Data operation and maintenance processing method and device, storage medium and electronic equipment

By generating a visual SPL code structure configuration view, the problem of difficult SPL rule configuration is solved, improving operation and maintenance efficiency and realizing the convenience and controllability of rules, thus adapting to the intelligent operation and maintenance needs of complex business logic.

CN121455481APending Publication Date: 2026-02-03BEIJING QIHOOD TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511621505.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-06
Publication Date
2026-02-03

AI Technical Summary

Technical Problem

In existing data operation and security operation scenarios, the analysis of system logs, alarm events and behavioral data relies on the SPL structured query language, which makes rule configuration difficult, has low readability, and is highly dependent on professionals, thus restricting the improvement of operation and maintenance efficiency and response time.

Method used

By obtaining the target rule SPL code input by the user from the code operation and maintenance component interface, determining its syntax structure, generating multiple operation nodes and attribute items, and displaying it as a visual code structure configuration view, it supports interactive adjustment and updating of rule code by users.

Benefits of technology

It improves the readability and comprehension efficiency of rules, reduces the reliance on professional knowledge, supports user interactivity, enhances the convenience and controllability of operation and maintenance, adapts to the intelligent operation and maintenance needs in complex backgrounds, realizes bidirectional synchronous updates from text to structure, and realizes rule orchestration and evolution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121455481A_ABST
    Figure CN121455481A_ABST
Patent Text Reader

Abstract

The invention discloses a data operation and maintenance processing method and device, a storage medium and electronic device.The method comprises the steps that a target rule SPL code input by a user is obtained from an operation and maintenance code area of a code operation and maintenance component interface, and a target SPL code grammar structure corresponding to the target rule SPL code is determined, determining a plurality of SPL code operation nodes and operation node attribute items corresponding to the SPL code operation nodes based on the target SPL code syntax structure, and generating a target code structure configuration view based on the target SPL code syntax structure, the SPL code operation nodes and the operation node attribute items, displaying a target code structure configuration view in an operation and maintenance code operation configuration area of a code operation and maintenance component interface, and obtaining a node configuration adjustment operation input by a user for the target code structure configuration view, and performing operation and maintenance code updating processing on the target rule SPL code of the operation and maintenance code area based on the node configuration adjustment operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and in particular to a data operation and maintenance processing method, apparatus, storage medium and electronic device. Background Technology

[0002] In current data operations and security scenarios, the analysis of system logs, alarm events, and behavioral data often relies on the SPL (Structured Query Language) for rule configuration and policy definition. As business complexity increases and operational rules become more granular, the syntax of the rule language becomes increasingly complex, leading to greater difficulty in rule configuration, reduced readability, and a significant increase in maintenance costs. Simultaneously, the process of rule interpretation and modification heavily relies on professional personnel, hindering improvements in operational efficiency and response time. Therefore, there is an urgent need for an operational processing method that can improve rule understandability, support structured configuration, and facilitate operation, in order to meet the development needs of intelligent operations and maintenance. Summary of the Invention

[0003] This specification provides a data operation and maintenance processing method, apparatus, storage medium, and electronic device, the technical solution of which is as follows: Firstly, this specification provides a data operation and maintenance processing method, the method comprising: Obtain the target rule SPL code input by the user from the operation and maintenance code area of ​​the code operation and maintenance component interface, determine the target SPL code syntax structure corresponding to the target rule SPL code, and determine multiple SPL code operation nodes and operation node attribute items corresponding to the SPL code operation nodes based on the target SPL code syntax structure. A target code structure configuration view is generated based on the target SPL code syntax structure, the SPL code operation node, and the operation node attribute items. The target code structure configuration view is then displayed in the operation and maintenance code operation configuration area of ​​the code operation and maintenance component interface. Obtain the node configuration adjustment operation input by the user for the target code structure configuration view, and perform operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node configuration adjustment operation.

[0004] Secondly, this specification provides a data operation and maintenance processing device, the device comprising: The code processing module is used to obtain the target rule SPL code input by the user from the operation and maintenance code area of ​​the code operation and maintenance component interface, determine the target SPL code syntax structure corresponding to the target rule SPL code, and determine multiple SPL code operation nodes and operation node attribute items corresponding to the SPL code operation nodes based on the target SPL code syntax structure. The view configuration module is used to generate a target code structure configuration view based on the target SPL code syntax structure, the SPL code operation node and the operation node attribute item, and to display the target code structure configuration view in the operation and maintenance code operation configuration area of ​​the code operation and maintenance component interface. The code update module is used to obtain the node attribute configuration information entered by the user for the target code structure configuration view, and to perform operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node attribute configuration information and the target SPL code syntax structure.

[0005] In one feasible implementation, the step of obtaining the node configuration adjustment operation input by the user for the target code structure configuration view, and performing operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node configuration adjustment operation, includes: Obtain the node configuration adjustment operation input by the user for the target code structure configuration view, and determine the node attribute item configuration information of the user for the target code structure configuration view based on the node configuration adjustment operation; Based on the node attribute configuration information and the target SPL code syntax structure, the target rule SPL code in the operation and maintenance code area is updated using operation and maintenance code.

[0006] In one feasible implementation, the step of updating the target rule SPL code in the operation and maintenance code region based on the node attribute configuration information and the target SPL code syntax structure includes: Based on the node attribute configuration information, determine the target SPL code operation node and the target node attribute configuration adjustment information; In the target SPL code syntax structure, the target SPL code operation nodes are updated based on the target node attribute item configuration adjustment information to obtain the target SPL code syntax structure after node update; Based on the updated target SPL code syntax structure, the target rule SPL code in the operation and maintenance code region is updated using operation and maintenance code.

[0007] In one feasible implementation, the step of obtaining the node configuration adjustment operation input by the user for the target code structure configuration view, and determining the node attribute item configuration information of the user for the target code structure configuration view based on the node configuration adjustment operation, includes: Monitor the user's target selection operation in the target node view box of the target code structure configuration view, and determine the target operation node item and target node parameter attribute information corresponding to the indicator control movement operation; Load the target interactive attribute panel of the target operation node item at the location of the target operation node item, so as to display the target node parameter attribute information in the target interactive attribute panel; Monitor the attribute operation instructions for the target interactive attribute panel, and determine the node attribute item configuration information based on the attribute operations.

[0008] In one feasible implementation, the step of loading a target interactive attribute panel for the target operation node item at the target operation node item location, displaying target node parameter attribute information in the target interactive attribute panel, monitoring attribute selection instructions for the target node parameter attribute information, and determining node attribute item configuration information based on the attribute selection operation includes: Load the target interactive attribute panel of the target operation node item at the location of the target operation node item, so as to display the target node parameter attribute information and the target node box interpretation information in the target interactive attribute panel. The target node box interpretation information is generated by the target large language model based on the target code structure configuration view and the target SPL code syntax structure. If an attribute selection instruction for the target node parameter attribute information is received, the configuration information of the first node attribute item is determined based on the attribute selection operation; If a natural language attribute modification instruction is received for the target node parameter attribute information, the configuration information is generated using the target large language model based on the natural language attribute modification instruction to obtain the second node attribute item configuration information.

[0009] In one feasible implementation, determining multiple SPL code operation nodes and corresponding operation node attribute items based on the target SPL code syntax structure includes: The target SPL code syntax structure is traversed to determine multiple syntax operation units; The syntax operation unit is instantiated to obtain the SPL code operation node; For each SPL code operation node, extract syntax context information from the target SPL code syntax structure, determine the node parameter attribute information and node relationship attribute information corresponding to the SPL code operation node based on the syntax context information, and generate the operation node attribute item corresponding to the SPL code operation node based on the node parameter attribute information and node relationship attribute information.

[0010] In one feasible implementation, generating a target code structure configuration view based on the target SPL code syntax structure, the SPL code operation nodes, and the operation node attribute items includes: The node unit type of the SPL code operation node is determined based on the target SPL code syntax structure, and the node view box corresponding to the SPL code operation node is determined based on the node unit type. Based on the node relationship attribute information of each SPL code operation node, a connection element is generated between the parent node and child node in the SPL code operation node, and the connection element is labeled with a syntax hierarchy relationship label. Based on the operation node attribute items, an interactive attribute panel is associated with each node view frame, and the interactive attribute panel is used to display node parameter attribute information; Based on the target SPL code syntax structure, the node view frame and the connecting elements are processed to obtain the target code structure configuration view.

