System alarm message generation method and device, electronic equipment and storage medium

By identifying the module call dependencies and timing compliance of the target software system, the target alarm messages that are actually used for alarms are filtered out, which solves the alarm storm problem when the system fails and improves the efficiency of troubleshooting.

CN121501593APending Publication Date: 2026-02-10LUOBO NETWORK (HANGZHOU) INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511470094.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-15
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing alarm technologies tend to generate a large number of repetitive, invalid, or low-priority alarm messages when system failures occur, leading to low operational efficiency and difficulty in troubleshooting the key causes of system failures.

Method used

By obtaining the latest weights and timing compliance identification results of the module call dependencies of the target software system, the target dependency links of the alarm triggering module are identified, and the target alarm messages actually used for alarms are filtered out based on this information to reduce interference messages.

Benefits of technology

When an alarm storm is detected in the system, the latest weights and timing compliance of module call dependencies are used to simplify alarm messages, reduce interference messages, and improve the efficiency of troubleshooting system failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121501593A_ABST
    Figure CN121501593A_ABST
Patent Text Reader

Abstract

The invention provides a system alarm message generation method and device, electronic equipment and a storage medium. The method comprises the steps that when it is monitored that a to-be-warned message of a target software system meets a preset warning storm condition, latest module weight data of the target software system is acquired; the method comprises the following steps: mapping a to-be-alarmed message to a preset blood relationship dependency graph, and identifying a target dependency link of an alarm triggering module; performing time sequence compliance identification on the target dependency link to obtain a time sequence compliance identification result; and determining a target alarm message from the to-be-alarmed message according to the latest weight of the calling dependency relationship of each module in the target dependency link and a time sequence compliance identification result, and sending the target alarm message to an alarm object. According to the invention, the system fault reason checking efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of computer, and particularly relates to a system alarm message generation method and device, electronic equipment and storage medium. BACKGROUND

[0002] In a large software system, the accuracy of alarm messages is the key to improving system operation efficiency and system fault troubleshooting efficiency, and accurate alarm messages can warn the root cause of system failure.

[0003] However, the existing alarm technology is prone to "alarm storm" when the system fails, that is, a large number of, repeated, invalid or low-priority alarm messages are generated due to various reasons, resulting in low operation efficiency and difficulty in troubleshooting the key cause of system failure. SUMMARY

[0004] Therefore, the purpose of the present disclosure is to provide a system alarm message generation method and device, electronic equipment and storage medium to improve the efficiency of troubleshooting system failure causes.

[0005] In a first aspect, the present disclosure provides a system alarm message generation method, which comprises: when it is monitored that a to-be-alarmed message of a target software system meets a preset alarm storm condition, acquiring latest module weight data of the target software system, wherein the latest module weight data is used to indicate the latest weight of a module call dependency relationship in a preset blood relationship dependency graph of the target software system, and the preset blood relationship dependency graph is used to indicate the call dependency relationship between each module in the target software system; identifying a target dependency link of an alarm triggering module by mapping the to-be-alarmed message to the preset blood relationship dependency graph; performing time sequence compliance identification on the target dependency link to obtain a time sequence compliance identification result; wherein the time sequence compliance identification result is used to indicate whether the call time sequence of each module in the target dependency link meets a preset time sequence rule; determining a target alarm message from the to-be-alarmed message according to the latest weight of the call dependency relationship of each module in the target dependency link and the time sequence compliance identification result, and sending the target alarm message to an alarm object.

[0006] In a second aspect, the embodiments of the present disclosure provide a system alarm message generation device, the device comprising: a monitoring module configured to obtain latest module weight data of a target software system when it is monitored that a to-be-alarmed message of the target software system meets preset alarm storm conditions, wherein the latest module weight data is used to indicate the latest weight of module call dependency relationship of the target software system in a preset blood relationship dependency graph, and the preset blood relationship dependency graph is used to indicate the call dependency relationship between modules in the target software system; an identifying module configured to identify a target dependency link of an alarm triggering module by mapping the to-be-alarmed message to the preset blood relationship dependency graph; a detecting module configured to perform timing compliance identification on the target dependency link to obtain a timing compliance identification result, wherein the timing compliance identification result is used to indicate whether the call timing of each module in the target dependency link meets preset timing rules; and a sending module configured to determine a target alarm message from the to-be-alarmed message according to the latest weight of the call dependency relationship of each module in the target dependency link and the timing compliance identification result, and send the target alarm message to an alarm object.

[0007] In a third aspect, the embodiments of the present disclosure provide an electronic device, comprising a processor and a memory, wherein the memory stores machine executable instructions capable of being executed by the processor, and the processor executes the machine executable instructions to implement the system alarm message generation method.

[0008] In a fourth aspect, the embodiments of the present disclosure provide a computer readable storage medium, wherein the computer readable storage medium stores computer executable instructions, and when the computer executable instructions are invoked and executed by a processor, the computer executable instructions cause the processor to implement the system alarm message generation method.

[0009] The embodiments of the present disclosure bring the following beneficial effects: The system alarm message generation method, device, electronic device and storage medium described above, when it is monitored that an alarm storm is about to occur in a system, the latest weight of the module call dependency relationship of the system and the compliance of the module call timing are used to perform noise reduction processing on a to-be-alarmed message, that is, to select a target alarm message actually used for alarm from the to-be-alarmed message, so as to simplify the alarm message, reduce interference messages, and improve the efficiency of system fault reason analysis.

