This is a second flowchart of the alarm processing method provided in the embodiments of this application;
[0036] Figure 4 This is a schematic diagram of the module configuration interface provided in an embodiment of this application;
[0037] Figure 5 This is a schematic diagram of the rule configuration interface provided in an embodiment of this application;
[0038] Figure 6 This is a schematic diagram of the alarm configuration management interface provided in an embodiment of this application;
[0039] Figure 7This is a system architecture diagram provided in the embodiments of this application;
[0040] Figure 8 This is the third flowchart of the alarm processing method provided in the embodiments of this application;
[0041] Figure 9 This is the fourth flowchart of the alarm processing method provided in the embodiments of this application;
[0042] Figure 10 This is the fifth flowchart of the alarm processing method provided in the embodiments of this application;
[0043] Figure 11 This is a schematic diagram of the alarm processing device provided in the embodiments of this application;
[0044] Figure 12 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0045] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0046] This application provides an alarm processing method and related equipment. The related equipment may include an alarm processing device, an electronic device, a computer-readable storage medium, and a computer program product. Specifically, the alarm processing device may be integrated into an electronic device, which may be a terminal or a server, etc.
[0047] It is understood that the alarm processing method in this embodiment can be executed on a terminal, on a server, or jointly by a terminal and a server. The above examples should not be construed as limiting this application.
[0048] like Figure 1 As shown, an alarm processing method jointly executed by a terminal and a server is used as an example. The alarm processing system provided in this application includes a terminal and a server, etc.; the terminal and the server are connected via a network, such as a wired or wireless network, etc., wherein the alarm processing device can be integrated into the server.
[0049] The server can be used to: when an alarm event is detected within the system, obtain the target service to which the alarm event belongs, and determine the target alarm module to which the target service belongs, as well as the target processing tool information required to process the target alarm type corresponding to the target alarm module, based on the alarm processing configuration information; determine whether the current alarm event needs to be intercepted based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, and obtain an interception determination result; generate a target alarm processing strategy corresponding to the alarm event based on the target processing tool information and the interception determination result, and process the alarm event based on the target alarm processing strategy. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. In the alarm processing method or apparatus disclosed in this application, multiple servers can form a blockchain, and the server is a node on the blockchain.
[0050] The terminal can be used to: acquire alarm configuration information edited according to different business needs. This alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to each alarm module, and the mapping relationship between different alarm types and processing tool information. The terminal can include mobile phones, smart voice interaction devices, smart home appliances, vehicle terminals, aircraft, tablets, laptops, or personal computers (PCs), etc. A client can also be set on the terminal, which can be an application client or a browser client, etc.
[0051] The following sections provide detailed descriptions of each example. It should be noted that the order in which the embodiments are described is not intended to limit the preferred order of the embodiments.
[0052] This embodiment will be described from the perspective of an alarm processing device, which can be integrated into an electronic device, such as a server or terminal. This embodiment can be applied to various scenarios such as cloud technology, artificial intelligence, smart transportation, and assisted driving.
[0053] It is understood that in the specific implementation of this application, data related to user information (such as alarm configuration information) is involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0054] like Figure 2 As shown, the specific process of this alarm handling method can be as follows:
[0055] S201. Obtain alarm configuration information edited according to different business needs.
[0056] The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different services. The alarm processing configuration information includes the alarm module to which each service belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information.
[0057] Alarm interception involves blocking recurring, redundant, or unprocessable alarms. Alarm interception effectively addresses issues such as excessive, duplicate, or redundant alarms, significantly improving alarm efficiency and quality. For example, this embodiment allows setting a processing threshold for alarm interception. This threshold represents the maximum number of alarms allowed. Setting the threshold to 5 means a maximum of 5 alarms are allowed for the same content. If a sixth alarm is triggered for the same content, automatic interception is required, ensuring the user receives a maximum of 5 alarms for that content.
[0058] In this application, multiple services can belong to the same alarm module. That is, although there are differences between services, services belonging to the same alarm module will follow the same rules corresponding to that alarm module. Furthermore, in this application embodiment, the alarm module can be divided into a first-level module, a second-level module, and a third-level module. There is a parent-child hierarchical relationship between the first-level module, the second-level module, and the third-level module. For example, the first-level module can include module A, module B, module C, etc. Module A can include several second-level modules such as module A1 and module A2. Module A1 can also include several third-level modules such as module A11 and module A12. For example, a specific service such as service 1 can belong to the third-level module A11 under the second-level module A1 under the first-level module A.
[0059] In one embodiment, it can be achieved through, as follows Figure 4 The module configuration interface shown and as follows Figure 5The rule configuration interface shown allows users to edit alarm configuration information according to different business needs. This enables users to flexibly configure alarm self-healing rules based on actual requirements, achieving automated alarm processing, improving alarm processing efficiency and quality, and reducing the risk of errors. Furthermore, by selecting different tool types and content, more complex and refined alarm self-healing operations can be achieved, thereby improving the intelligence and automation level of alarm processing. This approach also effectively leverages the experience of operations and maintenance personnel, leading to better handling of alarm situations.
[0060] For example, users can use, Figure 4 In the module configuration interface shown, the control corresponding to "Select Module" allows you to select the alarm module to which the specific service belongs; the control corresponding to "Processing Threshold" allows you to select the maximum allowed alarm value.
[0061] Depending on the severity of the situation or different business needs, users can choose whether to send alerts by phone. For more serious situations, phone alerts can be used to promptly notify staff and address the issues. Conversely, for less serious but frequent situations, phone alerts can be omitted to reduce staff workload. This allows for more targeted alert handling and also helps manage manpower costs. Therefore, users can... Figure 4 In the module configuration interface shown, the control corresponding to "Whether to use telephone" allows selection of whether to send alarms via telephone. Selecting the "Block" option means that alarms will not be sent via telephone, while selecting the "Do not block" option means that alarms can be sent via telephone. Furthermore, this application does not provide a restrictive interpretation of the concept of blocking; that is, blocking can be defined not only as not sending telephone alarms but also as blocking alarms, and can be specifically defined according to actual needs.