[0011] Thirdly, this specification provides a computer storage medium storing at least one instruction adapted for loading by a processor and executing method steps of one or more embodiments of this specification.

[0012] Fourthly, this specification provides a computer program product storing at least one instruction adapted to be loaded by a processor and to execute the method steps of one or more embodiments of this specification.

[0013] Fifthly, this specification provides an electronic device that may include: a processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the method steps of one or more embodiments of this specification.

[0014] The beneficial effects of the technical solutions provided in some embodiments of this specification include at least the following: In one or more embodiments of this specification, the target rule SPL code input by the user is obtained from the operation and maintenance code area of ​​the code operation and maintenance component interface. The target SPL code syntax structure corresponding to the target rule SPL code is determined, laying the foundation for structure visualization. Then, based on the target SPL code syntax structure, multiple SPL code operation nodes and corresponding operation node attribute items are determined. Based on the target SPL code syntax structure, SPL code operation nodes, and operation node attribute items, a target code structure configuration view is generated. The target code structure configuration view is displayed in the operation and maintenance code operation configuration area of ​​the code operation and maintenance component interface, so that complex rules are presented in a graphical way, which significantly improves readability and understanding efficiency. It supports users to make interactive configuration adjustments through view nodes. Based on the user's node configuration adjustment operation, the target rule SPL code in the operation and maintenance code area is updated with operation and maintenance code and the rule code text is updated in real time, realizing rule orchestration and evolution driven by structure. The overall solution reduces the reliance on professional grammar, improves the ease of operation and controllability of rule maintenance, effectively adapts to the intelligent maintenance needs under the background of increasingly complex business logic, and provides a method for text-image synchronous maintenance of structured rules, realizing bidirectional mapping and interactive updates of SPL rules from text to structured configuration views. Attached Figure Description

[0015] To more clearly illustrate the technical solutions in this specification or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 This is a schematic diagram of a data operation and maintenance processing system provided in this manual; Figure 2 This is a flowchart illustrating a data operation and maintenance processing method provided in this manual; Figure 3 This manual provides a graphical configuration interface based on SPL rule syntax. Figure 4 This is a schematic diagram of an interactive property panel provided in this manual; Figure 5 This is a flowchart illustrating a data operation and maintenance processing method provided in this manual; Figure 6 This is a flowchart illustrating an information configuration process provided in this manual; Figure 7 This is a flowchart illustrating an information configuration process provided in this manual; Figure 8 This is a schematic diagram of the structure of a data operation and maintenance processing device provided in this manual; Figure 9 This is a schematic diagram of the structure of an electronic device provided in this specification. Detailed Implementation

[0017] The technical solutions in this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.

[0018] In the description of this specification, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. In the description of this specification, it should be noted that, unless otherwise expressly specified and limited, "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. Those skilled in the art can understand the specific meaning of the above terms in this specification based on the specific circumstances. Furthermore, in the description of this specification, unless otherwise stated, "multiple" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.

[0019] The present specification will now be described in detail with reference to specific embodiments.

[0020] Please see Figure 1 This is a schematic diagram of a data operation and maintenance processing system provided in this specification. Figure 1 As shown, the data operation and maintenance processing system may include at least a client cluster and a service platform 100.

[0021] The client cluster may include at least one client, such as Figure 1 As shown, it specifically includes client 1 corresponding to user 1, client 2 corresponding to user 2, ..., client n corresponding to user n, where n is an integer greater than 0.

[0022] Each client in a client cluster can be an electronic device with communication capabilities, including but not limited to: wearable devices, handheld devices, personal computers, tablets, in-vehicle devices, smartphones, computing devices, or other processing devices connected to a wireless modem. Electronic devices may have different names in different networks, such as: user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, electronic device, wireless communication device, user agent or user device, cellular phone, cordless phone, personal digital assistant (PDA), and electronic devices in 5G networks or future evolved networks.

[0023] The service platform 100 can be a standalone server device, such as a rack-mount, blade, tower, or cabinet-type server device, or a workstation, mainframe, or other hardware device with strong computing power; or it can be a server cluster composed of multiple servers. The servers in the service cluster can be composed in a symmetrical manner, wherein each server is functionally and hierarchically equivalent in the transaction chain, and each server can provide services independently. The independent provision of services can be understood as not requiring the assistance of other servers.

[0024] In one or more embodiments of this specification, the service platform 100 can establish a communication connection with at least one client in the client cluster, and complete data interaction during the data operation and maintenance process based on the communication connection, such as online transaction data interaction. For example, the service platform 100 can recommend content to the client based on the target neural network model obtained by the data operation and maintenance processing method of this specification; or the service platform 100 can obtain training data from the client, such as the first training data.

[0025] It should be noted that the service platform 100 establishes a communication connection with at least one client in the client cluster via a network for interactive communication. This network can be a wireless network or a wired network. Wireless networks include, but are not limited to, cellular networks, wireless LANs, infrared networks, or Bluetooth networks. Wired networks include, but are not limited to, Ethernet, universal serial bus (USB), or controller area networks. In one or more embodiments of the specification, technologies and / or formats including Hyper Text Markup Language (HTML), Extensible Markup Language (XML), etc., are used to represent data exchanged over the network (such as target compressed packets). Furthermore, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) can be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can be used to replace or supplement the aforementioned data communication technologies.

[0026] The data operation and maintenance processing system embodiments provided in this specification and the data operation and maintenance processing methods described in one or more embodiments belong to the same concept. The execution entity corresponding to the data operation and maintenance processing method involved in one or more embodiments of this specification can be an electronic device, which can be the aforementioned service platform 100; the execution entity corresponding to the data operation and maintenance processing method involved in one or more embodiments of this specification can also be a client, specifically determined based on the actual application environment. The implementation process of the data operation and maintenance processing system embodiments can be detailed in the following method embodiments, and will not be repeated here.

[0027] based on Figure 1 The following is a detailed description of the data operation and maintenance processing methods provided by one or more embodiments of this specification, as illustrated in the scenario diagram.

[0028] Please see Figure 2 This document provides a flowchart illustrating a data operation and maintenance processing method according to one or more embodiments. This method can be implemented using a computer program and can run on a data operation and maintenance processing device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application. The data operation and maintenance processing device can be an electronic device.

[0029] Specifically, the data operation and maintenance processing method includes: S102: Obtain the target rule SPL code input by the user from the operation and maintenance code area of ​​the code operation and maintenance component interface, determine the target SPL code syntax structure corresponding to the target rule SPL code, and determine multiple SPL code operation nodes and operation node attribute items corresponding to the SPL code operation nodes based on the target SPL code syntax structure. Target Rule SPL Code: This refers to the rule code to be processed that the user enters in the operation and maintenance code area of ​​the code operation and maintenance component interface. SPL (Search Processing Language) is a structured query language oriented towards data querying, log analysis, and event detection. Its syntax is characterized by strong nesting, complex logical combinations, and flexible expression, and it is often used to describe filtering conditions and event characteristics.

[0030] Target SPL code syntax structure: refers to the structured representation of the target rule SPL code generated through the syntax parsing process. For example, it can be an abstract syntax tree, where each node represents a semantic unit, such as logical operation, field comparison, or function call, reflecting the hierarchical nesting structure of the SPL code.

[0031] SPL code operation nodes: These are operation objects instantiated from the semantic units in the syntax structure. They are used to represent semantic processing units, such as "field comparison conditions", "logical operation units", and "function call expressions", which facilitate graphical configuration and user interaction.

[0032] Operation node attribute items: refers to the structured information collection associated with each SPL code operation node, which usually includes field name, operation type, value parameter, node hierarchy path, parent and child relationship information, etc., and is used to support operations such as view rendering, editing form display, and reverse synchronization update.

