Substation operation-based lock control terminal work log query method and system

By performing time-series processing and semantic parsing of the substation lock control terminal work logs, combined with spatial topology indexing and intent recognition models, the problem of insufficient identification of entity interaction relationships in lock control terminal log queries was solved. This enabled deep binding of log data with equipment relationships and multi-dimensional retrieval, thereby improving the decision support value of the query results.

CN121092403BActive Publication Date: 2026-04-17GUANGDONG ZHONGXING ELECTRIC SWITCH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGDONG ZHONGXING ELECTRIC SWITCH
Filing Date
2025-11-12
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively identify entity interaction relationships and behavioral attributes in the operation logs of substation interlocking terminals. They are unable to correlate log records with the physical layout and electrical connections of equipment, resulting in query results limited to isolated log entries and failing to provide comprehensive and accurate operational backtracking and risk assessment data.

Method used

By collecting and serializing the original operation log stream, using semantic parsing algorithms for contextual association analysis, constructing a spatial topology index, and combining an intent recognition model for multi-dimensional retrieval, log query results containing operation chain evolution paths and potential risk warnings are generated.

Benefits of technology

It achieves deep binding of log data with device spatial location and electrical connection relationship, improves the relevance and interpretability of query results, lowers the operation threshold for users, and provides more comprehensive basis for operation process backtracking and risk prediction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121092403B_ABST
    Figure CN121092403B_ABST
Patent Text Reader

Abstract

This invention provides a method and system for querying the operation logs of substation lock control terminals. It collects raw operation log streams generated by substation lock control terminals within a preset time period, serializes them to obtain a log data sequence, and then uses context association analysis to identify entity interaction relationships and behavioral attribute descriptions in the log text. After standardization and integration, a structured log metadata set is obtained. A spatial topology index is constructed based on the physical layout and electrical connection relationships of substation equipment, mapping the equipment association information to the corresponding node positions in the spatial topology index to generate a spatially enhanced log data set. Natural language query requests are received, a structured query expression is generated, and multi-dimensional retrieval and matching are performed on the spatially enhanced log data set to output a preliminary query result set. Temporal correlation analysis and operational impact assessment are performed on the log records to generate a query report. This invention enables efficient and accurate querying of substation lock control terminal operation logs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing, and more specifically, to a method and system for querying the work logs of a lock control terminal based on substation operation and maintenance. Background Technology

[0002] In the field of substation operation and maintenance management, interlocking terminals are key facilities for ensuring equipment operation safety and tracing operational processes. Their work logs record important information such as equipment operation, status changes, and abnormal events, serving as the basic data source for maintenance personnel to conduct fault diagnosis, operation auditing, and safety control. Currently, querying interlocking terminal work logs typically involves keyword matching or simple condition filtering based on preset fields to obtain log records containing specific words or meeting basic conditions. However, because substation interlocking terminal logs usually contain a large amount of unstructured text information, and operational behaviors have temporal and equipment-related correlations, traditional query methods struggle to effectively identify entity interaction relationships and behavioral attributes within the log text. They cannot correlate log records with the physical layout and electrical connections of substation equipment, resulting in query results often limited to isolated log entries. This makes it difficult to present the complete evolution process and potential impact of operational events, and fails to provide maintenance personnel with comprehensive and accurate operational backtracking and risk assessment basis. Therefore, how to achieve efficient and accurate querying of substation interlocking terminal work logs has become an urgent problem to be solved. Summary of the Invention

[0003] In view of this, the present invention provides a method and system for querying the work log of a lock control terminal based on substation operation and maintenance.

[0004] According to one aspect of the present invention, a method for querying the operation logs of a lock control terminal based on substation operation and maintenance is provided. The method includes: collecting the original operation log stream generated by the lock control terminal of the substation within a preset time period; serializing the original operation log stream according to the timestamp order to obtain a log data sequence with temporal correlation; performing contextual correlation analysis on each log record using a semantic parsing algorithm to identify entity interaction relationships and behavioral attribute descriptions in the log text; standardizing and integrating the identification results according to a preset data structure to obtain a structured log metadata set; and constructing a spatial topology index based on the physical layout and electrical connection relationship of substation equipment, and then... Device association information in the structured log metadata set is mapped to the corresponding node location in the spatial topology index, generating a spatially enhanced log data set containing spatial location attributes. Natural language query requests input by the user are received, and the core intent and constraints in the natural language query request are parsed using an intent recognition model to generate a structured query expression. Based on the structured query expression, multi-dimensional retrieval and matching are performed on the spatially enhanced log data set, outputting a preliminary query result set. Temporal correlation analysis and operational impact assessment are performed on the log records in the preliminary query result set, generating a log query result report containing the operational chain evolution path and potential risk warnings.

[0005] According to another aspect of the present invention, a computer system is provided, comprising: a processor; and a memory, wherein the memory stores computer-readable code that, when executed by the processor, causes the processor to perform the method as described above.

[0006] The present invention provides a method for querying the operation logs of lock control terminals based on substation operation and maintenance. By performing time-series processing on the original operation log stream, a sequence of log data with temporal correlations is obtained, providing temporal context support for subsequent semantic parsing. This allows semantic parsing to move beyond the independent analysis of single log entries and instead identify cross-log entity interaction relationships and behavioral attribute descriptions by combining temporal correlations. The structured log metadata set obtained through standardized integration effectively improves the accuracy of structured integration and the completeness of semantic expression of log data. Furthermore, a spatial topology index is constructed based on the physical layout and electrical connection relationships of substation equipment. Equipment association information from the structured log metadata set is mapped to index nodes to generate a spatially enhanced log data set. This achieves deep binding between log data and the physical spatial location and electrical connection relationships of equipment, solving the problem of traditional log queries where log records and equipment spatial attributes are mismatched. The system addresses the issue of spatial disconnect by enhancing the spatial relevance and interpretability of log data. Upon receiving natural language query requests from users, it uses an intent recognition model to parse and generate structured query expressions. These expressions are then combined with the multi-dimensional attributes of the spatially enhanced log data set for retrieval and matching. This not only lowers the operational threshold for users and avoids reliance on specialized query syntax but also improves the accuracy of matching query results with user intent through multi-dimensional retrieval. Furthermore, it performs temporal correlation analysis and operational impact assessment on the initial query result set, generating a log query result report that includes the operational chain evolution path and potential risk warnings. This transforms the query results from isolated log record listings into a presentation of the temporal evolution process and potential impact of operational events, effectively enhancing the decision support value of log query results and providing substation maintenance personnel with a more comprehensive basis for operational process retrospectives and risk prediction. Attached Figure Description

[0007] Figure 1 This is a schematic diagram of the application scenario provided by the present invention;

[0008] Figure 2 This is a flowchart illustrating a method for querying the work logs of a lock control terminal based on substation operation and maintenance, provided by the present invention.

[0009] Figure 3 This is a schematic diagram of the structure of a computer system provided in an embodiment of the present invention. Detailed Implementation

[0010] To facilitate a clearer understanding of this invention, we will first introduce the application scenarios in which this invention is implemented, such as... Figure 1 As shown, this application scenario includes a computer system 10 and a terminal cluster. The terminal cluster can include one or more terminals; the number of terminals will not be limited here. Figure 1As shown, the terminal cluster may specifically include terminal 1, terminal 2, ..., terminal n; it can be understood that terminal 1, terminal 2, terminal 3, ..., terminal n can all be connected to the computer system 10 via a network so that each terminal can interact with the computer system 10 via the network connection.

[0011] Understandably, computer system 10 refers to the device that executes the method of the present invention, such as a background management system. The terminal specifically refers to a lock control terminal, which may include electronic keys and smart padlocks. The electronic key contains a key chip, enabling read / write storage. Through computer-assigned tasks, patrol task details are stored in the chip, such as dynamic passwords, task locations, and dates. Simultaneously, the time is recorded when the smart lock is activated, thus calculating the execution time of a single task. Secondly, it has a data transmission function; when the electronic key is connected to the smart lock, only by entering the correct dynamic password and transmitting the correct password data to the smart lock chip can its switch be activated.

[0012] Further, please see Figure 2 This is a flowchart illustrating a method for querying the work logs of a lock control terminal based on substation operation and maintenance, provided by an embodiment of the present invention. Figure 2 As shown, this method can be derived from... Figure 1 The computer system in the substation is used to execute the following steps: Step S100: Collect the original operation log stream generated by the substation lock control terminal within a preset time period, and serialize the original operation log stream according to the timestamp order to obtain a log data sequence with time sequence correlation.

[0013] The raw operation log stream is a collection of operation logs generated by the substation interlocking terminal within a preset time period. These logs record various operation information of the interlocking terminal during that time period, such as operation time, operation type, and operation object. A timestamp is an identifier used to mark the time each log record was generated, clearly indicating the chronological order of the log records. Serialization is the process of arranging the raw operation log stream according to the chronological order of the timestamps, aiming to establish a temporal correlation between the log records for easier subsequent analysis and processing.

[0014] In practice, the preset time period can be set according to actual needs, such as one day, one week, or one month. The raw operation log stream can be collected by interfacing with the substation's lock control terminal via a data interface to obtain all operation logs generated within the preset time period. For scenarios where server log files are stored, log collection tools, such as Filebeat, can be used to periodically scan the log files and extract log records that match the preset time period. After obtaining the raw operation log stream, the timestamp of each log record is parsed, and the log records are sorted in ascending order of timestamp.

[0015] Step S200: Perform contextual analysis on each log record using a semantic parsing algorithm to identify entity interaction relationships and behavioral attribute descriptions in the log text. Standardize and integrate the identification results according to a preset data structure to obtain a structured log metadata set.

[0016] Semantic parsing algorithms are used for semantic understanding and analysis of text, capable of uncovering hidden semantic information and relationships within the text. Contextual association analysis analyzes the relationships between various elements in the log text, considering the context of the log record. Entity interaction relationships are the interactions between different entities (such as devices, operation instructions, operation results, etc.) in the log text, such as the execution relationship between a device and an operation instruction, or the causal relationship between a device and an operation result. Behavioral attribute descriptions describe the behavioral characteristics exhibited by entities during interactions, such as the type of operation, the time of the operation, and the status of the operation. Predefined data structures are predefined data organization forms used to standardize and integrate identification results, giving them a unified format and structure. Structured log metadata sets are collections of standardized and integrated log metadata, containing information such as entity interaction relationships and behavioral attribute descriptions from the log text, facilitating subsequent querying and analysis.

[0017] As one implementation method, step S200 may include the following steps S210~S250: Step S210: Divide the log records in the log data sequence into continuous log segment units according to the time window, perform context semantic completion on each log segment unit, calculate the semantic correlation degree between adjacent log records through the context semantic coding model, and generate a log segment semantic correlation matrix.

[0018] A time window is a fixed time range used to divide a log data sequence into multiple consecutive log segment units. Each log segment unit contains log records generated within that time window. Contextual semantic completion, based on the context of log records, supplements and improves missing or incomplete semantic information in the log text to enhance the accuracy of semantic understanding. Contextual semantic encoding models are models used to encode the contextual semantics of text, converting text into vector representations to facilitate the calculation of semantic relationships between texts. The log segment semantic association matrix is ​​a two-dimensional matrix, where each element represents the semantic relationship between adjacent log records.

[0019] In practice, the size of the time window can be adjusted according to specific needs, such as setting it to one hour or one day. When dividing the log data sequence by time window, the range of each log segment unit can be determined based on the timestamp of the log record. For contextual semantic completion, a pre-trained language model, such as BERT, can be used to process the log records, and the missing semantic information can be supplemented by the model's contextual understanding ability. When calculating the semantic correlation between adjacent log records, each log record is input into the contextual semantic encoding model to obtain its corresponding vector representation. Then, methods such as cosine similarity are used to calculate the similarity between the vectors, and the similarity is used as the semantic correlation. Finally, the calculated semantic correlation is filled into the log segment semantic correlation matrix.

[0020] Step S220: Based on the semantic association matrix of log fragments, perform co-occurrence frequency statistics and semantic distance calculation on entity words in the log text, construct an entity association strength matrix, and mine the dependency path between devices and operation instructions and operation results through the entity association strength matrix to generate an entity interaction relationship network.

