Alarm analysis method and device based on character type

By analyzing the character types of alarm information for vectorization and similarity calculation, the problem of identifying the relationship between different instance objects in complex business systems is solved, improving the efficiency of fault diagnosis and analysis.

CN120994507APending Publication Date: 2025-11-21SHANGHAI PUDONG DEVELOPMENT BANK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510950060.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing alarm analysis methods cannot effectively analyze the relationships between different instance objects in complex business systems, resulting in the inability to determine the root cause of alarms. Furthermore, the computational load of querying deployment information is large, reducing analysis efficiency.

Method used

By analyzing the character types of multiple fields in the alarm information, vectorizing and concatenating them, calculating similarity, grouping and determining the deployment level, and using the alarm information of the specified level as the root cause alarm.

Benefits of technology

It improves troubleshooting efficiency, reduces the computational load of deployment information queries, accurately identifies root cause alarms, and simplifies the fault analysis process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120994507A_ABST
    Figure CN120994507A_ABST
Patent Text Reader

Abstract

The invention relates to an alarm analysis method and device based on character types. Comprising the following steps: respectively analyzing character types of field values of a plurality of fields in each alarm message; vectorizing the field value of the character type in the alarm information according to a format corresponding to the character type to obtain a plurality of vectors of different formats of the plurality of field values in the alarm information; splicing a plurality of vectors of different formats of a plurality of field values in the alarm information to form a multi-dimensional target vector of the alarm information; calculating the similarity between the multi-dimensional target vectors of the alarm information; grouping the alarm information according to the similarity to obtain a plurality of groups; and for each group, determining a deployment hierarchy of the instance object corresponding to each piece of alarm information in the group, and taking the alarm information of the specified deployment hierarchy as a root cause alarm of the group. And fault analysis is carried out on the corresponding instance object according to the root cause alarm, so that cascading faults caused by faults of the instance object can be solved, and the troubleshooting efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present specification relate to the technical field of computer technology, and particularly relate to a character type-based alarm analysis method and device. BACKGROUND

[0002] The existing alarm analysis methods are all to align alarm fields, compare field values of the same field of alarm information, so as to classify and analyze the alarm information. The association relationship between different instance objects in the configuration management in the prior art is usually a deployment relationship, for example, a database is deployed on a host, the host is deployed on a certain port of a switch, and the like. In this deployment mode, usually the failure of one instance object will trigger a chain reaction, and multiple instance objects related to each other will all generate alarms, but the field values of the same field (for example, an IP field) in the alarm information of these instance objects cannot directly present the association between the instance objects, so the association between these alarm information cannot be analyzed, resulting in that the root cause alarm in the alarm information cannot be determined. Although the association between the alarm information can be determined by searching the deployment information in the configuration management, the deployment information of a large-scale business system is very complex, searching the association relationship will introduce a huge amount of calculation, increase the calculation burden, and also reduce the efficiency of alarm analysis. SUMMARY

[0003] To solve the problems in the prior art, the embodiments of the present specification provide a character type-based alarm analysis method and device, which discards the technical solution of aligning alarm fields, proposes to analyze the character types of the field values of multiple alarm fields in alarm information, vectorize the field values of the character types in the alarm information according to the format corresponding to the character types, obtain vectors of the multiple field values of the alarm information, then splice the vectors, calculate the similarity between the spliced vectors corresponding to each alarm information, so as to group the alarm information, then determine the level corresponding to each alarm information in the group, and take the alarm information of a specified level as a root cause alarm.

[0004] The specific technical solutions of the embodiments of the present specification are as follows:

[0005] On one hand, the embodiments of the present specification provide a character type-based alarm analysis method, which comprises:

[0006] analyze the character types of the field values of multiple fields in each alarm information respectively;

[0007] vectorize the field values of the character types in the alarm information according to the format corresponding to the character types, obtain multiple vectors of different formats of the multiple field values in the alarm information;

[0008] Splice multiple vectors of different formats of the multiple field values in the alarm information to form a multi-dimensional target vector of the alarm information;

[0009] Calculate the similarity between the multi-dimensional target vectors of each alarm information;

[0010] Group each alarm information according to the similarity to obtain multiple groups;

[0011] For each group, determine the deployment level of the instance object corresponding to each alarm information in the group, and take the alarm information of the specified deployment level as the root cause alarm of the group.