[0033] As an example, a parsing mechanism based on rule templates and pattern matching can be used to achieve structured recognition and node extraction of SPL query statements with low parsing cost.

[0034] Rule templates: These are pre-defined syntactic expressions used by the system to match and recognize SPL expression structures. They abstractly describe the general semantic format of a class of structured query statements. For example, the template "field name operator value" can be used to match comparison statements, and the template "function name (field name, parameter)" can be used to match function expressions.

[0035] Syntactic fragments: These refer to basic clause fragments in SPL rule statements that are split according to logical structure or brackets. Each syntactic fragment represents a semantically complete unit of operation or combination and can be used as the smallest unit of analysis for node identification.

[0036] Node reduction rules refer to the processing logic of reducing one or more syntactic segments to a logical OR computation node based on their semantic combination. For example, "expression A AND expression B" is reduced to an AND node, whose child nodes are the subtrees corresponding to expression A and expression B.

[0037] In one feasible implementation, the target rule SPL code is first received and read. To improve matching efficiency, the SPL text can be preprocessed, such as removing surrounding spaces, standardizing capitalization, and inserting separators between logical control characters such as AND, OR, and parentheses () and the conditional statements. Use bracket pairing to encapsulate nested expressions into independent syntax fragments; For example, for the following SPL expression: (duration>= 259200 AND malware_name contains "samsam") OR severity = "high"; The system can be segmented into: Segment 1: duration >= 259200; Segment 2: malware_name contains "samsam"; Segment 3: Logical segment AND(...); Segment 4: severity = "high"; Segment 5: Logical segment OR(...) Then, the system performs sequential matching on the above grammatical fragments according to a preset template, for example: If it matches the "field name + operator + value" template, mark it as a comparison operation node; If it matches the "function name (field, parameter)" template, mark it as a function call node; If it matches the template "expression1 AND expression2" or "expression1 OR expression2", it is marked as a logical operation node.

[0038] By sequentially reducing basic fragments to subtree nodes, and then merging them layer by layer upwards to finally generate a structured node tree, each node is an SPL code operation node, recording its template source, fragment content, semantic tags, and list of child nodes. Based on the successfully matched template structure, the system can directly extract core semantic information such as field names, comparison values, logical types, and function parameters from the fragments to construct operation node attribute items, including: Field attributes (such as duration, malware_name), operator attributes (such as >=, contain), Values ​​or parameter list attributes (such as 259200, "samsam"), structure path attributes: generate a unique path according to the reduction order, such as "OR.items[0].AND.items[1]", whether it is a leaf node identifier, etc.

[0039] This structured information set can be used as node definition data in the configuration view to enable visual display and subsequent interactive operations.

[0040] Example using the following SPL rule: (file_type = "exe" AND ext_malware contain "ransom") OR severity = "high" The system preprocesses and segments the data to obtain: Segment A: file_type = "exe" → matches the "field comparison" template; Fragment B: ext_malware contains "ransom" → matches the "field function" template; Fragment C: A AND B → Reduced to an AND node; Fragment D: severity = "high" → Matches the "field comparison" template Fragment E: C OR D → Reduced to the root node of OR.

[0041] The final structure is as follows: The root node is OR, child node 1 is AND, and child node 2 has severity = "high"; The child nodes of the AND node are: file_type = "exe" (field comparison); ext_malware contains "ransom" (function expression).

[0042] As can be seen, each node is bound to the extracted attribute items and its path structure in the configuration view is marked for use in the subsequent S104 step.

[0043] In one feasible implementation, the process of determining multiple SPL code operation nodes and corresponding operation node attribute items based on the target SPL code syntax structure can be performed as follows: A2: Perform a syntax structure traversal on the target SPL code syntax structure to determine multiple syntax operation units; Syntactic operation units refer to the smallest structural expression blocks with independent semantics in the SPL rule syntax structure, which typically include logical operation expressions, field comparison expressions, function call expressions, and other types.

[0044] In a schematic representation, after a user completes the rule writing operation in the operation and maintenance interface, the electronic device's system listens for input events in the operation and maintenance code area, extracts the user-inputted rule text in real time, and uses it as the target rule SPL code to be processed. The system performs lexical and syntactic analysis on the target rule SPL code based on predefined SPL language syntax rules. Optionally, a language parser can be built using syntax recognition tools such as ANTLR. In the lexical analysis stage, the input text is decomposed into tokens, such as field names, operators, string values, and parentheses. In the syntactic analysis stage, the above tokens are reduced to an abstract syntax tree according to the SPL syntax rules. Each syntax node corresponds to a syntax component and its hierarchical dependencies. The abstract syntax tree is the syntactic structure of the target SPL code, and its structure can accurately represent the logical nesting relationships, operation combinations, and field constraints in the code.

[0045] Furthermore, the system performs a depth-first traversal of the abstract syntax tree, identifying semantically independent operational units during the traversal. These operational units include, but are not limited to: Logical operation units: such as logical decision nodes composed of AND, OR, and NOT operators; Comparison operation units: such as "field ≥ number", "field contains string", etc.; Function call unit: such as a call expression like "contain_any(field, list value)".

[0046] A4: Perform node instantiation processing on the syntax operation unit to obtain SPL code operation nodes; Node instantiation refers to constructing SPL code operation node objects with structural properties based on the identified syntactic operation units. Each operation node represents a configuration unit that can be displayed in the graphical view.

[0047] Each identified syntactic operation unit is instantiated as an SPL code operation node. The operation node includes, but is not limited to, the following fields: unique node ID, node type (logical, comparison, function), original expression content, path (e.g., root.items[0].left), and initial attribute value mapping (e.g., field name, function name, value parameter, etc.). The node structure will serve as the basic unit for subsequent attribute extraction and graphical rendering.

[0048] Example explanation: Operation Unit 3 → Operation Node A: Type is "Comparison Node", field name is file_type, operator is =, value is "exe"; Operation Unit 4 → Operation Node B: Type is "Function Node", function is contain, parameter is "ransom"; Operation Unit 2 → Operation Node C: Type is "Logic Node", logical operation is AND, child nodes are A and B; Operation Unit 1 → Operation Node D: Type is "Logic Node", logical operation is OR, child node is C and the corresponding node of Operation Unit 5.

[0049] A6: Extract syntax context information from the target SPL code syntax structure for each SPL code operation node, determine the node parameter attribute information and node relationship attribute information corresponding to the SPL code operation node based on the syntax context information, and generate the operation node attribute item corresponding to the SPL code operation node based on the node parameter attribute information and node relationship attribute information.

[0050] Syntactic context information refers to the structural associations, parent-child relationships, and order information of the operation nodes in the original syntactic structure; node attribute items are structured meta-information bound to the operation nodes, used for view configuration, display, and backfilling.

[0051] Further extract contextual information related to each operation node from the syntax structure, including: node parameter attribute information: including field name, comparison operator, comparison value, function name and its parameters, etc.; node relationship attribute information: including the path of the node in the syntax tree, parent node identifier, sibling order number, etc.

[0052] The above information is encapsulated into corresponding attribute items and bound to node objects. The final output is a set of structured data consisting of "SPL code operation node + operation node attribute item operation node", which provides support for subsequent graphical configuration views.

[0053] Node parameter attribute information: For comparison nodes: field name, operator, constant value; for function nodes: field name, function name, function parameters; for logical nodes: operation type (AND, OR, NOT), list of child node IDs.

[0054] Node relationship attribute information: parent node ID; level; path number (e.g., root.items[1].items[0]); whether it is a root node or a leaf node.

[0055] The above information constitutes the attribute items of the operation node, which can be encapsulated as a key-value structure or a configuration object structure for subsequent steps to bind and render the target code structure configuration view based on the front-end view component.

[0056] S104: Generate a target code structure configuration view based on the target SPL code syntax structure, the SPL code operation node, and the operation node attribute items, and display the target code structure configuration view in the operation and maintenance code operation configuration area of ​​the code operation and maintenance component interface; Target code structure configuration view: This view maps the syntax structure, operation nodes, and attributes corresponding to SPL rules to a set of configuration components on the front-end graphical interface, used to display the semantic hierarchy and operational logic of the original rule code. Figure 1 It is typically presented in the form of a tree structure, nested cards, or flowcharts, and supports node viewing, editing, and interaction.