[0021] Entity lexicons are words representing various entities in the log text, such as device names, operation command names, and operation result names. Co-occurrence frequency (COF) is the frequency with which two entity lexicons appear simultaneously in the same log segment unit; COF reflects the degree of association between the two entities. Semantic distance is an indicator used to measure the semantic similarity between two entity lexicons; the smaller the semantic distance, the more semantically similar the two entity lexicons are. The entity association strength matrix is ​​a two-dimensional matrix where each element represents the overall association degree between two entities; this matrix is ​​obtained by weighting and fusing COF and semantic similarity. Dependency paths are the paths of dependency relationships between devices and operation commands / results; mining these paths reveals the device's operation flow and causal relationships. The entity interaction relationship network is a hierarchical network that maps the path nodes and connections in the entity interaction path set to network nodes and edges, visually displaying the interaction relationships between entities.

[0022] As one implementation method, step S220 may include the following steps S221~S225: Step S221: Extract entity words from log fragment units, perform deduplication and type labeling on entity words, establish an entity word library, calculate the co-occurrence frequency of entity words by the occurrence position and frequency of words in the entity word library in log fragment units, and generate a co-occurrence frequency matrix.

[0023] Entity vocabulary extraction is the process of identifying words representing various entities from log fragment units. Named Entity Recognition (NER) algorithms, such as the BiLSTM-CRF-based model, can be used to process the log text and identify entity words. Deduplication removes duplicate words from the entity vocabulary to reduce redundancy. Type labeling assigns the entity type to each entity word, such as device type, operation command type, or operation result type. The entity vocabulary database stores all deduplicated and labeled entity words. Co-occurrence frequency (COF) is calculated by counting the number of times entity words appear simultaneously in log fragment units. The COF matrix is ​​a two-dimensional matrix where each element represents the COF of two entity words.

[0024] In the specific implementation, a named entity recognition model is used to process log segment units and extract entity words. Then, a set data structure is used to deduplicate the entity words and label each entity word with its corresponding entity type. After establishing the entity vocabulary, each log segment unit is traversed to count the occurrence position and frequency of entity words, and the co-occurrence frequency of entity words is calculated. For example, a nested loop is used to traverse each pair of entity words in the entity vocabulary, count the number of times they appear together in the same log segment unit, divide the number of times by the total number of log segment units to obtain the co-occurrence frequency, and finally generate a co-occurrence frequency matrix.

[0025] Step S222: Based on the co-occurrence frequency matrix, a semantic distance calculation model is used to quantitatively evaluate the semantic similarity between entity words. The co-occurrence frequency and semantic similarity are weighted and fused to generate an entity association strength matrix. The matrix element values ​​represent the comprehensive association degree of entity pairs.

[0026] Semantic distance calculation models are used to calculate the semantic distance between two entity words. Feasible models include Word2Vec and GloVe. These models convert entity words into vector representations and measure semantic similarity by calculating the distance between vectors. Semantic similarity is a quantitative representation of the degree of semantic similarity between two entity words; the higher the semantic similarity, the closer the two entity words are semantically. Weighted fusion is the process of combining co-occurrence frequency and semantic similarity according to certain weights. Weighted fusion can comprehensively consider the influence of co-occurrence frequency and semantic similarity on the degree of entity association. In essence, co-occurrence frequency and semantic similarity can be normalized separately, and then the normalized co-occurrence frequency and semantic similarity can be weighted and fused to generate an entity association strength matrix. The matrix element values ​​represent the comprehensive association degree of the entity pair. The entity association strength matrix is ​​a two-dimensional matrix, where each element represents the comprehensive association degree between two entities. In implementation, a pre-trained semantic distance calculation model, such as Word2Vec, is used to convert each entity word in the entity vocabulary into a vector representation. Then, the similarity between any two entity word vectors is calculated using methods such as cosine similarity, resulting in a semantic similarity matrix. Next, weights are assigned to co-occurrence frequency and semantic similarity, and the corresponding elements in the co-occurrence frequency matrix and semantic similarity matrix are summed according to their weights to obtain the entity association strength matrix. The larger the value of a matrix element, the higher the overall association degree of the corresponding entity pair.

[0027] Step S223: Select entity pairs in the entity association strength matrix whose matrix element values ​​are greater than the association strength threshold as strong association entity pairs. Starting from the strong association entity pairs, perform path traversal on the entity association strength matrix to discover multi-hop dependency paths containing intermediate entities.

[0028] The association strength threshold is a critical value used to determine whether the association between entity pairs is strong enough. Only entity pairs with matrix element values ​​greater than this threshold are considered strongly associated entity pairs. A multi-hop dependency path is a dependency path that includes intermediate entities; that is, the dependency from one entity to another is not direct but is achieved through one or more intermediate entities. Path traversal is the process of starting from strongly associated entity pairs and searching for possible dependency paths in the entity association strength matrix.

[0029] In practice, the association strength threshold can be adjusted according to specific needs. The entity association strength matrix is ​​traversed, and entity pairs with element values ​​greater than the association strength threshold are selected as strongly associated entity pairs. Starting from these strongly associated entity pairs, a depth-first search (DFS) or breadth-first search (BFS) algorithm is used to traverse the entity association strength matrix. During the traversal, the entities and paths visited are recorded, and when a multi-hop dependency path containing intermediate entities is found, it is recorded.

[0030] Step S224: Perform directional labeling on multi-hop dependency paths, determine the interaction initiator, interaction object and interaction result of entities in the path, classify the paths according to the interaction direction and interaction type, and generate a set of entity interaction paths containing hierarchical relationships.

[0031] Directional annotation marks the interaction direction for each path in a multi-hop dependency relationship, thus determining the interaction initiator, interaction object, and interaction result for entities within the path. The interaction initiator is the entity that initiates the interaction, the interaction object is the entity being interacted with, and the interaction result is the outcome of the interaction. The interaction type is the specific type of interaction behavior, such as performing an operation or generating a result. Classifying paths based on interaction direction and type allows paths with the same interaction direction and type to be grouped together, generating a set of entity interaction paths that include hierarchical relationships.

[0032] During implementation, the semantic and contextual information of entities in multi-hop dependency paths is analyzed to determine the interaction initiator, interaction object, and interaction result for each entity in each path. For example, if the path represents "Device A executes operation instruction B to produce operation result C," then Device A is the interaction initiator, operation instruction B is the interaction object, and operation result C is the interaction result. Paths are categorized based on interaction direction and interaction type; for example, paths involving execution of operations are grouped into one category, and paths involving the production of results are grouped into another. Finally, the categorized paths are organized into a hierarchical set of entity interaction paths for easier subsequent management and analysis.

[0033] Step S225: Map the path nodes and connection relationships in the entity interaction path set to network nodes and edges. The node attributes include entity type and interaction weight, and the edge attributes include interaction type and association strength, generating a hierarchical entity interaction relationship network.

[0034] Path nodes are nodes representing entities within a set of entity interaction paths, and connections are the ways in which path nodes are connected. Network nodes are nodes that map path nodes to the network, and edges are line segments connecting network nodes. Node attributes are the attribute information set for each network node, including entity type and interaction weight. Entity type indicates the type of entity the node represents, and interaction weight indicates the importance of the node in the interaction process. Edge attributes are the attribute information set for each edge, including interaction type and association strength. Interaction type indicates the type of interaction behavior represented by the edge, and association strength indicates the degree of association between the two nodes connected by the edge.

[0035] In the implementation, the set of entity interaction paths is traversed, each path node is mapped to a network node, and entity type and interaction weight attributes are set for each node. For example, the interaction weight of a node is assigned based on the entity's role and importance in the interaction path. Simultaneously, the connections between path nodes are mapped to network edges, and interaction type and association strength attributes are set for each edge. Association strength can be directly obtained using the values ​​of the corresponding elements in the entity association strength matrix. Finally, all network nodes and edges are combined to generate a hierarchical entity interaction relationship network, which can intuitively display the interaction relationships between entities.

[0036] Step S230: Predict behavioral attribute labels for nodes in the entity interaction relationship network. By analyzing the role positioning and contextual description text of the entity in the interaction path, determine the behavioral feature description corresponding to each entity interaction event, bind the behavioral feature description to the node of the entity interaction relationship network, and generate an enhanced interaction network with behavioral attributes.

[0037] Behavioral attribute label prediction is the process of predicting the behavioral attribute labels corresponding to each entity's interaction event based on the entity's role positioning and contextual description text within the interaction path. Behavioral feature description is a detailed description of the behavioral characteristics exhibited by each entity's interaction event, including the time, type, and state of the operation. Node binding is the process of associating behavioral feature descriptions with corresponding nodes in the entity interaction relationship network. Node binding allows the entity interaction relationship network to contain more behavioral attribute information, generating an enhanced interaction network with behavioral attributes.

[0038] As one implementation, step S230 may include the following steps S231~S235: Step S231: Extract the context description text of each entity interaction event in the entity interaction relationship network, extract key information from the context description text, and generate a set of text fragments containing time stamps, status descriptions, and result descriptions.

[0039] Contextual description text refers to the relevant textual information surrounding each entity interaction event in the entity interaction relationship network. This textual information contains a detailed description of the interaction event, such as the operation time, operation status, and operation result. Key information extraction is the process of identifying important information from the contextual description text. Text mining algorithms, such as TF-IDF-based keyword extraction algorithms, can be used to process the contextual description text and extract key information. Time stamps are identifiers used to mark the time when the interaction event occurred. The state description describes the state of the interaction event at a certain moment, and the result description explains the result produced by the interaction event. The text fragment set is a collection storing all the extracted key information.

[0040] In practice, each entity interaction event in the entity interaction relationship network is traversed, and its contextual description text is extracted. Then, the TF-IDF algorithm is used to calculate the importance of each word in the context, and words with higher importance are selected as key information. For the extraction of time stamps, regular expressions can be used to match time information in the context. For the extraction of state descriptions and result descriptions, filtering can be performed based on keywords such as "state" and "result." Finally, the extracted time stamps, state descriptions, and result descriptions are combined into text fragments to generate a set of text fragments.

[0041] Step S232: Based on the role positioning of the entity in the interaction path, determine the subject and object of the entity interaction event, predict the possible categories of behavioral attributes that the entity interaction event may contain by the interaction type of the subject and object, and generate a candidate set of attribute categories.

[0042] An entity's role in the interaction path refers to the specific role it plays, such as initiator, recipient, or result-receiver. The actor is the entity that initiates the interaction, and the recipient is the entity being interacted with. The interaction type is the manner of interaction between the actor and the recipient, such as performing an operation or generating a result. Behavioral attribute categories are classifications of the behavioral attributes possessed by the entity's interaction events, such as operation type, operation time, and operation status. The attribute category candidate set is a collection storing all possible behavioral attribute categories.

[0043] In practical implementation, the position and role of entities in the interaction path are analyzed to determine the action subject and action object. For example, if the path represents "device A executes operation instruction B to produce operation result C", then device A is the action subject, and operation instruction B is the action object. Based on the interaction type between the action subject and action object, and combined with predefined behavior attribute category rules, the possible behavior attribute categories that the entity's interaction event may contain are predicted. For example, if the interaction type is "execute operation", the possible behavior attribute categories include operation time, operation type, operation status, etc. The predicted behavior attribute categories are then combined into a candidate attribute category set.

[0044] Step S233: Match the set of text fragments with the candidate set of attribute categories, filter the text fragments with the highest matching degree with the attribute categories by calculating the semantic similarity of the text, and use the filtered text fragments as behavioral feature descriptions of the entity's interaction event.

[0045] Text semantic similarity calculation is a method used to measure the degree of semantic similarity between two texts. Feasible methods for text semantic similarity calculation include cosine similarity and edit distance. Through text semantic similarity calculation, text fragments with the highest matching degree to attribute categories can be selected. Behavioral feature description is a detailed description of the behavioral characteristics of entity interaction events. The selected text fragments can accurately describe the behavioral characteristics of the entity's interaction events.

[0046] During implementation, cosine similarity is used to calculate the semantic similarity between each text fragment in the text fragment set and each attribute category in the attribute category candidate set. For each attribute category, the text fragment with the highest semantic similarity is selected as the matching text fragment. The selected text fragments are then combined to serve as a behavioral feature description of the entity's interaction event. For example, for the attribute category "operation time," the text fragment containing a time stamp with the highest semantic similarity to that attribute category is selected as the description of the operation time.

[0047] Step S234: Perform structured processing on the behavioral feature description, extract key parameters from the behavioral feature description, convert the key parameters into standardized attribute values, and generate behavioral attribute labels containing attribute categories and attribute values.

[0048] Structured processing is the process of organizing and standardizing behavioral feature descriptions, giving them a specific structure and format. Key parameters are important information in the behavioral feature description, such as the specific time of the operation and the specific name of the operation type. Standardized attribute values ​​convert key parameters into attribute values ​​with a unified format and range, facilitating subsequent storage and retrieval. Behavioral attribute tags are tags containing attribute categories and attribute values, used to describe the behavioral attributes of entity interaction events.

