Alarm event processing method and device, equipment, storage medium and product
By aggregating and intelligently processing business data from a multi-source big data platform, and using an alarm processing model to generate processing solutions, the problems of flexibility and accuracy in existing alarm systems have been solved, and efficient automated fault handling has been achieved.
Patent Information
- Application Number
- CN202511219417.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-28
- Publication Date
- 2025-11-28
AI Technical Summary
Existing big data platform alarm systems lack flexibility and accuracy, are unable to detect faults in a timely manner, and cannot be automatically intervened, which may lead to service paralysis and cause unavoidable losses.
By acquiring multi-source business data sets, performing aggregation processing, identifying alarm events, and using alarm processing models based on rules trained on historical data and logs to generate processing schemes, automated processing is achieved.
It improves the data analysis rate and alarm event response speed, realizes automated processing of alarm events, and enhances the accuracy and flexibility of fault handling.
Smart Images

Figure CN121037201A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of financial technology and the field of artificial intelligence, in particular to a processing method and device of an alarm event, equipment, a storage medium and a product. BACKGROUND
[0002] With the rapid development of the big data industry, the stability of big data platform services has become a key factor to ensure the continuity of financial services and the reliability of data. The stability of big data platform services is mainly measured by pre-warning, intervention and post-mortem.
[0003] The existing big data platform usually deploys an alarm system based on a timing task, which collects data based on a timing task, compares the collected data with manually defined indicators, and triggers an alarm if the manually defined indicator threshold is exceeded or below. After triggering the alarm, the fault is handled by manual intervention.
[0004] Therefore, although the existing technology can trigger an alarm based on manual rules, the manual rules lack flexibility and accuracy, so that the fault cannot be discovered in time and effectively, and there is no automatic intervention measure for the fault. If the best solution time of the fault is missed, the entire service may be paralyzed, causing unavoidable losses. SUMMARY
[0005] The present application provides a processing method, device, equipment, storage medium and product of an alarm event to solve the defects in the prior art that the manual rules lack flexibility and accuracy, cannot discover faults in time and effectively, and cannot execute automatic intervention measures for the faults.
[0006] In a first aspect, the present application provides a processing method of an alarm event, which comprises:
[0007] Obtaining a plurality of sets of business data, and aggregating the business data in the plurality of sets of business data to obtain a corresponding target set of business data;
[0008] Based on the target set of business data, determining whether there is an alarm event;
[0009] If it is determined that there is an alarm event, determining the first data log corresponding to the alarm event, and inputting the first data log into an alarm processing model to obtain a processing scheme corresponding to the alarm event, wherein the alarm processing model is trained based on an alarm processing rule, a historical alarm log and a corresponding historical processing scheme;
[0010] Based on the processing scheme, processing the alarm event.
[0011] In a possible implementation, the aggregation processing of the business data in the multi-source business data set to obtain the corresponding target business data set comprises the following steps.
[0012] For any one of the business data in the multi-source business data set, the association relationship between the business data and other business data is determined, wherein the naming manners of the business data corresponding to different data categories are different.
[0013] Based on the association relationship, the full-amount business data in the multi-source business data set is integrated to obtain the target business data set.
[0014] In a possible implementation, the determination of whether there is an alarm event based on the target business data set comprises the following steps.
[0015] For any one of the target business data in the target business data set, it is judged whether the target business data is within a dynamic alarm index threshold range.
[0016] If yes, it is determined that there is an alarm event.
[0017] And / or,
[0018] For any one of the target business data sub-set in the target business data set, a combined alarm index corresponding to the target business data sub-set is determined, wherein the target business data sub-set comprises at least two target business data with an association relationship.
[0019] It is judged whether a plurality of target business data in the target business data sub-set reaches the combined alarm index.
[0020] If yes, it is determined that there is an alarm event.
[0021] In a possible implementation, the processing of the alarm event based on the processing scheme comprises the following steps.
[0022] The alarm level of the alarm event is determined, and the alarm level is used to indicate the degree of human intervention required.
[0023] In the case where the alarm level is a first alarm level, the alarm event and the processing scheme are sent to an alarm processing personnel, so that the alarm processing personnel reviews the processing scheme.
[0024] In the case where the alarm level is a second alarm level, the alarm event is processed according to the processing scheme.