[0012] The character type includes numerical type, encoding type and string type.

[0013] Further, the vectorization of the field value of the character type in the alarm information according to the format corresponding to the character type to obtain multiple vectors of different formats of the multiple field values in the alarm information further includes:

[0014] Convert the field value of the numerical type into a numerical vector;

[0015] Convert the field value of the encoding type into a one-hot encoding vector;

[0016] Convert the field value of the string type into a semantic vector.

[0017] Further, the formula for calculating the similarity between the multi-dimensional target vectors of each alarm information is:

[0018]

[0019] Where d represents the similarity between the multi-dimensional target vector (x 1,i ,x 2,i ,…,x n,i ) of alarm information i and the multi-dimensional target vector (x 1,j ,x 2,j ,…,x n,j ) of alarm information j, and x1,x2,…,x n represent the n different dimensions of the target vector respectively.

[0020] Further, determining the deployment level of the instance object corresponding to each alarm information in the group further includes:

[0021] Extract the instance object corresponding to each alarm information in the group;

[0022] Determine the deployment level of the instance object.

[0023] Further, the alarm information of the specified deployment level is further included as a root cause alarm of the group.

[0024] The alarm information of the lowest deployment level is taken as the root cause alarm.

[0025] In another aspect, the embodiments of the present specification also provide an alarm analysis device based on character types, which comprises:

[0026] a character type analysis unit, configured to analyze character types of field values of a plurality of fields in each alarm information respectively;

[0027] a vectorization unit, configured to vectorize the field values of the character types in the alarm information according to a format corresponding to the character types, to obtain a plurality of vectors of different formats of the field values in the alarm information;

[0028] a vector splicing unit, configured to splice the plurality of vectors of different formats of the field values in the alarm information, to form a multi-dimensional target vector of the alarm information;

[0029] a similarity calculation unit, configured to calculate similarities between the multi-dimensional target vectors of the alarm information;

[0030] a grouping unit, configured to group the alarm information according to the similarities, to obtain a plurality of groups;

[0031] a root cause alarm determination unit, configured to determine, for each group, deployment levels of instance objects corresponding to the alarm information in the group, and to take alarm information of a specified deployment level as a root cause alarm of the group.

[0032] In another aspect, the embodiments of the present specification also provide a computer device, which comprises a memory, a processor, and a computer program stored in the memory, and the processor implements the above method when executing the computer program.

[0033] In another aspect, the embodiments of the present specification also provide a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the above method.

[0034] Finally, the embodiments of the present specification also provide a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the above method.

[0035] The embodiment of the present specification discards the method of aligning and analyzing the alarm field, and in the scenario where there is a deployment relationship between instance objects, the field values in the alarm information of the instance objects are vectorized according to the format corresponding to the character type of each field value. That is, the embodiment of the present specification no longer analyzes the meaning of the fields in the alarm information in the business scenario, but directly analyzes the character type of each field value, and vectorizes according to the format corresponding to the character type, such as numerical type, coding type and string type. Therefore, in the scenario where there is a deployment relationship between instance objects, although there is no correlation between the field values in the alarm information reported by multiple different instance objects of the same field, the information that exists correlation is the field values of different fields, but because the present application directly analyzes the character type of the field value, the field values of different fields that have a correlation relationship can also be analyzed for their correlation relationship because of the similar character types, thereby obtaining the correlation relationship between the alarm information. Therefore, the embodiment of the present specification splices multiple vectors of different formats of multiple field values in the alarm information to form a multi-dimensional target vector of the alarm information; calculates the similarity between the multi-dimensional target vectors of each alarm information; groups each alarm information according to the similarity to obtain multiple groups. The alarm information belonging to the same group has a correlation.