[0049] In practice, regular expressions or natural language processing techniques are used to parse the behavioral feature descriptions and extract key parameters. Then, these key parameters are converted into standardized attribute values, such as converting time information into timestamp format. Finally, the attribute categories and standardized attribute values ​​are combined to form behavioral attribute labels.

[0050] Step S235: Dynamically bind the behavioral attribute labels to the corresponding nodes in the entity interaction relationship network, establish the mapping relationship between nodes and attribute labels, allow the attribute labels to be dynamically adjusted as entity interaction events are updated, and generate an enhanced interaction network with behavioral attributes.

[0051] Dynamic binding is the process of associating behavioral attribute labels with corresponding nodes in the entity interaction relationship network, and this association can be dynamically adjusted as entity interaction events are updated. Mapping relationships are data structures used to record the correspondence between nodes and attribute labels, allowing for convenient searching and updating of node attribute labels. Enhanced interaction networks with behavioral attributes build upon entity interaction relationship networks by adding behavioral attribute label information, providing a more comprehensive view of the interaction relationships and behavioral attributes between entities.

[0052] In the implementation, each node in the entity interaction network is traversed, and the corresponding behavioral attribute label is found based on the entity interaction event represented by the node. Then, a dictionary data structure is used to establish a mapping relationship between nodes and attribute labels, binding the behavioral attribute labels to nodes. When an entity interaction event is updated, the behavioral attribute labels are recalculated, and the mapping relationship is updated, so that the attribute labels can be dynamically adjusted as the entity interaction event updates. Finally, an enhanced interaction network with behavioral attributes is obtained.

[0053] Step S240: Standardize the mapping of entity names and behavioral characteristic descriptions in the enhanced interactive network according to the substation operation and maintenance specifications, unify the expression of equipment identification and operation type, and eliminate the association gaps caused by differences in expression.

[0054] Substation operation and maintenance specifications are standards and norms established for substation operation and maintenance management. These include standardized expressions for things like equipment identification and operation types. Standardized mapping is the process of converting entity names and behavioral characteristic descriptions in an enhanced interactive network according to the substation operation and maintenance specifications. The goal is to ensure that entity names and behavioral characteristic descriptions have a unified expression, avoiding gaps in association caused by differences in expression. Equipment identification is a unique identifier for substation equipment, and operation type is a classification of various operations, such as switching operations and maintenance operations.

[0055] In practice, a standardized mapping table can be established, recording the correspondence between entity names and behavioral characteristic descriptions in the enhanced interaction network and the unified expression methods in substation operation and maintenance specifications. Each node in the enhanced interaction network is traversed, and its entity name and behavioral characteristic description are transformed according to the standardized mapping table. A similar transformation is performed on the descriptions of operation types, ultimately eliminating the disconnect caused by differences in expression.

[0056] Step S250: Dynamically encapsulate the standardized enhanced interaction network according to the preset hierarchical data structure, take the entity interaction relationship as the main hierarchical framework and the behavior attribute description as the sub-hierarchical content, realize the dynamic calling of interaction relationship and attribute description through parent-child node association, and generate a structured log metadata set.

[0057] The predefined hierarchical data structure is a predefined data organization form with hierarchical relationships, used to encapsulate the standardized enhanced interaction network. Dynamic encapsulation is the process of organizing and packaging the standardized enhanced interaction network according to the predefined hierarchical data structure. Entity interaction relationships serve as the main hierarchical framework, using the interaction relationships between entities as the main layer of the hierarchical structure to display the associations between entities. Behavioral attribute descriptions serve as sub-level content, using the behavioral attribute descriptions of each entity interaction event as sub-levels under the main hierarchy to describe the behavioral characteristics of entity interaction events in detail. Parent-child node associations are established by creating associations between parent and child nodes to achieve dynamic invocation of interaction relationships and attribute descriptions. The structured log metadata collection is a collection of dynamically encapsulated log metadata with a clear hierarchical structure, facilitating subsequent querying and analysis.

[0058] In implementation, the pre-defined hierarchical data structure can be designed as a tree structure, where entity interaction relationships serve as the trunk nodes and behavioral attribute descriptions serve as the leaf nodes. The standardized enhanced interaction network is traversed, organizing entity interaction relationships and behavioral attribute descriptions according to the tree structure. For each entity interaction relationship node, its corresponding behavioral attribute description node is added as a child node. By establishing the association between parent and child nodes, when a query for a specific entity interaction relationship is needed, its corresponding behavioral attribute description can be dynamically invoked. Ultimately, a structured log metadata set is generated.

[0059] Step S300: Construct a spatial topology index based on the physical layout and electrical connection relationship of substation equipment, map the equipment association information in the structured log metadata set to the corresponding node position of the spatial topology index, and generate a spatially enhanced log data set containing spatial location attributes.

[0060] The physical layout of substation equipment refers to the actual physical location distribution of various devices within the substation, while electrical connection relationships describe the electrical connection methods and relationships between devices. The spatial topology index is an index structure used to represent the spatial location and connection relationships of substation equipment, using nodes and edges to represent these relationships. Equipment association information is equipment-related information in the structured log metadata set, such as equipment identifier, equipment type, and operation information. Spatial location attributes are attribute information such as the coordinates of the equipment in space. The spatially enhanced log dataset is a log dataset that adds spatial location attribute information to the structured log metadata set, providing a more comprehensive view of equipment operation information and spatial location relationships.

[0061] As one implementation method, step S300 may include the following steps S310~S350: Step S310: Obtain the physical layout drawings and electrical wiring diagrams of the substation equipment, convert the equipment location information in the physical layout drawings into three-dimensional spatial coordinates through a spatial coordinate transformation model, and construct an initial spatial topology index by combining the connection relationship data in the electrical wiring diagram.

[0062] Physical layout drawings are used to represent the physical location distribution of substation equipment, including information such as equipment location and dimensions. Electrical wiring diagrams represent the electrical connections between substation equipment, including connection methods and wiring information. Spatial coordinate transformation models convert the equipment location information in the physical layout drawings into three-dimensional spatial coordinates; feasible spatial coordinate transformation models include projection transformation models. The initial spatial topology index is an index structure built after converting the equipment location information into three-dimensional spatial coordinates and combining it with electrical connection data; it represents the spatial location and connection relationships of substation equipment.

[0063] In practical implementation, physical layout drawings and electrical wiring diagrams are obtained from substation design documents or databases. For physical layout drawings, image recognition technology, such as OpenCV, is used to extract equipment location information. Then, a spatial coordinate transformation model is used to convert the equipment location information into three-dimensional spatial coordinates. For electrical wiring diagrams, connection relationship data, such as connection lines and ports between equipment, is parsed. Finally, the three-dimensional spatial coordinates and connection relationship data are integrated to construct an initial spatial topology index. For example, a graph database, such as Neo4j, can be used, with equipment as nodes and connections between equipment as edges. Node attributes include three-dimensional spatial coordinates, and edge attributes include connection type and other information, to construct the initial spatial topology index.

[0064] As one implementation method, step S310 may include the following steps S311~S315: Step S311: Vectorize the physical layout drawing of the substation equipment, extract the equipment outline, location mark and dimension annotation information in the drawing, and convert the vertex coordinates of the equipment outline into three-dimensional spatial coordinates through the mapping relationship between image coordinates and actual spatial coordinates.

[0065] Vectorization is the process of converting graphic information in physical layout drawings into vector graphics. Vectorization allows for the easy extraction of equipment outlines, location markers, and dimensions from the drawings. Equipment outlines are the physical shapes of the equipment on the drawing; location markers are identifiers used to mark the equipment's location; and dimensions are information such as the equipment's size. Image coordinates are the coordinate system on the drawing, while actual space coordinates represent the coordinate system of the equipment in actual space. By establishing a mapping relationship between image coordinates and actual space coordinates, the vertex coordinates of the equipment outline can be converted from image coordinates to three-dimensional space coordinates.

[0066] In practical implementation, image processing software, such as Adobe Illustrator, is used to vectorize the physical layout drawings. Then, computer vision algorithms, such as edge detection algorithms, are used to extract the equipment outlines, location markers, and dimension information from the drawings. To establish the mapping relationship between image coordinates and actual spatial coordinates, several reference points with known actual spatial coordinates can be selected on the drawings. The mapping relationship is calculated using affine transformations and other methods based on the image coordinates and actual spatial coordinates of these reference points. Finally, the vertex coordinates of the equipment outlines are substituted into the mapping relationship to convert them into three-dimensional spatial coordinates.

[0067] Step S312: Extract the topology from the electrical wiring diagram data, identify the connection relationships and connection types between electrical components, and generate an electrical connection relationship table containing component identifiers, connection endpoints, and connection methods.

[0068] Topology extraction is the process of analyzing and extracting the connection relationships and connection types between electrical components from electrical wiring diagram data. Electrical components are various electrical devices in a substation, such as transformers and switches. Connection relationships refer to the connection arrangements between electrical components, such as series or parallel connections. Connection types refer to the connection methods between electrical components, such as conductor connections or busbar connections. An electrical connection relationship table is a table used to record the connection relationships between electrical components, containing information such as component identification, connection endpoints, and connection methods.

[0069] In practice, electrical CAD software or custom parsing tools can be used to process electrical wiring diagram data and extract its topological information. By identifying the graphic symbols of electrical components and their connecting lines, the connection relationships and connection types between electrical components can be determined. For each connection relationship, the component identification, connection endpoints, and connection method are recorded. For example, if a switch is connected to a transformer via a wire, the component identification of the switch and transformer, the connection endpoints (such as the switch port and the transformer port), and the connection method (wire connection) are recorded, ultimately generating an electrical connection relationship table.

[0070] Step S313: Match the equipment location information in the three-dimensional spatial coordinates with the electrical connection relationship table to establish an association mapping between the physical location of the equipment and the electrical connection relationship, and generate the equipment space-electrical association matrix.

[0071] Equipment identification matching is the process of comparing and matching equipment location information in three-dimensional spatial coordinates with equipment identification in an electrical connection table. This matching determines the correspondence between the spatial location of each piece of equipment and its electrical connection. The association mapping between equipment physical location and electrical connection is the process of establishing a mapping relationship between the spatial location information of equipment and its electrical connection. This association mapping integrates the spatial location information and electrical connection information of the equipment. The equipment spatial-electrical association matrix is ​​a matrix used to represent the association between equipment spatial location and electrical connection; the elements of the matrix represent the degree of association between the equipment.

[0072] In the specific implementation, the device location information in the three-dimensional spatial coordinates and the device identifiers in the electrical connection relationship table are traversed, and the device location information and electrical connection relationships of devices with the same device identifier are associated. For example, for a device with the device identifier "XX switch 1", its corresponding location information is found in the three-dimensional spatial coordinates, and its corresponding connection relationship information is found in the electrical connection relationship table, establishing an association mapping between the two. Then, a matrix is ​​used to represent the association relationship between device spatial location and electrical connection relationship. The rows and columns of the matrix represent devices, and the values ​​of the matrix elements represent the degree of association between devices, such as whether there is an electrical connection, etc., ultimately generating a device spatial-electrical association matrix.

[0073] Step S314: Based on the equipment space-electrical association matrix, construct an initial spatial topology index using a graph structure modeling method. The index nodes contain the three-dimensional coordinates of the equipment and electrical connection port information, while the index edges contain the connection type and distance parameters.

[0074] Graph structure modeling is a method for constructing graph structures, which consist of nodes and edges. Nodes represent entities, and edges represent relationships between entities. The initial spatial topology index is an index structure built on the equipment space-electrical association matrix, used to represent the spatial location and connection relationships of substation equipment. Index nodes are nodes in the graph structure, containing the equipment's three-dimensional coordinates and electrical connection port information. The three-dimensional coordinates represent the equipment's location in space, and the electrical connection port information represents the equipment's connection port configuration. Index edges are edges in the graph structure, containing connection type and distance parameters. The connection type indicates the connection method between equipment, and the distance parameter represents the spatial distance between equipment.

[0075] In practical implementation, a graph database, such as Graphviz, is used to construct a graph structure based on the device spatial-electrical association matrix. Each device is treated as a node, with attributes set to the device's 3D coordinates and electrical connection port information. Connections between devices are represented using edges, with attributes set to connection type and distance parameters. The distance parameter can be obtained by calculating the distance between the device's 3D coordinates. Finally, an initial spatial topology index is constructed, which visually displays the spatial location and connection relationships of substation devices.