[0025] In one possible implementation, before acquiring the multi-source business data set, the method further includes:
[0026] Obtain multiple historical alarm logs, the historical handling solutions corresponding to each historical alarm log, and the alarm handling rules;
[0027] The input data consists of multiple historical alarm logs and their corresponding alarm processing rules, and the output data consists of multiple historical processing schemes.
[0028] Based on the input data and the output data, the large model is iteratively trained until the loss function of the large model is less than a preset value or the number of iterations reaches the maximum number of iterations, thus obtaining the alarm processing model.
[0029] In one possible implementation, the method further includes:
[0030] Determine the verification data corresponding to the alarm event, wherein the verification data includes: the second data log corresponding to the alarm event after the processing scheme is executed;
[0031] Based on the second data log, the processing result of the alarm event is determined, and the processing result is used to indicate whether the alarm event has been resolved;
[0032] Based on the processing results, the threshold range of the dynamic alarm indicator and / or the combined alarm indicator are dynamically optimized.
[0033] Secondly, embodiments of this application provide an alarm event processing apparatus, the apparatus comprising:
[0034] The acquisition module is used to acquire multi-source business data sets;
[0035] The processing module is used to aggregate the business data within the multi-source business data set to obtain the corresponding target business data set.
[0036] The determination module is used to determine whether an alarm event exists based on the target business data set; and if an alarm event is determined to exist, determine the first data log corresponding to the alarm event.
[0037] The processing module is further configured to input the first data log into the alarm processing model to obtain a processing scheme corresponding to the alarm event, wherein the alarm processing model is trained based on alarm processing rules, historical alarm logs, and corresponding historical processing schemes; and to process the alarm event based on the processing scheme.
[0038] In one possible implementation, for any one piece of business data in the multi-source business data set, the determining module is further configured to determine the association between the business data and other business data, wherein the naming methods for business data corresponding to different data categories are different;
[0039] The processing module is used to integrate and process all business data within the multi-source business data set based on the association relationship, so as to obtain the target business data set.
[0040] In one possible implementation, the device further includes: a determination module;
[0041] For any target business data within the target business data set, the judgment module is used to determine whether the target business data is within the dynamic alarm indicator threshold range;
[0042] The determining module is further configured to determine the existence of an alarm event when the target business data is within the dynamic alarm indicator threshold range;
[0043] And / or,
[0044] For any subset of target business data within the target business data set, the determining module is further configured to determine the combined alarm indicator corresponding to the subset of target business data, wherein the subset of target business data includes at least two target business data that are related.
[0045] The judgment module is used to determine whether multiple target business data within the target business data subset have reached the combined alarm indicator;
[0046] The determining module is further configured to determine that an alarm event exists when multiple target business data within the target business data subset reach the combined alarm indicator.
[0047] In one possible implementation, the determining module is further configured to determine the alarm level of the alarm event, the alarm level being used to indicate the degree to which manual intervention is required;
[0048] The processing module is configured to send the alarm event and the processing plan to the alarm handler when the alarm level is the first alarm level, so that the alarm handler can review the processing plan; and to process the alarm event according to the processing plan when the alarm level is the second alarm level.
[0049] In one possible implementation, the acquisition module is further configured to acquire multiple historical alarm logs, historical processing schemes corresponding to each historical alarm log, and alarm processing rules;
[0050] The processing module is further configured to take multiple historical alarm logs and corresponding alarm processing rules as input data, and multiple historical processing schemes as output data; and to perform iterative training on the large model based on the input data and the output data until the loss function of the large model is less than a preset value or the number of iterations reaches the maximum number of iterations, thereby obtaining the alarm processing model.
[0051] In one possible implementation, the determining module is further configured to determine verification data corresponding to the alarm event, wherein the verification data includes: a second data log corresponding to the alarm event after the processing scheme is executed; and based on the second data log, to determine the processing result of the alarm event, wherein the processing result is used to indicate whether the alarm event has been resolved;
[0052] The processing module is further configured to dynamically optimize the threshold range of the dynamic alarm indicator and / or the combined alarm indicator based on the processing result.
[0053] Thirdly, embodiments of this application provide an alarm event processing device, including: a processor, and a memory communicatively connected to the processor;
[0054] The memory stores computer-executed instructions;
[0055] The processor executes computer execution instructions stored in the memory to implement the first aspect and / or various possible implementations of the first aspect.
[0056] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.
[0057] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.