[0010] Other features and advantages of the present disclosure will be described in the following description, and some will become apparent from the description, or will be learned from practice of the present disclosure. The purpose and other advantages of the present disclosure will be achieved and obtained by the structure specifically pointed out in the description, claims and drawings.

[0011] To make the above-mentioned objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the specific embodiments of this disclosure or the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0013] Figure 1 This is a flowchart of one embodiment of the method for generating system alarm messages in this disclosure; Figure 2 This is a flowchart of another embodiment of the method for generating system alarm messages in this disclosure; Figure 3 A schematic diagram of a system alarm message generation device provided in an embodiment of this disclosure; Figure 4 This is a schematic diagram of an electronic device provided in an embodiment of the present disclosure. Detailed Implementation

[0014] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0015] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in this disclosure, claims, and accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” or “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] For ease of understanding, the specific process of the embodiments of this disclosure is described below. Please refer to [link / reference]. Figure 1One embodiment of the method for generating system alarm messages in this disclosure includes: Step S10: When the alarm message to be alarmed in the target software system meets the preset alarm storm conditions, the latest module weight data of the target software system is obtained. The latest module weight data is used to indicate the latest weight of the module call dependency relationship of the target software system in the preset lineage dependency relationship graph. The preset lineage dependency relationship graph is used to indicate the call dependency relationship between each module in the target software system. A target software system is a software system that includes multiple modules, such as a content management system, an order system, an appointment system, and a human resource management system. The modules of a software system can be divided according to function, independent programs, or other custom methods. No specific restrictions are imposed here.

[0017] During the operation of the target software system, the operating status of modules can be monitored. When the operating status of any module triggers the corresponding preset alarm condition, a pending alarm message is generated. More than one pending alarm message can be generated within a certain time period. A pending alarm message is a message to be sent to an alarm object. This embodiment analyzes the pending alarm messages generated within a certain time period to determine whether to send the pending alarm message to the alarm object, thereby avoiding an "alarm storm" and making alarm messages more accurate and effective.

[0018] The preset alarm storm conditions are the triggering conditions in this embodiment of the disclosure. By monitoring the alarm messages to be alarmed generated by the target software system within a certain period of time, the occurrence of alarm storm events can be predicted, and a series of technical means can be taken to avoid the occurrence of alarm storm events, making alarm messages more accurate and effective.

[0019] In one implementation, the preset alarm storm conditions can be set according to the preset alarm conditions of the target software system, or alarm storm prediction can be performed by a pre-trained artificial intelligence model, or custom rules can be set according to business scenarios and system characteristics, etc., without further limitation here. Among them, the artificial intelligence model for alarm storm prediction can be pre-trained using alarm messages from the target software system, so that the alarm storm prediction is more consistent with the alarm pattern of the target software system, which will not be elaborated here.

[0020] When the detected alarm messages of the target software system meet the preset alarm storm conditions, it indicates that an alarm storm event is about to occur in the target software system. An alarm storm event is a custom event that can be used to indicate a situation where there are too many interfering alarm messages. The specific settings can be combined with the business scenario.

[0021] In this embodiment, when the alarm message of the target software system is detected to meet the preset alarm storm conditions, the latest module weight data of the target software system is obtained. The module weight data of the target software system is used to represent the weight of the call dependency relationship between the various modules of the target software system in the preset lineage dependency relationship map. The weight can represent the business importance of the corresponding module call dependency relationship in the target software system, the tightness of the dependency relationship between modules, the call heat, the call dependency frequency, data traffic and other dynamic indicators. The specifics are not limited here.

[0022] In one implementation, the module weight data of the target software system can be updated at a preset frequency to obtain the latest module weight data. It should be noted that the preset lineage dependency graph is used to represent the call dependencies between various modules in the target software system, where nodes represent modules and edges represent module call dependencies. Each time the module weight data is updated, the latest weight of the call dependencies between modules in the preset lineage dependency graph can be calculated by traversing each module. The latest module weight data can be obtained by associating module identifiers with nodes in the preset lineage dependency graph.

[0023] Step S20: Identify the target dependency link of the alarm triggering module by mapping the alarm message to a preset lineage dependency graph; In one implementation, at least one alarm triggering module can be identified through the alarm message to be alarmed. Then, the alarm triggering module corresponding to the alarm message to be alarmed is mapped to a preset lineage dependency graph. The target node corresponding to the alarm triggering module in the preset lineage dependency graph is determined. Then, the dependency link of the target node is extracted from the preset lineage dependency graph to obtain the target dependency link.

[0024] In one implementation, the dependency link of the target node can consist of any number of upstream nodes in the same dependency chain, and can be traced back to the root node of the target node. Different alarm triggering modules correspond to different target dependency links, but there may be overlapping parts, which are not limited here.

[0025] In one implementation, when at least one alarm triggering module can be identified through the alarm message to be alarmed, the identification information of the alarm triggering module in the alarm message to be alarmed can be identified, or the identification information of the alarm triggering module can be identified through the alarm message to be alarmed, thereby determining at least one alarm triggering module corresponding to the alarm message to be alarmed.

