Call log processing method and device, equipment and medium
By grouping and aggregating call logs, and combining anomaly detection and root cause analysis, the call logs are processed automatically, solving the problems of high cost and low efficiency caused by manual operation, and achieving fast and accurate anomaly detection and cause determination.
Patent Information
- Application Number
- CN202511249353.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2025-11-18
AI Technical Summary
Existing log processing solutions rely on manual operation, which is costly in terms of time and manpower, inefficient, and difficult to guarantee in terms of accuracy.
By periodically acquiring call logs within a preset time window, grouping them according to the call process identifier, aggregating performance indicator data, using the anomaly detection module to detect anomalies, and using the root cause detection module to determine the primary and secondary anomaly causes, an anomaly detection report is generated.
It enables automated, rapid, and accurate detection of performance metrics data anomalies during the call process, reducing time and labor costs while improving processing efficiency and accuracy.
Smart Images

Figure CN120973586A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, and in particular, to a method and device for processing call logs, an apparatus and a medium. BACKGROUND
[0002] A business system of an enterprise usually has multiple services and multiple hosts. Each service can be a software module for implementing different business functions of the enterprise. In the running process of the business system, each service can call a host in the business system to perform a specified operation. After each service calls a host, the business system can record the calling process of the service calling the host by generating multiple different call logs for describing the calling process. Each call log can be a text for describing the calling process. Each call log belonging to the same calling process contains different performance indicator data. Each performance indicator data can be multiple parameters that can be used to evaluate whether the calling process is abnormal. The performance indicator data contained in each call log is counted by the business system in the calling process.
[0003] In related technologies, a commonly used call log processing scheme is that a technician regularly performs statistics and analysis on the call logs generated in the business system, aggregates each call log belonging to the same calling process, detects whether each performance indicator data of the calling process is abnormal, and determines the cause of the abnormality and a solution to the abnormality after determining that there is abnormal performance indicator data. The call log processing scheme in related technologies relies on manual operation, has high time cost and labor cost, is low in efficiency, and is difficult to ensure accuracy. SUMMARY
[0004] The present application provides a call log processing method, device, apparatus and medium to solve the problem that the call log processing scheme in related technologies relies on manual operation, has high time cost and labor cost, is low in efficiency, and is difficult to ensure accuracy.
[0005] According to an aspect of the present application, a call log processing method is provided, comprising:
[0006] regularly obtaining each call log in a preset time window, grouping each call log according to a calling process identifier in each call log, and obtaining multiple call log groups; wherein the call logs in each call log group belong to the same calling process;
[0007] aggregating the call logs in each call log group, and obtaining an aggregation result of each call log group; wherein the aggregation result of each call log group contains a calling process identifier of the calling process to which the call log group belongs and each performance indicator data;
[0008] The abnormality detection module detects whether each performance indicator data in the aggregation result is abnormal according to the same-time point indicator data of each performance indicator data in the aggregation result, and an abnormality mark corresponding to the abnormal performance indicator data is added in the aggregation result;
[0009] The root cause detection module determines the main abnormal cause and the secondary abnormal cause of the aggregation result according to the abnormal occurrence probability of each alternative abnormal cause, for each aggregation result with the abnormality mark;
[0010] The report providing unit determines the solution corresponding to the main abnormal cause and the secondary abnormal cause of the aggregation result, generates an abnormality detection report of the aggregation result, and provides the abnormality detection report to a target user, for each aggregation result with the abnormality mark.
[0011] According to another aspect of the present application, a call log processing device is provided, comprising:
[0012] The log grouping unit groups each call log according to the call process identifier in each call log, and obtains a plurality of call log groups, for each call log in a preset time window;
[0013] The log aggregation unit aggregates the call logs in each call log group, and obtains an aggregation result of each call log group; wherein the aggregation result of each call log group comprises the call process identifier of the call process to which the call log group belongs and each performance indicator data;
[0014] The log detection unit detects whether each performance indicator data in the aggregation result is abnormal according to the same-time point indicator data of each performance indicator data in the aggregation result, and an abnormality mark corresponding to the abnormal performance indicator data is added in the aggregation result, for each aggregation result;
[0015] The cause determination unit determines the main abnormal cause and the secondary abnormal cause of the aggregation result according to the abnormal occurrence probability of each alternative abnormal cause, for each aggregation result with the abnormality mark; wherein the abnormal occurrence probability of each alternative abnormal cause is the probability that each alternative abnormal cause causes the performance indicator data in the aggregation result to be abnormal;
[0016] The report providing unit determines the solution corresponding to the main abnormal cause and the secondary abnormal cause of the aggregation result, generates an abnormality detection report of the aggregation result, and provides the abnormality detection report to a target user, for each aggregation result with the abnormality mark.
[0017] According to another aspect of the present application, there is provided an electronic device comprising:
[0018] at least one processor;
[0019] and a memory connected to the at least one processor in communication;
[0020] wherein the memory stores a computer program to be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the call log processing method according to any one of the embodiments of the present application.
[0021] According to another aspect of the present application, there is provided a computer readable storage medium storing computer instructions for causing a processor to implement the call log processing method according to any one of the embodiments of the present application when executed by the processor.
[0022] According to another aspect of the present application, there is provided a computer program product comprising a computer program to implement the call log processing method according to any one of the embodiments of the present application when executed by a processor.
[0023] The technical scheme of the embodiment of the present application comprises the following steps: acquiring each calling log in a preset time window in a timely manner, grouping each calling log according to the calling process identifier in each calling log, and obtaining a plurality of calling log groups; wherein the calling logs in each calling log group belong to the same calling process; then, aggregating the calling logs in each calling log group, and obtaining the aggregation result of each calling log group; wherein the aggregation result of each calling log group comprises the calling process identifier of the calling process to which the calling log group belongs and each performance indicator data; for each aggregation result, detecting whether each performance indicator data in the aggregation result is abnormal according to the same time point indicator data of each performance indicator data in the aggregation result through an exception detection module, and adding an exception mark corresponding to the abnormal performance indicator data in the aggregation result; for each aggregation result with an exception mark, determining the main abnormal cause and the secondary abnormal cause of the aggregation result according to the abnormal occurrence probability of each alternative abnormal cause through a root cause detection module; wherein the abnormal occurrence probability of each alternative abnormal cause is the probability that each alternative abnormal cause causes the performance indicator data in the aggregation result to be abnormal; for each aggregation result with an exception mark, determining the solution corresponding to the main abnormal cause and the secondary abnormal cause of the aggregation result, generating an exception detection report of the aggregation result, and providing the exception detection report to a target user, thereby solving the problem in the related art that the calling log processing scheme relies on manual operation, the time cost and the labor cost are high, the efficiency is low, and the accuracy is difficult to guarantee, and the calling logs belonging to the same calling process can be automatically aggregated in a timely manner, whether each performance indicator data of the calling process is abnormal can be quickly and accurately detected based on the same time point indicator data, the main abnormal cause and the secondary abnormal cause that cause the performance indicator data of the calling process to be abnormal can be quickly and accurately determined based on the abnormal occurrence probability of each alternative abnormal cause after the performance indicator data with an exception is determined, and then the solution corresponding to the main abnormal cause and the secondary abnormal cause is determined to form an exception detection report provided to a target user, thereby realizing automatic and timely processing of the calling logs generated in a business system, aggregation of each calling log belonging to the same calling process, detection of whether each performance indicator data of the calling process is abnormal, determination of the cause that causes the abnormal performance indicator data after the abnormal performance indicator data is determined, and determination of the solution for processing the abnormal performance indicator data, thereby reducing the time cost and the labor cost of the calling log processing process, and improving the efficiency and the accuracy of the calling log processing process.
[0024] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiment description. Obviously, the drawings in the following description only show some embodiments of the present application, and other drawings can be obtained by those of ordinary skill in the art without any creative effort.
[0026] Figure 1 A flow chart of a calling log processing method provided for the first embodiment of the present application.
[0027] Figure 2 A flow chart of a calling log processing method provided for the second embodiment of the present application.
[0028] Figure 3 A structural schematic diagram of a calling log processing device provided for the third embodiment of the present application.
[0029] Figure 4 A structural schematic diagram of an electronic device for implementing the calling log processing method of the embodiments of the present application. DETAILED DESCRIPTION
[0030] In order to make the person skilled in the art better understand the present application, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without any creative effort should be within the scope of the present application.
[0031] It should be noted that the terms "target", "first", "second" and the like in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include", "contain" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device containing a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0032] Embodiment one
[0033] Figure 1A flowchart of a method for processing calling logs is provided for the first embodiment of the present application. The present embodiment can be applied to the case of processing calling logs generated in a business system of an enterprise. The method can be executed by a calling log processing apparatus, which can be implemented in the form of hardware and / or software, and can be configured in an electronic device arranged in the enterprise. The electronic device can be an electronic device arranged in the enterprise for processing calling logs generated in the business system of the enterprise. As shown in Figure 1 the method comprises:
[0034] Step 101: Obtain each calling log in a preset time window, group each calling log according to the calling process identifier in each calling log, and obtain a plurality of calling log groups.