[0076] Step S315: Perform node clustering on the initial spatial topology index. By calculating the three-dimensional spatial coordinate distance between device nodes and the shortest path length of electrical connection, when the three-dimensional spatial coordinate distance between two device nodes is less than a preset physical distance threshold, and the shortest path length between the two in the electrical connection relationship is less than a preset path length threshold, it is determined that the two device nodes meet the clustering conditions. The device nodes that meet the clustering conditions are divided into the same device group, and an initial spatial topology index containing the device group hierarchy is generated.

[0077] Node clustering is the process of grouping nodes in the initial spatial topology index. The goal is to group device nodes with similar spatial locations and electrical connections into the same group. 3D spatial coordinate distance is the distance between two device nodes in 3D space, which can be obtained by calculating the Euclidean distance between the 3D coordinates of the two nodes. The shortest path length for electrical connection is the length of the shortest path between two device nodes in their electrical connection relationship, which can be calculated using graph algorithms such as Dijkstra's algorithm. Physical distance threshold and path length threshold are pre-set thresholds used to determine whether two device nodes meet the clustering criteria. Device groups are groups of device nodes that meet the clustering criteria. The device group hierarchy adds a hierarchical structure of device group information to the initial spatial topology index, which can more clearly show the grouping relationships between devices.

[0078] In the specific implementation, each pair of device nodes in the initial spatial topology index is traversed, and their 3D spatial coordinate distance and shortest electrical connection path length are calculated. For each pair of device nodes, if their 3D spatial coordinate distance is less than the physical distance threshold and their shortest electrical connection path length is less than the path length threshold, then the two device nodes are determined to meet the clustering conditions. The device nodes that meet the clustering conditions are grouped into the same device group, and device group information is added to the initial spatial topology index to generate an initial spatial topology index containing the device group hierarchy.

[0079] Step S320: Extract device association information from the structured log metadata set, and associate the device association information with the device nodes in the initial spatial topology index by matching device identifiers to determine the candidate mapping nodes of the device association information in the initial spatial topology index.

[0080] Device association information comprises device-related information in the structured log metadata set, such as device identifier, device type, and operation information. Device identifier matching is the process of comparing and matching the device identifiers in the device association information with the device identifiers of the device nodes in the initial spatial topology index. This matching determines the correspondence between the device association information and the device nodes in the initial spatial topology index. Candidate mapping nodes are the device nodes in the initial spatial topology index that may correspond to the device association information during the device identifier matching process.

[0081] As one implementation method, step S320 may include the following steps S321 to S325: Step S321: Parse the field information containing device identifiers from the structured log metadata set, standardize the device identifiers, unify the format and encoding rules of the device identifiers, and generate a standardized device identifier set.

[0082] Field information parsing is the process of extracting fields containing device identifiers from a structured log metadata collection. Data parsing tools, such as JSON parsers, can be used to parse the structured log metadata collection and extract the device identifier field. Device identifier standardization is the process of converting device identifiers according to a unified format and encoding rules. The purpose is to eliminate differences in device identifier representation and facilitate subsequent matching operations. The standardized device identifier set is a collection that stores all standardized device identifiers.

[0083] In the implementation, a JSON parser can be used to parse the structured log metadata collection and extract the device identifier field. For device identifier standardization, a standardization rule table can be created, recording the correspondence between device identifiers in different formats and a unified format. The device identifier fields are then iterated through, and the device identifiers are converted according to the standardization rule table. Finally, a standardized device identifier set is generated.

[0084] Step S322: Traverse the device nodes in the initial spatial topology index, extract the device identification information from the node attributes, match the standardized device identification set with the node device identification information, and determine the directly matching device nodes.

[0085] Node attribute extraction is the process of obtaining attribute information from device nodes in the initial spatial topology index. Attribute information includes device identifiers, 3D coordinates, etc. Matching the standardized set of device identifiers with the node device identifier information involves comparing each device identifier in the standardized set with the device identifier of the device node in the initial spatial topology index. Through matching, directly matching device nodes can be identified.

[0086] In practice, graph database queries, such as Cypher queries, can be used to retrieve device identifier information for all device nodes from the initial spatial topology index. Then, the standardized device identifier set is traversed, and each device identifier is compared with the device identifier of a device node. If they are identical, the device node is considered a direct match. For example, for the standardized device identifier "XX1 switch", the device node with the device identifier "XX1 switch" is searched in the initial spatial topology index and identified as a direct match.

[0087] Step S323: For device association information that is not directly matched, predict possible associated device nodes and generate a candidate mapping node set by calculating device name similarity and analyzing contextual device association.

[0088] Device name similarity calculation is a method used to measure the degree of similarity between two device names. Feasible methods for calculating device name similarity include cosine similarity and edit distance. Contextual device association analysis is the process of determining possible associated device nodes by analyzing the contextual information of device association information, such as operation information and time information. The candidate mapping node set is a collection that stores all predicted possible associated device nodes.

[0089] In the specific implementation, for device association information that does not directly match, cosine similarity is used to calculate the similarity between the device name in the device association information and the device name of the device node in the initial spatial topology index. Simultaneously, the contextual information of the device association information, such as operation information and time information, is analyzed, and combined with the device connection relationships in the initial spatial topology index, possible associated device nodes are predicted. For example, if the device association information records an operation on an unmatched device at a certain moment, and this operation has an electrical connection relationship with a device node in the initial spatial topology index, then that device node is considered a possible associated device node. All predicted possible associated device nodes are combined into a candidate mapping node set.

[0090] Step S324: Prioritize the nodes in the candidate mapping node set, determine the node priority based on device type matching degree, historical association frequency, and spatial proximity, and select the candidate mapping node with the highest priority as the target mapping node.

[0091] Device type matching degree is the degree to which the device type of the candidate mapping node matches the device type in the device association information. The higher the matching degree, the more similar the device types are. Historical association frequency is the frequency of association between the candidate mapping node and the device association information in historical records. The higher the association frequency, the stronger the association between the two. Spatial proximity is the degree of proximity between the candidate mapping node and the device in the device association information. The closer the spatial locations, the stronger the spatial relationship between the two. Node priority is the priority of the candidate mapping node determined by a combination of device type matching degree, historical association frequency, and spatial proximity. The higher the priority, the greater the likelihood that the node will become the target mapping node. The target mapping node is the highest priority node selected from the set of candidate mapping nodes and will be used as the mapping node for the device association information in the initial spatial topology index.

[0092] In practice, weights are assigned to device type matching degree, historical association frequency, and spatial proximity. For each node in the candidate mapping node set, its device type matching degree, historical association frequency, and spatial proximity score are calculated. The scores are then weighted and summed to obtain the node priority score. The nodes in the candidate mapping node set are sorted from highest to lowest priority score, and the node with the highest priority is selected as the target mapping node.

[0093] Step S325: Establish a dynamic association between device association information and target mapping nodes. Record the mapping rules between the fields of device association information and node attributes through the association relationship table to generate device association information containing dynamic association relationships.

[0094] Dynamic association relationships are the connections between device association information and target mapping nodes. These relationships can be dynamically adjusted as the device association information is updated. The association table records the mapping rules between fields in the device association information and node attributes. Through the association table, it is clear which attribute of the target mapping node each field in the device association information corresponds to. Device association information containing dynamic association relationships adds information about the dynamic association with the target mapping node to the existing device association information, thus more accurately reflecting the correspondence between the device association information and the device nodes in the initial spatial topology index.

[0095] In the implementation, a dictionary data structure is used to establish a dynamic association between device association information and target mapping nodes. The dictionary keys are fields from the device association information, and the values ​​are attributes of the target mapping nodes. For example, if the "Device Identifier" field in the device association information corresponds to the "Device Identifier" attribute of the target mapping node, then "Device Identifier:Device Identifier" is recorded in the dictionary. These mapping rules are recorded in the association table. When the device association information is updated, the attributes of the target mapping node are automatically updated according to the association table to maintain the real-time nature of the dynamic association. Finally, device association information containing the dynamic association is generated.

[0096] Step S330: Calculate the spatial matching degree between the device association information and the candidate mapping nodes. By analyzing the spatial coordinate relationship between the location description text in the device association information and the candidate mapping nodes, adjust the location parameters of the candidate mapping nodes and optimize the mapping accuracy.

[0097] Spatial matching degree is an indicator used to measure the degree of spatial location matching between device association information and candidate mapping nodes. It can be calculated by analyzing the spatial coordinate relationship between the location description text in the device association information and the candidate mapping nodes. The location description text is a description of the device's location in the device association information, such as "located in area A" or "near device XX". The spatial coordinate relationship is the relationship between the spatial coordinates of the candidate mapping node and the spatial location represented by the location description text. Adjusting the position parameters of the candidate mapping node is the process of adjusting the spatial coordinates of the candidate mapping node based on the spatial matching degree calculation results. The purpose is to make the spatial location of the candidate mapping node more consistent with the location description in the device association information and optimize the mapping accuracy. In specific implementation, text parsing techniques, such as regular expression matching, are used to extract the location description text from the device association information. Then, based on the location description text and the spatial information in the initial spatial topology index, the distance between the candidate mapping node and the spatial location represented by the location description text is calculated. For example, if the location description text is "located in area A", the spatial range of area A is searched in the initial spatial topology index, and the distance between the candidate mapping node and the center of area A is calculated. Based on the distance calculation results, the position parameters of the candidate mapping nodes are adjusted, such as moving the candidate mapping nodes a certain distance towards the center of area A. Through multiple adjustments and calculations of spatial matching degree, the mapping accuracy is continuously optimized.

[0098] Step S340: Based on the optimized mapping node location, bind dynamic data such as operation events and status changes in the device association information with the node attributes of the spatial topology index to generate a spatial topology index containing a dynamic data update interface.

[0099] Operation events are the operational behaviors of devices recorded in the device association information, such as switching operations and maintenance operations. State changes are the changes in the device state recorded in the device association information, such as turning the device on or off. Dynamic data is data that changes over time, such as operation events and state changes. Node attributes are the attribute information of device nodes in the spatial topology index, such as device status and operation time. Binding is the process of associating dynamic data with the node attributes of the spatial topology index. Through binding, the spatial topology index can reflect the operation and state changes of devices in real time. The dynamic data update interface is an interface used to receive and process dynamic data updates, enabling real-time updates of the node attributes of the spatial topology index.

[0100] As one implementation method, step S340 may include the following steps S341~S345: Step S341: Extract dynamic data such as operation events and status changes from the device association information, extract timestamps and classify types of the dynamic data, and generate a dynamic data sequence with timestamps.

[0101] Dynamic data extraction is the process of identifying and extracting dynamic data such as operation events and status changes from device-related information. Data parsing tools, such as JSON parsers, can be used to parse the device-related information and extract the dynamic data. Timestamp extraction is the process of extracting timestamps from dynamic data to record the time the data was generated. Timestamps clearly indicate the order in which the dynamic data was generated. Type classification is the process of categorizing dynamic data according to its type, such as classifying operation events into on / off operations and maintenance operations, and classifying status changes into on / off, etc. Time-stamped dynamic data sequences are sequences of dynamic data arranged and categorized according to their timestamps, facilitating subsequent processing and analysis.

[0102] In the implementation, a JSON parser is used to parse the device association information, extracting dynamic data such as operation events and state changes. Then, regular expressions are used to match the timestamp information in the dynamic data and extract the timestamps. Based on the content of the dynamic data, it is categorized into different types. All dynamic data is then arranged in timestamp order to generate a time-stamped dynamic data sequence.

[0103] Step S342: Analyze the data update frequency and associated device range in the dynamic data sequence, determine the binding rules between dynamic data and spatial topology index nodes, and establish a mapping relationship table between dynamic data fields and node attribute fields.

[0104] Data update frequency refers to the number of times dynamic data is updated within a certain period. Analyzing the data update frequency helps us understand the changes in dynamic data. Associated device scope refers to the range of devices involved in the dynamic data. Analyzing the associated device scope helps us determine which spatial topology index nodes the dynamic data is associated with. Binding rules are the rules used to determine how dynamic data is bound to spatial topology index nodes, such as binding based on device identifiers or spatial locations. The mapping table is a table used to record the mapping relationships between dynamic data fields and node attribute fields. The mapping table clarifies which attribute of the spatial topology index node each field in the dynamic data corresponds to.