[0026] Step S30: Perform timing compliance identification on the target dependency link to obtain timing compliance identification results; wherein, the timing compliance identification results are used to indicate whether the calling timing of each module in the target dependency link conforms to the preset timing rules; It is understandable that in the target software system, the calls of some / all modules need to follow certain timing rules. Disorders in timing logic may also trigger an alarm storm. Therefore, in this embodiment, the timing compliance identification result is obtained by identifying whether the call timing of each module in the target dependency chain conforms to the preset timing rules. The timing compliance identification result can also be used to indicate modules with timing violations, that is, modules whose call timing does not conform to the preset timing rules. The specifics are not limited here.

[0027] In one implementation, when performing timing compliance identification, the occurrence time of lifecycle events (such as initialization, running, destruction, etc.) of modules in the target dependency chain can be monitored. The occurrence time can be used to determine whether the calling sequence of each module conforms to the preset timing rules, making the timing compliance identification more accurate.

[0028] In one implementation, the preset timing rules can be set manually, or they can be identified and recorded during the normal operation of the target software system. Alternatively, the timing rules can be generated by training an artificial intelligence model using historical alarm messages. For example, a timing rule could be: "Module A must start after module B is initialized." The specific rules are not limited here.

[0029] Step S40: Based on the latest weights and timing compliance identification results of the module call dependencies in the target dependency chain, determine the target alarm message from the pending alarm messages and send the target alarm message to the alarm object.

[0030] In this embodiment, based on the latest weights and timing compliance identification results of the module call dependencies in the target dependency chain, the messages to be alarmed can be divided into noise messages and non-noise messages. Non-noise messages can be used as target alarm messages for alarming. Target alarm messages will be sent to the alarm object in the form of non-noise messages, while noise messages may not be sent to the alarm object or may be sent to the alarm object in the form of noise messages, such as merging them into the same list of silent messages. The specifics are not limited here.

[0031] In one implementation, alarm messages corresponding to modules in the target dependency link whose latest weight is less than a certain threshold and whose call timing conforms to preset timing rules can be identified as noise messages, while other alarm messages can be identified as non-noise messages. This reduces the sending of interfering alarm messages and improves the efficiency of troubleshooting system faults.

[0032] The system alarm message generation method provided in the above implementation method, when detecting that an alarm storm is about to occur in the system, performs noise reduction processing on the alarm messages to be alarmed by using the latest weight of the system's module call dependencies and the compliance of the module call timing. That is, it filters out the target alarm messages that are actually used for alarming from the alarm messages to be alarmed, thereby simplifying the alarm messages, reducing interference messages, and improving the efficiency of troubleshooting system faults.

[0033] Please see Figure 2 Another embodiment of the method for generating system alarm messages in this disclosure includes: Step S201: When the alarm message to be alarmed in the target software system meets the preset alarm storm conditions, the latest module weight data of the target software system is obtained. The latest module weight data is used to indicate the latest weight of the module call dependency relationship of the target software system in the preset lineage dependency relationship graph. The preset lineage dependency relationship graph is used to indicate the call dependency relationship between each module in the target software system. In one implementation, before step S201, the method further includes: when any module of the target software system triggers the corresponding preset alarm condition, generating a corresponding alarm message to be alarmed; determining whether the frequency and / or number of alarm messages to be alarmed within a preset time period starting from the current time reaches a preset threshold; if the frequency and / or number reaches the preset threshold, determining that the alarm messages to be alarmed in the target software system meet the preset alarm storm conditions.

[0034] For each module in the target software system, corresponding alarm conditions can be preset. That is, each module corresponds to a preset alarm condition. When the status of the module meets the corresponding preset alarm condition, an alarm message is generated. The alarm message can contain the identification information of the corresponding module, i.e., the alarm triggering module, and can also contain the status parameters of the alarm triggering module that triggers the corresponding preset alarm condition, such as the module's error code, CPU usage, memory usage, etc. The specifics are not limited here.

[0035] The generated pending alarm messages are not immediately sent to the alarm object. Instead, the system continues to collect pending alarm messages within a preset time period starting from the current moment and calculates whether the frequency and / or quantity of the collected pending alarm messages have reached a certain preset threshold. If they have, it means that the pending alarm messages of the target software system meet the preset alarm storm conditions. Otherwise, it means that the pending alarm messages of the target software system do not meet the preset alarm storm conditions.

[0036] The frequency mentioned above refers to the number of pending alarm messages generated per unit time (e.g., per second), and the quantity refers to the total number of pending alarm messages generated within the entire preset time period. In one implementation, the preset threshold can be set based on the system's historical operating data and maintenance experience. For example, if the number of alarms from a certain module exceeds 50 within 1 minute, it is considered to have reached the alarm storm threshold.

[0037] Taking the target software system as an order system as an example, for the order receiving module of the order system, one of the preset alarm conditions for the order receiving module can be set that the response time for processing order requests is less than 500 milliseconds. When a promotional activity starts, a large number of order creation requests may be generated that need to call the order receiving module, which will cause the response time for order processing requests to increase and exceed 500 milliseconds. At this time, your system will start to continuously generate alarm messages for "order service response delay".