[0035] Each calling log in each calling log group belongs to the same calling process.
[0036] Optionally, the business system of the enterprise can be a server for managing the business of the enterprise. The business system is provided with a plurality of services and a plurality of hosts. Each service can be a software module for implementing different business functions of the enterprise. The business functions include but are not limited to production process management functions and payment functions. The production process management function can refer to a function of managing the production process of the enterprise. The production process can refer to a process of producing a software product or a hardware product with specified functions. The payment function can refer to a function of obtaining fees provided by other enterprises or individuals for purchasing products. In the running process of the business system, each service can call the host in the business system to execute a specified operation. Each service is provided with identification information. The identification information of the service can be a string for uniquely identifying the service. Each host is provided with identification information. The identification information of the host can be a string for uniquely identifying the host.
[0037] Optionally, after each service invocation of the host, the business system generates a plurality of invocation logs for describing the invocation process. Each invocation log can be text for describing the invocation process. Each invocation log contains an invocation process identifier and a performance indicator data. The invocation process identifier can be information capable of identifying the invocation process to which the invocation log belongs. The invocation process to which the invocation log belongs is the invocation process described by the invocation log. The invocation process identifier can include an invocation timestamp, service identification information, and host identification information. The invocation timestamp can be a date value, an hour value, a minute value, and a second value of the time when the business system records the start of the invocation process. The service identification information can be identification information of the service that initiates the invocation process. The host identification information can be identification information of the host that is invoked. Each invocation log belonging to the same invocation process is a plurality of invocation logs for describing the same invocation process. The invocation process identifiers contained in each invocation log belonging to the same invocation process are the same. The performance indicator data contained in each invocation log belonging to the same invocation process is different. Each performance indicator data can be a plurality of parameters capable of evaluating whether the invocation process is abnormal. The performance indicator data contained in each invocation log is counted by the business system during the invocation process. The invocation log file can be a file for storing the invocation log. The business system can create an invocation log file for storing the invocation logs generated in the current date every day, and store the invocation logs generated in the current date into the invocation log file created in the current date.
[0038] Optionally, each performance indicator data capable of evaluating whether the invocation process is abnormal can include a central processing unit (CPU) utilization rate, a delay time, and a thread number. The CPU utilization rate can be the CPU utilization rate of the host that is invoked counted by the business system during the invocation process. The unit of the CPU utilization rate is %. The delay time can be the time consumed from the service requesting the host to the host responding to the invocation request counted by the business system during the invocation process. The unit of the delay time is millisecond. The thread number can be the total number of threads running in the host that is invoked counted by the business system during the invocation process. The unit of the thread number is piece. After each service invocation of the host, the business system generates three invocation logs for describing the invocation process. The invocation process identifiers contained in the three invocation logs are the same. The performance indicator data contained in the three invocation logs are different, which are the CPU utilization rate, the delay time, and the thread number, respectively.
[0039] Optionally, the call logs in the preset time window can be call logs whose call timestamps contained in the call log files created on the current date represent time points within a preset time period before the current time. The call logs in the preset time window are obtained in a timing manner, including: after the business system creates the call log files on the current date, performing the operation of obtaining the call logs whose call timestamps contained in the call logs stored in the call log files created on the current date represent time points within a preset time period before the current time every preset time period. The preset time period can be a preset time period. For example, the preset time period is 1 minute. After obtaining the call logs whose call timestamps contained in the call logs stored in the call log files created on the current date represent time points within a preset time period before the current time every time, the call logs are grouped according to the call process identifiers in the call logs to obtain a plurality of call log groups. Each call log group is composed of a plurality of call logs belonging to the same call process. If there is no call log whose call timestamp contained in the call log files created on the current date represents a time point within a preset time period before the current time, it is determined that the current obtaining process is ended, and the next obtaining process is waited to be performed.
[0040] Optionally, the call logs are grouped according to the call process identifiers in the call logs to obtain a plurality of call log groups, including: the call logs are grouped according to the call timestamps, service identifier information and host identifier information in the call logs to obtain a plurality of call log groups; wherein the call timestamps, service identifier information and host identifier information in the call logs in each call log group are the same.
[0041] Optionally, the call logs whose call timestamps, service identifier information and host identifier information contained in the call logs are the same are divided into a call log group to obtain at least one call log group. Each call log group contains three call logs. The call timestamps, service identifier information and host identifier information contained in the three call logs are the same. The call logs in each call log group belong to the same call process and are call logs for describing the same call process. The performance indicator data contained in the three call logs are different, and are CPU utilization, delay time and thread number respectively.
[0042] Step 102, aggregating the call logs in each call log group to obtain an aggregation result of each call log group.
[0043] The aggregation result of each call log group contains the call process identifier of the call process to which the call log group belongs and the performance indicator data.
[0044] Optionally, the call logs in each call log group are aggregated to obtain an aggregation result of each call log group, including: for each call log group, performing the following operations: extracting the call timestamp, service identification information and host identification information in any one of the call logs in the call log group; extracting the performance indicator data in each of the call logs in the call log group; and determining the extracted call timestamp, service identification information, host identification information and each performance indicator data as the aggregation result of the call log group.
[0045] Optionally, aggregating the call logs in the call log group can mean summarizing the call process identification and performance indicator data in the call logs in the call log group. The aggregation result of the call log group is information obtained by summarizing the call process identification and performance indicator data in the call logs in the call log group. The aggregation result of the call log group contains the call process identification of the call process to which the call log group belongs and each performance indicator data. The call process identification includes the call timestamp, service identification information and host identification information. Each performance indicator data includes CPU utilization, delay time and thread number.
[0046] Thus, each call log belonging to the same call process is aggregated to obtain the call timestamp, service identification information, host identification information and each performance indicator data of the call process.
[0047] Step 103, for each aggregation result, through the exception detection module, according to the same time point indicator data of each performance indicator data in the aggregation result, detecting whether each performance indicator data in the aggregation result is abnormal, and adding an exception mark corresponding to the abnormal performance indicator data in the aggregation result.
[0048] Optionally, the exception detection module can be a software module or a hardware module provided in the electronic device for detecting whether each performance indicator data of the call process is abnormal.
[0049] Optionally, for each aggregation result, the abnormality detection module detects whether each performance indicator data in the aggregation result is abnormal according to the same-time point indicator data of each performance indicator data in the aggregation result, and adds an abnormality mark corresponding to the abnormal performance indicator data in the aggregation result, including: for each aggregation result, the abnormality detection module performs the following operations: according to the same-time point indicator data of each performance indicator data in the aggregation result, determining the dynamic upper threshold and the dynamic lower threshold of each performance indicator data in the aggregation result; according to the dynamic upper threshold and the dynamic lower threshold of each performance indicator data in the aggregation result, detecting whether each performance indicator data in the aggregation result is abnormal; if the target performance indicator data is detected to be abnormal, adding an abnormality mark corresponding to the target performance indicator data in the aggregation result.
[0050] Optionally, according to the same-time point indicator data of each performance indicator data in the aggregation result, the dynamic upper threshold and the dynamic lower threshold of each performance indicator data in the aggregation result are determined, including: according to the same-time point indicator data of the CPU utilization in the aggregation result, the dynamic upper threshold and the dynamic lower threshold of the CPU utilization in the aggregation result are determined; according to the same-time point indicator data of the delay time in the aggregation result, the dynamic upper threshold and the dynamic lower threshold of the delay time in the aggregation result are determined; according to the same-time point indicator data of the thread number in the aggregation result, the dynamic upper threshold and the dynamic lower threshold of the thread number in the aggregation result are determined.
[0051] Optionally, the same-time point indicator data of the CPU utilization in the aggregation result can be the CPU utilization in each call log containing the CPU utilization and containing the same call timestamp, service identification information and host identification information as the call timestamp, service identification information and host identification information in the aggregation result, which is generated within n days before the current date. The same-time point indicator data of the CPU utilization in the aggregation result contains n CPU utilizations. n is an integer greater than or equal to 3. The same-time point indicator data of the CPU utilization in the aggregation result can be obtained from the call log file created within n days before the current date. For example, n is 7. The same-time point indicator data of the CPU utilization in the aggregation result is the CPU utilization in each call log containing the CPU utilization and containing the same call timestamp, service identification information and host identification information as the call timestamp, service identification information and host identification information in the aggregation result, which is generated within 7 days before the current date. The same-time point indicator data of the CPU utilization in the aggregation result can be obtained from the call log file created within 7 days before the current date. The same-time point indicator data of the CPU utilization in the aggregation result contains 7 CPU utilizations.