[0105] In practice, the update time interval of each dynamic data point in the dynamic data sequence is statistically analyzed to calculate the data update frequency. The device identifiers and spatial location information involved in the dynamic data are analyzed to determine the range of associated devices. Based on the data update frequency and the range of associated devices, the binding rules between the dynamic data and the spatial topology index nodes are determined. For example, if the dynamic data update frequency is high and the range of associated devices is small, binding can be based on device identifiers. A mapping table between dynamic data fields and node attribute fields is established, such as mapping the "operation time" field in the dynamic data to the "operation time" attribute of the spatial topology index node.

[0106] Step S343: Based on the mapping relationship table, write the data values ​​in the dynamic data sequence into the attribute fields of the corresponding nodes of the spatial topology index, realize the temporal association of dynamic data through timestamp alignment, and generate a node dynamic attribute sequence.

[0107] Data value writing is the process of writing data values ​​from the dynamic data sequence into the attribute fields of the corresponding nodes in the spatial topology index according to the mapping table. Timestamp alignment is the process of aligning the timestamps in the dynamic data sequence with the time attributes of the spatial topology index nodes. Timestamp alignment enables temporal correlation of dynamic data, ensuring that the dynamic data correctly updates the attributes of the spatial topology index nodes in chronological order. The node dynamic attribute sequence is a sequence containing dynamic attribute information generated after the dynamic data is written into the attribute fields of the spatial topology index nodes, reflecting the changes in node attributes over time.

[0108] In the specific implementation, each dynamic data point in the dynamic data sequence is traversed, and according to the mapping table, the data values ​​in the dynamic data are written into the attribute fields of the corresponding nodes in the spatial topology index. Simultaneously, the dynamic data is sorted according to the timestamp to ensure that the node attributes are updated in chronological order. Finally, a sequence of dynamic node attributes is generated.

[0109] Step S344: Listen for device association information update events through the dynamic data update interface. When new dynamic data is received, automatically trigger the update operation of the spatial topology index node attributes to maintain data real-time performance.

[0110] The dynamic data update interface is used to receive and process dynamic data updates. It can listen for update events in device association information. Update events are events that occur when dynamic data in device association information is updated, such as new operation events or state changes. When the dynamic data update interface receives new dynamic data, it automatically triggers the update operation of the spatial topology index node attributes. That is, it updates the attributes of the corresponding nodes in the spatial topology index according to the new dynamic data, maintaining the real-time nature of the data.

[0111] In practical implementation, a message queue, such as Kafka, is used to implement the dynamic data update interface. Update events for device association information are sent as messages to the Kafka message queue, and the dynamic data update interface listens to this queue. When a new dynamic data message is received, the interface parses the message content and updates the attributes of the corresponding node in the spatial topology index according to the mapping table.

[0112] Step S345: Perform integrity verification on the updated node dynamic attribute sequence, verify the rationality of the updated data by comparing it with historical data, mark abnormal updated data and trigger the manual review process, and generate a spatial topology index containing the dynamic data update interface.

[0113] Integrity verification checks the updated node dynamic attribute sequence to ensure its data is complete and without missing data. Comparing with historical data involves comparing the updated data with historical data to check its reasonableness. Abnormal update data refers to data that differs significantly from historical data and does not conform to normal logic. Tagging is the process of identifying abnormal update data for subsequent manual review. The manual review process involves manually checking and confirming abnormal update data to ensure its accuracy and reliability. The spatial topology index, which includes a dynamic data update interface, is generated after integrity verification and abnormal data processing. It reflects real-time dynamic data changes of the device and has dynamic data update capabilities.

[0114] In the implementation, data verification algorithms, such as hash verification, are used to perform integrity checks on the updated node dynamic attribute sequence. The updated data is compared with historical data, such as checking whether the operation time is reasonable and whether the operation type matches the device status. If a significant difference is found between the updated data and historical data, the updated data is marked as abnormal. For abnormal updated data, a manual review process is triggered, such as sending a notification to operations personnel, requiring them to check and confirm the abnormal updated data. Finally, a spatial topology index containing the dynamic data update interface is generated.

[0115] Step S350: By calling the interface of the node attributes of the spatial topology index, the spatial attribute information such as spatial location coordinates and device connection relationship is dynamically integrated with the structured log metadata set to generate a spatially enhanced log data set containing spatial location attributes.

[0116] The node attribute call interface is used to access node attribute information in the spatial topology index. Through this interface, spatial attribute information such as the spatial coordinates of device nodes and device connection relationships can be obtained. Dynamic integration is the process of real-time association and merging of spatial attribute information with the structured log metadata set. Dynamic integration ensures that the structured log metadata set includes spatial location attribute information. The spatially enhanced log dataset is a log dataset that adds spatial location attribute information to the structured log metadata set, providing a more comprehensive display of device operation information and spatial relationships.

[0117] In practical implementation, the node attribute call interface of the spatial topology index, such as a RESTful API interface, is used to query spatial attribute information such as the spatial location coordinates and device connection relationships of device nodes in the spatial topology index. The retrieved spatial attribute information is dynamically integrated with the structured log metadata set; for example, spatial location coordinates are added to the corresponding fields of the device association information in the structured log metadata set, and device connection relationships are added to the association fields of the device association information in the structured log metadata set. Real-time calls to the node attribute call interface ensure the real-time nature of the spatial attribute information. Finally, a spatially enhanced log data set containing spatial location attributes is generated.

[0118] Step S400: Receive the natural language query request input by the user, parse the core intent and constraints in the natural language query request through the intent recognition model, generate a structured query expression, perform multi-dimensional retrieval and matching on the spatial augmented log data set based on the structured query expression, and output a preliminary query result set.

[0119] A natural language query request is a query requirement described by a user using natural language. An intent recognition model is a model used to parse the core intent and constraint conditions in a natural language query request. Feasible intent recognition models include intent recognition models based on deep learning, such as BERT-based intent recognition models. The core intent is the main purpose of a natural language query request, such as querying operation records, querying device status, etc. Constraint conditions are restrictions on the query scope, such as time range, space range, device type, etc. A structured query expression is to convert the core intent and constraint conditions into a query statement that can be understood by a computer, such as an SQL query statement. Multi-dimensional retrieval matching is a process of retrieving and matching from multiple dimensions such as the time dimension, space dimension, and device dimension of a spatially enhanced log data set according to the structured query expression. The preliminary query result set is a set of log records that meet the query conditions obtained after multi-dimensional retrieval matching.

[0120] As an implementation manner, step S400 may include the following steps S410 to S450: Step S410: Perform text preprocessing on the natural language query request input by the user. By performing word segmentation, stop word removal, and keyword extraction, generate a query keyword set, and perform semantic expansion on the query keyword set to generate an extended keyword set containing synonyms and hypernyms / hyponyms.

[0121] Text preprocessing is a process of preliminarily processing a natural language query request, and its purpose is to convert natural language text into a form suitable for subsequent processing. Word segmentation is a process of splitting a natural language query request into individual words, and a word segmentation tool, such as Jieba segmentation, can be used to perform word segmentation on the query request. Stop word removal is to remove words in the query request that have little impact on the query result, such as "de", "shi", etc. Stop word removal can reduce noise and improve query efficiency. Keyword extraction is to extract key words from the query request, such as the query topic, constraint conditions, etc. Semantic expansion is a process of expanding the query keyword set to add related words such as synonyms and hypernyms / hyponyms. By semantic expansion, the recall rate of the query can be improved. The extended keyword set is a query keyword set containing synonyms and hypernyms / hyponyms.

[0122] In the specific implementation, Jieba segmentation is used to segment the natural language query request input by the user, resulting in a word list. Then, a stop word list is used to remove stop words from the word list. For example, the Harbin Institute of Technology stop word list is used to remove words that are stop words. The TF-IDF algorithm is used to extract keywords, selecting words with higher importance as keywords. For the query keyword set, semantic knowledge bases such as WordNet are used for semantic expansion, searching for synonyms, hyponyms, etc., for each keyword. For example, for the keyword "switch operation," its synonyms "circuit breaker operation" and hyponyms "electrical operation" are searched, and these related words are added to the query keyword set to generate an expanded keyword set.

[0123] Step S420: Input the extended keyword set into the intent recognition model, determine the core intent category of the query request through the intent classifier, extract the constraints corresponding to the core intent in combination with the query context, and generate an intent-constraint association table.

[0124] An intent classifier is a component of an intent recognition model used to categorize the core intent of a query request. Core intent categories classify the core intent of the query request, such as query operation records or query device status. Query context includes other relevant information in the query request besides the core intent, such as time, location, and device type. Constraints are restrictions on the query scope extracted from the query context, such as time range, spatial range, and device type. The intent-constraint association table records the relationships between core intents and constraints, clearly defining the constraints corresponding to each core intent.

[0125] As one implementation, step S420 may include the following steps S421 to S425: Step S421: Convert the extended keyword set into a word vector representation, and perform deep semantic feature extraction on the word vectors through the feature extraction layer of the intent recognition model to generate a query semantic feature vector.

[0126] Word vector representation is the process of converting each keyword in an expanded keyword set into a vector. Feasible word vector representation methods include Word2Vec and GloVe. The feature extraction layer of the intent recognition model is the part of the model used to extract features from the input data. It can perform deep semantic feature extraction on word vectors, uncovering the semantic information behind the keywords. The query semantic feature vector is a vector obtained after processing by the feature extraction layer, containing the semantic feature information of the query request.

[0127] In practical implementation, a pre-trained Word2Vec model is used to convert each keyword in the expanded keyword set into a word vector. These word vectors are then input into the feature extraction layer of the intent recognition model, which can employ structures such as convolutional neural networks (CNNs) or recurrent neural networks (RNNs). Taking CNNs as an example, convolutional layers perform convolution operations on the word vectors to extract local features, and then pooling layers reduce the dimensionality of the features to ultimately generate query semantic feature vectors.

[0128] Step S422: Input the query semantic feature vector into the intent classifier of the intent recognition model, calculate the probability value of the query semantic feature vector belonging to each intent category through a multi-classification algorithm, and select the intent category with the highest probability value as the core intent category.

[0129] An intent classifier is a component in an intent recognition model used to classify the core intent of a query request. It determines which intent category a query request belongs to based on the query's semantic feature vector. Multi-class classification algorithms are used to solve multi-class classification problems; feasible multi-class classification algorithms include Softmax regression and multi-class extensions of Support Vector Machines (SVM). Probability values ​​represent the likelihood that the query's semantic feature vector belongs to each intent category; these probability values ​​can be calculated using multi-class classification algorithms. The core intent category is the intent category with the highest probability value, representing the main purpose of the query request.

[0130] In practice, Softmax regression is used as a multi-classification algorithm, inputting the query semantic feature vector into the intent classifier. Softmax regression performs a linear transformation on the query semantic feature vector, and then converts the transformed result into probability values ​​through the Softmax function. For example, assuming there are three intent categories: query operation records, query device status, and query fault information, Softmax regression calculates the probability values ​​of the query semantic feature vector belonging to these three intent categories, such as [0.7, 0.2, 0.1], indicating that the probability of belonging to the query operation record category is 0.7, the probability of belonging to the query device status category is 0.2, and the probability of belonging to the query fault information category is 0.1. The category with the highest probability value, i.e., query operation records, is selected as the core intent category.

[0131] Step S423: Based on the core intent category, extract constraint keywords from the context text of the query request, and determine the type and value range of the constraint by matching the constraint keywords with the preset constraint types.

[0132] Constraint keywords are keywords used in the query request context to limit the scope of the query, such as time, location, and device type. Predefined constraint types are predefined categories of constraints, such as time constraints, spatial constraints, and device type constraints. By matching constraint keywords with predefined constraint types, the type and value range of the constraint can be determined.

[0133] In practice, based on the core intent category, the context text of the query request is analyzed, and regular expressions or keyword matching methods are used to extract constraint keywords.

[0134] Step S424: Standardize the range of values ​​for the constraints by converting the range described in natural language into a computable range of values ​​or a set of enumerated values ​​to generate standardized constraints.

[0135] The range of values ​​for constraints may exist in various forms in natural language descriptions, such as "January 1, 2024" or "morning". To facilitate subsequent query operations, these ranges of natural language descriptions need to be converted into a computable numerical range or a set of enumerated values. Standardized constraints are the converted constraints, with a unified format and range, making them easy to calculate and compare.