[0062] Users can, for example Figure 4 In the module configuration interface shown, the person in charge of the business is selected through the control corresponding to "Person in Charge"; the group to which the person in charge belongs is selected through the control corresponding to "Group" to more clearly allocate alarm processing tasks; and the business affiliation is determined through the control corresponding to "Business Affiliation" to more accurately analyze and process alarms. In addition to the above basic configurations, this application embodiment can also set advanced configurations, platform IDs, scheduling and inspection methods, etc., to achieve more complex and refined alarm processing.
[0063] After the user finishes editing Figure 4 After viewing the module configuration interface shown, you can use the "Next" control to navigate to the page shown. Figure 5The rule configuration interface is shown below. Since each alarm module corresponds to one or more alarm types, users can configure the rules as follows: Figure 5 In the rule configuration interface shown, the control corresponding to "Alarm Type" allows for the selection of the appropriate alarm type for more accurate alarm matching. The controls for "Tool Type" and "Select Tool" allow for the selection of the tool type and specific tool required to handle the alarm type. This setting establishes a mapping relationship between different alarm types and processing tool information, enabling the application to utilize appropriate tools for alarm self-healing. For example, the tool type can include a script task management platform, an SSS tool platform, and special tools. If the user selects a script task management platform, the "Select Tool" will change accordingly, allowing the user to select pre-configured script tasks on the platform for automated alarm processing. Users can also use controls such as... Figure 5 The rule configuration interface shown allows you to set whether to pass through alarm content, so that you can have a clearer understanding of the specific information of the alarm.
[0064] Optionally, in one embodiment, after the step "obtaining alarm configuration information edited according to different business needs", the following may also be included:
[0065] The alarm configuration management interface is displayed. The alarm configuration management interface includes alarm modules belonging to different services and alarm rules corresponding to different services. The alarm rules include one or more alarm types corresponding to the alarm module and the processing tools required to process each alarm type.
[0066] For example, when users target such as Figure 4 The module configuration interface shown, and as Figure 5 After editing the alarm configuration information in the rule configuration interface shown, it can display the following: Figure 6 The alarm configuration management interface shown allows users to easily view and manage the alarm configuration information they have set. Through this interface, users can learn about the alarm modules to which different services belong, the alarm rules corresponding to different services, the usage of threshold quotas, the responsible persons, and the activation status. The alarm rules include one or more alarm types corresponding to the alarm module, as well as the processing tools required to handle each alarm type.
[0067] Furthermore, the alarm configuration management interface allows direct modification or copying of relevant alarm configuration information; it also provides a query function, enabling users to search for corresponding configurations using different filter criteria; and it offers batch operation functionality, facilitating faster batch enabling, disabling, modification, and deletion of alarm configuration information by operations and maintenance personnel, thereby improving the platform's efficiency.
[0068] Optionally, in one embodiment, the alarm processing method may further include:
[0069] When a hover operation targeting a specific service is detected on the alarm configuration management interface, a sub-interface for alarm configuration management corresponding to that specific service will pop up on the alarm configuration management interface. The sub-interface for alarm configuration management includes one or more alarm types corresponding to the specific service, as well as the processing tools required to handle each alarm type.
[0070] For example, if a user hovers their mouse over a specific business area in the alarm configuration management interface, it can display something like this: Figure 6 The pop-up window shown includes multiple alarm types corresponding to the specific service, the processing tool for each alarm type, and the alarm content for each alarm type.
[0071] S202. When an alarm event is detected in the system, obtain the target service to which the alarm event belongs, and determine the target alarm module to which the target service belongs, as well as the target processing tool information required to process the target alarm type corresponding to the target alarm module, based on the alarm processing configuration information.
[0072] For example, when an alarm event is generated in the system, the target service to which the alarm event belongs can be obtained, and the target alarm module to which the target service belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module can be determined according to the alarm processing configuration information set in step S201.
[0073] Optionally, in one embodiment, the step "obtaining the target service to which the alarm event belongs, and determining the target alarm module to which the target service belongs, and the target processing tool information required to process the target alarm type corresponding to the target alarm module, based on the alarm processing configuration information" may include:
[0074] Obtain the target service to which the alarm event belongs, and determine the target alarm module to which the target service belongs based on the alarm handling configuration information;
[0075] Based on the alarm configuration information, determine whether the target alarm module is in a blocking period. If the target alarm module is in a blocking period, suspend alarm processing.
[0076] If the target alarm module is not in a shielding period, the device corresponding to the alarm event is checked by scheduling and inspection to determine whether it is disabled, and the detection result is obtained.
[0077] If the detection result indicates that the device is disabled, no alarm will be triggered.
[0078] If the detection result indicates that the device is not disabled, determine the target processing tool information required for the target alarm type corresponding to the target alarm module based on the alarm processing configuration information.
[0079] For example, when an alarm event is generated in the system, the target service to which the alarm event belongs can be obtained. Then, based on the alarm processing configuration information edited in step S201, the target alarm module to which the target service belongs can be determined, and it can be counted whether the target alarm module is configured. After confirming that the target alarm module has the corresponding configuration, the following steps are executed to ensure the effectiveness of the target alarm module.
[0080] Then, the configuration rules corresponding to the alarm modules can be statistically analyzed to enable alarm processing based on these rules. Furthermore, the alarm configuration information can be used to determine whether the target alarm module is in a blocking period. If the target alarm module is in a blocking period, alarm processing is paused. If the target alarm module is not in a blocking period, alarms can be triggered. A scheduling check operation is then performed to detect whether the device corresponding to the alarm event is disabled, obtaining the detection result. If the detection result indicates that the device is disabled, no alarm processing is performed. If the detection result indicates that the device is not disabled, a user-defined analysis tool can be executed to perform self-healing judgment and obtain analysis results to determine whether the alarm requires self-healing processing. If self-healing processing is required, the target processing tool information needed to process the target alarm type corresponding to the target alarm module is determined based on the alarm processing configuration information.