[0058] The alarm event processing method, apparatus, device, storage medium, and product provided in this application acquire a multi-source business data set and aggregate the business data within the multi-source business data set to obtain a corresponding target business data set; based on the target business data set, determine whether an alarm event exists; if an alarm event is determined to exist, determine the first data log corresponding to the alarm event and input the first data log into the alarm processing model to obtain a processing scheme corresponding to the alarm event; based on the processing scheme, process the alarm event. This method achieves automated processing of alarm events, and because it aggregates multi-source data, it improves the data analysis rate, thereby improving the response speed of alarm events. Attached Figure Description
[0059] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0060] Figure 1 A flowchart illustrating an alarm event handling method provided in this application embodiment. Figure One ;
[0061] Figure 2 A flowchart illustrating an alarm event handling method provided in this application embodiment. Figure Two ;
[0062] Figure 3 A schematic diagram of the structure of an alarm event processing device provided in an embodiment of this application;
[0063] Figure 4 This is a schematic diagram of the structure of an alarm event processing device provided in an embodiment of this application.
[0064] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0065] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0066] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation portals for users to choose to authorize or refuse.
[0067] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.
[0068] It should be noted that the alarm event processing methods, devices, equipment, storage media and products provided in this application can be used in the fields of financial technology and artificial intelligence technology, as well as in any field other than financial technology and artificial intelligence technology. The application fields of the alarm event processing methods, devices, equipment, storage media and products in this application are not limited.
[0069] With the rapid development of the big data industry, the stability of big data platform services has become a key factor in ensuring the continuity of financial business and the reliability of data. The stability of big data platform services is mainly measured through pre-event early warning, in-event intervention, and post-event review.
[0070] Existing big data platforms typically deploy alarm systems based on scheduled tasks. These systems collect data based on scheduled tasks, compare the collected data with manually defined indicators, and trigger corresponding alarms if the data exceeds or falls below the manually defined indicator thresholds. After the alarm is triggered, human intervention is required to handle the fault.
[0071] However, the above method has the following drawbacks:
[0072] Defect 1: Inflexible data collection, with data stored in different databases, making it impossible to centrally manage the collected data;
[0073] Defect 2: The alarm indicator configuration is not flexible enough. For example, it only has judgments such as greater than, equal to, and less than, and cannot predict trends.
[0074] Thirdly, it lacks automatic fault intervention measures, cannot automatically analyze and locate the cause, and cannot provide corresponding solutions to the fault;
[0075] Fourthly, when manual intervention is needed for troubleshooting, the slow speed of log analysis can cause the entire service to be paralyzed and result in unavoidable losses if the best time to resolve the fault is missed.
[0076] To address the aforementioned issues, this application provides a method for handling alarm events. This method aggregates acquired multi-source business data to obtain a target business data set, then determines whether an alarm event exists based on this target business data set. If an alarm event is determined to exist, an alarm processing model is used to analyze the corresponding data logs to obtain a corresponding processing solution, and the alarm event is processed according to the processing solution. This method aggregates multi-source data, improving the analysis speed of subsequent data analysis, and also automates the processing of alarm events, thereby improving the response speed of alarm events.
[0077] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0078] The implementation entity of the embodiments described in this application can be, for example, a financial system in a fintech scenario, on which a big data platform is deployed. This big data platform can, for example, be used to monitor business data from multiple data sources, centrally manage alarm indicators, and perform hierarchical and categorized management of alarm indicators.
[0079] Figure 1 A flowchart illustrating an alarm event handling method provided in this application embodiment. Figure One .like Figure 1 As shown in the embodiments of this application, the alarm event processing method includes:
[0080] S101. Obtain a multi-source business data set and aggregate the business data within the multi-source business data set to obtain the corresponding target business data set.
[0081] The multi-source business data set can include business data stored in multiple data sources or databases. This business data may include, for example, CPU utilization, memory capacity, response latency, communication channel usage, and business execution status.
[0082] Existing technologies typically require cross-database ETL transfer when dealing with different data categories across multiple databases in order to achieve unified processing of business data across different data categories.
[0083] In this embodiment, the data type of the business data can be, for example, structured data, unstructured data, and semi-structured data. Different naming methods can be used to name the business data according to its data category.
[0084] For example, a triplet naming convention, i.e., a hierarchical naming convention of [data category], [data source], and [specific table], can be used to name business data. In this way, when managing data in a unified manner, only the data itself is used, without having to care which data source the business data belongs to or which database it is stored in, thereby avoiding data migration between databases and reducing the complexity of data use.