[0136] In practical implementation, for time constraints, date and time processing libraries, such as Python's `datetime` library, are used to convert the time range described in natural language into timestamps or date-time objects. For example, "January 1, 2024" is converted into the timestamp 1704084000. For spatial constraints, if it is a region description, it can be converted into a spatial coordinate range. For example, for "Area A", if the spatial coordinate range of Area A is known to be [(x1, y1, z1), (x2, y2, z2)], then it is used as the standardized spatial constraint value range. For device type constraints, the device type described in natural language can be converted into an enumeration set of values. For example, "switching equipment" is converted into an enumeration set of values ​​["circuit breaker", "disconnect switch"], ultimately generating standardized constraint conditions.

[0137] Step S425: Construct an intent-constraint association table, with the core intent category as the primary key and the constraint type and standardized value range as attribute values, to establish a dynamic association between the core intent and the constraints, supporting the combined association of multiple constraints.

[0138] The Intent-Constraint Association Table records the relationships between core intents and constraints. It uses the core intent category as the primary key and the constraint type and standardized value range as attribute values. Dynamic associations allow the relationship between core intents and constraints to adjust dynamically based on changes in the query request. Support for combined associations with multiple constraints means that a core intent can be associated with multiple constraints simultaneously, such as time constraints, space constraints, and device type constraints.

[0139] In practical implementation, a dictionary data structure is used to construct the intent-constraint association table. The core intent category serves as the key of the dictionary, while the constraint type and standardized value range serve as the values. For example, for the core intent category "Query Operation Records," the associated constraints include a time constraint (value range: January 1, 2024), a spatial constraint (value range: Area A), and an equipment type constraint (value range: ["Circuit Breaker", "Disconnect Switch"]). The intent-constraint association table can then be represented as {"Query Operation Records": {"Time Constraint": "January 1, 2024", "Spatial Constraint": "Area A", "Equipment Type Constraint": ["Circuit Breaker", "Disconnect Switch"]}}. This method establishes a dynamic association between core intents and constraints, supporting combined associations of multiple constraints.

[0140] Step S430: Based on the intent-constraint association table, the core intents and constraints are converted into standardized query operators and query parameters. By mapping the query parameters to the fields of the spatially enhanced log data set, a structured query expression is generated.

[0141] Standardized query operators are symbols used to represent query operations, such as "=", ">", and "<". Query parameters are specific values ​​used to represent query conditions, such as time, location, and device type. Field mapping maps query parameters to fields in the spatially enhanced log dataset, determining the corresponding fields for each parameter. Structured query expressions translate the core intent and constraints into computer-understandable query statements, such as SQL queries.

[0142] In practical implementation, based on the intent-constraint association table, the core intent and constraints are converted into standardized query operators and query parameters. For example, for the core intent "query operation records" with a time constraint of "January 1, 2024", it can be converted into the query operator "=" and the query parameter "January 1, 2024". By analyzing the field structure of the spatial augmented log dataset, the query parameters are mapped to their corresponding fields. For example, the time query parameter is mapped to the "operation time" field in the spatial augmented log dataset. Finally, based on the query operators, query parameters, and field mapping relationships, a structured query expression is generated.

[0143] Step S440: Based on the query dimensions in the structured query expression, perform multi-dimensional retrieval and matching on the spatially enhanced log data set, matching the retrieval conditions from the time dimension, spatial dimension, and device dimension respectively, and generating retrieval results for each dimension.

[0144] Query dimensions refer to the scope of a query in a structured query expression, including time, space, and device dimensions. Multi-dimensional retrieval and matching is the process of searching and matching across different dimensions of the spatially augmented log data set based on the query dimensions. Time-dimensional retrieval filters log records that match a given time range based on time constraints; space-dimensional retrieval filters log records that match a given space range based on space constraints; and device-dimensional retrieval filters log records that match a given device type based on device type constraints. The result of each dimension's retrieval is a collection of log records obtained after searching and matching within each dimension.

[0145] As one implementation, step S440 may include the following steps S441~S445: Step S441: Parse the time dimension constraints from the structured query expression, convert the time dimension constraints into timestamp ranges, perform timestamp filtering on the log records in the spatially enhanced log data set, filter out the log records whose timestamps are within the timestamp range, and generate time dimension retrieval results.

[0146] Time-dimensional constraints are time-range constraints in structured query expressions. Timestamp ranges convert these constraints into timestamp representations, where a timestamp is a numerical value used to represent time, facilitating comparison and filtering. Timestamp filtering is the process of filtering log records in a spatially augmented log dataset based on their timestamp ranges, selecting those records whose timestamps fall within that range. The time-dimensional search result is the set of log records obtained after searching and matching along the time dimension.

[0147] In the implementation, regular expressions are used to parse the time-dimensional constraints from the structured query expression. For the parsed time-dimensional constraints, a date and time processing library, such as Python's `datetime` library, is used to convert them into a timestamp range. The log records in the spatially augmented log dataset are traversed, the timestamp of each log record is extracted, and the timestamps are compared with the timestamp range to filter out log records whose timestamps fall within the range, generating the time-dimensional search results.

[0148] Step S442: Parse the spatial location description in the spatial dimension constraint, convert the spatial location description into a spatial coordinate range, query the device nodes within the spatial coordinate range through the spatial topology index, associate the log records of the corresponding device nodes in the spatial augmented log data set, and generate spatial dimension retrieval results.

[0149] Spatial dimension constraints are constraints on spatial ranges in structured query expressions, such as "Area A" or "from coordinates (x1, y1, z1) to coordinates (x2, y2, z2)". Spatial location descriptions are the specific descriptions of spatial locations within spatial dimension constraints. Spatial coordinate ranges are the ranges represented by spatial coordinates, facilitating spatial queries. Spatial topology indexes are index structures used to represent the spatial locations and connections of substation equipment; they allow queries to find equipment nodes within a spatial coordinate range. Spatial dimension retrieval results are the collection of log records obtained after spatial dimension retrieval and matching.

[0150] In practice, regular expressions are used to parse the spatial location descriptions from the spatial dimension constraints in the structured query expressions. These descriptions are then transformed according to their specific form. If it's a region description, such as "Area A," it's converted into a spatial coordinate range by querying the substation's spatial layout information. If it's a coordinate description, it's directly used as the spatial coordinate range. The spatial topology index query interface is then used to query the device nodes within the spatial coordinate range. Finally, the log records of the corresponding device nodes in the spatial augmented log dataset are correlated to generate the spatial dimension retrieval results.

[0151] Step S443: Parse the device identifier and device type in the device dimension constraints, perform device identifier matching and type filtering on the device association information in the spatial augmentation log data set, and generate device dimension search results.

[0152] Device dimension constraints are constraints on the scope of devices in a structured query expression, such as device identifier and device type. A device identifier is a unique number or name used to identify a device, and a device type is a classification of the device, such as switchgear or transformer. Device identifier matching is the process of comparing device association information in the spatially augmented log dataset with the device identifiers in the device dimension constraints, filtering out log records with matching device identifiers. Device type filtering is the process of filtering device association information in the spatially augmented log dataset based on the device type in the device dimension constraints, filtering out log records whose device type meets the requirements. The device dimension search result is the set of log records obtained after searching and matching at the device dimension.

[0153] In the specific implementation, regular expressions are used to parse the device identifier and device type from the structured query expression to extract the device dimension constraints. The device association information in the spatially enhanced log dataset is traversed, and the device identifier is compared with the parsed device identifier to filter out log records with matching device identifiers. Simultaneously, based on the parsed device type, the log records are filtered by type to select log records whose device types meet the requirements, generating the device dimension search results.

[0154] Step S444: Align the data formats of the time-dimension search results, spatial-dimension search results, and device-dimension search results to unify the field structure and data types of log records and avoid data format conflicts between dimensions.

[0155] Data format alignment is the process of unifying the data formats of search results from the time dimension, spatial dimension, and device dimension. The purpose is to avoid data format conflicts between dimensions and facilitate subsequent intersection calculations and weight sorting. Field structure refers to the composition and arrangement of fields in a log record, while data type refers to the type of data within those fields, such as integers or strings.

[0156] In practice, the field structures and data types of the search results from the time dimension, spatial dimension, and device dimension are analyzed to identify their differences. For differences in field structure, the field names and their order are standardized. For differences in data type, the data types are converted to maintain consistency. For example, if the "Operation Time" field in the time dimension search results is a string type, while the "Operation Time" field in the spatial dimension search results is a date / time type, then the string type "Operation Time" field is converted to a date / time type, ultimately achieving data format alignment.

[0157] Step S445: By associating the fields of the search results in each dimension, establish a mapping relationship between the search results in each dimension, and generate search results in each dimension that include time, space, and device dimension tags.

[0158] Field association is the process of linking fields with the same meaning in time-dimension, space-dimension, and device-dimension search results. Field association establishes a mapping relationship between search results across dimensions. The search result mapping relationship is a data structure used to record the correspondence between search results from different dimensions. This mapping relationship facilitates searching and associating search results across different dimensions. Time, space, and device dimension markers are used to distinguish search results from different dimensions, clearly indicating which dimension's search result each log record belongs to.

[0159] In the specific implementation, the field structure of the time-dimension, spatial-dimension, and device-dimension search results is analyzed to identify fields with the same meaning, such as "device identifier" and "operation time." Based on these fields with the same meaning, a mapping relationship between the search results of different dimensions is established. For example, for time-dimension and spatial-dimension search results, a mapping relationship is established using "device identifier" and "operation time" as the associated fields. Time, spatial, and device dimension tags are added to each log record to generate search results for each dimension that include these time, spatial, and device dimension tags.

[0160] Step S450: Perform intersection calculation and weight sorting on the search results of each dimension. Determine the priority of the results based on the matching degree of the search conditions and the weight coefficient of each dimension. Select the search results with the highest priority to form a preliminary query result set.

[0161] Intersection calculation is the process of intersecting the search results from the time dimension, spatial dimension, and device dimension. Its purpose is to identify log records that simultaneously satisfy multiple search criteria. Weighted ranking is the process of sorting the search results after intersection calculation based on the weight coefficients of each dimension. These weight coefficients represent the pre-defined importance of each dimension in the query results. Search condition matching degree is the degree to which the search results match the query conditions; a higher matching degree indicates that the search results better meet the query requirements. Result priority is the order in which the search results are prioritized based on the matching degree of the search conditions and the weight coefficients of each dimension. Search results with higher priority are selected first. The preliminary query result set is the set of search results selected after intersection calculation and weighted ranking, representing the highest priority search results.

[0162] In practice, the intersection operation of sets is used to calculate the intersection of search results from the time, space, and device dimensions, identifying log records that simultaneously meet the search criteria across multiple dimensions. A weight coefficient is assigned to each dimension, such as 0.4 for the time dimension, 0.3 for the space dimension, and 0.3 for the device dimension. For the search results after the intersection calculation, the matching degree of each log record is calculated, which can be obtained by calculating the similarity between the log record and the query criteria. Based on the matching degree of the search criteria and the weight coefficients of each dimension, the priority of each log record is calculated. The search results are then sorted from highest to lowest priority, and the highest priority search results are selected to form a preliminary query result set.

[0163] Step S500: Perform time-series correlation analysis and operational impact assessment on the log records in the preliminary query result set, and generate a log query result report containing the operational chain evolution path and potential risk warnings.

[0164] Temporal correlation analysis analyzes log records in the preliminary query result set in chronological order to determine the temporal correlations between log records, such as the order of operations and causal relationships between operations. Operational impact assessment analyzes the degree and scope of impact of each operational event on related equipment and systems, assessing potential risks. Operational chain evolution path describes the path of dependencies and causal chains between operational events, revealing the development process and trends of operations. Potential risk alerts, based on the operational impact assessment results, highlight potential risks to help operations personnel take proactive measures. The log query result report is generated by organizing and summarizing the results of temporal correlation analysis and operational impact assessment, including operational chain evolution paths and potential risk alerts, facilitating viewing and analysis by operations personnel.

[0165] As one implementation method, step S500 may include the following steps S510~S550: Step S510: Sort the log records in the preliminary query result set by timestamp, generate a time-series log sequence, calculate the time interval and operation type changes between adjacent log records through time-series difference analysis, and identify continuous operation events.

[0166] Timestamp sorting is the process of arranging log records in the initial query result set according to their timestamps, thus giving the log records a temporal order. A time-series log sequence is a sequence of log records obtained after sorting by timestamps. Time-series difference analysis is the process of analyzing the timestamps and operation types of adjacent log records in a time-series log sequence. Through time-series difference analysis, the time intervals and changes in operation types between adjacent log records can be calculated. Consecutive operation events are operation events that occur consecutively in time; identifying consecutive operation events can determine the relationships between operations.