[0038] Assuming the preset threshold for the number of pending alarm messages is 30, and the preset time period is 1 minute, if the number of pending alarm messages for "order service response delay" exceeds 30 within 1 minute, the alarm storm threshold is reached. This confirms that the pending alarm messages of the target software system meet the preset alarm storm conditions, and the subsequent alarm noise reduction process can be initiated to deal with the upcoming alarm storm and prevent maintenance personnel from being overwhelmed by a large number of invalid alarms.

[0039] In one implementation, the step of obtaining the latest module weight data of the target software system includes: using pre-inserted code instrumentation points, performing statistical analysis on the call dependency frequency and data flow of each module call dependency relationship in the current state of the target software system for a certain period of time, to obtain the call dependency frequency information and data flow information corresponding to each module call dependency relationship in the target software system; and normalizing the call dependency frequency information and data flow information corresponding to each module call dependency relationship to obtain the latest module weight data of the target software system.

[0040] In module call dependencies, there are calling / dependent modules and called / dependent modules. In this embodiment, the call dependency frequency and data flow of each module call dependency in the target software system are statistically analyzed to obtain basic data for measuring the weight of module call dependencies in the preset lineage dependency graph. The call dependency frequency refers to the number of times a calling / dependent module calls / depends on a called / dependent module per unit time. The data flow of a module call dependency refers to the amount of data transmitted between modules during a single call / dependency process, usually measured in bytes or data packets; specific measurements are not limited here.

[0041] In this embodiment, code instrumentation points pre-installed in the target software system can capture inter-module call behavior and data transmission information in real time without intrusion. Specifically, probes or proxy code pre-implanted at key code locations (such as function calls, method entry / exit points) in the target software system can serve as code instrumentation points. The data captured by the code instrumentation points can be sent to a designated database for statistical purposes.

[0042] In this embodiment, after obtaining the call dependency frequency information and data flow information corresponding to the call dependency relationships of each module in the target software system, this information can be converted to a unified numerical range (such as between 0 and 1) and updated to the preset lineage dependency relationship map to obtain the latest module weight data of the target software system.

[0043] Step S202: Identify the target dependency link of the alarm triggering module by mapping the alarm message to a preset lineage dependency graph; In one implementation, step S202 includes: parsing the metadata of the alarm message to be alarmed to obtain the alarm module identifier corresponding to the alarm message; matching the node corresponding to the alarm module identifier from the preset lineage dependency graph, and determining the module corresponding to the node as the alarm triggering module; and tracing the upstream dependency link of the alarm triggering module in reverse from the preset lineage dependency graph to obtain the target dependency link of the alarm triggering module.

[0044] In this embodiment, the metadata can be parsed from the message to be alarmed. The metadata contains the alarm module identifier corresponding to the message to be alarmed, which is used to determine the unique alarm source module. For example, the alarm identifier can be a microservice name, hostname, IP address, port number, source file name, function name, etc., and the specifics are not limited here.

[0045] After obtaining the alarm module identifier, the corresponding node can be matched from the preset lineage dependency graph, and the module corresponding to the node can be identified as the alarm triggering module. It should be noted that the alarm triggering module may not be the root cause of the alarm, but rather a link in the fault propagation chain. This implementation provides a reverse description of the upstream dependency link of the node corresponding to the alarm triggering module, which is helpful in locating the root cause of the alarm, thereby triggering an alarm for the root cause and improving the efficiency of troubleshooting system faults.

[0046] The upstream dependency link includes all upstream paths of the node corresponding to the alarm triggering module, that is, the path consisting of all modules that the alarm triggering module depends on. By tracing back the preset lineage dependency graph, the accuracy and efficiency of dependency path determination can be improved, and the efficiency of system fault diagnosis can also be improved.

[0047] Step S203: Perform timing compliance identification on the target dependency link to obtain timing compliance identification results; wherein, the timing compliance identification results are used to indicate whether the calling sequence of each module in the target dependency link conforms to the preset timing rules; In one implementation, step S203 includes: obtaining the call timestamps of each module in the target dependency chain; determining whether the call sequence of each module in the target dependency chain conforms to the preset timing rules based on the call timestamps of each module, and obtaining the timing compliance identification result.

[0048] The call timestamps of each module in the target dependency chain are the times recorded when each module executes a preset lifecycle event (such as startup or response). In one implementation, a distributed tracing system (such as OpenTracing) can be used to record the call timestamps of each module, making the judgment of timing compliance more accurate.

[0049] After obtaining the call timestamps of each module, it can be determined whether the call sequence of each module in the target dependency chain conforms to the preset timing rules. The preset timing rules may include: whether the call times between specified modules conform to the preset call order (e.g., module A must be called before module B, module A must be called after module B), whether the interval between the call times between specified modules is within the preset range (the call time of module A minus the call time of module B must be less than 500ms), etc. The specifics are not limited here.

[0050] Step S204: Calculate the target alarm priority of the message to be alarmed based on the latest weight of the module call dependency relationship in the target dependency chain and the timing compliance identification result. In this step, a comprehensive evaluation is conducted by combining the closeness of bloodline dependence (represented by the latest weight) and the compliance of timing logic (represented by the timing compliance identification result) to obtain the target alarm priority corresponding to each pending alarm message. This priority is used to distinguish whether the corresponding pending alarm message is identified as a target alarm message and sent to the alarm object.