[0052] Optionally, the dynamic upper threshold and the dynamic lower threshold of the CPU utilization rate can be two values determined according to the same-time point index data of the CPU utilization rate, and used to measure whether the CPU utilization rate is abnormal. The dynamic upper threshold of the CPU utilization rate is greater than the dynamic lower threshold of the CPU utilization rate. Generally, when the CPU utilization rate is less than or equal to the dynamic upper threshold of the CPU utilization rate, and the CPU utilization rate is greater than or equal to the dynamic lower threshold of the CPU utilization rate, it can be determined that the CPU utilization rate is normal. When the CPU utilization rate is greater than the dynamic upper threshold of the CPU utilization rate or the CPU utilization rate is less than the dynamic lower threshold of the CPU utilization rate, it can be determined that the CPU utilization rate is abnormal.
[0053] Optionally, the dynamic upper threshold and the dynamic lower threshold of the CPU utilization rate in the aggregation result are determined according to the same-time point index data of the CPU utilization rate in the aggregation result, including: obtaining the same-time point index data of the CPU utilization rate in the aggregation result from the call log files created within n days before the current date; calculating the average value and the standard deviation of the n CPU utilization rates in the same-time point index data; determining the dynamic lower threshold of the CPU utilization rate in the aggregation result according to the calculated average value and the standard deviation; and determining the dynamic upper threshold of the CPU utilization rate in the aggregation result according to the calculated average value and the standard deviation.
[0054] Optionally, the average value of the n CPU utilization rates in the same-time point index data is calculated, including: using the following calculation formula to calculate the average value of the n CPU utilization rates in the same-time point index data: wherein μ c is the average value of the n CPU utilization rates in the same-time point index data, n is the total number of the CPU utilization rates in the same-time point index data, the n CPU utilization rates in the same-time point index data are arranged in the order of the dates from the front to the back, x ci is the CPU utilization rate arranged in the i-th position in the n CPU utilization rates in the same-time point index data, i = 1, 2, 3…n.
[0055] Optionally, the standard deviation of the n CPU utilization rates in the same-time point index data is calculated, including: using the following calculation formula to calculate the standard deviation of the n CPU utilization rates in the same-time point index data: wherein σ c is the standard deviation of the n CPU utilization rates in the same-time point index data, μ c is the average value of the n CPU utilization rates in the same-time point index data, n is the total number of the CPU utilization rates in the same-time point index data, the n CPU utilization rates in the same-time point index data are arranged in the order of the dates from the front to the back, x ciCPU utilization ranked at the i-th position in the n CPU utilizations in the same point in time indicator data, i = 1, 2, 3,... n.
[0056] Optionally, the dynamic threshold lower limit of the CPU utilization in the aggregation result is determined according to the calculated mean value and standard deviation, including: using the following calculation formula, calculating the dynamic threshold lower limit of the CPU utilization in the aggregation result: M c0 = μ c - 3 * σ c ; wherein, M c0 is the dynamic threshold lower limit of the CPU utilization in the aggregation result, μ c is the mean value of the n CPU utilizations in the same point in time indicator data of the CPU utilization in the aggregation result, and σ c is the standard deviation of the n CPU utilizations in the same point in time indicator data of the CPU utilization in the aggregation result.
[0057] Optionally, the dynamic threshold upper limit of the CPU utilization in the aggregation result is determined according to the calculated mean value and standard deviation, including: using the following calculation formula, calculating the dynamic threshold upper limit of the CPU utilization in the aggregation result: M c1 = μ c + 3 * σ c ; wherein, M c1 is the dynamic threshold upper limit of the CPU utilization in the aggregation result, μ c is the mean value of the n CPU utilizations in the same point in time indicator data of the CPU utilization in the aggregation result, and σ c is the standard deviation of the n CPU utilizations in the same point in time indicator data of the CPU utilization in the aggregation result.
[0058] Optionally, in one specific example, n is 7, the same point in time indicator data of the CPU utilization in the aggregation result contains 7 CPU utilizations, which are: 70, 72, 71, 73, 74, 70, 72. The unit of the CPU utilization is %. The mean value of the n CPU utilizations in the same point in time indicator data of the CPU utilization in the aggregation result is 71.7 (rounded to one decimal place). The standard deviation of the n CPU utilizations in the same point in time indicator data of the CPU utilization in the aggregation result is 1.5 (rounded to one decimal place). The dynamic threshold lower limit of the CPU utilization in the aggregation result is 67.2. The dynamic threshold upper limit of the CPU utilization in the aggregation result is 76.2.
[0059] Optionally, the same-time-point indicator data of the delay time in the aggregation result can refer to the delay time in each of the call logs generated within n days before the current date and containing the delay time and the calling timestamp, the service identification information, and the host identification information same as the calling timestamp, the service identification information, and the host identification information in the aggregation result. The same-time-point indicator data of the delay time in the aggregation result contains n delay times. n is an integer greater than or equal to 3. The same-time-point indicator data of the delay time in the aggregation result can be obtained from the call log files created within n days before the current date. For example, n is 7. The same-time-point indicator data of the delay time in the aggregation result refers to the delay time in each of the call logs generated within 7 days before the current date and containing the delay time and the calling timestamp, the service identification information, and the host identification information same as the calling timestamp, the service identification information, and the host identification information in the aggregation result. The same-time-point indicator data of the delay time in the aggregation result can be obtained from the call log files created within 7 days before the current date. The same-time-point indicator data of the delay time in the aggregation result contains 7 delay times.
[0060] Optionally, the dynamic upper threshold and the dynamic lower threshold of the delay time can be two values determined according to the same-time-point indicator data of the delay time for measuring whether the delay time is abnormal. The dynamic upper threshold of the delay time is greater than the dynamic lower threshold of the delay time. Generally, when the delay time is less than or equal to the dynamic upper threshold of the delay time and the delay time is greater than or equal to the dynamic lower threshold of the delay time, it can be determined that the delay time is normal. When the delay time is greater than the dynamic upper threshold of the delay time or the delay time is less than the dynamic lower threshold of the delay time, it can be determined that the delay time is abnormal.
[0061] Optionally, according to the same-time-point indicator data of the delay time in the aggregation result, determining the dynamic upper threshold and the dynamic lower threshold of the delay time in the aggregation result includes: obtaining the same-time-point indicator data of the delay time in the aggregation result from the call log files created within n days before the current date; calculating the average value and the standard deviation of the n delay times in the same-time-point indicator data; determining the dynamic lower threshold of the delay time in the aggregation result according to the calculated average value and the standard deviation; and determining the dynamic upper threshold of the delay time in the aggregation result according to the calculated average value and the standard deviation.
[0062] Optionally, calculating the average value of the n delay times in the same-time-point indicator data includes: using the following calculation formula to calculate the average value of the n delay times in the same-time-point indicator data: wherein μ yis an average value of n delay times in the same time point index data, n is a total number of the delay times in the same time point index data, the n delay times in the same time point index data are arranged in a sequence from early to late according to the belonging date, x yi is the i-th delay time in the n delay times in the same time point index data, i = 1, 2, 3…n.
[0063] Optionally, a standard deviation of the n delay times in the same time point index data is calculated, including: using the following calculation formula, calculating the standard deviation of the n delay times in the same time point index data: wherein, σ y is the standard deviation of the n delay times in the same time point index data, μ y is an average value of n delay times in the same time point index data, n is a total number of the delay times in the same time point index data, the n delay times in the same time point index data are arranged in a sequence from early to late according to the belonging date, x yi is the i-th delay time in the n delay times in the same time point index data, i = 1, 2, 3…n.
[0064] Optionally, according to the calculated average value and the standard deviation, a dynamic threshold lower limit of the delay time in the aggregation result is determined, including: using the following calculation formula, calculating the dynamic threshold lower limit of the delay time in the aggregation result: M y0 = μ y - 3 * σ y ; wherein, M y0 is the dynamic threshold lower limit of the delay time in the aggregation result, μ y is the average value of the n delay times in the same time point index data of the delay time in the aggregation result, σ y is the standard deviation of the n delay times in the same time point index data of the delay time in the aggregation result.
[0065] Optionally, according to the calculated average value and the standard deviation, a dynamic threshold upper limit of the delay time in the aggregation result is determined, including: using the following calculation formula, calculating the dynamic threshold upper limit of the delay time in the aggregation result: M y1 = μ y + 3 * σ y ; wherein, M y1 is the dynamic threshold upper limit of the delay time in the aggregation result, μ y is the average value of the n delay times in the same time point index data of the delay time in the aggregation result, σ y is the standard deviation of the n delay times in the same time point index data of the delay time in the aggregation result.
[0066] Optionally, the same-time-point indicator data of the thread quantity in the aggregation result can refer to the thread quantity in each of the call logs generated within n days before the current date and containing the thread quantity and the same call time stamp, service identification information, and host identification information as the call time stamp, service identification information, and host identification information in the aggregation result. The same-time-point indicator data of the thread quantity in the aggregation result contains n thread quantities. n is an integer greater than or equal to 3. The same-time-point indicator data of the thread quantity in the aggregation result can be obtained from the call log files created within n days before the current date. For example, n is 7. The same-time-point indicator data of the thread quantity in the aggregation result refers to the thread quantity in each of the call logs generated within 7 days before the current date and containing the thread quantity and the same call time stamp, service identification information, and host identification information as the call time stamp, service identification information, and host identification information in the aggregation result. The same-time-point indicator data of the thread quantity in the aggregation result can be obtained from the call log files created within 7 days before the current date. The same-time-point indicator data of the thread quantity in the aggregation result contains 7 thread quantities.