[0167] In the specific implementation, the `sort` method is used to sort the log records in the initial query result set by timestamp, generating a time-series log sequence. The time-series log sequence is traversed, and the time interval between adjacent log records is calculated, which is the timestamp of the later log record minus the timestamp of the earlier log record. Simultaneously, the operation types of adjacent log records are compared to determine if the operation types have changed. If the time interval is less than a preset time interval threshold and the operation types are related, then these two log records are considered to be consecutive operation events.

[0168] Step S520: Based on continuous operation events, construct a directed graph of operation events, with operation events as nodes and operation order as directed edges. Use graph traversal algorithm to mine the dependencies and causal chains between operation events and generate operation chain evolution paths.

[0169] A directed graph of operations is a graph structure where nodes represent operations, and directed edges represent the order in which these operations occur. The order of operations determines the sequence in which they happen, and the direction of the directed edges is determined by this order. Graph traversal algorithms are used to traverse graph structures; feasible algorithms include Depth-First Search (DFS) and Breadth-First Search (BFS). Graph traversal algorithms can uncover dependencies and causal chains between operations. The evolution path of an operation chain describes the dependencies and causal chains between operations, showcasing the development process and trends of operations.

[0170] As one implementation method, step S520 may include the following steps S521 to S525: Step S521: Extract continuous operation events from the time-series log sequence, assign a unique event identifier to each operation event, record the start time, end time, operation object and operation result of the event, and generate a basic information table of operation events.

[0171] Extracting continuous operation events is the process of identifying operation events that conform to the definition of continuous operation events from a time-series log sequence. A unique event identifier is a unique identifier assigned to each operation event to distinguish different operation events. Start time and end time are the time range in which the operation event occurs; the operation object is the device or system to which the operation event is applied; and the operation result is the result produced after the operation event is executed. The operation event basic information table is a table that stores basic information for each operation event, including event identifier, start time, end time, operation object, and operation result.

[0172] In the specific implementation, the time-series log sequence is traversed, and all consecutive operation events are extracted based on the identification results. A unique event identifier is assigned to each operation event, such as using a UUID to generate a unique identifier. The start time, end time, operation object, and operation result of the operation event are extracted from the log records, and this information is recorded in the operation event basic information table.

[0173] Step S522: Using operation events as nodes, draw directed edges to connect adjacent operation events according to the chronological order of the operation events and the correlation of the operation objects. The weight of the directed edge represents the correlation strength between the operation events, and a directed graph of operation events is generated.

[0174] The construction of a directed graph of operation events involves drawing directed edges based on the order of the operation events and the relationships between the operation objects, with operation events as nodes. The weight of a directed edge is a numerical value used to represent the strength of the relationship between operation events; the higher the relationship strength, the closer the relationship between the two operation events.

[0175] In implementation, each operation event in the basic information table is treated as a node in the directed graph of operation events. The order of operation events is determined by their start time. For adjacent operation events, if their operation objects are related, a directed edge is drawn to connect the two operation events. The correlation strength can be calculated based on factors such as the time interval between operation events and the relevance of their operation types. For example, if the time interval between two operation events is short and their operation types have a causal relationship, the correlation strength is high. The calculated correlation strength is used as the weight of the directed edge, ultimately generating the directed graph of operation events.

[0176] Step S523: Select entity pairs in the directed graph of operation events whose matrix element values ​​are greater than the association strength threshold as strongly associated entity pairs. Starting from the strongly associated entity pairs, perform path traversal on the directed graph of operation events to discover multi-hop dependency paths containing intermediate entities.

[0177] The association strength threshold is a pre-set critical value used to determine whether the association strength between operation events is strong enough. Strongly associated entity pairs are entity pairs in the directed graph of operation events whose association strength is greater than the association strength threshold. Path traversal starting from strongly associated entity pairs can more effectively uncover dependencies between operation events. Multi-hop dependency paths are dependency paths that include intermediate entities. By mining multi-hop dependency paths, more complex causal chains between operation events can be identified.

[0178] In the specific implementation, the edges of the directed graph of operation events are traversed, and entity pairs whose edge weights (association strength) are greater than the association strength threshold are selected as strongly associated entity pairs. Starting from these strongly associated entity pairs, a depth-first search (DFS) algorithm is used to traverse the directed graph of operation events. During the traversal, the nodes and edges visited are recorded to determine multi-hop dependency paths containing intermediate entities. For example, assuming there are operation events A, B, and C, and the association strength between operation events A and B is greater than the association strength threshold, a multi-hop dependency path of operation event A -> operation event B -> operation event C might be found by traversing the path starting from operation events A and B.

[0179] Step S524: Perform directional labeling on multi-hop dependency paths, determine the interaction initiator, interaction object and interaction result of entities in the path, classify the paths according to the interaction direction and interaction type, and generate a set of entity interaction paths containing hierarchical relationships.

[0180] Directional annotation is the process of labeling the interaction direction of each path in a multi-hop dependency path. Directional annotation clarifies the initiator, object, and result of the interaction among entities within the path. The initiator is the entity that initiates the interaction, the object is the entity being interacted with, and the result is the outcome of the interaction. The interaction type is the specific type of interaction behavior, such as performing an operation or generating a result. Classifying paths based on interaction direction and type allows paths with the same interaction direction and type to be grouped together, generating a set of entity interaction paths containing hierarchical relationships. This facilitates the management and analysis of relationships between operation events.

[0181] In practice, the role and operation content of each entity in a multi-hop dependency path are analyzed to determine the interaction initiator, interaction object, and interaction result. For example, for the path "Operation Event A -> Operation Event B -> Operation Event C", if Operation Event A is "Switch Closing Operation", Operation Event B is "Equipment Start-up Operation", and Operation Event C is "Equipment Operation Normal", then the operation object of Operation Event A is the switch, Operation Event A is the interaction initiator, the switch is the interaction object, and Operation Event B is the interaction result of Operation Event A; the operation object of Operation Event B is the equipment, Operation Event B is the interaction initiator, the equipment is the interaction object, and Operation Event C is the interaction result of Operation Event B. Paths are classified according to the interaction direction and interaction type, such as classifying paths that perform operations into one category and paths that produce results into another. Finally, a set of entity interaction paths containing hierarchical relationships is generated.

[0182] Step S525: Map the path nodes and connection relationships in the entity interaction path set to network nodes and edges. The node attributes include entity type and interaction weight, and the edge attributes include interaction type and association strength, generating a hierarchical entity interaction relationship network.

[0183] Path nodes are nodes representing operation events in the set of entity interaction paths, and connection relationships are the ways in which path nodes are connected. Network nodes are nodes that map path nodes to the network, and edges are line segments connecting network nodes. Node attributes are the attribute information set for each network node, including entity type and interaction weight. Entity type indicates the type of operation event represented by the node, and interaction weight indicates the importance of the operation event in the interaction process. Edge attributes are the attribute information set for each edge, including interaction type and association strength. Interaction type indicates the type of interaction behavior represented by the edge, and association strength indicates the degree of association between the two nodes connected by the edge.

[0184] In the implementation, the set of entity interaction paths is traversed, each path node is mapped to a network node, and entity type and interaction weight attributes are set for each node. For example, the interaction weight of a node is assigned based on the importance and influence of the operation event. Simultaneously, the connections between path nodes are mapped to network edges, and interaction type and association strength attributes are set for each edge. Association strength can be directly obtained by using the weight of the corresponding edge in the directed graph of the operation event. Finally, all network nodes and edges are combined to generate a hierarchical entity interaction relationship network, which can intuitively display the interaction relationships between operation events.

[0185] Step S530: Assess the impact range of each operation event in the operation chain evolution path. By analyzing the equipment association and spatial location attributes corresponding to the operation event, determine the degree of impact and duration of the impact of the operation event on the associated equipment.

[0186] Impact scope assessment is the process of evaluating the impact range of each operational event in the operational chain evolution path on related equipment and systems. Equipment correlation refers to the connections and interactions between equipment involved in the operational event; analyzing these correlations reveals other equipment that may be affected by the event. Spatial location attributes are the spatial location information of the equipment; analyzing these attributes reveals the spatial propagation range of the operational event's impact. Impact degree refers to the magnitude of the operational event's impact on related equipment, such as whether the equipment operates normally or whether its performance degrades. Impact duration refers to the length of time the operational event's impact on related equipment lasts.

[0187] In practice, for each operational event in the operational chain evolution path, the corresponding device associations and spatial location attributes are obtained from the spatial augmentation log dataset. The device associations are analyzed to identify other devices related to the operational event. Based on the nature of the operational event and the characteristics of the devices, the impact of the operational event on the associated devices is assessed. Simultaneously, based on historical data and experience, the duration of the impact of the operational event on the associated devices is predicted. Finally, the impact degree and duration of each operational event on the associated devices are determined.

[0188] Step S540: Based on the historical execution records and impact scope assessment results of the operation chain evolution path, predict the subsequent operations and potential risk points that the current operation chain may trigger, and generate a risk probability assessment matrix.

[0189] The historical execution record of the operation chain evolution path is a record of the operational events and results generated during the past execution of the operation chain evolution path. By analyzing the historical execution record, we can understand the development patterns and trends of the operation chain. The impact scope assessment result is the result obtained after assessing the impact scope of each operational event in the operation chain evolution path, including information such as the degree of impact of the operational event on related equipment and the duration of the impact. Subsequent operations are the next operations that the current operation chain may trigger, and potential risk points are the potential risks that the current operation chain may have. The risk probability assessment matrix is ​​a matrix used to record the probability of occurrence and the degree of impact of each potential risk point. Through the risk probability assessment matrix, potential risks can be quantitatively assessed.

[0190] In practical implementation, historical execution records of the operation chain evolution path are collected, and the sequence of operation events, operation results, and interrelationships between operations are analyzed. Combined with the impact scope assessment results, subsequent operations that the current operation chain may trigger are predicted. For example, if a "XX1 switch tripping operation" occurs in the current operation chain, based on historical execution records and impact scope assessment results, it is predicted that subsequent operations may include "troubleshooting operations" and "equipment repair operations." For each subsequent operation, potential risk points are analyzed. For example, in troubleshooting operations, there is a risk of misdiagnosing the cause of the fault; in equipment repair operations, there is a risk of incomplete repair. Based on historical data and experience, the probability and impact of each potential risk point are estimated. The probability and impact of potential risk points are recorded in a risk probability assessment matrix, ultimately generating the risk probability assessment matrix.

[0191] Step S550: Integrate the operation chain evolution path, impact scope assessment results, and risk probability assessment matrix into structured report content, and use a natural language generation model to convert the structured report content into readable text to generate a log query result report.

[0192] The structured report content integrates the operation chain evolution path, impact scope assessment results, and risk probability assessment matrix, resulting in a report with a specific structure and format for easy processing and analysis. Natural language generation (NLP) models are used to convert the structured report content into readable text. Feasible NLP models include rule-based NLP models and deep learning-based NLP models, such as the GPT series models. Readable text is text that is easy to understand and read. NLP models can convert the structured report content into natural and fluent text, facilitating viewing and analysis by operations personnel. The log query result report is generated after converting the structured report content into readable text, containing information such as the operation chain evolution path, impact scope assessment results, and potential risk warnings.

[0193] In practical implementation, the operation chain evolution path, impact scope assessment results, and risk probability assessment matrix are integrated to form structured report content. For example, the operation chain evolution path is displayed in chart form, the impact scope assessment results are displayed in table form, and the risk probability assessment matrix is ​​displayed in matrix form. The structured report content is input into a natural language generation model (such as GPT), which generates readable text based on the input structured report content. For example, for the operation chain evolution path, the natural language generation model generates text describing the development process of the operation chain; for the impact scope assessment results, it generates text describing the degree and duration of the impact of the operation event on related equipment; for the risk probability assessment matrix, it generates text highlighting potential risk points and risk probabilities. Finally, the generated readable text is organized and formatted to generate a log query result report.

[0194] It is understood that the various algorithms involved in the above descriptions of the embodiments of the present invention can all be obtained from relevant content in the prior art. To save space, they will not be elaborated on in the embodiments of the present invention. In addition, those skilled in the art can supplement the details based on common knowledge in the art when implementing the solutions of the present invention. For example, they can use normalization to eliminate dimensional conflicts before feature fusion, use interpolation to eliminate dimensional differences, reasonably set thresholds based on historical data, experience or business scenario requirements, train the model based on a general model training method, set the number of layers in the model structure based on actual needs, select activation functions, etc. The present invention will not provide redundant descriptions of overly detailed implementation processes here.