[0057] Operation and maintenance component interface: refers to the operation container in the front-end interface, which contains at least two areas: Operation and maintenance code area: used to display or edit the raw text of SPL rules; Operation and maintenance code operation configuration area: used to display the generated graphical structure view, supporting visual operation of rule logic.

[0058] In one feasible implementation, the execution process of step S104 may include the following sub-operations: S104-1: First, organize the node tree structure: Based on the SPL code operation node set and its attribute items generated in step S102, the system constructs an operation node tree according to the node relationship attribute information (such as parent-child structure, hierarchical path). Each branch of the tree represents a logical structure, and each leaf node represents the final field comparison or function call condition.

[0059] In the operation node tree, logical nodes are used as intermediate nodes, comparison nodes and function nodes are used as leaf nodes, and then the parentId and children list of each node are maintained.

[0060] S104-2: Then, the nodes are mapped to view components: The system maps each type of operation node to a corresponding view node component. View node components refer to the interface elements in the configuration view used to graphically present SPL operation nodes. Different node types (such as logic nodes, comparison nodes, and function nodes) correspond to different component styles and interaction attributes. For example: Logic nodes → are displayed as logic container boxes containing operation labels (such as "AND", "OR", and "NOT"); Comparison nodes → are displayed as condition configuration cards containing field selectors, operator selectors, and value input boxes; Function nodes → are displayed as function expression cards, supporting multi-parameter editing and field binding. Each component maintains a two-way data binding with its bound operation node attribute items, ensuring that graphical modifications can be written back to the source structure.

[0061] S104-3: Finally, set the component display style and layout structure: To improve view readability, the system can optimize the layout and style in the following ways: Tree-like indented structure: the root node is at the top, and child nodes are arranged downwards in order; Connection relationship display: parent-child dependency relationship is displayed through connection icons; Grouping highlighting and color differentiation: different types of nodes are distinguished to enhance structural awareness; Expand / collapse mechanism: support the collapsed display of substructures to save space.

[0062] S104-4: Displaying the target code structure configuration view in the operation and maintenance code configuration area: After the view structure is built, the system renders and loads the above-mentioned view node component set into the "operation and maintenance code operation configuration area" of the front-end interface. At this time, the target code structure configuration view is displayed to the user. Users can perform interactive operations such as clicking to view nodes, editing attributes, adding and deleting nodes in this area. It supports the reconstruction and fine-tuning of SPL rules based on the structure view.

[0063] For example, such as Figure 3 As shown, Figure 3 This is a graphical configuration interface based on SPL rule syntax. The user's original input SPL rule text has been automatically parsed by the system and converted into a clearly structured and interactive graphical configuration view. This interface displays the results after steps S102 + S104 have been executed.

[0064] Figure 3The SPL rule entered by the user and displayed in the top text box is: alarm_description contain "Number of abnormal nodes: 8" AND file_name contain_any ["SamSa" ,"Samas" ,"samsam"] AND (ext_malware contain "samsam" OR malware_name contain "samsam" OR (service_code = 7 AND sae_rule_type = "availability" AND duration>=259200) OR (ext_virus_type = "ransomware" AND service_code = 12)). Execute step S102, parse Figure 3 The SPL rule text shown is used to extract its syntax structure and operation nodes: 1) Syntax structure recognition: The system recognizes that the outer layer is AND, the inner layer contains an OR, and the OR structure contains two AND branches; 2) Processing of extracting arithmetic units: Field comparison nodes: such as alarm_description contains "Number of abnormal nodes: 8", service_code = 7, etc.; Function nodes: such as file_name contain_any [...]; Logical nodes: such as outer AND, inner OR, and AND in substructures; 3) Node instantiation processing: Each syntax unit is instantiated as an SPL operation node, containing information such as fields, values, and operators; 4) Attribute extraction and processing: Each node is bound to its syntax context path, child node structure, parameter information and other attribute items.

[0065] Then execute step S104: Build and render the target code structure configuration view. 1) View structure construction and processing: Construct a logic tree: with AND as the root node; The node layout uses a nested structure, with the parent node wrapping the child's decision logic; 2) View node rendering and display Figure 3 The lower half shows the target code structure configuration view: Field comparisons and function nodes are displayed in card boxes, such as "ext_malware contains 'samsam'"; Logical combinational structures such as AND / OR use logical connectors to graphically enclose their child nodes; All nodes have "Edit" or "Delete" buttons in the upper right corner for easy configuration modification. 3) Future updates can provide users with view behavior support: for example, clicking on a field or value will bring up an input box for editing; for example, support for adding new conditions and dragging to adjust the order; for example, all changes to view nodes will be written back to the top SPL text box to keep the text and images synchronized.

[0066] Figure 3 The tree structure in the code presents a clear logical hierarchy, as shown below: The top-level logical operator is AND; The first child node on the left is the field matching condition: alarm_description contains "Number of abnormal nodes: 8"; The second child node is the function call file_name contain_any [...]; The third child node is an OR logic branch, containing four nested sub-conditions: The single-field function expression ext_malware contains "samsam"; The field expression `malware_name` contains "samsam"; A nested AND structure containing three conditional statements; A nested AND structure containing two conditional statements.

[0067] Figure 3 The displayed target code structure configuration view maintains the logical structure completely consistent with the original syntax, and clearly indicates its affiliation and hierarchy through indentation, node boxes, and logical connections.

[0068] In one feasible implementation, to achieve a graphical representation of the target SPL code syntax structure, the system may perform the following steps to generate a clearly structured and interactive target code structure configuration view based on SPL code operation nodes. The generation of the target code structure configuration view based on the target SPL code syntax structure, the SPL code operation nodes, and the operation node attribute items in step S104 can be performed as follows: B2: Determine the node unit type of the SPL code operation node based on the target SPL code syntax structure, and determine the node view box corresponding to the SPL code operation node based on the node unit type; A node viewbox is a graphical component used to display a specific SPL code operation node in a visual interface. Different types of syntax nodes correspond to different viewbox styles. Node unit types include, but are not limited to: logical nodes (such as AND, OR), comparison nodes (such as "field = value"), function nodes (such as "field contains value"), etc. For example, using... Figure 3 Indication, Figure 3 The option box containing "duration>= 259200" is the node view box. In a schematic way, based on the node parameter attribute information and syntax context information of the SPL code operation node, the node unit type to which it belongs is identified, and a preset view frame component template is matched based on the type.

[0069] For example, if the node type is a logical operation node, a container view box containing logical keywords (such as "AND", "OR", "NOT") will be generated. If it is a comparison node, a configuration panel view box with field drop-down lists, operator selectors, and value input boxes will be generated; If it is a function call node, a function name display component will be generated, and the parameter configuration fields will be listed.

[0070] As an illustration, a view box instance is assigned to each operation node, and a view tree structure is added in subsequent steps.

[0071] For the expression duration>= 259200, a function node view box will be generated. After the user triggers the function node view box, the field name, function name and value array will be displayed in the interactive property panel. The function node view box provides user operation functions, such as drop-down selection for field items and addition and deletion for array items.

[0072] B4: Based on the node relationship attribute information of each SPL code operation node, generate connection elements between the parent node and child node in the SPL code operation node, and label the connection elements with syntax hierarchy relationship tags; Connecting elements are visual connections used in a graphical interface to represent parent-child node relationships. They reflect the logical combination and nesting hierarchy between operational nodes in a syntactic structure. Syntactic hierarchy labels are used to explicitly display the structure's affiliation or path number.

[0073] Based on the node relationship attribute information recorded in the operation node set, the system constructs a path structure from parent node to child node, and sequentially inserts connecting line elements into the configuration view to connect the node view boxes. Optionally, the system adds syntax hierarchy labels next to the connecting elements to explain the semantic belonging and hierarchical relationship of the substructures in the original syntax, improving configuration comprehensibility.