[0085] It is understandable that there may be relationships between business data within a multi-source business data set. For example, the first business data in data source 1 is used to characterize the CPU usage of device A, and the second business data in data source 2 is used to characterize the real-time traffic volume of device A. Since both the first and second business data characterize the operating status of device A, they are related.
[0086] In this step, the business data within the multi-source business data set is aggregated. For example, the relationship between each business data in the multi-source business data set and other business data can be determined. Then, based on the relationship, multiple business data are integrated to obtain the corresponding target business data set.
[0087] S102. Based on the target business data set, determine whether there is an alarm event.
[0088] Alarm events may include, for example, resource utilization alarm events, node and service status alarm events, scheduling and timeliness alarm events, and access anomaly alarm events.
[0089] Resource utilization alarm events can indicate, for example, that cluster nodes or corresponding financial business servers have high CPU usage, high memory usage, high disk usage, and high network bandwidth usage.
[0090] Node and service status alerts can indicate, for example, whether a financial server is offline or whether a critical process is alive.
[0091] Scheduling and timeliness alarm events can indicate, for example, whether a scheduled task has failed to execute, or whether a financial transaction has timed out or been delayed.
[0092] Access anomaly alert events can be used to indicate, for example, whether there are abnormal IP addresses accessing the corresponding financial server. This application does not limit the specific type or content of the alert events; any alert event existing in the financial technology field falls within the scope described in the embodiments of this application.
[0093] In this step, for example, a corresponding scheduled task can be set first, and the corresponding multi-source business data set can be obtained according to the start time, end time and frequency of the scheduled task. Then, based on the target business data set and the alarm parameters such as the custom alarm indicator threshold, frequency, indicator level and alarm strategy, it can be determined whether there is an alarm event.
[0094] In one possible implementation, for any target business data in the target business data set, the range of dynamic alarm indicators corresponding to the target business data can be determined first, and then it can be determined whether the target business data is within the threshold range of the dynamic alarm indicator. If so, it is determined that there is an alarm event.
[0095] The dynamic alarm indicator threshold range can be generated in real time based on multi-dimensional indicator rules such as threshold, slope, year-on-year / month-on-month comparison, etc., or it can be obtained by user-defined settings, or it can be obtained by adjusting and optimizing the preset alarm indicator threshold based on the current alarm strategy and the indicator level corresponding to the target business data.
[0096] Understandably, when determining the range of dynamic alarm indicators, it is possible to optimize the range based on historical trends, pre-set warning lines, intervention lines, and intervention thresholds. In other words, a tiered alarm strategy can be configured, with different alarm indicators and varying degrees of intervention for different levels.
[0097] S103. If an alarm event is determined to exist, determine the first data log corresponding to the alarm event and input the first data log into the alarm processing model to obtain the processing scheme corresponding to the alarm event.
[0098] The first data log may be, for example, a business data log that is related to the alarm event. It may include contextual business data of the target business data, or business data from other data sources that are related to the target business data.
[0099] The alarm handling model is trained based on alarm handling rules, historical alarm logs, and corresponding historical handling schemes. This model can be, for example, a large model used to extract and summarize the first data logs corresponding to alarm events and provide corresponding handling schemes. Its processing of the first log data may include, for example:
[0100] First, determine the keyword vector corresponding to the first log data. Then, match the corresponding historical alarm logs through the keyword vectors. Based on the historical alarm logs, perform knowledge retrieval in the vector database to form alarm analysis results and processing solutions corresponding to the alarm events.
[0101] The training process of the alarm handling model is explained below:
[0102] First, you can obtain multiple historical alarm logs, the historical processing solutions corresponding to each historical alarm log, and the corresponding alarm processing rules;
[0103] Then, multiple historical alarm logs and corresponding alarm handling rules are used as input data, and multiple historical handling schemes are used as output data.
[0104] Based on the input and output data, the standard large model is iteratively trained until the loss function of the standard large model is less than the preset value or the number of iterations reaches the maximum number of iterations, thus obtaining the trained alarm processing model.
[0105] S104. Based on the processing scheme, process the alarm event.
[0106] After obtaining the handling plan, it can be executed directly, or it can be sent to the alarm handling personnel first so that they can review the plan or intervene in the results to form the final handling plan.