[0195] Please see Figure 3 This is a schematic diagram of the structure of a computer system provided in an embodiment of the present invention. Figure 3 As shown, the computer system 10 described above may include: a processor 1001, a network interface 1004, and a memory 1005. Furthermore, the computer system 10 may also include: a user interface 1003, and at least one communication bus 1002. The communication bus 1002 is used to implement communication between these components. The user interface 1003 may include a display screen and a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. Optionally, the memory 1005 may also be at least one storage device located remotely from the processor 1001. Figure 3As shown, the memory 1005, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a device control application.

[0196] exist Figure 3 In the computer system 10 shown, the network interface 1004 provides network communication functions; the user interface 1003 is mainly used to provide an input interface; and the processor 1001 can be used to call the device control application stored in the memory 1005 to implement the methods provided in the above embodiments.

Claims

1. A method for querying the work logs of a lock control terminal based on substation operation and maintenance, characterized in that, The method includes: collecting raw operation log streams generated by substation interlocking terminals within a preset time period; serializing the raw operation log streams according to timestamp order to obtain a log data sequence with temporal correlation; performing contextual correlation analysis on each log record using a semantic parsing algorithm to identify entity interaction relationships and behavioral attribute descriptions in the log text; and standardizing and integrating the identification results according to a preset data structure to obtain a structured log metadata set. Specifically, this includes: dividing the log records in the log data sequence into continuous log segment units according to time windows; performing contextual semantic completion on each log segment unit; and using a contextual semantic coding model. Calculate the semantic association degree between adjacent log records to generate a log fragment semantic association matrix. Based on the log fragment semantic association matrix, perform co-occurrence frequency statistics and semantic distance calculation on entity words in the log text to construct an entity association strength matrix. Use the entity association strength matrix to mine dependency paths between devices, operation instructions, and operation results to generate an entity interaction relationship network. Predict behavioral attribute labels for nodes in the entity interaction relationship network. By analyzing the role positioning of entities in the interaction path and the contextual description text, determine the behavioral feature description corresponding to each entity interaction event. Then, integrate the behavioral feature description with the entity interaction relationship network. Point binding is performed to generate an enhanced interactive network with behavioral attributes. Based on substation operation and maintenance specifications, entity names and behavioral characteristic descriptions in the enhanced interactive network are standardized and mapped to unify the expression methods of equipment identifiers and operation types, eliminating association gaps caused by differences in expression. The standardized enhanced interactive network is dynamically encapsulated according to a preset hierarchical data structure, using entity interaction relationships as the main hierarchical framework and behavioral attribute descriptions as sub-hierarchical content. Dynamic invocation of interaction relationships and attribute descriptions is achieved through parent-child node associations, generating a structured log metadata set. A spatial topology index is constructed based on the physical layout and electrical connection relationships of substation equipment, and the structure... The device association information in the log metadata set is mapped to the corresponding node location in the spatial topology index, generating a spatially enhanced log data set containing spatial location attributes. Natural language query requests input by the user are received, and the core intent and constraints in the natural language query request are parsed using an intent recognition model to generate a structured query expression. Based on the structured query expression, multi-dimensional retrieval and matching are performed on the spatially enhanced log data set, outputting a preliminary query result set. Temporal correlation analysis and operational impact assessment are performed on the log records in the preliminary query result set, generating a log query result report containing the operational chain evolution path and potential risk warnings.

2. The method according to claim 1, characterized in that, The process involves, based on the semantic association matrix of the log fragments, performing co-occurrence frequency statistics and semantic distance calculation on entity words in the log text to construct an entity association strength matrix. This matrix is ​​then used to mine dependency paths between devices, operation commands, and operation results, generating an entity interaction relationship network. The process includes: extracting entity words from log fragment units; deduplicating and labeling the entity words; establishing an entity vocabulary library; calculating the co-occurrence frequency of entity words based on their position and frequency in the log fragment units; generating a co-occurrence frequency matrix; and using a semantic distance calculation model to quantitatively evaluate the semantic similarity between entity words based on the co-occurrence frequency matrix. Finally, a weighted fusion of co-occurrence frequency and semantic similarity is performed to generate the entity association strength matrix. The matrix element values ​​represent the overall correlation degree of entity pairs. Entity pairs with matrix element values ​​greater than the correlation strength threshold in the entity correlation strength matrix are selected as strongly correlated entity pairs. Starting from these strongly correlated entity pairs, the entity correlation strength matrix is ​​traversed to discover multi-hop dependency paths containing intermediate entities. The multi-hop dependency paths are labeled with directions to determine the interaction initiator, interaction object, and interaction result of entities in the path. The paths are classified according to the interaction direction and interaction type to generate a set of entity interaction paths containing hierarchical relationships. The path nodes and connection relationships in the entity interaction path set are mapped to network nodes and edges. Node attributes include entity type and interaction weight, and edge attributes include interaction type and correlation strength, generating a hierarchical entity interaction relationship network.

3. The method according to claim 2, characterized in that, The step of predicting behavioral attribute labels for nodes in the entity interaction network involves analyzing the role positioning and contextual description text of entities in the interaction path to determine the behavioral feature description corresponding to each entity interaction event. This behavioral feature description is then bound to nodes in the entity interaction network to generate an enhanced interaction network with behavioral attributes. The process includes: extracting the contextual description text of each entity interaction event in the entity interaction network; extracting key information from the contextual description text to generate a set of text fragments containing time stamps, status descriptions, and result descriptions; determining the behavioral subject and behavioral object of the entity interaction event based on the role positioning of the entity in the interaction path; and then determining the behavioral subject and behavioral object through the interaction between the behavioral subject and the behavioral object. The system predicts the possible behavioral attribute categories that the entity's interaction event may contain, generating a candidate set of attribute categories. It then matches a set of text fragments with this candidate set, using text semantic similarity calculation to select the text fragment with the highest matching degree to the attribute category. This selected text fragment serves as the behavioral feature description for the entity's interaction event. The behavioral feature description is then structured, extracting key parameters and converting them into standardized attribute values ​​to generate behavioral attribute labels containing attribute categories and values. Finally, the behavioral attribute labels are dynamically bound to corresponding nodes in the entity interaction relationship network, establishing a mapping relationship between nodes and attribute labels, thus generating an enhanced interaction network with behavioral attributes.

4. The method according to claim 1, characterized in that, The process involves constructing a spatial topology index based on the physical layout and electrical connections of substation equipment. This maps equipment association information from the structured log metadata set to corresponding node positions in the spatial topology index, generating a spatially enhanced log data set containing spatial location attributes. This includes: acquiring physical layout drawings and electrical wiring diagrams of substation equipment; converting equipment location information from the physical layout drawings into three-dimensional spatial coordinates using a spatial coordinate transformation model; combining this with connection relationship data from the electrical wiring diagrams to construct an initial spatial topology index; extracting equipment association information from the structured log metadata set; and associating the equipment association information with device nodes in the initial spatial topology index through equipment identifier matching to determine the... The device association information is used to identify candidate mapping nodes in the initial spatial topology index; the spatial matching degree between the device association information and the candidate mapping nodes is calculated; by analyzing the spatial coordinate relationship between the location description text in the device association information and the candidate mapping nodes, the position parameters of the candidate mapping nodes are adjusted to optimize the mapping accuracy; based on the optimized mapping node positions, the dynamic data in the device association information is bound to the node attributes of the spatial topology index to generate a spatial topology index containing a dynamic data update interface; through the node attribute call interface of the spatial topology index, the spatial attribute information is dynamically integrated with the structured log metadata set to generate a spatially enhanced log data set containing spatial location attributes.

5. The method according to claim 4, characterized in that, The process of acquiring physical layout drawings and electrical wiring diagrams of substation equipment involves converting the equipment location information in the physical layout drawings into three-dimensional spatial coordinates using a spatial coordinate transformation model. Combined with the connection relationship data in the electrical wiring diagrams, an initial spatial topology index is constructed. This includes: vectorizing the physical layout drawings of substation equipment, extracting equipment outlines, location markers, and dimension annotations from the drawings, and converting the vertex coordinates of the equipment outlines into three-dimensional spatial coordinates through the mapping relationship between image coordinates and actual spatial coordinates; extracting the topology structure from the electrical wiring diagram data, identifying the connection relationships and connection types between electrical components, and generating an electrical connection relationship table containing component identifiers, connection endpoints, and connection methods; and identifying the equipment location information in the three-dimensional spatial coordinates against the electrical connection relationship table. The system matches and establishes an association mapping between the physical location of the equipment and its electrical connection, generating a device space-electrical association matrix. Based on this matrix, an initial spatial topology index is constructed. Index nodes contain the three-dimensional coordinates of the equipment and electrical connection port information, while index edges contain connection type and distance parameters. The initial spatial topology index is then clustered by calculating the three-dimensional spatial coordinate distance between the equipment nodes and the shortest path length of the electrical connection. If the three-dimensional spatial coordinate distance between two equipment nodes is less than a preset physical distance threshold, and the shortest path length between them in the electrical connection relationship is less than a preset path length threshold, the two equipment nodes are determined to meet the clustering conditions. The equipment nodes that meet the clustering conditions are grouped into the same equipment group, generating an initial spatial topology index containing a hierarchical structure of the equipment group.

6. The method according to claim 5, characterized in that, The step of extracting device association information from the structured log metadata set and associating the device association information with device nodes in the initial spatial topology index through device identifier matching to determine the candidate mapping nodes of the device association information in the initial spatial topology index includes: parsing field information containing device identifiers from the structured log metadata set, standardizing the device identifiers to generate a standardized device identifier set; traversing the device nodes in the initial spatial topology index, extracting device identifier information from node attributes, matching the standardized device identifier set with the node device identifier information to determine directly matching device nodes; for device association information that is not directly matched, predicting possible associated device nodes through device name similarity calculation and contextual device association analysis to generate a candidate mapping node set; prioritizing the nodes in the candidate mapping node set, determining node priorities based on device type matching degree, historical association frequency, and spatial proximity, and selecting the candidate mapping node with the highest priority as the target mapping node; establishing a dynamic association relationship between the device association information and the target mapping node, and recording the mapping rules between the fields of the device association information and the node attributes through an association relationship table.

7. The method according to claim 6, characterized in that, The process involves binding dynamic data from device association information to node attributes of the spatial topology index based on optimized mapping node positions, generating a spatial topology index with a dynamic data update interface. This includes: extracting dynamic data from device association information; extracting timestamps and classifying the dynamic data to generate a time-stamped dynamic data sequence; analyzing the data update frequency and associated device range in the dynamic data sequence to determine the binding rules between dynamic data and spatial topology index nodes, and establishing a mapping table between dynamic data fields and node attribute fields; writing data values ​​from the dynamic data sequence into the attribute fields of the corresponding nodes in the spatial topology index based on the mapping table, achieving temporal association of dynamic data through timestamp alignment, and generating a node dynamic attribute sequence; monitoring update events of device association information through the dynamic data update interface, automatically triggering an update operation for the spatial topology index node attributes when new dynamic data is received; performing integrity verification on the updated node dynamic attribute sequence, verifying the rationality of the updated data by comparing it with historical data, marking abnormal update data and triggering a manual review process, and generating a spatial topology index with a dynamic data update interface.

8. The method according to claim 1, characterized in that, The process of receiving a natural language query request from a user, parsing the core intent and constraints in the natural language query request using an intent recognition model, generating a structured query expression, and performing multi-dimensional retrieval and matching on the spatial augmented log data set based on the structured query expression to output a preliminary query result set includes: preprocessing the natural language query request input by the user to generate a set of query keywords; semantically expanding the set of query keywords to generate an extended keyword set; inputting the extended keyword set into the intent recognition model, determining the core intent category of the query request through an intent classifier, extracting the constraints corresponding to the core intent based on the query context, and generating an intent-constraint association table; based on the intent-constraint association table, converting the core intent and constraints into standardized query operators and query parameters, generating a structured query expression by mapping the query parameters to the fields of the spatial augmented log data set; performing multi-dimensional retrieval on the spatial augmented log data set according to the query dimensions in the structured query expression, generating retrieval results for each dimension; performing intersection calculation and weight sorting on the retrieval results for each dimension, determining the priority of the results based on the matching degree of the retrieval conditions and the weight coefficients of each dimension, and selecting the retrieval results with the highest priority to form a preliminary query result set.

9. A computer system, characterized in that, include: processor; And a memory, wherein the memory stores computer-readable code that, when executed by the processor, causes the processor to perform the method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Management and control method, device and equipment of intelligent operation and maintenance terminal and storage medium

    CN119065946A

  • Abnormal behavior detection method and system based on multi-source log and electronic equipment

    CN120050108A