[0036] Because in the scenario where there is a deployment relationship between instance objects, the failure of one instance object often triggers a chain reaction, causing the failure of multiple instance objects, the embodiment of the present specification can divide the alarm information of the failed instance object and the alarm information of other instance objects of its chain reaction into one group by grouping the alarm information. Then, for each group, the deployment level of the instance object corresponding to each alarm information in the group is determined, and the alarm information of the specified deployment level is determined as the root cause alarm of the group, that is, the instance object corresponding to the root cause alarm is the root cause. Therefore, the staff can analyze the failure of the corresponding instance object according to the root cause alarm, which can solve the chain failure reaction caused by the failure of the instance object and improve the efficiency of troubleshooting. BRIEF DESCRIPTION OF DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present specification, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0038] Figure 1 The flowchart of the character type-based alarm analysis method in the embodiment of the present specification is shown;

[0039] Figure 2Fig. 4 shows a flowchart illustrating a process of vectorizing field values of a character type in the alarm information according to a format corresponding to the character type in some embodiments of the present specification;

[0040] Figure 3 Fig. 5 shows a flowchart illustrating a process of determining a deployment level of an instance object corresponding to each alarm information in the group in some embodiments of the present specification;

[0041] Figure 4 Fig. 6 shows a structural diagram of an alarm analysis device based on a character type in some embodiments of the present specification;

[0042] Figure 5 Fig. 7 shows a structural diagram of a computer device in some embodiments of the present specification.

[0043]

Explanation of Reference Signs

[0044] 401, character type analysis unit;

[0045] 402, vectorization unit;

[0046] 403, vector splicing unit;

[0047] 404, similarity calculation unit;

[0048] 405, grouping unit;

[0049] 406, root cause alarm determination unit;

[0050] 502, computer device;

[0051] 504, processor;

[0052] 506, memory;

[0053] 508, driving mechanism;

[0054] 510, input / output module;

[0055] 512, input device;

[0056] 514, output device;

[0057] 516, presentation device;

[0058] 518, graphical user interface;

[0059] 520, network interface;

[0060] 522, communication link;

[0061] 524, communication bus. DETAILED DESCRIPTION

[0062] The technical solutions in the embodiments of the present specification will be described clearly and completely in combination with the drawings in the embodiments of the present specification. Obviously, the described embodiments are only part of the embodiments of the present specification, rather than all the embodiments. Based on the embodiments in the embodiments of the present specification, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the embodiments of the present specification.

[0063] It should be noted that the terms "first", "second" and the like in the description and claims of the embodiments of the present specification and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present specification described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, device, product or apparatus that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or apparatuses.

[0064] It should be noted that the acquisition, storage, use, processing, etc. of data in the technical solutions of the embodiments of the present specification comply with the relevant provisions of national laws and regulations.

[0065] It should be noted that in the embodiments of the present specification, some existing industry solutions of software, components, models, etc. may be mentioned, which should be considered as exemplary, and the purpose is only to illustrate the feasibility of the technical solution implementation of the present application, but it does not mean that the applicant has or will necessarily use the solution.

[0066] In view of the problems in the prior art, the embodiments of the present specification provide a character type-based alarm analysis method. Figure 1 The flowchart of the character type-based alarm analysis method in the embodiments of the present specification is shown. The process of analyzing the alarm information is described in the figure. The order of the steps listed in the embodiments is only one of the many step execution orders, and does not represent the only execution order. In actual system or device product execution, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings.

[0067] Specifically, as shown in Figure 1 The method can be executed by a server, and the method can include:

[0068] Step 101: analyze the character type of the field value of each field in each alarm information, respectively;

[0069] Step 102: vectorizing the field value of the character type in the alarm information according to the format corresponding to the character type, to obtain a plurality of vectors of different formats of the plurality of field values in the alarm information;

[0070] Step 103: splicing the plurality of vectors of different formats of the plurality of field values in the alarm information to form a multi-dimensional target vector of the alarm information;

[0071] Step 104: calculating the similarity between the multi-dimensional target vectors of each alarm information;

[0072] Step 105: grouping each alarm information according to the similarity to obtain a plurality of groups;

[0073] Step 106: for each group, determining the deployment level of the instance object corresponding to each alarm information in the group, and taking the alarm information of the specified deployment level as the root cause alarm of the group.