[0074] B6: Based on the operation node attribute items, an interactive attribute panel is associated with each node view frame, and the interactive attribute panel is used to display node parameter attribute information; The interactive property panel is a user interface unit bound to the node view box. It displays the node's property information (such as field names, operators, comparison values, function names, etc.) and allows users to directly edit the node content within the interface. (See reference.) Figure 4 , Figure 4 This is a schematic diagram of an interactive property panel interface. Figure 4 The text shows user clicks. Figure 3 The interactive properties panel displayed after selecting the "duration>= 259200" option (a node view box) will show: Rule statement: duration>= 259200 (can be modified) Condition Yes / No: Yes (Optional: No) Variable: duration Operator: >= (other operators can be selected from the dropdown menu) Value: Number type 259200 (The input box can be adjusted to display the type and the numerical value within that type) As an illustration, based on the operation node attribute items of each SPL code operation node, a corresponding interactive attribute configuration module is generated and embedded into the corresponding node view box or its pop-up interactive interface through a data binding mechanism. When the user clicks or hovers over a node, the attribute panel is triggered to display the field information and parameter options bound to the current node, and allows modification.

[0075] B8: Based on the target SPL code syntax structure, perform view layout processing on the node view box and the connecting elements to obtain the target code structure configuration view.

[0076] View layout processing refers to the automatic optimization of the position, spacing, and arrangement of all view elements in the visualization interface based on the node hierarchy, logical affiliation, and connection information between nodes, in order to generate a graphical interface with a clear structure and intuitive semantics.

[0077] As an illustration, based on the constructed node tree structure and all connecting paths, the node boxes are organized into layers and their coordinates are calculated: logical combination structures are grouped and nested; sibling nodes are arranged horizontally; substructures are displayed with downward indentation; and intersecting lines are automatically avoided to improve readability.

[0078] The final target code structure configuration view is rendered and loaded into the "Operation and Maintenance Code Operation Configuration Area" on the front end of the interface, where users can intuitively view, adjust, and supplement the rule structure content.

[0079] In this manual, the coordinated execution of the above steps successfully transforms the original SPL rules from "plain text" syntax into a structured, interactive, and easily maintainable graphical rule view, significantly improving user comprehensibility and operational efficiency.

[0080] S106: Obtain the node configuration adjustment operation input by the user for the target code structure configuration view, and perform operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node configuration adjustment operation.

[0081] In one feasible implementation, step S106 can automatically write back and update the target rule SPL code based on the adjusted content after the user makes structured adjustments to the SPL rules through the graphical interface, achieving bidirectional synchronization between graphical editing and text rules. This step ensures that users can accurately reconstruct complex syntax without directly writing or modifying the rule text.

[0082] Node configuration adjustment operations: refer to the interactive modification behaviors performed by users on one or more view nodes in the target code structure configuration view, including but not limited to changing field names, changing operators, replacing values, adjusting function parameters, deleting nodes, dragging structures, adjusting logical connection relationships, adding new nodes, etc.

[0083] Operation and maintenance code update processing: This refers to the system synchronizing the attributes of the operation nodes affected by the above-mentioned adjustment behavior to the SPL syntax tree structure, and regenerating the SPL rule text based on the updated syntax structure, and writing it into the operation and maintenance code area.

[0084] As an illustration, the system first listens for and captures node configuration adjustment operations: It monitors various node interaction events in the target code structure configuration view in real time within the front-end interface. When a user modifies field values, drags and drops structural order, or changes logical relationships in a view node, the system extracts the corresponding node identifier and updated content, constructing a standard "node configuration adjustment operation" description structure.

[0085] Then, the modified node is located and its syntax structure is updated: based on node identification information (such as node ID and path location), the corresponding operation node is located in the target SPL code syntax structure, and the extracted modifications are injected into the node's syntax parameters, keeping the node hierarchy unchanged and only updating its content locally. If the user performs a structural adjustment operation (such as deleting a child node or changing AND to OR), the system simultaneously changes the node relationship attributes and synchronously affects the connection paths between adjacent parent and child nodes.

[0086] Then, the updated SPL syntax structure and updated SPL code text are generated: After updating node parameters or structure, the system automatically reconstructs the SPL code syntax structure tree, ensuring that the structure conforms to syntax rules, is logically complete, and reflects all adjustments performed by the user. The reconstructed SPL syntax structure tree is then input into the code generation module, which traverses the node structure, concatenates the nodes to generate a standard-formatted SPL query expression string, and outputs it as new SPL rule text.

[0087] Finally, the system automatically writes the updated SPL rule text into the "Operations Code Area" of the code operations component interface, replacing the original text content and ensuring that the graphical operation and text content remain synchronized. The system can optionally compare and record the rule content before and after the update to support version management and rollback processing.

[0088] This specification describes how the target rule SPL code input by the user is obtained from the operation and maintenance code area of ​​the code operation and maintenance component interface. The target SPL code syntax structure is determined, laying the foundation for structure visualization. Then, based on the target SPL code syntax structure, multiple SPL code operation nodes and their corresponding operation node attribute items are determined. A target code structure configuration view is generated based on the target SPL code syntax structure, SPL code operation nodes, and operation node attribute items. This view is displayed in the operation and maintenance code operation configuration area of ​​the code operation and maintenance component interface, presenting complex rules graphically and significantly improving readability and comprehension efficiency. Users can interactively adjust configurations through view nodes. By adjusting the user's node configuration, the target rule SPL code in the operation and maintenance code area is updated, and the rule code text is updated in real time, achieving structure-driven rule orchestration and evolution. The overall solution reduces reliance on specialized syntax, improves the ease of operation and controllability of rule operation and maintenance, and effectively adapts to the intelligent operation and maintenance needs in the context of increasingly complex business logic. This paper presents a method for synchronized operation and maintenance of text and images based on structured rules, which realizes bidirectional mapping and interactive updates of SPL rules from text to structured configuration views.

[0089] Optional, please see Figure 5 , Figure 5 This is a flowchart illustrating a data operation and maintenance processing method proposed in one or more embodiments of this specification. Specifically, the process of obtaining the node configuration adjustment operation input by the user for the target code structure configuration view, and updating the target rule SPL code in the operation and maintenance code area based on the node configuration adjustment operation, can be performed as follows: S202: Obtain the node configuration adjustment operation input by the user for the target code structure configuration view, and determine the node attribute item configuration information of the user for the target code structure configuration view based on the node configuration adjustment operation; Node configuration adjustment operations: refer to the actions performed by users on one or more operation nodes in the graphical structure configuration view, such as editing, adding, deleting, moving, and changing logical relationships. Node attribute configuration information: refers to the set of updated fields corresponding to a certain operation node after user adjustment. Optional fields typically include field name, operator, field value, function name, parameter list, node type, parent-child relationship position, etc.

[0090] As an illustration, the system deploys an event listener module in the graphical configuration view to detect user interactions in real time. When a user modifies a node (e.g., changing the value of the "duration" field from "259200" to "86400"), or adjusts the node structure (e.g., moving a child node from the OR branch to the AND branch), the system records the operation and generates a node configuration description object containing the updated fields. Based on this object, the system extracts all node configuration changes currently entered by the user regarding the view structure and forms structured node attribute configuration information to drive subsequent rule code updates.

[0091] Example: If a user changes the field value in the original node "ext_virus_type = ransomware" to "worm virus", the system will extract the following configuration information: Node type: Comparison node; Field name: ext_virus_type; Operator: =; New field value: worm virus.

[0092] S204: Based on the node attribute configuration information and the target SPL code syntax structure, perform operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area.

[0093] Based on the configuration information obtained in step S202, and combined with the pre-built target SPL code syntax structure tree, the following processing flow is executed: 1) Locating the target node path operation: Based on the node's unique identifier or syntax path in the node attribute item, accurately locate the corresponding operation node in the original SPL syntax tree; 2) Inject update parameter operation: Overwrite the original node's syntax fields with the update fields from the node configuration adjustment; 3) Update logical structure operation: If a node is reattached to a new parent node (e.g., the logical operator is changed from OR to AND), the node reference relationship in the syntax tree is adjusted synchronously. 4) Syntax Structure Reconstruction and Verification: Reconstruct and semantically verify the updated SPL syntax tree to ensure logical validity; 5) Rule text reorganization and writing operation: The system performs traversal and concatenation operations based on the updated SPL syntax tree to generate the updated target SPL query expression, and automatically writes the expression as the new rule code text into the operation and maintenance code area; 6) Version saving operation: The system can optionally record the rule text content before and after this update to support version management and change traceability.