[0081] Optionally, in one embodiment, the step "obtaining the target service to which the alarm event belongs, and determining the target alarm module to which the target service belongs, and the target processing tool information required to process the target alarm type corresponding to the target alarm module, based on the alarm processing configuration information" may include:
[0082] When an alarm event is detected in the system, the target service to which the alarm event belongs is obtained, and the target alarm module to which the target service belongs and the target alarm type corresponding to the target alarm module are determined according to the alarm processing configuration information.
[0083] If the target alarm type is determined to include a fault alarm type, the alarm event will be sent to the callback result processor for event processing.
[0084] If the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event can be obtained, the alarm event and the preset analysis result are sent to the callback result processor for event processing.
[0085] If the target alarm type does not include the fault alarm type and the preset analysis result corresponding to the alarm event cannot be obtained, the target processing tool information required for the target alarm type corresponding to the target alarm module is determined according to the alarm processing configuration information.
[0086] For example, since different alarm types are predefined, and the urgency and severity of handling vary for each type, fault alarms are among the more severe alarm types, and should be handled as soon as possible. Therefore, when an alarm event is detected in the system, the target service to which the alarm event belongs can be obtained, and the target alarm module and the target alarm type corresponding to the target alarm module can be determined based on the alarm handling configuration information.
[0087] If the target alarm type includes a fault alarm type, it indicates that the fault needs to be handled as soon as possible. The alarm event can then be sent to the callback result processor for timely event processing. If the target alarm type does not include a fault alarm type, and the preset analysis result corresponding to the alarm event can be obtained, the alarm event and the preset analysis result are sent to the callback result processor so that it can process the alarm event based on the preset analysis result. The preset analysis result is obtained through historical verification or accumulated experience, effectively utilizing past experience to improve alarm processing efficiency.
[0088] If the target alarm type does not include the fault alarm type and the preset analysis result corresponding to the alarm event cannot be obtained, then alarm processing can only be carried out based on the pre-configured information. In this case, the target processing tool information required for the target alarm type corresponding to the target alarm module can be determined based on the alarm processing configuration information.
[0089] Specifically, if the target alarm type does not include fault alarm types and the preset analysis results corresponding to the alarm event cannot be obtained, the solution can be further improved to enhance the overall alarm handling effect. For example, if the target alarm type does not include fault alarm types and the preset analysis results corresponding to the alarm event cannot be obtained, the target service to which the alarm event belongs can be obtained. Then, based on the alarm handling configuration information edited in step S201, the target alarm module to which the target service belongs can be determined, and it can be checked whether the target alarm module is configured. After confirming that the target alarm module has the corresponding configuration, the following steps are executed to ensure the effectiveness of the target alarm module. Then, the configuration rules corresponding to the alarm module can be counted so that alarm handling can be performed according to the rules. Furthermore, based on the alarm configuration information, it can be determined whether the target alarm module is in a blocking period. If the target alarm module is in a blocking period, alarm processing is suspended. If the target alarm module is not in a blocking period, it means that alarms can be issued. In this case, a scheduling check operation is performed to detect whether the device corresponding to the alarm event is disabled, and the detection result is obtained. If the detection result shows that the device is disabled, no alarm processing is performed. If the detection result shows that the device is not disabled, a user-defined analysis tool can be executed to perform self-healing judgment and obtain analysis results to determine whether the alarm needs to be self-healed. If self-healing is required, the target processing tool information required to process the target alarm type corresponding to the target alarm module is determined based on the alarm processing configuration information.
[0090] Optionally, in one embodiment, before the step "obtaining the target service to which the alarm event belongs, and determining the target alarm module to which the target service belongs and the target alarm type corresponding to the target alarm module based on the alarm processing configuration information", the following may be included:
[0091] When an alarm event is detected in the system, events that do not require processing are filtered out from the alarm events, and the alarm events are updated based on the filtering results;
[0092] Query the alarm storage information corresponding to the alarm event, and terminate alarm events that are determined not to exist based on the alarm storage information.
[0093] For example, since not all alarm events require processing, some minor alarm events that do not affect normal operation can be ignored. Therefore, when an alarm event is detected in the system, it can first pass through tmp filtering, then through uwork filtering (uwork is a custom filtering method), and finally reach the AAA system to filter out events that do not require processing. The tmp file consists of temporary files generated by various software or systems and can be deleted through tmp file cleanup to ensure proper system operation. The AAA system, short for Authentication, Authorization, and Accounting, is a network security management mechanism that provides authentication, authorization, and accounting security functions.
[0094] Since alarms are stored after they are triggered, the stored content may not be found for some reason. In this case, a query can be performed to determine if the alarm still exists. Only alarms that still exist need to be processed. That is, after contacting the AAA system, the alarm record can be queried. If the query fails, it means that the alarm no longer exists, and the process can end. If the query succeeds, it means that the alarm still exists and needs to be processed. This involves retrieving the target service to which the alarm event belongs, and determining the target alarm module to which the target service belongs and the target alarm type corresponding to the target alarm module based on the alarm processing configuration information.
[0095] S203. Based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, determine whether the current alarm event needs to be intercepted, and obtain the interception determination result.
[0096] For example, through the steps described in step S202, the alarm module can be fully verified and judged to ensure the accuracy and effectiveness of alarm processing. Then, the step of determining alarm interception can be entered, that is, obtaining the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event. If the historical alarm count is less than the processing threshold, it means that the current alarm event does not need to be intercepted; if the historical alarm count is greater than or equal to the processing threshold, it means that the current alarm event needs to be intercepted.
[0097] S204. Based on the target processing tool information and the interception judgment result, generate the target alarm processing strategy corresponding to the alarm event, and process the alarm event based on the target alarm processing strategy.
[0098] For example, after obtaining the target processing tool information and the interception judgment result, the target alarm processing strategy corresponding to the alarm event can be generated, and the alarm event can be processed based on the target alarm processing strategy, thereby realizing alarm self-healing.