[0051] In one implementation, the target alarm priority is calculated by using a weighted summation or other multi-factor evaluation model to obtain a priority score, and then the target alarm priority is divided according to the priority score. For example, the priority score S can be calculated using the following weighted summation formula: S = α * M + β * N Where M represents the sum of the latest weights of the module call dependencies in the target dependency chain, N represents the time-series violation penalty factor, and α and β represent the weights of M and N, respectively. Specifically, the time-series violation penalty factor can be determined based on the corresponding time-series compliance identification result. If the time-series compliance identification result is a time-series violation, the factor is positive to increase the alarm priority; if it is compliant, it is 0 or negative to decrease the priority.

[0052] In one implementation, step S204 includes: determining the first alarm priority of the alarm triggering module corresponding to the alarm message based on the latest weight of the module call dependency relationship in the target dependency link; and upgrading the first alarm priority of the alarm triggering module whose call timing does not conform to the preset timing rule based on the timing compliance identification result, so as to obtain the target alarm priority of the alarm message.

[0053] In this implementation, the first alarm priority can be determined first based on the latest weight of the calling dependency relationship of each module. If the calling sequence of the corresponding module does not conform to the preset timing rule, the first alarm priority is upgraded based on the first alarm priority. Otherwise, the first alarm priority is not upgraded and the first alarm priority is determined as the target alarm priority.

[0054] Step S205: Identify the alarm messages with a target alarm priority higher than a preset threshold as target alarm messages, and send the target alarm messages to the alarm objects.

[0055] The preset threshold is a configurable alarm priority boundary. Only when the priority score of an alarm exceeds this threshold is it considered an important alarm and needs to be sent to the alarm object. Otherwise, it is determined to be an alarm message that needs noise reduction and can be sent to the alarm object in the form of a noise message, or it can not be sent to the alarm object. The specifics are not limited here.

[0056] The system alarm message generation method provided in the above implementation method, when detecting that an alarm storm is about to occur in the system, determines the alarm priority of the alarm message to be alarmed by the latest weight of the system's module call dependency relationship and the compliance of the module call timing, thereby determining whether to perform noise reduction processing on the alarm message to be alarmed, that is, to filter out the target alarm message actually used for alarming from the alarm message to be alarmed, thereby simplifying the alarm message, reducing interference messages, and improving the efficiency of troubleshooting system fault causes.

[0057] For the corresponding method embodiments described above, see [link to relevant documentation]. Figure 3The diagram illustrates a system alarm message generation device, comprising: a monitoring module 32, configured to acquire the latest module weight data of the target software system when an alarm message to be alarmed in the target software system meets preset alarm storm conditions, wherein the latest module weight data is used to indicate the latest weight of the module call dependency relationship of the target software system in a preset lineage dependency relationship graph, and the preset lineage dependency relationship graph is used to indicate the call dependency relationship between modules in the target software system; an identification module 34, configured to identify the target dependency link of the alarm triggering module by mapping the alarm message to be alarmed to the preset lineage dependency relationship graph; a detection module 36, configured to perform time sequence compliance identification on the target dependency link and obtain a time sequence compliance identification result, wherein the time sequence compliance identification result is used to indicate whether the call sequence of each module in the target dependency link conforms to a preset time sequence rule; and a sending module 38, configured to determine the target alarm message from the alarm message to be alarmed based on the latest weight of the call dependency relationship of each module in the target dependency link and the time sequence compliance identification result, and send the target alarm message to the alarm object.

[0058] When the alarm message generation device of the above system detects that an alarm storm is about to occur in the system, it performs noise reduction processing on the alarm messages to be alarmed by using the latest weight of the system's module call dependencies and the compliance of the module call timing. In other words, it filters out the target alarm messages that are actually used for alarming from the alarm messages to be alarmed, thereby simplifying the alarm messages, reducing interference messages, and improving the efficiency of troubleshooting system faults.

[0059] Optionally, before the step of obtaining the latest module weight data of the target software system when the detected alarm message of the target software system meets the preset alarm storm conditions, the method further includes: generating a corresponding alarm message when any module of the target software system triggers the corresponding preset alarm conditions; determining whether the frequency and / or number of alarm messages within a preset time period starting from the current time reaches a preset threshold; if the frequency and / or number reaches the preset threshold, then determining that the detected alarm message of the target software system meets the preset alarm storm conditions.

[0060] Optionally, the step of obtaining the latest module weight data of the target software system includes: using pre-installed code instrumentation points to statistically analyze the call dependency frequency and data flow of each module call dependency relationship in the current state of the target software system for a certain period of time, to obtain the call dependency frequency information and data flow information corresponding to each module call dependency relationship in the target software system; and normalizing the call dependency frequency information and data flow information corresponding to each module call dependency relationship to obtain the latest module weight data of the target software system.

[0061] Optionally, the step of identifying the target dependency link of the alarm triggering module by mapping the message to be alarmed to the preset lineage dependency graph includes: parsing the metadata of the message to be alarmed to obtain the alarm module identifier corresponding to the message to be alarmed; matching the node corresponding to the alarm module identifier from the preset lineage dependency graph, and determining the module corresponding to the node as the alarm triggering module; and tracing the upstream dependency link of the alarm triggering module backward from the preset lineage dependency graph to obtain the target dependency link of the alarm triggering module.