[0074] The alarm field is aligned and analyzed in the method of the embodiments of the present specification, and for the scenario where there is a deployment relationship between instance objects, the field values are vectorized according to the format corresponding to the character type of each field value in the alarm information of the instance object, that is, the embodiments of the present specification no longer analyze the meaning of the field in the business scenario in the alarm information, but directly analyze the character type of each field value itself, and vectorize according to the format corresponding to the character type, such as numerical type, coding type and string type. Therefore, in the scenario where there is a deployment relationship between instance objects, although the field values in the alarm information reported by a plurality of different instance objects of the same field may have no correlation, the information that exists correlation is the field values of different fields, but because the character type of the field value is directly analyzed, the field values of different fields that exist correlation can also be analyzed to have a correlation relationship because of the similar character type, thereby obtaining the correlation relationship between the alarm information. Therefore, the embodiments of the present specification splice a plurality of vectors of different formats of a plurality of field values in the alarm information to form a multi-dimensional target vector of the alarm information; calculate the similarity between the multi-dimensional target vectors of each alarm information; group each alarm information according to the similarity to obtain a plurality of groups. The alarm information belonging to the same group has a correlation.

[0075] Further, in a scenario where there is a deployment relationship between instance objects, the failure of one instance object often triggers a chain reaction, leading to the failure of multiple instance objects. By grouping the alarm information, the alarm information of the failed instance object and the alarm information of other instance objects in the chain reaction can be divided into one group. Then, for each group, the deployment level of the instance object corresponding to each alarm information in the group is determined, and the alarm information of the specified deployment level is taken as the root cause alarm of the group. The instance object corresponding to the root cause alarm is the root cause, so the staff can analyze the failure of the corresponding instance object according to the root cause alarm, which can solve the chain failure reaction caused by the failure of the instance object, and improve the efficiency of troubleshooting.

[0076] In the embodiments of the present specification, the fields of the alarm information can include an instance object identifier, an IP field, a fault type field, a time field, and a message content field, etc. The field values of the above fields of the alarm information are extracted, and then the character types of the field values are analyzed.

[0077] In the embodiments of the present specification, the character types include numerical type, coding type and string type. For example, the field value of the instance object identifier can be of numerical type, the field value of the fault type field can be of coding type, and the field values of the IP field and the message content field can be of string type. In actual implementation, a trained large model can be used to identify the character types of the field values, or a regular expression can be used to identify the character types of the field values, and the embodiments of the present specification are not limited thereto.

[0078] In the embodiments of the present specification, the staff pre-sets the vector format corresponding to the character type, so as to vectorize the field value of the character type in the alarm information according to the format corresponding to the character type. Specifically, as shown in Figure 2 The method further includes:

[0079] Step 201: converting the field value of the numerical type into a numerical vector;

[0080] Step 202: converting the field value of the coding type into a one-hot coding vector;

[0081] Step 203: converting the field value of the string type into a semantic vector.

[0082] In the embodiments of the present specification, for a numerical field, a standardization process is directly performed on the numerical value, such as normalization or Z-score standardization, so that the data is kept in the same order of magnitude, and the purpose is to convert the numerical features into a distribution with the same scale; for a field of category characteristics, such as the region and the field to which it belongs, there is no order relationship between the fields, and hot one-hot encoding can be used to represent each category as a binary vector; for a text field, such as message content, a pre-trained word vector model (such as Word2Vec) can be used to represent the text as a vector.

[0083] It can be understood that the method of the embodiments of the present specification does not align the fields of the alarm information, that is, it no longer compares the similarity between the field values of the same field of the alarm information to determine whether the alarm information is similar, but analyzes the character types of the field values.

[0084] In the embodiments of the present specification, for a numerical field, a standardization process is directly performed on the numerical value, such as normalization or Z-score standardization, so that the data is kept in the same order of magnitude, and the purpose is to convert the numerical features into a distribution with the same scale; for a field of category characteristics, such as the region and the field to which it belongs, there is no order relationship between the fields, and hot one-hot encoding can be used to represent each category as a binary vector; for a text field, such as message content, a pre-trained word vector model (such as Word2Vec) can be used to represent the text as a vector.

[0085] The method of the embodiments of the present specification no longer aligns the IP field, that is, it does not care which field the field value belongs to, but directly analyzes the character type of the field value, for example, the character type of the field value IP of the IP field in the alarm information of the intranet server is a string type, the character type of the field value of the IP field in the alarm information of the load balancing device is a string type, and the character type of the field value of the message content field in the alarm information of the load balancing device is also a string type. Therefore, the association relationship between the alarm information can be analyzed based on the character type, so that the topology of the business system does not need to be queried, and additional calculation amount is avoided.