[0099] Optionally, in one embodiment, the step of "generating a target alarm handling strategy corresponding to the alarm event based on the target processing tool information and the interception determination result, and processing the alarm event based on the target alarm handling strategy" may include:
[0100] If the alarm event is determined to need to be blocked based on the blocking judgment result, the blocking operation is performed on the alarm event;
[0101] If the alarm event is determined not to need to be blocked based on the interception judgment result, a target alarm handling strategy corresponding to the alarm event is generated based on the target processing tool information, and the alarm event is processed based on the target alarm handling strategy.
[0102] For example, alarms can be blocked according to the configured blocking policy to prevent alarm information that does not conform to the policy from spreading. Then, it can be determined whether to silence the alarm. Silent alarms will no longer trigger subsequent processing.
[0103] Optionally, in one embodiment, after the step "processing alarm events based on the target alarm processing strategy", the following may also be included:
[0104] If the script determines that the intercepted alarm event has been recovered, it generates the target alarm handling policy corresponding to the alarm event based on the target handling tool information, and processes the alarm event based on the target alarm handling policy.
[0105] For example, a script can be invoked to determine whether the alarm has been recovered. Once recovered, the alarm will re-enter the processing flow. Based on the alarm interception logic described above, the system will obtain the interception results. If a silent alarm or an alarm is not blocked is triggered based on the interception results, the system will send a standalone alarm message to the user so that the user can be informed of the alarm status in a timely manner.
[0106] Optionally, in one embodiment, after the step "processing alarm events based on the target alarm processing strategy", the following may also be included:
[0107] Store the target alarm handling policy corresponding to the alarm event, and asynchronously send the target alarm handling policy corresponding to the alarm event to the user.
[0108] For example, in order to promptly notify users of the current status of the system, alarm events and their corresponding target alarm handling strategies can be sent to users asynchronously.
[0109] Optionally, in one embodiment, the alarm processing method may further include:
[0110] Based on the alarm configuration information and the target alarm handling strategy corresponding to the alarm event, the alarm data analysis interface is displayed. The alarm data analysis interface includes at least one of the following charts:
[0111] The access overview chart includes the number of alarm modules and alarm rules accessed by different business groups;
[0112] Alarm analysis quantity trend chart, including the number of alarm analyses performed by different businesses at different times;
[0113] Alarm blocking rate trend chart, including the alarm blocking situation of different services at different times;
[0114] A trend chart showing the proportion of alarms blocked based on specific business characteristics at different times.
[0115] For example, the alarm data analysis interface can be used to display the performance and effectiveness of the alarm interception and self-healing system in different business scenarios. The access overview chart, using bar charts showing the number of modules and rules connected to the alarm interception and self-healing system in different groups, allows users to understand the usage and scale of different groups, facilitating better resource allocation and management. The alarm analysis quantity trend chart, showing the alarm analysis quantity trend of different businesses, allows users to understand the alarm analysis situation of different businesses, providing a better understanding of business status and trends. The alarm interception ratio trend chart, showing the alarm interception ratio trend of different businesses, allows users to understand the alarm interception situation of different businesses, providing a better understanding of alarm processing effectiveness and quality. The feature alarm interception ratio trend chart, showing the feature alarm interception ratio trend of different businesses, allows users to understand the alarm interception situation of different business features, providing a better understanding of business characteristics and alarm processing effectiveness. Through these charts, users can better understand the usage and effectiveness of the alarm interception and self-healing system, enabling better management and optimization, and improving alarm processing efficiency and quality.
[0116] In one embodiment, such as Figure 10 As shown, this alarm handling method also supports users to search by username, whether it has been blocked, or alarm keywords. After retrieving data that meets the requirements, the data can be extracted from the database and aggregated for display. The displayed content may include module name, IP, data center, alarm content, analysis results, blocking results, specific alarm time, etc.
[0117] Existing alarm systems typically employ a workflow-driven approach, acquiring real-time data through data reporting and then processing it in real-time using streaming computing. When the data meets preset alarm conditions, the system immediately issues an alarm. However, this functionality only meets the basic needs of operations and maintenance personnel to understand the current network situation. They still need to expend significant manpower to process alarms one by one. This process includes not only alarm handling and convergence but also the tedious task of repeatedly collecting and recurring alarms, thus continuously increasing system maintenance costs.
[0118] The technical solution presented in this application enables a high degree of automation in the alarm handling process, ensuring that alarms from each connected network cluster are processed according to a predetermined workflow, including alarm analysis, alarm handling, alarm interception, and alarm forwarding. Furthermore, this technical solution supports highly efficient customization of alarm analysis logic for specific scenarios. Operations personnel can customize corresponding configuration information based on the characteristics of current business needs, better adapting to changes and requirements, and achieving more accurate alarm self-healing and interception. Simultaneously, applying this technical solution systematizes operational experience. By leveraging the mature operational experience of operations personnel in the current network, a systematic framework is gradually formed during the system's continuous evolution. This allows newcomers to quickly and effectively grasp key learning points, thereby improving operational efficiency.
[0119] Furthermore, this technical solution provides a user-friendly interface, allowing users to directly input configuration information and clearly view the current system's alarm status, facilitating centralized management of different services. Moreover, by collecting alarm self-healing interception data from various dimensions and displaying it in rich chart formats, this solution enables sustainable system operation. In this way, operations and maintenance personnel can analyze and investigate scenarios that do not meet expectations, identify problems and bottlenecks in the business alarm handling process, and then add analysis, forwarding, or interception logic as needed. This technical solution also enables cluster-level management, capable of handling alarm events on multiple nodes or servers simultaneously.
[0120] As can be seen from the above, this embodiment can obtain alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information. When an alarm event is detected in the system, the target business to which the alarm event belongs is obtained, and the target alarm module to which the target business belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module are determined according to the alarm processing configuration information. Based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, it is determined whether the current alarm event needs to be intercepted, and an interception determination result is obtained. Based on the target processing tool information and the interception determination result, a target alarm processing strategy corresponding to the alarm event is generated, and the alarm event is processed based on the target alarm processing strategy. This application combines real-time detection, automated decision-making, and automatic interception technologies to realize automated processing and interception of cluster alarms in the existing network, reducing the need for manual intervention and improving the stability, reliability, and efficiency of the system.