[0067] Optionally, the dynamic upper threshold and the dynamic lower threshold of the thread quantity can be two values determined according to the same-time-point indicator data of the thread quantity for measuring whether the thread quantity is abnormal. The dynamic upper threshold of the thread quantity is greater than the dynamic lower threshold of the thread quantity. Generally, when the thread quantity is less than or equal to the dynamic upper threshold of the thread quantity and the thread quantity is greater than or equal to the dynamic lower threshold of the thread quantity, it can be determined that the thread quantity is normal. When the thread quantity is greater than the dynamic upper threshold of the thread quantity or the thread quantity is less than the dynamic lower threshold of the thread quantity, it can be determined that the thread quantity is abnormal.
[0068] Optionally, according to the same-time-point indicator data of the thread quantity in the aggregation result, determining the dynamic upper threshold and the dynamic lower threshold of the thread quantity in the aggregation result includes: obtaining the same-time-point indicator data of the thread quantity in the aggregation result from the call log files created within n days before the current date; calculating the average value and the standard deviation of the n thread quantities in the same-time-point indicator data; determining the dynamic lower threshold of the thread quantity in the aggregation result according to the calculated average value and the standard deviation; and determining the dynamic upper threshold of the thread quantity in the aggregation result according to the calculated average value and the standard deviation.
[0069] Optionally, calculating the average value of the n thread quantities in the same-time-point indicator data includes: using the following calculation formula to calculate the average value of the n thread quantities in the same-time-point indicator data: wherein μ xis an average value of the n thread quantities in the same time point index data, n is a total number of thread quantities in the same time point index data, the n thread quantities in the same time point index data are arranged in a sequence from early to late according to the dates to which the n thread quantities belong, x xi is the thread quantity arranged in the i-th position in the n thread quantities in the same time point index data, i = 1, 2, 3…n.
[0070] Optionally, a standard deviation of the n thread quantities in the same time point index data is calculated, including: using the following calculation formula, calculating the standard deviation of the n thread quantities in the same time point index data: wherein, σ x is a standard deviation of the n thread quantities in the same time point index data, μ x is an average value of the n thread quantities in the same time point index data, n is a total number of thread quantities in the same time point index data, the n thread quantities in the same time point index data are arranged in a sequence from early to late according to the dates to which the n thread quantities belong, x xi is the thread quantity arranged in the i-th position in the n thread quantities in the same time point index data, i = 1, 2, 3…n.
[0071] Optionally, according to the calculated average value and standard deviation, a dynamic threshold lower limit of the thread quantity in the aggregation result is determined, including: using the following calculation formula, calculating the dynamic threshold lower limit of the thread quantity in the aggregation result: M x0 = μ x - 3 * σ x ; wherein, M x0 is the dynamic threshold lower limit of the thread quantity in the aggregation result, μ x is the average value of the n thread quantities in the same time point index data of the thread quantity in the aggregation result, σ x is the standard deviation of the n thread quantities in the same time point index data of the thread quantity in the aggregation result.
[0072] Optionally, according to the calculated average value and standard deviation, a dynamic threshold upper limit of the thread quantity in the aggregation result is determined, including: using the following calculation formula, calculating the dynamic threshold upper limit of the thread quantity in the aggregation result: M x1 = μ x + 3 * σ x ; wherein, M x1 is the dynamic threshold upper limit of the thread quantity in the aggregation result, μ x is the average value of the n thread quantities in the same time point index data of the thread quantity in the aggregation result, σ x is the standard deviation of the n thread quantities in the same time point index data of the thread quantity in the aggregation result.
[0073] Optionally, according to the upper dynamic threshold and the lower dynamic threshold of each performance indicator data in the aggregation result, it is detected whether each performance indicator data in the aggregation result is abnormal, including: for the CPU utilization in the aggregation result, it is judged whether the CPU utilization is less than or equal to the upper dynamic threshold of the CPU utilization and greater than or equal to the lower dynamic threshold of the CPU utilization; if the CPU utilization is less than or equal to the upper dynamic threshold of the CPU utilization and greater than or equal to the lower dynamic threshold of the CPU utilization, it is determined that the CPU utilization is normal; if the CPU utilization is greater than the upper dynamic threshold of the CPU utilization or the CPU utilization is less than the lower dynamic threshold of the CPU utilization, it is determined that the CPU utilization is abnormal; for the delay time in the aggregation result, it is judged whether the delay time is less than or equal to the upper dynamic threshold of the delay time and greater than or equal to the lower dynamic threshold of the delay time; if the delay time is less than or equal to the upper dynamic threshold of the delay time and greater than or equal to the lower dynamic threshold of the delay time, it is determined that the delay time is normal; if the delay time is greater than the upper dynamic threshold of the delay time or the delay time is less than the lower dynamic threshold of the delay time, it is determined that the delay time is abnormal; for the thread quantity in the aggregation result, it is judged whether the thread quantity is less than or equal to the upper dynamic threshold of the thread quantity and greater than or equal to the lower dynamic threshold of the thread quantity; if the thread quantity is less than or equal to the upper dynamic threshold of the thread quantity and greater than or equal to the lower dynamic threshold of the thread quantity, it is determined that the thread quantity is normal; if the thread quantity is greater than the upper dynamic threshold of the thread quantity or the thread quantity is less than the lower dynamic threshold of the thread quantity, it is determined that the thread quantity is abnormal.
[0074] Optionally, if the target performance indicator data is detected to be abnormal, an abnormality mark corresponding to the target performance indicator data is added in the aggregation result, including: if the CPU utilization is detected to be abnormal, a CPU utilization abnormality mark is added in the aggregation result; if the delay time is detected to be abnormal, a delay time abnormality mark is added in the aggregation result; if the thread quantity is detected to be abnormal, a thread quantity abnormality mark is added in the aggregation result. The CPU utilization abnormality mark can be a pre-set text for representing the abnormality of the CPU utilization. The delay time abnormality mark can be a pre-set text for representing the abnormality of the delay time. The thread quantity abnormality mark can be a pre-set text for representing the abnormality of the thread quantity.
[0075] In step 104, for each aggregation result with an abnormality mark, a main abnormality cause and a secondary abnormality cause of the aggregation result are determined by a root cause detection module according to the abnormality occurrence probability of each alternative abnormality cause.
[0076] The abnormality occurrence probability of each alternative abnormality cause is the probability of each alternative abnormality cause leading to the abnormality of the performance indicator data in the aggregation result.
[0077] Optionally, each candidate anomaly cause can be multiple reasons that lead to abnormal performance metric data in the calling process. These candidate anomaly causes can include: CPU overload, network failure, and memory leak. The aggregated result with anomaly markers is the aggregated result containing abnormal performance metric data. The primary anomaly cause of the aggregated result can refer to the main reason causing the abnormal performance metric data in the aggregated result. The secondary anomaly cause of the aggregated result can refer to the minor reason causing the abnormal performance metric data in the aggregated result. The root cause detection module can be a software or hardware module installed in the electronic device to determine the primary and secondary anomaly causes of the aggregated result based on the anomaly occurrence probability of each candidate anomaly cause. For example, the root cause detection module can be a Bayesian network built in the electronic device to determine the primary and secondary anomaly causes of the aggregated result based on the anomaly occurrence probability of each candidate anomaly cause.
[0078] Optionally, for each aggregation result with an anomaly marker, the root cause detection module determines the primary and secondary anomaly causes of the aggregation result based on the anomaly occurrence probability of each candidate anomaly cause. This includes: for each aggregation result with an anomaly marker, the root cause detection module performs the following operations: determining the anomaly occurrence probability of each candidate anomaly cause based on historical statistical probabilities; sorting the candidate anomaly causes in descending order of anomaly occurrence probability, determining the candidate anomaly cause ranked first as the primary anomaly cause of the aggregation result, and determining the candidate anomaly cause ranked second as the secondary anomaly cause of the aggregation result.
[0079] Optionally, historical statistical probabilities can be multiple probabilities related to candidate anomaly causes and performance indicators, statistically derived from collected fault record data and fault handling data. Fault record data can describe faults detected during the call process. Fault handling data can describe faults actually occurring during the call process. Historical statistical probabilities may include: the probability of CPU overload (P1), the probability of network failure (P2), the probability of memory leak (P3), the probability of abnormal CPU utilization when CPU overload exists (P4), the probability of abnormal latency when CPU overload exists (P5), the probability of abnormal thread count when CPU overload exists (P6), the probability of abnormal CPU utilization when no CPU overload exists (P7), the probability of abnormal latency when no CPU overload exists (P8), the probability of abnormal thread count when no CPU overload exists (P9), and the probability of abnormal CPU utilization when a network failure exists (P1). 10 The probability P of abnormal latency when a network failure occurs. 11 The probability P of an abnormal number of threads occurring when a network failure occurs.12 , the probability P of the CPU utilization rate anomaly occurring when there is no network fault 13 , the probability P of the delay time anomaly occurring when there is no network fault 14 , the probability P of the thread quantity anomaly occurring when there is no network fault 15 , the probability P of the CPU utilization rate anomaly occurring when there is a memory leak 16 , the probability P of the delay time anomaly occurring when there is a memory leak 17 , the probability P of the thread quantity anomaly occurring when there is a memory leak 18 .