[0086] The above example is the simplest scenario. In actual applications, the deployment structure of a business system is more complex, including but not limited to a machine room, equipment, a server host, a virtual machine, a container, system software, and a user unit (for example, a microservice). Therefore, merely comparing the similarity between vectors of the same character type can not accurately analyze the correlation between alarm information. Therefore, the embodiment of the present specification splices multiple vectors of different formats of multiple field values in the alarm information to form a multi-dimensional target vector of the alarm information. The dimensions in the multi-dimensional target vector can correspond to character types one by one. Then, the similarity between the multi-dimensional target vectors of each alarm information is calculated.

[0087] Specifically, the formula for calculating the similarity between the multi-dimensional target vectors of each alarm information is as follows:

[0088]

[0089] wherein d represents the similarity between the multi-dimensional target vector (x 1,i ,x 2,i ,…,x n,i ) of the alarm information i and the multi-dimensional target vector (x 1,j ,x 2,j ,…,x n,j ) of the alarm information j, x1, x2, …, x n represent the attributes of n different dimensions of the target vector, respectively.

[0090] Then, each alarm information is grouped according to the similarity, and multiple groups are obtained.

[0091] In the embodiment of the present specification, clustering analysis can be carried out based on the similarity between the multi-dimensional target vectors of the alarm information, so as to group the alarm information. The alarm information in the same group has a strong correlation, wherein a certain alarm information is a root cause alarm, and other alarm information is caused by the root cause alarm.

[0092] Therefore, the embodiment of the present specification analyzes the root cause alarm in each group, so as to facilitate the staff to locate the fault according to the root cause alarm.

[0093] In the embodiment of the present specification, each instance object is labeled with its belonging deployment level in advance. If the instance object at the bottom layer fails, it will cause the instance object at the upper layer to fail. For example, an intranet server is an instance object at the bottom layer, a load balancing device is an instance object at the upper layer, and the failure of the intranet server will cause the load balancing device to report an alarm information. A server host is an instance object at the bottom layer, and a virtual machine deployed on the server host is an instance object at the upper layer. The failure of the server host will cause the virtual machine to report an alarm information.

[0094] It should be noted that the deployment level of the instance object in the embodiments of the present specification can be an attribute of the instance object, and the deployment level information of the instance object is recorded. The type of the deployment level can be a numerical type, and the smaller the numerical value, the more the deployment level is biased to the lower level. Therefore, after grouping, as shown in Figure 3 The method further includes:

[0095] Step 301: Extracting the instance object corresponding to each alarm information in the group;

[0096] Step 302: Determining the deployment level of the instance object.

[0097] In the embodiments of the present specification, only the deployment level information of the instance object needs to be recorded, and the deployment level information is of a numerical type. Subsequently, only the numerical values need to be compared to find the instance object with the smallest numerical value, and the instance object of the bottom layer deployment level is obtained. The alarm information of the instance object is taken as the root cause alarm.

[0098] It should be noted that the embodiments of the present specification do not need to find the association relationship between the instance objects, for example, the embodiments of the present specification do not find which server host the virtual machine is deployed on, because the grouping method proposed in the embodiments of the present specification can group the alarm information of the instance objects with an association relationship into a group. The embodiments of the present specification only need to find the deployment level of the instance object.

[0099] In some other embodiments of the present specification, the deployment level of the instance object can also be recorded in the alarm information. Therefore, the field value of the deployment level field of each alarm information in the group is extracted, and the size of the field value is compared to find the alarm information of the bottom layer as the root cause alarm.

[0100] Based on the same inventive concept, the embodiments of the present specification also provide an alarm analysis device based on character types, as shown in Figure 4 The device includes:

[0101] The character type analysis unit 401 is configured to analyze the character types of the field values of the plurality of fields in each alarm information respectively.

[0102] The vectorization unit 402 is configured to vectorize the field values of the character types in the alarm information according to the format corresponding to the character types, to obtain a plurality of vectors of different formats of the plurality of field values in the alarm information.