[0121] Based on the methods described in the preceding embodiments, the following will provide a more detailed explanation using the example of the alarm processing device being specifically integrated into an electronic device. This application provides an alarm processing method, such as... Figure 3 As shown, the specific process of this alarm handling method can be as follows:
[0122] S301. Electronic devices acquire alarm configuration information edited according to different business needs.
[0123] For example, such as Figure 8 As shown, the user access phase is mainly responsible for allowing users to customize appropriate alarm configuration information according to their needs and scenarios. This includes a series of configurations such as module selection, attribution selection, threshold selection, alarm type selection, and tool selection. Through these configurations, the system can automatically generate alarm rules and automatically complete alarm access.
[0124] S302. When an alarm event is detected in the system, the electronic device obtains the target service to which the alarm event belongs, and determines the target alarm module to which the target service belongs and the target alarm type corresponding to the target alarm module based on the alarm processing configuration information.
[0125] For example, such as Figure 8As shown, when an alarm event is detected in the system, the alarm event can be filtered first to remove alarm events that do not require processing. After filtering, the alarm is sent to the AAA system. Then, the storage information corresponding to the alarm event can be queried from the log records to determine whether the alarm event still exists. If the alarm event still exists, it can be determined whether the target alarm type includes the fault alarm type.
[0126] S303. If the target alarm type is determined to include a fault alarm type, the electronic device will send the alarm event to the callback result processor for event processing.
[0127] S304. If the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event can be obtained, the electronic device will send the alarm event and the preset analysis result to the callback result processor for event processing.
[0128] S305. If the target alarm type does not include the fault alarm type and the preset analysis result corresponding to the alarm event cannot be obtained, the electronic device determines the target processing tool information required for the target alarm type corresponding to the target alarm module based on the alarm processing configuration information.
[0129] For example, if the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event cannot be obtained, then it is necessary to obtain the corresponding analysis result through alarm analysis. That is, steps S305, S306, and S307 can be collectively referred to as the alarm analysis stage. Figure 9 As shown, the alarm analysis phase can be divided into two parts: a preprocessing phase and an interception phase. The preprocessing phase is mainly responsible for determining whether to configure blocking, calculating the configuration rules of the statistics module, executing tools to obtain analysis results, and counting the number of successful alarms based on the results. The interception phase blocks alarms according to the configured blocking policy, determines whether to silence the alarm, and calls scripts to determine whether to restore the alarm. Finally, based on the target processing tool information and the interception judgment results, a target alarm processing policy corresponding to the alarm event is generated. After the alarm process is completed, the alarm event and the corresponding target alarm processing policy can be sent to the user.
[0130] S306. The electronic device determines whether the current alarm event needs to be blocked based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, and obtains the interception determination result.
[0131] For example, after obtaining the interception determination result, the interception determination result can be persisted to the database and the user can be notified asynchronously.
[0132] S307. The electronic device generates a target alarm processing strategy corresponding to the alarm event based on the target processing tool information and the interception judgment result, and processes the alarm event based on the target alarm processing strategy.
[0133] S308: The electronic device displays an alarm data analysis interface based on the alarm configuration information and the target alarm handling strategy corresponding to the alarm event.
[0134] As can be seen from the above, this embodiment can obtain alarm configuration information edited according to different business needs through electronic devices; when an alarm event is detected in the system, the electronic device obtains the target business to which the alarm event belongs, and determines the target alarm module to which the target business belongs and the target alarm type corresponding to the target alarm module according to the alarm processing configuration information; if it is determined that the target alarm type includes a fault alarm type, the electronic device sends the alarm event to the callback result processor for event processing; if it is determined that the target alarm type does not include a fault alarm type, and the preset analysis result corresponding to the alarm event can be obtained, the electronic device sends the alarm event and the preset analysis result ... can be obtained, the electronic device sends the alarm event and the preset analysis result to the callback result processor for event processing; if it is determined that the target alarm type does not include a fault alarm type, and the preset analysis result can be obtained, the electronic device sends the alarm event and the preset analysis result to the callback result processor for event processing; if it is determined that the target alarm type does not include a fault alarm type, and the preset analysis result can be obtained, the electronic device sends the alarm event and the preset analysis result to the callback result processor for event processing; if it is determined that the target alarm type does not include a fault alarm type, and the preset analysis result can be obtained, the electronic device sends the alarm event and the preset analysis result to the callback result processor for event processing; if it The alarm types do not include fault alarm types, and the preset analysis results corresponding to the alarm events cannot be obtained. The electronic device determines the target processing tool information required for the target alarm type corresponding to the target alarm module based on the alarm processing configuration information. The electronic device determines whether the current alarm event needs to be intercepted based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, and obtains the interception judgment result. Based on the target processing tool information and the interception judgment result, the electronic device generates the target alarm processing strategy corresponding to the alarm event, and processes the alarm event based on the target alarm processing strategy. The electronic device displays the alarm data analysis interface based on the alarm configuration information and the target alarm processing strategy corresponding to the alarm event. This application combines real-time detection, automated decision-making, and automatic interception technologies to realize the automated processing and interception of cluster alarms in the existing network, reducing the need for manual intervention and improving the stability, reliability, and efficiency of the system.
[0135] Based on the methods described in the preceding embodiments, the following embodiments provide an alarm processing system, such as... Figure 7 As shown, the alarm processing system can be specifically structured as follows:
[0136] The entire alarm handling system is divided into a client, a business layer, an operation support layer, a service application layer, a data layer, a database, and an operating environment.
[0137] The client is responsible for user access and can provide users with multiple access methods, including PC, APP, and H5. These clients can meet the needs of different users and enable users to interact with the system conveniently.
[0138] The business layer provides the system's external API interfaces, including alarm services, configuration services, data services, and analysis services. The alarm service handles various alarm messages; the configuration service assists users in customizing system settings; the data service provides data storage and retrieval capabilities; and the analysis service processes and analyzes the data to provide valuable information to users.