[0080] Optionally, according to the historical statistical probability, the anomaly occurrence probability of each candidate abnormal reason is determined, including: when the CPU utilization rate anomaly mark, the delay time anomaly mark and the thread quantity anomaly mark exist in the aggregation result, that is, the CPU utilization rate, the delay time and the thread quantity are all abnormal in the aggregation result, the anomaly occurrence probability of the CPU overload, the network fault and the memory leak is determined by performing the following operations: the anomaly occurrence probability of the CPU overload is calculated by the following calculation formula:
[0081]
[0082] the anomaly occurrence probability of the network fault is calculated by the following calculation formula:
[0083]
[0084] the anomaly occurrence probability of the memory leak is calculated by the following calculation formula:
[0085]
[0086] wherein, P C is the anomaly occurrence probability of the CPU overload, P W is the anomaly occurrence probability of the network fault, P N is the anomaly occurrence probability of the memory leak, P1 is the probability of the CPU overload occurring, P2 is the probability of the network fault occurring, P3 is the probability of the memory leak occurring, P4 is the probability of the CPU utilization rate anomaly occurring when there is the CPU overload, P5 is the probability of the delay time anomaly occurring when there is the CPU overload, P6 is the probability of the thread quantity anomaly occurring when there is the CPU overload, P 10 is the probability of the CPU utilization rate anomaly occurring when there is the network fault, P 11 is the probability of the delay time anomaly occurring when there is the network fault, P 12 is the probability of the thread quantity anomaly occurring when there is the network fault, P 16 is the probability of the CPU utilization rate anomaly occurring when there is the memory leak, P17 P represents the probability of an abnormal delay occurring when a memory leak exists. 18 This represents the probability of an abnormal number of threads occurring when a memory leak exists.
[0087] Optionally, based on historical statistical probabilities, determine the probability of occurrence of each candidate anomaly cause, including: when only CPU utilization anomaly markers exist in the aggregation result, i.e., when CPU utilization is abnormal in the aggregation result but latency and thread count are normal, determine the probability of occurrence of CPU overload, network failure, and memory leak by performing the following operations: Calculate the probability of occurrence of CPU overload using the following formula:
[0088]
[0089] The probability of network failures occurring is calculated using the following formula:
[0090]
[0091] The probability of a memory leak occurring is calculated using the following formula:
[0092]
[0093] Where, P′5=(1-P5), P′6=(1-P6), P′ 11 =(1-P 11 ), P′ 12 =(1-P 12 ), P′ 17 =(1-P 17 ), P′ 18 =(1-P 18 The meanings of the other parameters are the same as those in the formulas used to calculate the probability of CPU overload, network failure, and memory leak.
[0094] Optionally, based on historical statistical probabilities, determine the probability of occurrence of each candidate anomaly cause, including: when only a latency anomaly marker exists in the aggregation result, i.e., the latency in the aggregation result is abnormal while CPU utilization and the number of threads are normal, determine the probability of occurrence of CPU overload, network failure, and memory leak by performing the following operations: Calculate the probability of occurrence of CPU overload using the following formula:
[0095]
[0096] The probability of network failures occurring is calculated using the following formula:
[0097]
[0098] The probability of a memory leak occurring is calculated using the following formula:
[0099]
[0100] Where, P′4=(1-P4), P′6=(1-P6), P′ 10 =(1-P 10 ), P′ 12 =(1-P 12 ), P′ 16 =(1-P 16 ), P′ 18 =(1-P 18 The meanings of the other parameters are the same as those in the formulas used to calculate the probability of CPU overload, network failure, and memory leak.
[0101] Optionally, based on historical statistical probabilities, determine the probability of occurrence of each candidate anomaly cause, including: when the aggregation result only contains an abnormal thread count marker, i.e., the thread count in the aggregation result is abnormal while CPU utilization and latency are normal, determine the probability of occurrence of CPU overload, network failure, and memory leak by performing the following operations: Calculate the probability of occurrence of CPU overload using the following formula:
[0102]
[0103] The probability of network failures occurring is calculated using the following formula:
[0104]
[0105] The probability of a memory leak occurring is calculated using the following formula:
[0106]
[0107] Where, P′4=(1-P4), P′5=(1-P5), P′ 10 =(1-P 10 ), P′ 11 =(1-P 11 ), P′ 16 =(1-P 16 ), P′ 17 =(1-P 17 The meanings of each parameter are the same as those in the formulas used to calculate the probability of CPU overload, network failure, and memory leak.
[0108] Optionally, according to the historical statistical probability, the abnormal occurrence probability of each candidate abnormal reason is determined, including: when only the CPU utilization abnormality mark and the delay time abnormality mark exist in the aggregation result, that is, the CPU utilization and the delay time are abnormal and the thread quantity is normal in the aggregation result, the abnormal occurrence probability of the CPU overload, the network fault and the memory leakage is determined by performing the following operations: the abnormal occurrence probability of the CPU overload is calculated by the following calculation formula:
[0109]
[0110] The abnormal occurrence probability of the network fault is calculated by the following calculation formula:
[0111]
[0112] The abnormal occurrence probability of the memory leakage is calculated by the following calculation formula:
[0113]
[0114] Wherein, the meanings of the parameters are the same as the parameters of the aforementioned calculation formula for calculating the abnormal occurrence probability of the CPU overload, the network fault and the memory leakage.
[0115] Optionally, according to the historical statistical probability, the abnormal occurrence probability of each candidate abnormal reason is determined, including: when the CPU utilization abnormality mark and the thread quantity abnormality mark exist in the aggregation result, that is, the CPU utilization and the thread quantity are abnormal and the delay time is normal in the aggregation result, the abnormal occurrence probability of the CPU overload, the network fault and the memory leakage is determined by performing the following operations: the abnormal occurrence probability of the CPU overload is calculated by the following calculation formula:
[0116]
[0117] The abnormal occurrence probability of the network fault is calculated by the following calculation formula:
[0118]
[0119] The abnormal occurrence probability of the memory leakage is calculated by the following calculation formula:
[0120]
[0121] Wherein, the meanings of the parameters are the same as the parameters of the aforementioned calculation formula for calculating the abnormal occurrence probability of the CPU overload, the network fault and the memory leakage.
[0122] Optionally, according to the historical statistical probability, the abnormal occurrence probability of each candidate abnormal reason is determined, including: when the thread number abnormality mark and the delay time abnormality mark exist in the aggregation result, that is, the delay time and the thread number are abnormal and the CPU utilization is normal, the abnormal occurrence probability of the CPU overload, the network fault and the memory leakage is determined by performing the following operations: the abnormal occurrence probability of the CPU overload is calculated by the following calculation formula:
[0123]
[0124] The abnormal occurrence probability of the network fault is calculated by the following calculation formula:
[0125]
[0126] The abnormal occurrence probability of the memory leakage is calculated by the following calculation formula:
[0127]
[0128] Wherein, the meanings of the parameters are the same as the parameters of the aforementioned calculation formula for calculating the abnormal occurrence probability of the CPU overload, the network fault and the memory leakage.
[0129] Optionally, each candidate abnormal reason is sorted according to the order from large to small of the abnormal occurrence probability, the candidate abnormal reason ranked first is determined as the main abnormal reason of the aggregation result, and the candidate abnormal reason ranked second is determined as the secondary abnormal reason of the aggregation result, including: the CPU overload, the network fault and the memory leakage are sorted according to the order from large to small of the abnormal occurrence probability, the candidate abnormal reason ranked first in the CPU overload, the network fault and the memory leakage is determined as the main abnormal reason of the aggregation result, and the candidate abnormal reason ranked second in the CPU overload, the network fault and the memory leakage is determined as the secondary abnormal reason of the aggregation result.