[0107] If the alarm handler has doubts about the handling solution, they can activate the corresponding interactive question-and-answer mode to interact with the alarm handler via voice, thereby correcting the handling solution. Voice interaction can be implemented, for example, based on a speech recognition model. This application does not limit the specific implementation process.
[0108] The alarm event processing method provided in this application embodiment obtains a multi-source business data set and aggregates the business data within the multi-source business data set to obtain a corresponding target business data set; based on the target business data set, it determines whether an alarm event exists; if an alarm event is determined to exist, it determines the first data log corresponding to the alarm event and inputs the first data log into the alarm processing model to obtain a processing scheme corresponding to the alarm event; based on the processing scheme, the alarm event is processed. This method realizes automated processing of alarm events, and because multi-source data is aggregated, the data analysis rate is improved, thereby improving the response speed of alarm events.
[0109] Figure 2 A flowchart illustrating an alarm event handling method provided in this application embodiment. Figure Two The multi-source business data set in this embodiment may include, for example, structured data and unstructured data. This embodiment is... Figure 1 Based on the embodiments, a possible implementation of the alarm event handling method is described in detail. The alarm event handling method provided in this application embodiment includes:
[0110] S201. Obtain a multi-source business data set.
[0111] Step S201 is similar to step S101 above, and will not be described again here.
[0112] S202. For any one piece of business data in the multi-source business data set, determine the association relationship between the business data and other business data.
[0113] S203. Based on the aforementioned relationship, the full set of business data within the multi-source business data set is integrated and processed to obtain the target business data set.
[0114] Within a multi-source business data set, there may be correlations between the business data. For example, the first business data in data source 1 represents the CPU usage of device A, while the second business data in data source 2 represents the real-time traffic volume of device A. Since both the first and second business data represent the operating status of device A, they are correlated.
[0115] When determining the relationships between business data, you only need to focus on the business data itself, without having to make cross-database data calls.
[0116] Integration processing could include establishing relationships between each business data point and other business data points, or sorting multiple business data points based on these relationships to obtain multiple subsets of business data.
[0117] S204. For any subset of target business data within the target business data set, determine the combined alarm indicators corresponding to the subset of target business data.
[0118] The target service data subset may include, for example, at least two related target service data sets. Continuing with the example above: both the first service data and the second service data are service data representing the operating status of device A, therefore they can belong to the same target service data subset.
[0119] Because there may be relationships between business data, when determining alarm metrics, a combined alarm metric can be determined based on multiple related business data. This step fully considers the impact of the relationships between multiple business data on the accuracy of alarm event identification. By determining a combined alarm metric using multiple related business data, alarm events can be identified more accurately.
[0120] S205. Determine whether multiple target business data within the target business data subset have reached the combined alarm indicator; if yes, proceed to step S206; if no, proceed to step S207.
[0121] The combined alarm indicators may include one indicator threshold or multiple indicator thresholds.
[0122] When making a judgment, you can first determine the corresponding indicator threshold of each target business data in the target business data subset within the combined alarm indicator, and then determine whether the target business data has reached the indicator threshold. If there is at least one target business data that has reached the corresponding indicator threshold, then it is determined that there is an alarm event.
[0123] S206. Determine that an alarm event exists, determine the first data log corresponding to the alarm event, and input the first data log into the alarm processing model to obtain the processing scheme corresponding to the alarm event.
[0124] This step is similar to step S103 above, and will not be described again here.
[0125] S207. Confirm that there are no alarm events.
[0126] S208. Determine the alarm level of the alarm event.
[0127] The alarm level indicates the degree to which manual intervention is required.
[0128] S209. If the alarm level is the first alarm level, the alarm event and the processing plan are sent to the alarm processing personnel so that the alarm processing personnel can review the processing plan.
[0129] The highest alert level indicates a high degree of need for manual intervention. At this point, the big data platform cannot directly execute the proposed solution; instead, it must send the solution to the alert handling personnel for review. Only after approval will the corresponding solution be executed, allowing for more flexible handling of alert events.
[0130] S210. If the alarm level is the second alarm level, the alarm event shall be processed according to the processing scheme.
[0131] In one possible implementation, after the processing solution is completed, the aforementioned alarm indicators can be optimized based on the execution results. The specific process is as follows:
[0132] Determine the verification data corresponding to the alarm event. The verification data may include, for example, the second data log corresponding to the alarm event after the processing solution is executed.