[0139] The runtime support layer primarily provides HTTP / DNS and CDN acceleration functions. HTTP / DNS is the infrastructure used to process user requests, ensuring that user requests are processed quickly and accurately; while CDN acceleration can improve system access speed and enhance user experience.
[0140] The service application layer is the core layer providing system functionality, responsible for offering a range of functions including data statistics, alarm analysis, single-machine alarm access, business alarm access, daily report push, data synchronization, inspection, and configuration center. The operation records of these core functions are logged for subsequent analysis and optimization.
[0141] The data layer sits between the service and the database, acting as an intermediary layer. Its primary responsibilities include providing data caching, database read / write operations, read / write caching, cache expiration control, and message broker functionality. Through these functions, the data layer effectively improves data processing efficiency and speed while ensuring data consistency and reliability.
[0142] Throughout the system, user authentication is involved in all interactions between the client, business layer, operation support layer, service application layer, and data layer. User authentication is a security mechanism designed to ensure data security and system stability. By implementing user authentication, the system can effectively prevent unauthorized access and operations, protecting data security. Furthermore, user authentication helps system administrators manage user behavior and promptly identify and address potential security issues.
[0143] The database layer is responsible for providing persistent storage of data to ensure data security and stability. This layer includes various database technologies such as Redis, MySQL, MongoDB, and Elasticsearch (ES). These databases each have different characteristics and advantages, and can be flexibly selected and combined according to the system's needs.
[0144] The service is primarily deployed on cloud servers. Cloud servers offer advantages such as high availability, scalability, and flexibility, allowing for rapid adjustment and expansion based on the system's actual needs.
[0145] To better implement the above methods, this application also provides an alarm processing device, such as... Figure 11 As shown, the alarm processing device may include a first acquisition unit 1101, a second acquisition unit 1102, an interception unit 1103, and a processing unit 1104, as follows:
[0146] The first acquisition unit 1101 is used to acquire alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information.
[0147] The second acquisition unit 1102 is used to acquire the target service to which the alarm event belongs when an alarm event is detected in the system, and to determine the target alarm module to which the target service belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module according to the alarm processing configuration information.
[0148] The interception unit 1103 is used to determine whether the current alarm event needs to be intercepted based on the processing threshold in the alarm interception configuration information and the number of historical alarms corresponding to the alarm event, and to obtain an interception determination result;
[0149] The processing unit 1104 is used to generate a target alarm processing strategy corresponding to the alarm event based on the target processing tool information and the interception determination result, and to process the alarm event based on the target alarm processing strategy.
[0150] Optionally, in some embodiments of this application, the second acquisition unit may be specifically used to acquire the target service to which the alarm event belongs, and determine the target alarm module to which the target service belongs based on the alarm processing configuration information; determine whether the target alarm module is in a blocking period based on the alarm configuration information; if the target alarm module is in a blocking period, suspend alarm processing; if the target alarm module is not in a blocking period, detect whether the device corresponding to the alarm event is disabled through a scheduling check operation, and obtain the detection result; if the detection result shows that the device is in a disabled state, no alarm processing is performed; if the detection result shows that the device is not in a disabled state, determine the target processing tool information required to process the target alarm type corresponding to the target alarm module based on the alarm processing configuration information.
[0151] Optionally, in some embodiments of this application, the second acquisition unit may include a first acquisition subunit and a sending subunit, as follows:
[0152] The first acquisition subunit is used to acquire the target service to which the alarm event belongs when an alarm event is detected in the system, and to determine the target alarm module to which the target service belongs and the target alarm type corresponding to the target alarm module according to the alarm processing configuration information.
[0153] The sending subunit is used to send the alarm event to the callback result processor for event processing if it is determined that the target alarm type includes a fault alarm type;
[0154] If it is determined that the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event can be obtained, the alarm event and the preset analysis result are sent to the callback result processor for event processing.
[0155] If it is determined that the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event cannot be obtained, the target processing tool information required to process the target alarm type corresponding to the target alarm module is determined according to the alarm processing configuration information.
[0156] Optionally, in some embodiments of this application, the second acquisition unit may further include a filtering subunit and a query subunit, as follows:
[0157] The filtering subunit is used to filter out events that do not need to be processed from the alarm events when an alarm event is detected in the system, and update the alarm events based on the filtering results.
[0158] The query subunit is used to query the alarm storage information corresponding to the alarm event and end the alarm event that is determined to be non-existent based on the alarm storage information.
[0159] Optionally, in some embodiments of this application, the processing unit may be specifically used to perform an interception operation on the alarm event if it is determined based on the interception determination result that the alarm event needs to be intercepted; if it is determined based on the interception determination result that the alarm event does not need to be intercepted, generate a target alarm processing strategy corresponding to the alarm event based on the target processing tool information, and process the alarm event based on the target alarm processing strategy.
[0160] Optionally, in some embodiments of this application, the processing unit may be specifically used to generate a target alarm processing strategy corresponding to the alarm event based on the target processing tool information if the script determines that the intercepted alarm event has been recovered, and process the alarm event based on the target alarm processing strategy.
[0161] Optionally, in some embodiments of this application, the first acquisition unit may be specifically used to display an alarm configuration management interface, which includes alarm modules belonging to different services and alarm rules corresponding to different services. The alarm rules include one or more alarm types corresponding to the alarm module and processing tools required to process each alarm type.
[0162] Optionally, in some embodiments of this application, the first acquisition unit may be specifically used to pop up an alarm configuration management sub-interface corresponding to the specific service on the alarm configuration management interface when a hover operation for a specific service is detected on the alarm configuration management interface. The alarm configuration management sub-interface includes one or more alarm types corresponding to the specific service, as well as processing tools required to process each alarm type.
[0163] Optionally, in some embodiments of this application, the processing unit may be specifically used to store the target alarm processing strategy corresponding to the alarm event and asynchronously send the target alarm processing strategy corresponding to the alarm event to the user.