[0130] Optionally, in one specific example, the probability of occurrence of CPU overload is 0.40, the probability of occurrence of network failure is 0.30, the probability of occurrence of memory leak is 0.25, the probability of occurrence of CPU utilization abnormality when there is CPU overload is 0.95, the probability of occurrence of delay time abnormality when there is CPU overload is 0.10, the probability of occurrence of thread quantity abnormality when there is CPU overload is 0.90, the probability of occurrence of CPU utilization abnormality when there is no CPU overload is 0.01, the probability of occurrence of delay time abnormality when there is no CPU overload is 0.02, the probability of occurrence of thread quantity abnormality when there is no CPU overload is 0.02, the probability of occurrence of CPU utilization abnormality when there is network failure is 0.05, the probability of occurrence of delay time abnormality when there is network failure is 0.85, the probability of occurrence of thread quantity abnormality when there is network failure is 0.15, the probability of occurrence of CPU utilization abnormality when there is no network failure is 0.01, the probability of occurrence of delay time abnormality when there is no network failure is 0.02, the probability of occurrence of thread quantity abnormality when there is no network failure is 0.02, the probability of occurrence of CPU utilization abnormality when there is memory leak is 0.80, the probability of occurrence of delay time abnormality when there is memory leak is 0.05, the probability of occurrence of thread quantity abnormality when there is memory leak is 0.95. When there is the CPU utilization abnormality flag, the delay time abnormality flag and the thread quantity abnormality flag in the aggregated result, the calculated abnormality occurrence probability of CPU overload is 0.750, the calculated abnormality occurrence probability of network failure is 0.042, and the calculated abnormality occurrence probability of memory leak is 0.208. The CPU overload, the network failure and the memory leak are sorted in descending order of abnormality occurrence probability, the CPU overload ranked first is determined as the primary abnormality cause of the aggregated result, and the memory leak ranked second is determined as the secondary abnormality cause of the aggregated result.
[0131] Step 105, for each aggregated result with an abnormality flag, determining a solution corresponding to the primary abnormality cause and the secondary abnormality cause of the aggregated result, generating an abnormality detection report of the aggregated result, and providing the abnormality detection report to a target user.
[0132] Optionally, the solution corresponding to the primary abnormality cause of the aggregated result can be text describing a method for solving the primary abnormality cause of the aggregated result. The solution corresponding to the secondary abnormality cause of the aggregated result can be text describing a method for solving the secondary abnormality cause of the aggregated result. The abnormality detection report of the aggregated result can be information related to the performance indicator data of the abnormality in the aggregated result after summarization. The target user can be a technical personnel responsible for handling the abnormality in the calling process.
[0133] Optionally, for each aggregated result with an exception mark, a solution corresponding to the primary exception cause and the secondary exception cause of the aggregated result is determined, including: for each aggregated result with an exception mark, performing the following operations: determining whether the preset knowledge graph contains a solution corresponding to the primary exception cause and the secondary exception cause of the aggregated result; if the preset knowledge graph contains a solution corresponding to the primary exception cause and the secondary exception cause of the aggregated result, obtaining the solution corresponding to the primary exception cause and the secondary exception cause of the aggregated result from the preset knowledge graph.
[0134] Optionally, the method further includes: if the preset knowledge graph does not contain a solution corresponding to the primary exception cause and / or the secondary exception cause of the aggregated result, generating a solution corresponding to the primary exception cause and / or the secondary exception cause of the aggregated result by using a pre-trained large language model, and adding the solution corresponding to the primary exception cause and / or the secondary exception cause of the aggregated result to the preset knowledge graph.
[0135] Optionally, the preset knowledge graph can be a knowledge graph for storing various causes of business system exceptions and solutions corresponding to the causes. The preset knowledge graph contains multiple nodes. Each node is composed of a cause and a solution corresponding to the cause. The solution corresponding to the cause is a text for describing a method for solving the cause.
[0136] Optionally, the pre-trained large language model can be a pre-trained large language model (LLM) that can be used for reasoning processing such as solution generation. The cause of the exception can be input to the pre-trained large language model. The pre-trained large language model analyzes the input cause of the exception, generates a solution corresponding to the cause, and then outputs the solution corresponding to the cause.
[0137] Optionally, determining whether the preset knowledge graph contains a solution corresponding to the primary exception cause and the secondary exception cause of the aggregated result includes: detecting whether the preset knowledge graph contains a node containing the primary exception cause of the aggregated result and a node containing the secondary exception cause of the aggregated result; if the preset knowledge graph contains a node containing the primary exception cause of the aggregated result, determining that the preset knowledge graph contains a solution corresponding to the primary exception cause of the aggregated result; and if the preset knowledge graph contains a node containing the secondary exception cause of the aggregated result, determining that the preset knowledge graph contains a solution corresponding to the secondary exception cause of the aggregated result.
[0138] Optionally, if the preset knowledge graph contains a solution corresponding to the primary abnormal reason of the aggregation result and a solution corresponding to the secondary abnormal reason of the aggregation result, the solution corresponding to the primary abnormal reason of the aggregation result is obtained from the node in the preset knowledge graph containing the primary abnormal reason of the aggregation result, and the solution corresponding to the secondary abnormal reason of the aggregation result is obtained from the node in the preset knowledge graph containing the secondary abnormal reason of the aggregation result.
[0139] Optionally, if the preset knowledge graph contains a solution corresponding to the primary abnormal reason of the aggregation result and does not contain a solution corresponding to the secondary abnormal reason of the aggregation result, the solution corresponding to the primary abnormal reason of the aggregation result is obtained from the node in the preset knowledge graph containing the primary abnormal reason of the aggregation result, the secondary abnormal reason of the aggregation result is input into the pre-trained large language model, a solution corresponding to the secondary abnormal reason of the aggregation result output by the pre-trained large language model is obtained, and the secondary abnormal reason of the aggregation result and the solution corresponding to the secondary abnormal reason of the aggregation result are added to the preset knowledge graph as a new node.
[0140] Optionally, if the preset knowledge graph does not contain a solution corresponding to the primary abnormal reason of the aggregation result and contains a solution corresponding to the secondary abnormal reason of the aggregation result, the primary abnormal reason of the aggregation result is input into the pre-trained large language model, a solution corresponding to the primary abnormal reason of the aggregation result output by the pre-trained large language model is obtained, and the primary abnormal reason of the aggregation result and the solution corresponding to the primary abnormal reason of the aggregation result are added to the preset knowledge graph as a new node.
[0141] Optionally, if the preset knowledge graph does not contain a solution corresponding to the primary abnormal reason of the aggregation result and contains a solution corresponding to the secondary abnormal reason of the aggregation result, the primary abnormal reason of the aggregation result is input into the pre-trained large language model, a solution corresponding to the primary abnormal reason of the aggregation result output by the pre-trained large language model is obtained, and the primary abnormal reason of the aggregation result and the solution corresponding to the primary abnormal reason of the aggregation result are added to the preset knowledge graph as a new node.
[0142] Optionally, in one specific example, the solution corresponding to the CPU overload is "scale instance, check thread leak". The solution corresponding to the memory leak is "restart service, analyze heap memory".
[0143] Optionally, for each aggregated result with the abnormal flag, an abnormality detection report of the aggregated result is generated, and the abnormality detection report is provided to the target user, including: for each aggregated result with the abnormal flag, performing the following operations: determining the aggregated result, the main abnormal reason of the aggregated result, the abnormal occurrence probability of the main abnormal reason of the aggregated result, the solution corresponding to the main abnormal reason of the aggregated result, the secondary abnormal reason of the aggregated result, the abnormal occurrence probability of the secondary abnormal reason of the aggregated result, and the solution corresponding to the secondary abnormal reason of the aggregated result as the abnormality detection report of the aggregated result, and sending the abnormality detection report of the aggregated result to the terminal device of the target user.
[0144] The technical solution of this invention involves periodically acquiring call logs within a preset time window, grouping the call logs according to the call process identifier in each call log, resulting in multiple call log groups; wherein the call logs in each call log group belong to the same call process; then, the call logs in each call log group are aggregated to obtain an aggregation result for each call log group; wherein the aggregation result for each call log group includes the call process identifier of the call process to which the call log group belongs and various performance indicator data; for each aggregation result, an anomaly detection module detects whether the performance indicator data in the aggregation result is abnormal based on the time-point indicator data of each performance indicator data in the aggregation result, and adds an anomaly marker corresponding to the abnormal performance indicator data to the aggregation result; for each aggregation result with an anomaly marker, a root cause detection module determines the primary and secondary anomaly causes of the aggregation result based on the anomaly occurrence probability of each candidate anomaly cause; wherein the anomaly occurrence probability of each candidate anomaly cause is the probability that each candidate anomaly cause leads to anomalies in the performance indicator data of the aggregation result; for each aggregation result with an anomaly marker, the primary and secondary anomaly causes are determined. The system automatically aggregates call logs belonging to the same call process, generates an anomaly detection report, and provides it to the target user. This addresses the issues of manual operation, high time and manpower costs, low efficiency, and difficulty in guaranteeing accuracy in related call log processing solutions. It can automatically and periodically aggregate call logs from the same call process, quickly and accurately detecting anomalies in various performance metrics based on data at the same point in time. After identifying abnormal performance metrics, it can quickly and accurately determine the primary and secondary causes of the anomalies based on the probability of occurrence of each alternative cause, and then determine the corresponding solutions. This generates an anomaly detection report for the target user, enabling automatic and periodic processing of call logs generated in the business system. It aggregates call logs belonging to the same call process, detects anomalies in various performance metrics, and, after identifying abnormal performance metrics, determines the cause and solutions for handling the anomalies. This reduces the time and manpower costs of call log processing and improves its efficiency and accuracy.