[0094] In this manual, by executing steps S202 and S204 above, the system effectively achieves real-time linkage updates between graphical configuration operations and SPL rule text, reducing user operation complexity and improving the consistency and maintainability of rule arrangement. To further expand support for advanced functions such as batch node changes and logical node reordering, a syntax tree difference detection and incremental construction mechanism can be added on this basis.

[0095] In one feasible implementation, S204 can be performed in the following manner: C2: Determine the target SPL code operation node and target node attribute configuration adjustment information based on the node attribute configuration information; Indicatively, the system locates the corresponding operation node in the constructed target SPL syntax tree based on the node identification information (such as node ID or path information) in the node attribute configuration information, and identifies its node type and original syntax content. Subsequently, the user's adjustment operation is converted into a syntax-level modification description, forming a "configuration adjustment information" object, which serves as the semantic unit driving node updates.

[0096] C4: In the target SPL code syntax structure, based on the target node attribute item configuration adjustment information, the target SPL code operation node is updated to obtain the target SPL code syntax structure after node update; The system performs semantic update processing on the located target SPL code operation nodes. Specifically, without changing the syntactic path and nesting level in the overall syntactic structure, the system only performs in-situ replacement or insertion operations on attributes such as node fields, operators, values, function parameters, node types, or child node structures.

[0097] The update process includes, but is not limited to: modifying field values ​​or operators; replacing function call names or parameter lists; adding or deleting child nodes for logical operation nodes; updating node relationship references and adjusting parent-child connections.

[0098] This update process ensures that the grammatical structure remains intact and valid, and preserves the original semantics of all non-changed path nodes.

[0099] C6: Based on the target SPL code syntax structure after node update, perform operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area.

[0100] After the system completes the syntax node update, it performs the following operations based on the updated target SPL code syntax structure: Perform a semantic consistency check on the updated target SPL code syntax structure to ensure that logical nesting, bracket matching, operation order, etc., conform to the SPL expression specification; The code generation engine is started, and the node chaining and reorganization of the target SPL code syntax structure are performed using a depth-first traversal method. Generate standard-formatted rule expression text by concatenating according to SPL syntax rules; Write the generated target SPL rule code text into the "Operation and Maintenance Code Area" in the interface to replace the old rule content; It can save the differences before and after the update to support rule version management and rollback tracking.

[0101] In this manual, by performing the above steps, the structural semantic update of SPL text rules is realized through graphical configuration modifications, ensuring high consistency and automatic synchronization between the structural view and the operation and maintenance rule text, which significantly improves the maintainability and operational efficiency of the operation and maintenance rules.

[0102] In one feasible implementation, such as Figure 6 As shown, Figure 6 This is a flowchart illustrating an information configuration process. Specifically, it involves obtaining the node configuration adjustment operation input by the user for the target code structure configuration view, and determining the node attribute item configuration information for the target code structure configuration view based on the node configuration adjustment operation. This can be done in the following ways: S302: Monitor the user's target selection operation on the target node view box in the target code structure configuration view, and determine the target operation node item and target node parameter attribute information corresponding to the indicator control movement operation; Selection operation: refers to the behavior of a user selecting a node view box by means of mouse click, keyboard selection, touch click, etc. Target operation node item: refers to the SPL operation node corresponding to the selected node view frame; Target node parameter attribute information: refers to the set of parameters associated with the target operation node item, such as field name, operation type, operator, comparison value, function name, function parameters, logical connection information, etc.

[0103] As an illustration, the system registers interactive listening logic in the target code structure configuration view to capture user selection events on the node view box in real time. When the system detects that a user clicks or focuses on a graphical node, it will identify the corresponding operation node item and extract the complete parameter attribute information of the node from the existing SPL code syntax structure for subsequent display in the attribute panel.

[0104] S304: Load the target interactive attribute panel of the target operation node item at the location of the target operation node item, so as to display the target node parameter attribute information in the target interactive attribute panel; After identifying the target operation node, an interactive property panel is dynamically loaded onto the node's view frame. The extracted parameter property information is then mapped to the corresponding control fields in the panel, such as field name dropdowns, operator selectors, value input boxes, and function parameter array input areas. This panel supports user interaction and modification, and changes can be recorded in real time.

[0105] S306: Monitor the attribute operation instructions for the target interactive attribute panel, and determine the node attribute item configuration information based on the attribute operation.

[0106] Attribute manipulation commands: refer to the actions that users perform on field names, values, operators, and other controls in the interactive attribute panel, such as input, selection, modification, and deletion. Node attribute configuration information: refers to the structured attribute data corresponding to SPL operation nodes that are set or changed by the user in the graphical interface, and serves as the basis for subsequent syntax structure updates.

[0107] As an illustration, the system uses an event-driven mechanism to monitor user actions in the interactive property panel in real time. When a user modifies a field value or selects a different operator, the system extracts the field name, value, operator, parameter type, etc., corresponding to this operation and encapsulates them into a structured "node attribute configuration information" object, which is used to drive the syntax update process of the SPL node.

[0108] This specification demonstrates how the above steps enable semantic recognition and attribute extraction when users interactively modify SPL operation nodes in a graphical view. This provides a structured and traceable attribute information foundation for graphically driven rule reconstruction, ensuring the accuracy and controllability of rule modifications. The process also exhibits good scalability and can be used to support attribute editing scenarios for diverse operational rules, including complex logical structures, multi-level nested syntax, and function chaining calls.

[0109] In one feasible implementation, the target node parameter attribute information and target node bounding box interpretation information can be displayed in the target interactive attribute panel, such as... Figure 7 As shown, Figure 7 This is a flowchart illustrating an information configuration process. Specifically, it involves loading a target interactive attribute panel for the target operation node at the target operation node location, displaying target node parameter attribute information in the target interactive attribute panel, monitoring attribute selection commands for the target node parameter attribute information, and determining node attribute item configuration information based on the attribute selection operations. The following method can be used as a reference: S402: Load the target interactive attribute panel of the target operation node item at the location of the target operation node item, so as to display the target node parameter attribute information and the target node box interpretation information in the target interactive attribute panel. The target node box interpretation information is generated by the target large language model based on the target code structure configuration view and the target SPL code syntax structure. Target node box interpretation information: refers to the natural language auxiliary description generated after comprehensive analysis of the syntax, context relationship and structural configuration view of the current SPL node through the target large language model, which is used to prompt the meaning of the node, the judgment logic, the execution effect, etc. Target Interactive Properties Panel: A graphical interactive panel bound to the selected SPL operation node item, supporting the display, editing, and interpretation of node content.

[0110] As an illustration, after the user selects a target operation node item, the target interactive property panel is automatically loaded based on its syntax structure and its position in the configuration view. The node information, such as field name, operator, value, and type, is extracted from the target SPL syntax structure and displayed as "parameter property information".

[0111] Based on this, the system calls the built-in large language model service driven by the target large language model, inputs the grammatical structure corresponding to the current node, the configuration view context and the historical rule text, and generates the semantic interpretation of the node through the prompt word template. This interpretation is displayed in the attribute panel as "target node box interpretation information" to help users understand the logical meaning expressed by the current node.

[0112] Example: The original SPL segment is: duration>= 259200 The generated interpretation information is as follows: "This judgment condition indicates that the duration is greater than or equal to three days (i.e., 259,200 seconds), and it is usually used to identify alarm situations where the service abnormality duration is too long." S404: If an attribute selection instruction for the target node parameter attribute information is received, the configuration information of the first node attribute item is determined based on the attribute selection operation; When a user modifies attributes such as field names, operators, comparison values, function names, or parameters in the interactive attribute panel through mouse clicks, drop-down selections, or input confirmation, the system captures the attribute selection command in real time, maps the changed content to structured fields, and generates the configuration information for the first node attribute item.