[0164] Optionally, in some embodiments of this application, the processing unit may be specifically used to display an alarm data analysis interface based on the alarm configuration information and the target alarm processing strategy corresponding to the alarm event. The alarm data analysis interface includes at least one of the following charts: an access overview chart, including the number of alarm modules and alarm rules accessed by different service groups; an alarm analysis quantity trend chart, including the number of alarm analyses performed by different services at different times; an alarm interception ratio trend chart, including the alarm interception situation generated by different services at different times; and a feature alarm interception ratio trend chart, including the alarm interception situation generated by different service features at different times.
[0165] As can be seen from the above, this embodiment can obtain alarm configuration information edited according to different business requirements through the first acquisition unit 1101. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information. When an alarm event is detected in the system, the target business to which the alarm event belongs is obtained through the second acquisition unit 1102, and the target alarm module to which the target business belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module are determined according to the alarm processing configuration information. The interception unit 1103 determines whether the current alarm event needs to be intercepted based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, and obtains the interception determination result. The processing unit 1104 generates the target alarm processing strategy corresponding to the alarm event based on the target processing tool information and the interception determination result, and processes the alarm event based on the target alarm processing strategy. This application combines real-time detection, automated decision-making, and automatic interception technologies to achieve automated processing and interception of cluster alarms in the existing network, reducing the need for manual intervention and improving the stability, reliability, and efficiency of the system.
[0166] This application also provides an electronic device, such as... Figure 12 The diagram shows a structural schematic of an electronic device involved in an embodiment of this application. This electronic device can be a terminal or a server, specifically:
[0167] The electronic device may include components such as a processor 1201 with one or more processing cores, a memory 1202 with one or more computer-readable storage media, a power supply 1203, and an input unit 1204. Those skilled in the art will understand that... Figure 12 The electronic device structure shown does not constitute a limitation on the electronic device and may include more or fewer components than shown, or combine certain components, or have different component arrangements. Wherein:
[0168] The processor 1201 is the control center of the electronic device, connecting various parts of the device via various interfaces and lines. It executes software programs and / or modules stored in the memory 1202, and calls data stored in the memory 1202 to perform various functions and process data. Optionally, the processor 1201 may include one or more processing cores; preferably, the processor 1201 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 1201.
[0169] The memory 1202 can be used to store software programs and modules. The processor 1201 executes various functional applications and data processing by running the software programs and modules stored in the memory 1202. The memory 1202 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device, etc. In addition, the memory 1202 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory 1202 may also include a memory controller to provide the processor 1201 with access to the memory 1202.
[0170] The electronic device also includes a power supply 1203 that supplies power to various components. Preferably, the power supply 1203 can be logically connected to the processor 1201 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The power supply 1203 may also include one or more DC or AC power supplies, recharging systems, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components.
[0171] The electronic device may also include an input unit 1204, which can be used to receive input digital or character information and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control.
[0172] Although not shown, the electronic device may also include a display unit, etc., which will not be described in detail here. Specifically, in this embodiment, the processor 1201 in the electronic device loads the executable files corresponding to the processes of one or more application programs into the memory 1202 according to the following instructions, and the processor 1201 runs the application programs stored in the memory 1202 to realize various functions, as follows:
[0173] This application provides an alarm processing method and related equipment. It can acquire alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information. When an alarm event is detected in the system, the target business to which the alarm event belongs is acquired, and the target alarm module to which the target business belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module are determined according to the alarm processing configuration information. Based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, it is determined whether the current alarm event needs to be intercepted, and an interception determination result is obtained. Based on the target processing tool information and the interception determination result, a target alarm processing strategy corresponding to the alarm event is generated, and the alarm event is processed based on the target alarm processing strategy.
[0174] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0175] As can be seen from the above, this embodiment can obtain alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information. When an alarm event is detected in the system, the target business to which the alarm event belongs is obtained, and the target alarm module to which the target business belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module are determined according to the alarm processing configuration information. Based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, it is determined whether the current alarm event needs to be intercepted, and an interception determination result is obtained. Based on the target processing tool information and the interception determination result, a target alarm processing strategy corresponding to the alarm event is generated, and the alarm event is processed based on the target alarm processing strategy. This application combines real-time detection, automated decision-making, and automatic interception technologies to realize automated processing and interception of cluster alarms in the existing network, reducing the need for manual intervention and improving the stability, reliability, and efficiency of the system.
[0176] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be performed by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0177] Therefore, embodiments of this application provide a computer-readable storage medium storing a plurality of instructions that can be loaded by a processor to execute steps in any of the alarm processing methods provided in embodiments of this application. For example, the instructions can execute the following steps:
[0178] This application provides an alarm processing method and related equipment. It can acquire alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information. When an alarm event is detected in the system, the target business to which the alarm event belongs is acquired, and the target alarm module to which the target business belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module are determined according to the alarm processing configuration information. Based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, it is determined whether the current alarm event needs to be intercepted, and an interception determination result is obtained. Based on the target processing tool information and the interception determination result, a target alarm processing strategy corresponding to the alarm event is generated, and the alarm event is processed based on the target alarm processing strategy.
[0179] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0180] The computer-readable storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0181] Since the instructions stored in the computer-readable storage medium can execute the steps in any of the alarm processing methods provided in the embodiments of this application, the beneficial effects that any of the alarm processing methods provided in the embodiments of this application can achieve can be realized. For details, please refer to the previous embodiments, which will not be repeated here.
[0182] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the various alternative implementations of the alarm handling described above.
[0183] The above provides a detailed description of an alarm processing method and related equipment provided by the embodiments of this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. An alarm processing method, characterized in that, include: Obtain alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information. When an alarm event is detected in the system, the target service to which the alarm event belongs is obtained, and the target alarm module to which the target service belongs, as well as the target processing tool information required to process the target alarm type corresponding to the target alarm module, are determined according to the alarm processing configuration information. Based on the processing threshold in the alarm interception configuration information and the historical alarm count corresponding to the alarm event, determine whether the current alarm event needs to be intercepted, and obtain the interception determination result; Based on the target processing tool information and the interception determination result, a target alarm processing strategy corresponding to the alarm event is generated, and the alarm event is processed based on the target alarm processing strategy.