[0145] Example 2
[0146] Figure 2 This is a flowchart illustrating a call log processing method according to Embodiment 2 of the present invention. This embodiment of the present invention can be combined with various optional solutions from one or more of the above embodiments. For example... Figure 2 As shown, the method includes:
[0147] Step 201, timing acquisition of each call log in a preset time window, grouping each call log according to the call timestamp, service identification information and host identification information in each call log, and obtaining a plurality of call log groups.
[0148] Each call log in each call log group belongs to the same call process, and the call timestamp, service identification information and host identification information in each call log in each call log group are the same.
[0149] Step 202, aggregating the call logs in each call log group to obtain an aggregation result of each call log group.
[0150] Each aggregation result of each call log group contains the call process identification of the call process to which the call log group belongs and each performance indicator data.
[0151] Step 203, for each aggregation result, detecting whether each performance indicator data in the aggregation result is abnormal by an exception detection module according to the same time point indicator data of each performance indicator data in the aggregation result, and adding an exception mark corresponding to the abnormal performance indicator data in the aggregation result.
[0152] Step 204, for each aggregation result with an exception mark, determining the main abnormal cause and the secondary abnormal cause of the aggregation result according to the abnormal occurrence probability of each alternative abnormal cause by a root cause detection module.
[0153] The abnormal occurrence probability of each alternative abnormal cause is the probability of causing the performance indicator data in the aggregation result to be abnormal.
[0154] Step 205, for each aggregation result with an exception mark, determining the solution corresponding to the main abnormal cause and the secondary abnormal cause of the aggregation result, generating an exception detection report of the aggregation result, and providing the exception detection report to a target user.
[0155] The technical scheme of the embodiment of the present application can automatically aggregate each calling log belonging to the same calling process according to the calling time stamp, service identification information and host identification information, quickly and accurately detect whether each performance index data of the calling process is abnormal based on the index data of the same time point, quickly and accurately determine the main abnormal reason and the secondary abnormal reason causing the performance index data of the calling process to be abnormal based on the abnormal occurrence probability of each alternative abnormal reason after the performance index data determined to be abnormal, further determine the solution corresponding to the main abnormal reason and the secondary abnormal reason, form an abnormal detection report and provide the target user, realize automatic processing of the calling log generated in the business system, aggregation of each calling log belonging to the same calling process, detection of whether each performance index data of the calling process is abnormal, determination of the reason causing the abnormality and the solution for processing the abnormality after the performance index data determined to be abnormal, and reduction of the time cost and the labor cost of the calling log processing process, and improvement of the efficiency and the accuracy of the calling log processing process.
[0156] Embodiment three
[0157] Figure 3 A structural schematic diagram of a calling log processing device provided by the embodiment three of the present application is shown in FIG. 3. The device can be configured in an electronic device. As shown in FIG. 3, the device comprises a log grouping unit 301, a log aggregation unit 302, a log detection unit 303, a reason determination unit 304 and a report providing unit 305. Figure 3
[0158] The log grouping unit 301 is configured to acquire each call log in a preset time window at a timing, group each call log according to a call process identifier in each call log, and obtain a plurality of call log groups; each call log in each call log group belongs to a same call process; the log aggregation unit 302 is configured to aggregate each call log in each call log group, and obtain an aggregation result of each call log group; the aggregation result of each call log group comprises a call process identifier of a call process to which the call log group belongs and each performance indicator data; the log detection unit 303 is configured to, for each aggregation result, detect, by using an exception detection module, whether each performance indicator data in the aggregation result is abnormal according to same-time point indicator data of each performance indicator data in the aggregation result, and increase an exception mark corresponding to the abnormal performance indicator data in the aggregation result; the cause determination unit 304 is configured to, for each aggregation result with the exception mark, determine a main abnormal cause and a secondary abnormal cause of the aggregation result by using a root cause detection module according to an abnormal occurrence probability of each candidate abnormal cause; the abnormal occurrence probability of each candidate abnormal cause is a probability that each candidate abnormal cause causes the performance indicator data in the aggregation result to be abnormal; and the report providing unit 305 is configured to, for each aggregation result with the exception mark, determine a solution corresponding to the main abnormal cause and the secondary abnormal cause of the aggregation result, generate an exception detection report of the aggregation result, and provide the exception detection report to a target user.
[0159] The technical scheme of the embodiment of the present application acquires each calling log in a preset time window in a timely manner, groups each calling log according to the calling process identifier in each calling log, and obtains a plurality of calling log groups; wherein the calling logs in each calling log group belong to the same calling process; then the calling logs in each calling log group are aggregated to obtain the aggregation result of each calling log group; wherein the aggregation result of each calling log group contains the calling process identifier of the calling process to which the calling log group belongs and each performance indicator data; for each aggregation result, the abnormality of each performance indicator data in the aggregation result is detected according to the same time point indicator data of each performance indicator data in the aggregation result through the exception detection module, and an exception mark corresponding to the abnormal performance indicator data is added in the aggregation result; for each aggregation result with an exception mark, the main abnormal cause and the secondary abnormal cause of the aggregation result are determined according to the abnormal occurrence probability of each alternative abnormal cause through the root cause detection module; wherein the abnormal occurrence probability of each alternative abnormal cause is the probability of causing the performance indicator data in the aggregation result to be abnormal; for each aggregation result with an exception mark, the solution corresponding to the main abnormal cause and the secondary abnormal cause of the aggregation result is determined, an exception detection report of the aggregation result is generated, the exception detection report is provided to the target user, and the calling log processing scheme in the related art depends on manual operation, the time cost and the labor cost are high, the efficiency is low, and the accuracy is difficult to guarantee. The problems are solved. Each calling log belonging to the same calling process can be automatically aggregated in a timely manner, whether each performance indicator data of the calling process is abnormal can be quickly and accurately detected based on the same time point indicator data, the main abnormal cause and the secondary abnormal cause causing the performance indicator data of the calling process to be abnormal can be quickly and accurately determined based on the abnormal occurrence probability of each alternative abnormal cause after the performance indicator data with an exception is determined, and then the solution corresponding to the main abnormal cause and the secondary abnormal cause is determined to form an exception detection report provided to the target user. The calling log generated in the business system is automatically processed in a timely manner, each calling log belonging to the same calling process is aggregated, whether each performance indicator data of the calling process is abnormal is detected, the cause causing the abnormality is determined after the performance indicator data with an exception is determined, and the solution for processing the abnormality is determined, thereby reducing the time cost and the labor cost of the calling log processing process, and improving the efficiency and the accuracy of the calling log processing process.
[0160] In an optional implementation of the embodiment of the application, optionally, the log grouping unit 301, in the operation of grouping the respective call logs according to the call process identifiers in the respective call logs to obtain a plurality of call log groups, is specifically configured to group the respective call logs according to the call timestamps, the service identifier information and the host identifier information in the respective call logs to obtain a plurality of call log groups; wherein the call timestamps, the service identifier information and the host identifier information in the respective call logs in each call log group are the same.
[0161] In an optional implementation of the embodiment of the application, optionally, the log aggregation unit 302 is specifically configured to perform the following operations for each call log group: extract the call timestamp, the service identifier information and the host identifier information in any one of the call logs in the call log group; extract the performance indicator data in each of the call logs in the call log group; and determine the extracted call timestamp, service identifier information, host identifier information and the respective performance indicator data as the aggregation result of the call log group.
[0162] In an optional implementation of the embodiment of the application, optionally, the log detection unit 303 is specifically configured to perform the following operations for each aggregation result by means of an anomaly detection module: determine the upper dynamic threshold and the lower dynamic threshold of the respective performance indicator data in the aggregation result according to the same-time point indicator data of the respective performance indicator data in the aggregation result; detect whether the respective performance indicator data in the aggregation result is abnormal according to the upper dynamic threshold and the lower dynamic threshold of the respective performance indicator data in the aggregation result; and if the target performance indicator data is detected to be abnormal, add an abnormality mark corresponding to the target performance indicator data in the aggregation result.
[0163] In an optional implementation of the embodiment of the application, optionally, the cause determination unit 304 is specifically configured to perform the following operations for each aggregation result with an abnormality mark by means of a root cause detection module: determine the abnormality occurrence probability of each alternative abnormality cause according to historical statistical probability; sort the respective alternative abnormality causes in descending order of the abnormality occurrence probability, determine the alternative abnormality cause ranked first as the primary abnormality cause of the aggregation result, and determine the alternative abnormality cause ranked second as the secondary abnormality cause of the aggregation result.
[0164] In an optional implementation of the embodiment of the application, optionally, the report providing unit 305, when performing the operation of determining the solution corresponding to the primary abnormal reason and the secondary abnormal reason of the aggregation result for each aggregation result with the abnormal flag, is specifically configured to: perform the following operation for each aggregation result with the abnormal flag: determining whether the preset knowledge graph has the solution corresponding to the primary abnormal reason and the secondary abnormal reason of the aggregation result; and if the preset knowledge graph has the solution corresponding to the primary abnormal reason and the secondary abnormal reason of the aggregation result, obtaining the solution corresponding to the primary abnormal reason and the secondary abnormal reason of the aggregation result from the preset knowledge graph.