[0133] Based on the second data log, the processing result of the alarm event is determined, and the processing result is used to indicate whether the alarm event has been resolved; then, based on the processing result, dynamic optimization processing is performed on the threshold range of dynamic alarm indicators and / or combined alarm indicators.
[0134] The alarm event processing method provided in this application does not affect the data itself because it uses different naming methods to name business data in different data sources, and the data corresponding to different data sources can be directly associated with each other. When determining whether an alarm event exists, it only uses the data itself, without having to care which data source the business data belongs to or which database it is stored in, thereby avoiding data migration between databases and reducing the complexity of data use.
[0135] Meanwhile, this method can determine the corresponding combined alarm indicators in real time based on multiple related business data, and then determine whether there is an alarm event based on the combined alarm indicators. In the financial scenario, it can flexibly determine alarm indicators and dynamically define alarm indicators, thereby improving the accuracy of alarm event determination.
[0136] Furthermore, this method employs different processing strategies for alarm events of different alarm levels. When faced with alarm events of high alarm levels, the alarm processing personnel first review the alarm, and only after the review is approved will the corresponding processing plan be executed, thus enabling more flexible handling of alarm events.
[0137] Figure 3 This is a schematic diagram of the structure of an alarm event processing device provided in an embodiment of this application. Figure 3 As shown, the alarm event processing apparatus 300 provided in this application embodiment includes:
[0138] Module 301 is used to acquire a multi-source business data set;
[0139] Processing module 302 is used to aggregate the business data within the multi-source business data set to obtain the corresponding target business data set;
[0140] The determination module 303 is used to determine whether an alarm event exists based on the target business data set; and if an alarm event is determined to exist, determine the first data log corresponding to the alarm event.
[0141] The processing module 302 is further configured to input the first data log into the alarm processing model to obtain a processing scheme corresponding to the alarm event, wherein the alarm processing model is trained based on alarm processing rules, historical alarm logs, and corresponding historical processing schemes; and to process the alarm event based on the processing scheme.
[0142] In one possible implementation, for any one piece of business data in the multi-source business data set, the determining module 303 is further used to determine the association between the business data and other business data, wherein the naming methods of business data corresponding to different data categories are different;
[0143] The processing module 302 is used to integrate and process all business data in the multi-source business data set based on the association relationship to obtain the target business data set.
[0144] In one possible implementation, the device further includes: a determination module 304;
[0145] For any target business data within the target business data set, the judgment module 304 is used to determine whether the target business data is within the dynamic alarm indicator threshold range;
[0146] The determining module 303 is further configured to determine that an alarm event exists when the target business data is within the dynamic alarm indicator threshold range;
[0147] And / or,
[0148] For any subset of target business data within the target business data set, the determining module 303 is further configured to determine the combined alarm indicator corresponding to the subset of target business data, wherein the subset of target business data includes at least two target business data that are related.
[0149] The judgment module 304 is used to determine whether multiple target business data within the target business data subset have reached the combined alarm indicator.
[0150] The determining module 303 is further configured to determine that an alarm event exists when multiple target business data within the target business data subset reach the combined alarm indicator.
[0151] In one possible implementation, the determining module 303 is further configured to determine the alarm level of the alarm event, the alarm level being used to indicate the degree to which manual intervention is required;
[0152] The processing module 302 is configured to send the alarm event and the processing plan to the alarm handler when the alarm level is the first alarm level, so that the alarm handler can review the processing plan; and to process the alarm event according to the processing plan when the alarm level is the second alarm level.
[0153] In one possible implementation, the acquisition module 301 is further configured to acquire multiple historical alarm logs, historical processing schemes corresponding to each historical alarm log, and alarm processing rules;
[0154] The processing module 302 is further configured to take multiple historical alarm logs and corresponding alarm processing rules as input data, and multiple historical processing schemes as output data; and based on the input data and the output data, to perform iterative training on the large model until the loss function of the large model is less than a preset value or the number of iterations reaches the maximum number of iterations, thereby obtaining the alarm processing model.
[0155] In one possible implementation, the determining module 303 is further configured to determine the verification data corresponding to the alarm event, wherein the verification data includes: a second data log corresponding to the alarm event after the processing scheme is executed; and based on the second data log, to determine the processing result of the alarm event, wherein the processing result is used to indicate whether the alarm event has been resolved;
[0156] The processing module 302 is further configured to perform dynamic optimization processing on the threshold range of the dynamic alarm indicator and / or the combined alarm indicator based on the processing result.