2. The alarm processing method according to claim 1, characterized in that, The step of obtaining the target service to which the alarm event belongs, and determining the target alarm module to which the target service belongs, and the target processing tool information required to process the target alarm type corresponding to the target alarm module, based on the alarm processing configuration information, includes: Obtain the target service to which the alarm event belongs, and determine the target alarm module to which the target service belongs based on the alarm processing configuration information; Based on the alarm configuration information, determine whether the target alarm module is in a blocking period. If the target alarm module is in a blocking period, suspend alarm processing. If the target alarm module is not in a blocking period, the device corresponding to the alarm event is checked by a scheduling check operation to determine whether it is disabled, and the detection result is obtained. If the detection result indicates that the device is disabled, no alarm will be triggered. If the detection result indicates that the device is not disabled, the target processing tool information required to process the target alarm type corresponding to the target alarm module is determined according to the alarm processing configuration information.
3. The alarm processing method according to claim 1, characterized in that, The step of obtaining the target service to which the alarm event belongs, and determining the target alarm module to which the target service belongs, and the target processing tool information required to process the target alarm type corresponding to the target alarm module, based on the alarm processing configuration information, further includes: When an alarm event is detected in the system, the target service to which the alarm event belongs is obtained, and the target alarm module to which the target service belongs and the target alarm type corresponding to the target alarm module are determined according to the alarm processing configuration information. If it is determined that the target alarm type includes a fault alarm type, the alarm event is sent to the callback result processor for event processing; If it is determined that the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event can be obtained, the alarm event and the preset analysis result are sent to the callback result processor for event processing. If it is determined that the target alarm type does not include the fault alarm type, and the preset analysis result corresponding to the alarm event cannot be obtained, the target processing tool information required to process the target alarm type corresponding to the target alarm module is determined according to the alarm processing configuration information.
4. The alarm processing method according to claim 3, characterized in that, Before obtaining the target service to which the alarm event belongs, and determining the target alarm module to which the target service belongs and the target alarm type corresponding to the target alarm module based on the alarm processing configuration information, the method further includes: When an alarm event is detected in the system, events that do not require processing are filtered out from the alarm events, and the alarm events are updated based on the filtering results; Query the alarm storage information corresponding to the alarm event, and terminate the alarm event that was determined to be non-existent based on the alarm storage information.
5. The alarm processing method according to claim 1, characterized in that, The step of generating a target alarm processing strategy corresponding to the alarm event based on the target processing tool information and the interception determination result, and processing the alarm event based on the target alarm processing strategy, includes: If the alarm event needs to be intercepted based on the interception determination result, the alarm event is intercepted. If the alarm event is determined not to need to be intercepted based on the interception determination result, a target alarm processing strategy corresponding to the alarm event is generated based on the target processing tool information, and the alarm event is processed based on the target alarm processing strategy.
6. The alarm processing method according to claim 5, characterized in that, After processing the alarm event based on the target alarm processing strategy, the method further includes: If the script determines that the intercepted alarm event has been recovered, it generates a target alarm processing strategy corresponding to the alarm event based on the target processing tool information, and processes the alarm event based on the target alarm processing strategy.
7. The alarm processing method according to claim 1, characterized in that, After obtaining the alarm configuration information edited according to different business needs, the process also includes: The alarm configuration management interface is displayed. The alarm configuration management interface includes alarm modules belonging to different services and alarm rules corresponding to different services. The alarm rules include one or more alarm types corresponding to the alarm module and processing tools required to process each alarm type.
8. The alarm processing method according to claim 7, characterized in that, The method further includes: When a hover operation targeting a specific service is detected on the alarm configuration management interface, an alarm configuration management sub-interface corresponding to the specific service pops up on the alarm configuration management interface. The alarm configuration management sub-interface includes one or more alarm types corresponding to the specific service, as well as processing tools required to process each alarm type.
9. The alarm processing method according to claim 1, characterized in that, After processing the alarm event based on the target alarm processing strategy, the method further includes: Store the target alarm handling policy corresponding to the alarm event, and asynchronously send the target alarm handling policy corresponding to the alarm event to the user.
10. The alarm processing method according to claim 1, characterized in that, The method further includes: Based on the alarm configuration information and the target alarm handling strategy corresponding to the alarm event, an alarm data analysis interface is displayed, which includes at least one of the following charts: The access overview chart includes the number of alarm modules and alarm rules accessed by different business groups; Alarm analysis quantity trend chart, including the number of alarm analyses performed by different businesses at different times; Alarm blocking rate trend chart, including the alarm blocking situation of different services at different times; A trend chart showing the proportion of alarm interceptions based on specific business characteristics at different times.
11. An alarm processing device, characterized in that, include: The first acquisition unit is used to acquire alarm configuration information edited according to different business needs. The alarm configuration information includes alarm interception configuration information and alarm processing configuration information corresponding to different businesses. The alarm processing configuration information includes the alarm module to which each business belongs, one or more alarm types corresponding to the alarm module, and the mapping relationship between different alarm types and processing tool information. The second acquisition unit is used to acquire the target service to which the alarm event belongs when an alarm event is detected in the system, and to determine the target alarm module to which the target service belongs and the target processing tool information required to process the target alarm type corresponding to the target alarm module according to the alarm processing configuration information. The interception unit is used to determine whether the current alarm event needs to be intercepted based on the processing threshold in the alarm interception configuration information and the number of historical alarms corresponding to the alarm event, and to obtain an interception determination result; The processing unit is configured to generate a target alarm processing strategy corresponding to the alarm event based on the target processing tool information and the interception determination result, and process the alarm event based on the target alarm processing strategy.
12. An electronic device, characterized in that, It includes a memory and a processor; the memory stores an application program, and the processor runs the application program within the memory to perform the operations in the alarm processing method according to any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a plurality of instructions adapted for loading by a processor to perform the steps of the alarm processing method according to any one of claims 1 to 10.
14. A computer program product comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by the processor, they implement the steps of the alarm processing method according to any one of claims 1 to 10.