[0113] This configuration information can include field update items, comparison of old and new values, modification timestamp, user of the operation source, etc., for subsequent synchronous updates of syntax structure.

[0114] Example: If a user changes the ">=" operator to ">" via a dropdown menu, the system will generate the following configuration information for the first node attribute item: Field name: duration; Original operator: >=; New operator: >; Comparison value: 259200.

[0115] S406: If a natural language attribute modification instruction for the target node parameter attribute information is received, configuration information is generated using the target large language model based on the natural language attribute modification instruction to obtain the second node attribute item configuration information.

[0116] In this implementation, the system supports users directly inputting attribute modification commands in natural language form, such as setting the time to two days or requesting a check to see if more than 5 minutes have passed. After recognizing the natural language input, the system parses the natural language attribute modification command based on the target large language model to obtain the natural language intent. The natural language intent, combined with the grammatical context of the current node, generates corresponding structured configuration change information, which serves as the configuration information for the second node's attribute item.

[0117] The system automatically maps the natural language intent to the corresponding field update, such as adjusting the value, switching operators, or modifying function parameters, ultimately forming a syntax configuration object that is completely corresponding to the structure node.

[0118] Example: Natural language input: "Change the judgment to within two days", target large language model parses and generates the following structured configuration: Field name: duration; Operators: <=; Value: 17280; This result is the configuration information for the second node attribute item, which can be directly used for updating the SPL node syntax tree.

[0119] Optionally, the target large language model can use a general multimodal large language model (MLLM), such as: GPT series large models, Wenxin Yiyan series large models, DeepSeek series large models, etc. In this manual, by executing steps S402 to S406, not only is node parameter configuration based on structured controls implemented, but also a large language model is introduced for semantic understanding and natural language-assisted generation. This significantly reduces the barrier for users to master SPL professional syntax, improves the intelligent interaction capabilities and usability of the rule configuration interface, and is suitable for both beginners and operation and maintenance experts.

[0120] The following will combine Figure 8 This manual provides a detailed introduction to the data operation and maintenance processing device provided. It should be noted that... Figure 7 The data operation and maintenance processing device shown is used to execute this manual. Figures 1-7 The methods of the embodiments shown are illustrated only in connection with this specification for ease of explanation. For specific technical details not disclosed, please refer to this specification. Figures 1-7 The example shown.

[0121] Please see Figure 8 This diagram illustrates the structure of the data operation and maintenance processing device described in this specification. This data operation and maintenance processing device 1 can be implemented as all or part of a user's electronic device through software, hardware, or a combination of both. According to some embodiments, the data operation and maintenance processing device 1 includes a code processing module 11, a view configuration module 12, and a code update module 13, specifically used for: Code processing module 11 is used to obtain the target rule SPL code input by the user from the operation and maintenance code area of ​​the code operation and maintenance component interface, determine the target SPL code syntax structure corresponding to the target rule SPL code, and determine multiple SPL code operation nodes and operation node attribute items corresponding to the SPL code operation nodes based on the target SPL code syntax structure. View configuration module 12 is used to generate a target code structure configuration view based on the target SPL code syntax structure, the SPL code operation node and the operation node attribute item, and display the target code structure configuration view in the operation and maintenance code operation configuration area of ​​the code operation and maintenance component interface; The code update module 13 is used to obtain the node attribute configuration information input by the user for the target code structure configuration view, and to perform operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node attribute configuration information and the target SPL code syntax structure.

[0122] In one feasible implementation, the step of obtaining the node configuration adjustment operation input by the user for the target code structure configuration view, and performing operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node configuration adjustment operation, includes: Obtain the node configuration adjustment operation input by the user for the target code structure configuration view, and determine the node attribute item configuration information of the user for the target code structure configuration view based on the node configuration adjustment operation; Based on the node attribute configuration information and the target SPL code syntax structure, the target rule SPL code in the operation and maintenance code area is updated using operation and maintenance code.

[0123] In one feasible implementation, the step of updating the target rule SPL code in the operation and maintenance code region based on the node attribute configuration information and the target SPL code syntax structure includes: Based on the node attribute configuration information, determine the target SPL code operation node and the target node attribute configuration adjustment information; In the target SPL code syntax structure, the target SPL code operation nodes are updated based on the target node attribute item configuration adjustment information to obtain the target SPL code syntax structure after node update; Based on the updated target SPL code syntax structure, the target rule SPL code in the operation and maintenance code region is updated using operation and maintenance code.

[0124] In one feasible implementation, the step of obtaining the node configuration adjustment operation input by the user for the target code structure configuration view, and determining the node attribute item configuration information of the user for the target code structure configuration view based on the node configuration adjustment operation, includes: Monitor the user's target selection operation in the target node view box of the target code structure configuration view, and determine the target operation node item and target node parameter attribute information corresponding to the indicator control movement operation; Load the target interactive attribute panel of the target operation node item at the location of the target operation node item, so as to display the target node parameter attribute information in the target interactive attribute panel; Monitor the attribute operation instructions for the target interactive attribute panel, and determine the node attribute item configuration information based on the attribute operations.

[0125] In one feasible implementation, the step of loading a target interactive attribute panel for the target operation node item at the target operation node item location, displaying target node parameter attribute information in the target interactive attribute panel, monitoring attribute selection instructions for the target node parameter attribute information, and determining node attribute item configuration information based on the attribute selection operation includes: Load the target interactive attribute panel of the target operation node item at the location of the target operation node item, so as to display the target node parameter attribute information and the target node box interpretation information in the target interactive attribute panel. The target node box interpretation information is generated by the target large language model based on the target code structure configuration view and the target SPL code syntax structure. If an attribute selection instruction for the target node parameter attribute information is received, the configuration information of the first node attribute item is determined based on the attribute selection operation; If a natural language attribute modification instruction is received for the target node parameter attribute information, the configuration information is generated using the target large language model based on the natural language attribute modification instruction to obtain the second node attribute item configuration information.

[0126] In one feasible implementation, determining multiple SPL code operation nodes and corresponding operation node attribute items based on the target SPL code syntax structure includes: The target SPL code syntax structure is traversed to determine multiple syntax operation units; The syntax operation unit is instantiated to obtain the SPL code operation node; For each SPL code operation node, extract syntax context information from the target SPL code syntax structure, determine the node parameter attribute information and node relationship attribute information corresponding to the SPL code operation node based on the syntax context information, and generate the operation node attribute item corresponding to the SPL code operation node based on the node parameter attribute information and node relationship attribute information.

[0127] In one feasible implementation, generating a target code structure configuration view based on the target SPL code syntax structure, the SPL code operation nodes, and the operation node attribute items includes: The node unit type of the SPL code operation node is determined based on the target SPL code syntax structure, and the node view box corresponding to the SPL code operation node is determined based on the node unit type. Based on the node relationship attribute information of each SPL code operation node, a connection element is generated between the parent node and child node in the SPL code operation node, and the connection element is labeled with a syntax hierarchy relationship label. Based on the operation node attribute items, an interactive attribute panel is associated with each node view frame, and the interactive attribute panel is used to display node parameter attribute information; Based on the target SPL code syntax structure, the node view frame and the connecting elements are processed to obtain the target code structure configuration view.

[0128] It should be noted that the data operation and maintenance processing device provided in the above embodiments is only illustrated by the division of the above functional modules when executing the data operation and maintenance processing method. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the data operation and maintenance processing device and the data operation and maintenance processing method embodiments provided in the above embodiments belong to the same concept, and the implementation process is detailed in the method embodiments, which will not be repeated here.

[0129] The serial numbers in this specification are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0130] This specification also provides a computer storage medium capable of storing multiple instructions adapted to be loaded and executed by a processor as described above. Figures 1-7 The data operation and maintenance processing method described in the illustrated embodiment can be found in the following documentation for its specific execution process. Figures 1-7 The specific details of the illustrated embodiments will not be elaborated here.