[0103] The vector splicing unit 403 is configured to splice the plurality of vectors of different formats of the plurality of field values in the alarm information to form a multi-dimensional target vector of the alarm information.

[0104] The similarity calculation unit 404 is configured to calculate the similarity between the multi-dimensional target vectors of the alarm information.

[0105] The grouping unit 405 is configured to group the alarm information according to the similarity to obtain a plurality of groups.

[0106] The root cause alarm determination unit 406 is configured to determine, for each group, the deployment level of the instance object corresponding to the alarm information in the group, and determine the alarm information of the specified deployment level as the root cause alarm of the group.

[0107] Further, the character type includes a numerical type, an encoding type, and a string type.

[0108] Further, the vectorization of the field value of the character type in the alarm information according to the format corresponding to the character type to obtain a plurality of vectors of different formats of the plurality of field values in the alarm information further includes:

[0109] The field value of the numerical type is converted into a numerical vector;

[0110] The field value of the encoding type is converted into a one-hot encoding vector;

[0111] The field value of the string type is converted into a semantic vector.

[0112] Further, the formula for calculating the similarity between the multi-dimensional target vectors of the alarm information is:

[0113]

[0114] Wherein d represents the similarity between the multi-dimensional target vector (x 1,i ,x 2,i ,…,x n,i ) of the alarm information i and the multi-dimensional target vector (x 1,j ,x 2,j ,…,x n,j ) of the alarm information j, x1, x2, …, x n represent the n different dimensions of the target vector respectively.

[0115] Further, the determination of the deployment level of the instance object corresponding to the alarm information in the group further includes:

[0116] Extracting the instance object corresponding to each alarm information in the group;

[0117] Determining the deployment level of the instance object.

[0118] Further, the determination of the alarm information of the specified deployment level as the root cause alarm of the group further includes:

[0119] The alarm information of the bottommost deployment level is taken as the root cause alarm.

[0120] Since the principle of solving the problem of the above device is similar to the above method, the implementation of the above system can refer to the implementation of the above method, and the repeated parts will not be described.

[0121] As Figure 5 shown, a computer device provided by the embodiments of the present application, the device herein can be a computer device in the embodiments, executing the method herein, the computer device 502 can include one or more processors 504, such as one or more central processing units (CPUs), each of which can implement one or more hardware threads. The computer device 502 can also include any memory 506 for storing any kind of information, such as code, settings, data, etc. Without limitation, for example, the memory 506 can include any one or combination of the following: any type of RAM, any type of ROM, a flash memory device, a hard disk, an optical disk, etc. More generally, any memory can store information using any technology. Further, any memory can provide volatile or non-volatile retention of information. Further, any memory can represent a fixed or removable component of the computer device 502. In one case, the computer device 502 can perform any operation of the associated instructions when the processor 504 executes the associated instructions stored in any memory or combination of memories. The computer device 502 also includes one or more drive mechanisms 508 for interacting with any memory, such as a hard disk drive mechanism, an optical disk drive mechanism, etc.

[0122] The computer device 502 can also include an input / output module 510 (I / O) for receiving various inputs (via input devices 512) and for providing various outputs (via output devices 514). One particular output mechanism can include a presentation device 516 and an associated graphical user interface (GUI) 518. In other embodiments, the input / output module 510 (I / O), input devices 512, and output devices 514 can also not be included, just as a computer device in a network. The computer device 502 can also include one or more network interfaces 520 for exchanging data with other devices via one or more communication links 522. One or more communication buses 524 couple the above-described components together.

[0123] The communication links 522 can be implemented in any manner, for example, through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication links 522 can include any combination of hardwired links, wireless links, routers, gateway functionality, name servers, etc., governed by any protocol or combination of protocols.

[0124] The embodiment of the present specification further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method.

[0125] The embodiment of the present specification further provides a computer readable instruction, wherein when the processor executes the instruction, the program in the instruction causes the processor to execute the method.

[0126] It should be understood that, in various embodiments of the embodiment of the present specification, the size of the sequence number of each process described above does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiment of the present specification.

[0127] It should also be understood that, in the embodiment of the present specification, the term "and / or" is only a description of the association relationship of the associated objects, which means that there can be three relationships. For example, A and / or B can represent three cases: A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in the embodiment of the present specification generally represents that the front and rear associated objects are in an "or" relationship.