[0165] In an optional implementation of the embodiment of the application, optionally, the report providing unit 305 is further configured to: if the preset knowledge graph does not have the solution corresponding to the primary abnormal reason and / or the secondary abnormal reason of the aggregation result, generating the solution corresponding to the primary abnormal reason and / or the secondary abnormal reason of the aggregation result by using the pre-trained large language model, and adding the solution corresponding to the primary abnormal reason and / or the secondary abnormal reason of the aggregation result to the preset knowledge graph.
[0166] The calling log processing apparatus provided in the embodiment of the application can execute the calling log processing method provided in any embodiment of the application, and has the function units and beneficial effects corresponding to the execution method.
[0167] Embodiment Four
[0168] Figure 4 A structural schematic diagram of an electronic device 10 that can be used to implement the calling log processing method of the embodiment of the application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, electronic devices, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (such as headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the application described and / or claimed in this document.
[0169] As Figure 4As shown, the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory 12, a random access memory 13, etc., communicatively connected to the at least one processor 11, where the memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer programs stored in the read-only memory 12 or loaded from the storage unit 18 into the random access memory 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the random access memory 13. The processor 11, the read-only memory 12, and the random access memory 13 are connected to each other through a bus 14. An input / output interface 15 is also connected to the bus 14.
[0170] Various components in the electronic device 10 are connected to the input / output interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, a speaker, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0171] The processor 11 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit, a graphics processing unit, various special-purpose artificial intelligence computing chips, various processors running machine learning model algorithms, a digital signal processor, and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the call log processing method.
[0172] In some embodiments, the call log processing method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit. In some embodiments, part or all of the computer program can be loaded and / or installed onto the heterogeneous hardware accelerator via the read-only memory and / or the communication unit. When the computer program is loaded into the random access memory and executed by the processor, one or more steps of the call log processing method described above can be performed. Alternatively, in other embodiments, the processor can be configured to perform the call log processing method by any other appropriate means, such as by means of firmware.
[0173] The various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, specially designed application specific integrated circuits, application specific standard products, chips, computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0174] Computer programs used to implement the methods of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program
[0175] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical fiber, a portable compact disc read-only memory, an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0176] To provide for interaction with a user, the systems and techniques described here can be implemented on a heterogeneous hardware accelerator having a display device (e.g., a cathode ray tube or a liquid crystal display monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the heterogeneous hardware accelerator. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0177] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a client computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), a blockchain network, and the Internet.
[0178] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server is a remote computer system accessible to a client computer through a communication network. Cloud server, also known as cloud computing server or cloud host, is a host product in the cloud computing service system, which solves the defects of large management difficulty and weak business scalability in traditional physical host and virtual private server service.
[0179] It should be understood that various forms of flow shown above can be used, with steps reordered, added, or removed. For example, the steps recited in the present invention can be performed in parallel, in series, or in a different order, without limitation herein, as long as the desired results of the technical solutions of the present invention can be achieved.
[0180] The specific embodiments described above are not intended to be limiting, and persons skilled in the art will appreciate that various modifications, combinations, sub-combinations and alternatives can be made to the specific embodiments without departing from the spirit and principles of the present invention. Accordingly, the disclosure is intended to embrace all such alternatives, modifications and variances that fall within the scope of the present invention, including the patent claims as allowed, and any further claims that may be filed in the future.
Claims
1. A method for handling call logs, characterized in that, include: The system periodically retrieves call logs within a preset time window, groups the call logs according to the call process identifier in each log, and obtains multiple call log groups; the call logs in each call log group belong to the same call process. The call logs in each call log group are aggregated to obtain the aggregated result of each call log group; the aggregated result of each call log group includes the call process identifier of the call process to which the call log group belongs and various performance index data; For each aggregation result, the anomaly detection module detects whether the performance metrics data in the aggregation result are abnormal based on the performance metrics data at the same time point in the aggregation result, and adds anomaly markers corresponding to the abnormal performance metrics data to the aggregation result. For each aggregation result with an anomaly marker, the root cause detection module determines the primary and secondary anomaly causes of the aggregation result based on the anomaly occurrence probability of each candidate anomaly cause; where the anomaly occurrence probability of each candidate anomaly cause is the probability that each candidate anomaly cause will cause anomalies in the performance index data of the aggregation result. For each aggregated result with an anomaly marker, determine the solutions corresponding to the primary and secondary anomaly causes of the aggregated result, generate an anomaly detection report for the aggregated result, and provide the anomaly detection report to the target user.
2. The call log processing method according to claim 1, characterized in that, The call logs are grouped according to the call procedure identifier in each call log, resulting in multiple call log groups, including: Each call log is grouped based on its call timestamp, service identifier, and host identifier, resulting in multiple call log groups. Within each call log group, the call timestamp, service identifier, and host identifier are identical across all call logs.
3. The call log processing method according to claim 2, characterized in that, The call logs in each call log group are aggregated to obtain the aggregated results for each call log group, including: Perform the following operations for each call log group: Extract the call timestamp, service identifier information, and host identifier information from any call log in the call log group; Extract performance metric data from each call log in the call log group; The extracted call timestamps, service identifiers, host identifiers, and various performance metrics are determined as the aggregated result of the call log group.
4. The call log processing method according to claim 2, characterized in that, For each aggregation result, the anomaly detection module checks for anomalies in the performance metrics data at the same time point within the aggregation result. Anomaly markers corresponding to the abnormal performance metrics data are then added to the aggregation result, including: For each aggregation result, the following operations are performed using the anomaly detection module: Based on the time-point data of each performance indicator in the aggregation result, determine the upper limit and lower limit of the dynamic threshold for each performance indicator in the aggregation result. Based on the upper and lower dynamic thresholds of each performance indicator data in the aggregation result, detect whether the performance indicator data in the aggregation result is abnormal; If an anomaly is detected in the target performance metric data, an anomaly marker corresponding to the target performance metric data is added to the aggregation result.
5. The call log processing method according to claim 1, characterized in that, For each aggregation result marked with an anomaly, the root cause detection module determines the primary and secondary anomaly causes based on the anomaly occurrence probability of each candidate anomaly cause, including: For each aggregation result marked with an anomaly, the following operations are performed using the root cause detection module: Based on historical statistical probabilities, determine the probability of occurrence of each candidate cause of anomaly. The candidate anomaly causes are sorted in descending order of anomaly occurrence probability. The candidate anomaly cause ranked first is determined as the primary anomaly cause of the aggregated result, and the candidate anomaly cause ranked second is determined as the secondary anomaly cause of the aggregated result.
6. The call log processing method according to claim 1, characterized in that, For each aggregation result with an anomaly marker, determine the solutions corresponding to the primary and secondary anomaly causes of the aggregation result, including: For each aggregation result with an anomaly marker, perform the following operation: Determine whether there are solutions in the preset knowledge graph that correspond to the primary and secondary anomalies of the aggregation results; If there are solutions in the preset knowledge graph that correspond to the primary and secondary causes of the aggregation result, then the solutions corresponding to the primary and secondary causes of the aggregation result are obtained from the preset knowledge graph.
7. The call log processing method according to claim 6, characterized in that, Also includes: If there is no solution in the preset knowledge graph corresponding to the primary and / or secondary anomaly causes of the aggregation result, then the solution corresponding to the primary and / or secondary anomaly causes of the aggregation result is generated by a pre-trained large language model, and the solution corresponding to the primary and / or secondary anomaly causes of the aggregation result is added to the preset knowledge graph.
8. A call log processing device, characterized in that, include: The log grouping unit is used to periodically retrieve each call log within a preset time window, and group the call logs according to the call process identifier in each call log to obtain multiple call log groups; wherein, the call logs in each call log group belong to the same call process; The log aggregation unit is used to aggregate the call logs in each call log group to obtain the aggregation result of each call log group; wherein, the aggregation result of each call log group includes the call process identifier of the call process to which the call log group belongs and various performance index data; The log detection unit is used to detect whether the performance index data in each aggregation result is abnormal by using the anomaly detection module based on the index data of each performance index data in the aggregation result at the same time point, and add anomaly markers corresponding to the abnormal performance index data to the aggregation result. The cause determination unit is used to determine the primary and secondary causes of anomalies in each aggregated result with an anomaly marker, based on the probability of occurrence of each candidate anomaly cause, through the root cause detection module. The probability of occurrence of each candidate anomaly cause is the probability that each candidate anomaly cause will cause anomalies in the performance index data of the aggregated result. The report providing unit is used to determine the solutions corresponding to the primary and secondary causes of the anomaly for each aggregated result with an anomaly marker, generate an anomaly detection report for the aggregated result, and provide the anomaly detection report to the target user.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and a memory communicatively connected to the at least one processor; The memory stores a computer program that is executed by the at least one processor, which enables the at least one processor to perform the call log processing method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the call log processing method according to any one of claims 1-7.