[0131] This specification also provides a computer program product that stores at least one instruction, said at least one instruction being loaded and executed by the processor as described above. Figures 1-7 The data operation and maintenance processing method described in the illustrated embodiment can be found in the following documentation for its specific execution process. Figures 1-7 The specific details of the illustrated embodiments will not be elaborated here.

[0132] Please refer to Figure 9 This is a structural block diagram of an electronic device provided in an embodiment of this specification. The electronic device in this specification may include one or more of the following components: a processor 1010, a memory 1020, an input device 1030, an output device 1040, and a bus 1050. The processor 1010, memory 1020, input device 1030, and output device 1040 may be connected to each other via the bus 1050.

[0133] Processor 1010 may include one or more processing cores. Processor 1010 connects to various parts of the electronic device using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 1020, and by calling data stored in memory 1020. Optionally, processor 1010 may be implemented using at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). Processor 1010 may integrate one or more of a central processing unit (CPU), graphics processing unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into processor 1010 and may be implemented separately through a communication chip.

[0134] The memory 1020 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 1020 may include non-transitory computer-readable storage medium. The memory 1020 may be used to store instructions, programs, code, code sets, or instruction sets.

[0135] The input device 1030 is used to receive input instructions or data, and includes, but is not limited to, a keyboard, mouse, camera, microphone, or touch device. The output device 1040 is used to output instructions or data, and includes, but is not limited to, a display device and a speaker. In this embodiment, the input device 1030 can be a temperature sensor for acquiring the operating temperature of the electronic device. The output device 1040 can be a speaker for outputting audio signals.

[0136] In addition, those skilled in the art will understand that the structure of the electronic device shown in the above figures does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements. For example, the electronic device may also include radio frequency circuits, input units, sensors, audio circuits, wireless fidelity (WIFI) modules, power supplies, Bluetooth modules, etc., which will not be described in detail here.

[0137] In the embodiments of this specification, the executing entity for each step can be the electronic device described above. Optionally, the executing entity for each step can be the operating system of the electronic device. The operating system can be Android, iOS, or other operating systems; this specification does not limit this.

[0138] exist Figure 9 In the electronic device, the processor 1010 can be used to call the program stored in the memory 1020 and execute it to implement the data operation and maintenance processing method as described in the various method embodiments of this specification.

[0139] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.

[0140] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the object characteristics, interactive behavior characteristics, and user information involved in this specification were all obtained under full authorization.

[0141] The above-disclosed embodiments are merely preferred embodiments of this specification and should not be construed as limiting the scope of this specification. Therefore, any equivalent variations made in accordance with the claims of this specification shall still fall within the scope of this specification.

Claims

1. A data operation and maintenance processing method, the method comprising: Obtain the target rule SPL code input by the user from the operation and maintenance code area of ​​the code operation and maintenance component interface, determine the target SPL code syntax structure corresponding to the target rule SPL code, and determine multiple SPL code operation nodes and operation node attribute items corresponding to the SPL code operation nodes based on the target SPL code syntax structure. A target code structure configuration view is generated based on the target SPL code syntax structure, the SPL code operation node, and the operation node attribute items. The target code structure configuration view is then displayed in the operation and maintenance code operation configuration area of ​​the code operation and maintenance component interface. Obtain the node configuration adjustment operation input by the user for the target code structure configuration view, and perform operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node configuration adjustment operation.

2. The method according to claim 1, wherein obtaining the node configuration adjustment operation input by the user for the target code structure configuration view, and performing operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node configuration adjustment operation, includes: Obtain the node configuration adjustment operation input by the user for the target code structure configuration view, and determine the node attribute item configuration information of the user for the target code structure configuration view based on the node configuration adjustment operation; Based on the node attribute configuration information and the target SPL code syntax structure, the target rule SPL code in the operation and maintenance code area is updated using operation and maintenance code.

3. The method according to claim 2, wherein the step of updating the target rule SPL code in the operation and maintenance code region based on the node attribute configuration information and the target SPL code syntax structure includes: Based on the node attribute configuration information, determine the target SPL code operation node and the target node attribute configuration adjustment information; In the target SPL code syntax structure, the target SPL code operation nodes are updated based on the target node attribute item configuration adjustment information to obtain the target SPL code syntax structure after node update; Based on the updated target SPL code syntax structure, the target rule SPL code in the operation and maintenance code region is updated using operation and maintenance code.

4. The method according to claim 3, wherein obtaining the node configuration adjustment operation input by the user for the target code structure configuration view, and determining the node attribute item configuration information of the user for the target code structure configuration view based on the node configuration adjustment operation, includes: Monitor the user's target selection operation in the target node view box of the target code structure configuration view, and determine the target operation node item and target node parameter attribute information corresponding to the indicator control movement operation; Load the target interactive attribute panel of the target operation node item at the location of the target operation node item, so as to display the target node parameter attribute information in the target interactive attribute panel; Monitor the attribute operation instructions for the target interactive attribute panel, and determine the node attribute item configuration information based on the attribute operations.

5. The method according to claim 4, wherein loading the target interactive attribute panel of the target operation node item at the target operation node item location to display target node parameter attribute information in the target interactive attribute panel, monitoring attribute selection instructions for the target node parameter attribute information, and determining node attribute item configuration information based on the attribute selection operation includes: Load the target interactive attribute panel of the target operation node item at the location of the target operation node item, so as to display the target node parameter attribute information and the target node box interpretation information in the target interactive attribute panel. The target node box interpretation information is generated by the target large language model based on the target code structure configuration view and the target SPL code syntax structure. If an attribute selection instruction for the target node parameter attribute information is received, the configuration information of the first node attribute item is determined based on the attribute selection operation; If a natural language attribute modification instruction is received for the target node parameter attribute information, the configuration information is generated using the target large language model based on the natural language attribute modification instruction to obtain the second node attribute item configuration information.

6. The method according to claim 1, wherein determining multiple SPL code operation nodes and corresponding operation node attribute items based on the target SPL code syntax structure includes: The target SPL code syntax structure is traversed to determine multiple syntax operation units; The syntax operation unit is instantiated to obtain the SPL code operation node; For each SPL code operation node, extract syntax context information from the target SPL code syntax structure, determine the node parameter attribute information and node relationship attribute information corresponding to the SPL code operation node based on the syntax context information, and generate the operation node attribute item corresponding to the SPL code operation node based on the node parameter attribute information and node relationship attribute information.

7. The method according to claim 1, wherein generating a target code structure configuration view based on the target SPL code syntax structure, the SPL code operation nodes, and the operation node attribute items comprises: The node unit type of the SPL code operation node is determined based on the target SPL code syntax structure, and the node view box corresponding to the SPL code operation node is determined based on the node unit type. Based on the node relationship attribute information of each SPL code operation node, a connection element is generated between the parent node and child node in the SPL code operation node, and the connection element is labeled with a syntax hierarchy relationship label. Based on the operation node attribute items, an interactive attribute panel is associated with each node view frame, and the interactive attribute panel is used to display node parameter attribute information; Based on the target SPL code syntax structure, the node view frame and the connecting elements are processed to obtain the target code structure configuration view.

8. A data operation and maintenance processing device, the device comprising: The code processing module is used to obtain the target rule SPL code input by the user from the operation and maintenance code area of ​​the code operation and maintenance component interface, determine the target SPL code syntax structure corresponding to the target rule SPL code, and determine multiple SPL code operation nodes and operation node attribute items corresponding to the SPL code operation nodes based on the target SPL code syntax structure. The view configuration module is used to generate a target code structure configuration view based on the target SPL code syntax structure, the SPL code operation node and the operation node attribute item, and to display the target code structure configuration view in the operation and maintenance code operation configuration area of ​​the code operation and maintenance component interface. The code update module is used to obtain the node attribute configuration information entered by the user for the target code structure configuration view, and to perform operation and maintenance code update processing on the target rule SPL code in the operation and maintenance code area based on the node attribute configuration information and the target SPL code syntax structure.

9. A computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the method steps of any one of claims 1 to 7.

10. An electronic device, comprising: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and executed the method steps as claimed in any one of claims 1 to 7.