[0157] The alarm event processing device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0158] Figure 4 This is a schematic diagram of the structure of an alarm event processing device provided in an embodiment of this application. Figure 4 As shown, the alarm event processing device 400 provided in this embodiment includes at least one processor 401 and a memory 402. Optionally, the device 400 further includes a communication interface 403. The processor 401, memory 402, and communication interface 403 are connected via a bus 404.
[0159] In a specific implementation, at least one processor 401 executes computer execution instructions stored in memory 402, causing at least one processor 401 to perform the above-described method.
[0160] The specific implementation process of processor 401 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0161] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0162] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0163] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0164] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0165] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.
[0166] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0167] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0168] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0169] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0170] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0171] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0172] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0173] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0174] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0175] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0176] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0177] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0178] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0179] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0180] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0181] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for handling alarm events, characterized in that, The method includes: Obtain a multi-source business data set, and aggregate the business data within the multi-source business data set to obtain the corresponding target business data set; Based on the target business data set, determine whether an alarm event exists; If an alarm event is confirmed, the alarm event is confirmed, the first data log corresponding to the alarm event is determined, and the first data log is input into the alarm processing model to obtain the processing solution corresponding to the alarm event. The alarm processing model is trained based on alarm processing rules, historical alarm logs and corresponding historical processing solutions. Based on the aforementioned processing scheme, the alarm event is processed.
2. The method according to claim 1, characterized in that, The aggregation process of the business data within the multi-source business data set to obtain the corresponding target business data set includes: For any one piece of business data in the multi-source business data set, determine the association between the business data and other business data, wherein the naming method of business data corresponding to different data categories is different; Based on the aforementioned relationship, all business data within the multi-source business data set are integrated and processed to obtain the target business data set.
3. The method according to claim 1, characterized in that, The step of determining whether an alarm event exists based on the target business data set includes: For any target business data within the target business data set, determine whether the target business data is within the dynamic alarm indicator threshold range; If so, then an alarm event has been confirmed; And / or, For any subset of target business data within the target business data set, determine the combined alarm indicator corresponding to the subset of target business data, wherein the subset of target business data includes at least two target business data that are related. Determine whether multiple target business data within the target business data subset reach the combined alarm indicator; If so, then an alarm event has been confirmed.
4. The method according to claim 1, characterized in that, The processing of the alarm event based on the processing scheme includes: Determine the alarm level of the alarm event, the alarm level being used to indicate the degree to which manual intervention is required; When the alarm level is the first alarm level, the alarm event and the handling plan are sent to the alarm handling personnel so that the alarm handling personnel can review the handling plan; When the alarm level is the second alarm level, the alarm event shall be processed in accordance with the processing scheme.
5. The method according to claim 1, characterized in that, Before acquiring the multi-source business data set, the method further includes: Obtain multiple historical alarm logs, the historical handling solutions corresponding to each historical alarm log, and the alarm handling rules; The input data consists of multiple historical alarm logs and their corresponding alarm processing rules, and the output data consists of multiple historical processing schemes. Based on the input data and the output data, the large model is iteratively trained until the loss function of the large model is less than a preset value or the number of iterations reaches the maximum number of iterations, thus obtaining the alarm processing model.
6. The method according to claim 1, characterized in that, The method further includes: Determine the verification data corresponding to the alarm event, wherein the verification data includes: the second data log corresponding to the alarm event after the processing scheme is executed; Based on the second data log, the processing result of the alarm event is determined, and the processing result is used to indicate whether the alarm event has been resolved; Based on the processing results, the threshold range of the dynamic alarm indicator and / or the combined alarm indicator are dynamically optimized.
7. An alarm event processing device, characterized in that, include: The acquisition module is used to acquire multi-source business data sets; The processing module is used to aggregate the business data within the multi-source business data set to obtain the corresponding target business data set. The determination module is used to determine whether an alarm event exists based on the target business data set; And if it is determined that an alarm event exists, determine the first data log corresponding to the alarm event; The processing module is further configured to input the first data log into the alarm processing model to obtain the processing scheme corresponding to the alarm event, wherein the alarm processing model is trained based on alarm processing rules, historical alarm logs and corresponding historical processing schemes. And based on the processing scheme, the alarm event is processed.
8. An alarm event processing device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 6.