[0062] Optionally, the step of performing time-series compliance identification on the target dependency link and obtaining the time-series compliance identification result includes: obtaining the call timestamp of each module in the target dependency link; determining whether the call sequence of each module in the target dependency link conforms to the preset time-series rules based on the call timestamp of each module, and obtaining the time-series compliance identification result.

[0063] Optionally, the step of determining a target alarm message from the pending alarm messages based on the latest weights of the module call dependencies in the target dependency chain and the timing compliance identification results, and sending the target alarm message to the alarm object, includes: calculating the target alarm priority of the pending alarm messages based on the latest weights of the module call dependencies in the target dependency chain and the timing compliance identification results; determining the pending alarm messages with target alarm priorities higher than a preset threshold as target alarm messages, and sending the target alarm messages to the alarm object.

[0064] Optionally, the step of calculating the target alarm priority of the message to be alarmed based on the latest weights of the call dependencies of each module in the target dependency chain and the timing compliance identification result includes: determining the first alarm priority of the message to be alarmed corresponding to the alarm triggering module based on the latest weights of the call dependencies of each module in the target dependency chain; and upgrading the first alarm priority of the module whose call timing does not conform to the preset timing rules based on the timing compliance identification result to obtain the target alarm priority of the message to be alarmed.

[0065] This embodiment also provides an electronic device, including a processor and a memory. The memory stores machine-executable instructions that can be executed by the processor. The processor executes the machine-executable instructions to implement the above-described method for generating system alarm messages. This electronic device can be a server or a terminal device.

[0066] See Figure 4 As shown, the electronic device includes a processor 100 and a memory 101. The memory 101 stores machine-executable instructions that can be executed by the processor 100. The processor 100 executes the machine-executable instructions to implement the above-described method for generating system alarm messages.

[0067] Furthermore, Figure 4 The electronic device shown also includes a bus 102 and a communication interface 103, with the processor 100, the communication interface 103 and the memory 101 connected via the bus 102.

[0068] The memory 101 may include high-speed random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 103 (which can be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc. The bus 102 may be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0069] The processor 100 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 100 or by instructions in software form. The processor 100 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this disclosure can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software module can reside in a readily available storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory 101. The processor 100 reads information from memory 101 and, in conjunction with its hardware, completes the steps of the method described in the foregoing embodiments, for example: When a pending alarm message from the target software system is detected to meet the preset alarm storm conditions, the latest module weight data of the target software system is obtained. This latest module weight data indicates the latest weight of the module call dependencies in the preset lineage dependency graph, which indicates the call dependencies between modules in the target software system. The pending alarm message is mapped to the preset lineage dependency graph to identify the target dependency chain of the alarm triggering module. The timing compliance of the target dependency chain is then assessed to obtain a timing compliance assessment result. This result indicates whether the call timing of each module in the target dependency chain conforms to preset timing rules. Based on the latest weight of the call dependencies of each module in the target dependency chain and the timing compliance assessment result, a target alarm message is determined from the pending alarm messages and sent to the alarm object.

[0070] In this approach, when an alarm storm is detected to be about to occur in the system, noise reduction processing is performed on the alarm messages to be alarmed by using the latest weight of the system's module call dependencies and the compliance of the module call timing. In other words, the target alarm messages that are actually used for alarming are filtered out from the alarm messages to be alarmed, thereby simplifying the alarm messages, reducing interference messages, and improving the efficiency of troubleshooting system faults.

[0071] Optionally, before the step of obtaining the latest module weight data of the target software system when the detected alarm message of the target software system meets the preset alarm storm conditions, the method further includes: generating a corresponding alarm message when any module of the target software system triggers the corresponding preset alarm conditions; determining whether the frequency and / or number of alarm messages within a preset time period starting from the current time reaches a preset threshold; if the frequency and / or number reaches the preset threshold, then determining that the detected alarm message of the target software system meets the preset alarm storm conditions.

[0072] Optionally, the step of obtaining the latest module weight data of the target software system includes: using pre-installed code instrumentation points to statistically analyze the call dependency frequency and data flow of each module call dependency relationship in the current state of the target software system for a certain period of time, to obtain the call dependency frequency information and data flow information corresponding to each module call dependency relationship in the target software system; and normalizing the call dependency frequency information and data flow information corresponding to each module call dependency relationship to obtain the latest module weight data of the target software system.

[0073] Optionally, the step of identifying the target dependency link of the alarm triggering module by mapping the message to be alarmed to the preset lineage dependency graph includes: parsing the metadata of the message to be alarmed to obtain the alarm module identifier corresponding to the message to be alarmed; matching the node corresponding to the alarm module identifier from the preset lineage dependency graph, and determining the module corresponding to the node as the alarm triggering module; and tracing the upstream dependency link of the alarm triggering module backward from the preset lineage dependency graph to obtain the target dependency link of the alarm triggering module.

[0074] Optionally, the step of performing time-series compliance identification on the target dependency link and obtaining the time-series compliance identification result includes: obtaining the call timestamp of each module in the target dependency link; determining whether the call sequence of each module in the target dependency link conforms to the preset time-series rules based on the call timestamp of each module, and obtaining the time-series compliance identification result.