[0128] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the disclosed embodiments in the embodiment of the present specification can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been described in the above description. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiment of the present specification.

[0129] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiment, which will not be repeated here.

[0130] In several embodiments provided in the present specification, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the described device embodiments are merely schematic. The division of the units is merely a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be electric, mechanical or other forms.

[0131] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present specification.

[0132] In addition, each functional unit in the various embodiments of the present specification can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be implemented in the form of hardware, or in the form of a software functional unit.

[0133] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such an understanding, the technical solutions of the embodiments of the present specification essentially, or the part that contributes to the prior art, or all or a part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present specification. The foregoing storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disk, and various other media that can store program codes.

[0134] The principles and implementation manners of the embodiments of the present specification are described by using specific examples in the embodiments of the present specification. The above example is only used to help understand the method and its core idea of the embodiments of the present specification. Meanwhile, for those skilled in the art, according to the idea of the embodiments of the present specification, the specific implementation manners and application ranges will be changed. In conclusion, the content of the present specification should not be understood as a limitation of the embodiments of the present specification.

Claims

1. A character type-based alarm analysis method, characterized by, The method comprises: respectively analyzing character types of field values of a plurality of fields in each alarm information; vectorizing the field values of the character types in the alarm information according to formats corresponding to the character types, to obtain a plurality of vectors of different formats of the field values in the alarm information; splicing the plurality of vectors of different formats of the field values in the alarm information to form a multi-dimensional target vector of the alarm information; calculating similarities between the multi-dimensional target vectors of the alarm information; grouping the alarm information according to the similarities to obtain a plurality of groups; for each group, determining deployment levels of instance objects corresponding to the alarm information in the group, and taking alarm information of a specified deployment level as root cause alarm of the group.

2. The method of claim 1, wherein, The character types comprise numerical type, coding type and string type.

3. The method of claim 2, wherein, The vectorizing the field values of the character types in the alarm information according to formats corresponding to the character types, to obtain a plurality of vectors of different formats of the field values in the alarm information further comprises: converting the field values of the numerical type into numerical vectors; converting the field values of the coding type into one-hot coding vectors; converting the field values of the string type into semantic vectors.

4. The method of claim 1, wherein, The formula for calculating the similarities between the multi-dimensional target vectors of the alarm information is: wherein d represents the similarity between the multi-dimensional target vector (x 1,i ,x 2,i ,…,x n,i ) of the alarm information i and the multi-dimensional target vector (x 1,j ,x 2,j ,…,x n,j ) of the alarm information j, and x1, x2, …, x n represent the attributes of n different dimensions of the target vector, respectively.

5. The method of claim 1, wherein, The determining deployment levels of instance objects corresponding to the alarm information in the group further comprises: extracting instance objects corresponding to the alarm information in the group; determining the deployment levels of the instance objects.

6. The method of claim 5, wherein, The taking alarm information of a specified deployment level as root cause alarm of the group further comprises: taking alarm information of the lowest deployment level as the root cause alarm.

7. A character type-based alarm analysis device characterized by comprising: The device comprises: a character type analysis unit configured to analyze character types of field values of a plurality of fields in each alarm information; a vectorization unit configured to vectorize the field values of the character types in the alarm information according to formats corresponding to the character types, to obtain a plurality of vectors of different formats of the field values in the alarm information; a vector splicing unit configured to splice the plurality of vectors of different formats of the field values in the alarm information to form a multi-dimensional target vector of the alarm information; a similarity calculation unit configured to calculate similarities between the multi-dimensional target vectors of the alarm information; a grouping unit configured to group the alarm information according to the similarities to obtain a plurality of groups; a root cause alarm determination unit configured to, for each group, determine deployment levels of instance objects corresponding to the alarm information in the group, and take alarm information of a specified deployment level as root cause alarm of the group.

8. A computer device comprising a memory, a processor, and a computer program stored on the memory, wherein, The processor, when executing the computer program, implements the method of any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program, when executed by a processor, implements the method of any one of claims 1 to 6.

10. A computer program product, characterised in that, The computer program product comprises a computer program, and the computer program, when executed by a processor, implements the method of any one of claims 1 to 6.