[0075] Optionally, the step of determining a target alarm message from the pending alarm messages based on the latest weights of the module call dependencies in the target dependency chain and the timing compliance identification results, and sending the target alarm message to the alarm object, includes: calculating the target alarm priority of the pending alarm messages based on the latest weights of the module call dependencies in the target dependency chain and the timing compliance identification results; determining the pending alarm messages with target alarm priorities higher than a preset threshold as target alarm messages, and sending the target alarm messages to the alarm object.

[0076] Optionally, the step of calculating the target alarm priority of the message to be alarmed based on the latest weights of the call dependencies of each module in the target dependency chain and the timing compliance identification result includes: determining the first alarm priority of the message to be alarmed corresponding to the alarm triggering module based on the latest weights of the call dependencies of each module in the target dependency chain; and upgrading the first alarm priority of the module whose call timing does not conform to the preset timing rules based on the timing compliance identification result to obtain the target alarm priority of the message to be alarmed.

[0077] This embodiment also provides a computer-readable storage medium storing computer-executable instructions. When these computer-executable instructions are invoked and executed by a processor, they cause the processor to implement the aforementioned method for generating system alarm messages, for example: When a pending alarm message from the target software system is detected to meet the preset alarm storm conditions, the latest module weight data of the target software system is obtained. This latest module weight data indicates the latest weight of the module call dependencies in the preset lineage dependency graph, which indicates the call dependencies between modules in the target software system. The pending alarm message is mapped to the preset lineage dependency graph to identify the target dependency chain of the alarm triggering module. The timing compliance of the target dependency chain is then assessed to obtain a timing compliance assessment result. This result indicates whether the call timing of each module in the target dependency chain conforms to preset timing rules. Based on the latest weight of the call dependencies of each module in the target dependency chain and the timing compliance assessment result, a target alarm message is determined from the pending alarm messages and sent to the alarm object.

[0078] In this approach, when an alarm storm is detected to be about to occur in the system, noise reduction processing is performed on the alarm messages to be alarmed by using the latest weight of the system's module call dependencies and the compliance of the module call timing. In other words, the target alarm messages that are actually used for alarming are filtered out from the alarm messages to be alarmed, thereby simplifying the alarm messages, reducing interference messages, and improving the efficiency of troubleshooting system faults.

[0079] Optionally, before the step of obtaining the latest module weight data of the target software system when the detected alarm message of the target software system meets the preset alarm storm conditions, the method further includes: generating a corresponding alarm message when any module of the target software system triggers the corresponding preset alarm conditions; determining whether the frequency and / or number of alarm messages within a preset time period starting from the current time reaches a preset threshold; if the frequency and / or number reaches the preset threshold, then determining that the detected alarm message of the target software system meets the preset alarm storm conditions.

[0080] Optionally, the step of obtaining the latest module weight data of the target software system includes: using pre-installed code instrumentation points to statistically analyze the call dependency frequency and data flow of each module call dependency relationship in the current state of the target software system for a certain period of time, to obtain the call dependency frequency information and data flow information corresponding to each module call dependency relationship in the target software system; and normalizing the call dependency frequency information and data flow information corresponding to each module call dependency relationship to obtain the latest module weight data of the target software system.

[0081] Optionally, the step of identifying the target dependency link of the alarm triggering module by mapping the message to be alarmed to the preset lineage dependency graph includes: parsing the metadata of the message to be alarmed to obtain the alarm module identifier corresponding to the message to be alarmed; matching the node corresponding to the alarm module identifier from the preset lineage dependency graph, and determining the module corresponding to the node as the alarm triggering module; and tracing the upstream dependency link of the alarm triggering module backward from the preset lineage dependency graph to obtain the target dependency link of the alarm triggering module.

[0082] Optionally, the step of performing time-series compliance identification on the target dependency link and obtaining the time-series compliance identification result includes: obtaining the call timestamp of each module in the target dependency link; determining whether the call sequence of each module in the target dependency link conforms to the preset time-series rules based on the call timestamp of each module, and obtaining the time-series compliance identification result.

[0083] Optionally, the step of determining a target alarm message from the pending alarm messages based on the latest weights of the module call dependencies in the target dependency chain and the timing compliance identification results, and sending the target alarm message to the alarm object, includes: calculating the target alarm priority of the pending alarm messages based on the latest weights of the module call dependencies in the target dependency chain and the timing compliance identification results; determining the pending alarm messages with target alarm priorities higher than a preset threshold as target alarm messages, and sending the target alarm messages to the alarm object.

[0084] Optionally, the step of calculating the target alarm priority of the message to be alarmed based on the latest weights of the call dependencies of each module in the target dependency chain and the timing compliance identification result includes: determining the first alarm priority of the message to be alarmed corresponding to the alarm triggering module based on the latest weights of the call dependencies of each module in the target dependency chain; and upgrading the first alarm priority of the module whose call timing does not conform to the preset timing rules based on the timing compliance identification result to obtain the target alarm priority of the message to be alarmed.

[0085] The computer program product of the system alarm message generation method, apparatus, electronic device and storage medium provided in the embodiments of this disclosure includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the preceding method embodiments. For specific implementation, please refer to the method embodiments, which will not be repeated here.

[0086] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the system and apparatus described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0087] Furthermore, in the description of the embodiments of this disclosure, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this disclosure based on the specific circumstances.

[0088] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0089] In the description of this disclosure, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing this disclosure and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this disclosure. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0090] Finally, it should be noted that the above embodiments are merely specific implementations of this disclosure, used to illustrate the technical solutions of this disclosure, and not to limit it. The protection scope of this disclosure is not limited thereto. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this disclosure. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this disclosure, and should all be covered within the protection scope of this disclosure. Therefore, the protection scope of this disclosure should be determined by the protection scope of the claims.

Claims

1. A method for generating system alarm messages, characterized in that, The method includes: When the alarm message of the target software system is detected to meet the preset alarm storm conditions, the latest module weight data of the target software system is obtained. The latest module weight data is used to indicate the latest weight of the module call dependency relationship of the target software system in the preset lineage dependency relationship graph. The preset lineage dependency relationship graph is used to indicate the call dependency relationship between each module in the target software system. By mapping the alarm message to the preset lineage dependency graph, the target dependency link of the alarm triggering module is identified; The target dependency link is subjected to timing compliance identification to obtain timing compliance identification results; wherein, the timing compliance identification results are used to indicate whether the calling timing of each module in the target dependency link conforms to preset timing rules; Based on the latest weights of the module call dependencies in the target dependency chain and the timing compliance identification results, the target alarm message is determined from the pending alarm messages and sent to the alarm object.

2. The method according to claim 1, characterized in that, Before the step of obtaining the latest module weight data of the target software system when the detected alarm message of the target software system meets the preset alarm storm conditions, the method further includes: When any module of the target software system triggers the corresponding preset alarm condition, a corresponding alarm message is generated. Determine whether the frequency and / or number of alarm messages within a preset time period starting from the current moment have reached a preset threshold; If the frequency and / or quantity reach a preset threshold, it is determined that the alarm messages to be detected in the target software system meet the preset alarm storm conditions.

3. The method according to claim 1, characterized in that, The steps for obtaining the latest module weight data of the target software system include: By pre-inserting code instrumentation points, the call dependency frequency and data traffic of each module in the target software system in the current state are statistically analyzed for a certain period of time to obtain the call dependency frequency information and data traffic information corresponding to the call dependency relationship of each module in the target software system. The call dependency frequency information and data traffic information corresponding to the call dependency relationships of each module are normalized to obtain the latest module weight data of the target software system.

4. The method according to claim 1, characterized in that, The step of identifying the target dependency link of the alarm triggering module by mapping the message to be alarmed to the preset lineage dependency graph includes: Metadata parsing is performed on the message to be alarmed to obtain the alarm module identifier corresponding to the message to be alarmed; Match the node corresponding to the alarm module identifier from the preset bloodline dependency graph, and determine the module corresponding to the node as the alarm triggering module; The target dependency link of the alarm triggering module is obtained by tracing back the upstream dependency link of the alarm triggering module from the preset bloodline dependency relationship graph.

5. The method according to claim 1, characterized in that, The steps of performing time-series compliance identification on the target dependency link and obtaining the time-series compliance identification result include: Obtain the call timestamps of each module in the target dependency chain; Based on the call timestamps of each module, it is determined whether the call sequence of each module in the target dependency chain conforms to the preset timing rules, and the timing compliance identification result is obtained.

6. The method according to claim 1, characterized in that, The steps of determining the target alarm message from the pending alarm messages and sending the target alarm message to the alarm object based on the latest weight of the module call dependencies in the target dependency chain and the timing compliance identification result include: Based on the latest weights of the module call dependencies in the target dependency chain and the timing compliance identification results, the target alarm priority of the message to be alarmed is calculated. Alarm messages with a target alarm priority higher than a preset threshold are identified as target alarm messages and sent to the alarm object.

7. The method according to claim 6, characterized in that, The step of calculating the target alarm priority of the message to be alarmed based on the latest weight of the module call dependency relationship in the target dependency chain and the timing compliance identification result includes: Based on the latest weight of the module call dependency relationship in the target dependency chain, determine the first alarm priority of the alarm triggering module corresponding to the alarm message to be alarmed; Based on the timing compliance identification result, the first alarm priority corresponding to the module whose call timing does not conform to the preset timing rules is upgraded to obtain the target alarm priority of the alarm message to be alarmed.

8. A device for generating system alarm messages, characterized in that, The device includes: The monitoring module is used to obtain the latest module weight data of the target software system when the alarm message of the target software system meets the preset alarm storm conditions. The latest module weight data is used to indicate the latest weight of the module call dependency relationship of the target software system in the preset lineage dependency relationship graph. The preset lineage dependency relationship graph is used to indicate the call dependency relationship between each module in the target software system. The identification module is used to identify the target dependency link of the alarm triggering module by mapping the message to be alarmed to the preset lineage dependency graph. The detection module is used to identify the timing compliance of the target dependency link and obtain the timing compliance identification result; wherein, the timing compliance identification result is used to indicate whether the calling timing of each module in the target dependency link conforms to the preset timing rules; The sending module is used to determine the target alarm message from the pending alarm messages based on the latest weight of the module call dependency relationship in the target dependency link and the timing compliance identification result, and send the target alarm message to the alarm object.

9. An electronic device, characterized in that, The system includes a processor and a memory, the memory storing machine-executable instructions that can be executed by the processor, the processor executing the machine-executable instructions to implement the method for generating system alarm messages according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when invoked and executed by a processor, cause the processor to implement the method for generating system alarm messages according to any one of claims 1-7.