Unattended monitoring platform alarm pushing method and system

By building a project monitoring table and an intelligent alarm push system, the shortcomings of the existing network monitoring platform in terms of monitoring dimensions and operation and maintenance mode have been solved, realizing unattended intelligent alarm push, ensuring the timely transmission of fault information and improving operation and maintenance efficiency.

CN121603347APending Publication Date: 2026-03-03FOUNDER BROADBAND NETWORK SERVICE +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511915039.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-18
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

Existing SNMP-based network monitoring platforms have shortcomings in monitoring dimensions, intelligent alarm push, and operation and maintenance modes, resulting in high operation and maintenance costs, delayed and missed fault response during off-working hours, and an inability to achieve comprehensive monitoring and customized push at the customer and business levels.

Method used

A project monitoring table is built, and traffic data is actively polled using Python and the netsnmp framework. Combined with alarm rules and blocking mechanisms, intelligent analysis and hierarchical push of alarms are achieved. Enterprise WeChat and telephone interfaces are used to deliver targeted alarm information to ensure that critical information reaches the responsible person as soon as possible.

Benefits of technology

It achieves 24/7 uninterrupted accurate data collection and alarm push, reduces false alarms and redundant information, ensures timely fault notifications outside of working hours, eliminates traditional manual duty positions, reduces operation and maintenance costs, and improves operation and maintenance efficiency and service stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121603347A_ABST
    Figure CN121603347A_ABST
Patent Text Reader

Abstract

The invention discloses an alarm pushing method and system for an unattended monitoring platform. The method comprises the following steps: constructing and initializing a project monitoring table; actively polling the project traffic of all projects in the project monitoring table in a preset period; comparing the collected current project flow value with the alarm threshold value, executing preset first alarm rule judgment, and if the result of continuous multiple judgment meets an alarm triggering condition, setting the alarm mark position as an effective state, and recording a corresponding alarm state type; determining a target personnel list which needs to receive the alarm message in combination with newly added sales notifiers in the project monitoring table, project alarm levels, project belonging technical department fields and a pre-established WeChat notification personnel table; according to the invention, the operation and maintenance guarantee capability of off-duty time, early morning and holidays is ensured not to be discounted, stable and reliable continuous services can be provided for clients, and the information push achievement rate is significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unattended monitoring and processing, and in particular to an alarm push method and system for an unattended monitoring platform. Background Technology

[0002] With the rapid development of information technology, enterprise networks are expanding in scale and becoming increasingly complex. The stable operation of network equipment (such as switches, routers, servers, and firewalls) and data center infrastructure (such as air conditioners, UPS, and temperature and humidity sensors) has become the lifeline of business continuity. To ensure this lifeline, network monitoring technology has emerged and continues to develop. Among them, SNMP (Simple Network Management Protocol), as a standard Internet protocol, has become the de facto industry standard in the field of network management due to its simplicity, universality, and support by the vast majority of network equipment manufacturers. Network monitoring platforms built on the SNMP protocol constitute the core of current enterprise IT operations and maintenance systems.

[0003] The basic principles and workflow of existing technologies are as follows: A typical SNMP-based network monitoring platform can be summarized as "collection-analysis-alarm". First, the monitoring platform, acting as the management station (Manager), actively polls the monitored devices (Agents) for specific Management Information Base (MIB) Object Identifiers (OIDs) via SNMP GET / GETNEXT requests at preset intervals (e.g., every 5 minutes). These OIDs correspond to various management parameters, such as the input / output traffic of device ports, CPU and memory utilization, and the temperature and humidity values ​​of the data center environment. Subsequently, the monitoring platform compares and analyzes the acquired values ​​with thresholds preset by the administrator. Once one or more indicators are detected to continuously exceed the threshold, the monitoring platform triggers an alarm mechanism, generating a fault record in the system's alarm list, and typically supplementing this with basic notification methods such as platform interface highlighting, sound emission, or sending emails / SMS to attract the attention of maintenance personnel.

[0004] Although the aforementioned technical solutions have been widely used in practice, their inherent technical limitations, especially in fault response during non-standard working hours, have become increasingly apparent with the evolution of enterprise business models and the increasing demands for operational efficiency. Through in-depth research and analysis, the existing technologies mainly suffer from the following three interrelated and progressively worsening technical defects:

[0005] Firstly, the monitoring and alerting dimensions are too limited to achieve comprehensive monitoring and customized push notifications at the customer and business levels.

[0006] The core logic of existing monitoring platforms is device- and metric-oriented. Their monitoring objects are discrete physical or logical devices, and alarm triggering conditions are based on thresholds of individual technical indicators. This design pattern has fundamental shortcomings.

[0007] Secondly, the system heavily relies on manual monitoring, resulting in high maintenance costs and poor scalability. To compensate for the aforementioned shortcomings of inaccurate push notifications and weak business relevance, and to ensure uninterrupted 24 / 7 fault response, enterprises are forced to establish dedicated 24 / 7 monitoring positions. This typically requires at least four maintenance personnel working in shifts to cover the monitoring tasks around the clock. This model presents significant technical and economic challenges: building a 24 / 7 monitoring team means a huge and continuous investment in human capital, including salaries, benefits, training, and management costs. For many small and medium-sized enterprises or maintenance service providers with limited profit margins, this is a heavy burden.

[0008] Thirdly, alarm responses outside of working hours carry the risk of delays or even omissions, compromising service quality. Even with monitoring positions in place, timely fault response during off-peak hours such as early morning, weekends, and holidays remains a significant technical challenge. At night, staff are often at a lower mental state, and fatigue can impair their ability to perceive platform alarms and slow their reaction time, leading to delayed alarm responses. Existing platforms typically rely heavily on email or built-in notifications. Outside of working hours, technicians are unlikely to check work emails frequently; and built-in notifications are ineffective without human intervention. While some platforms support SMS, notifications may fail due to gateway issues, poor mobile signal, or ignored messages.

[0009] In summary, existing SNMP-based network monitoring technologies, because they are designed with device metrics rather than business and customer needs in mind, have inherent and systemic technical defects in terms of monitoring dimensions, intelligent alarm push, and operation and maintenance models. Summary of the Invention

[0010] The purpose of this invention is to provide an alarm push method and system for an unattended monitoring platform, which can break down the information barriers between equipment and customers / businesses, enhance the monitoring perspective, and build an automated, intelligent, low-cost, and accurate alarm push and response system to solve the aforementioned technical problems pointed out in the prior art.

[0011] This invention proposes an alarm push method for an unattended monitoring platform, comprising the following steps:

[0012] Step S1: Build and initialize the project monitoring table. The project monitoring table is used to store the status information of the monitored project, including at least: project name, project number, monitoring device IP, device SNMP read community name, device port OID, traffic in / out direction, current traffic, maximum alarm threshold, minimum alarm threshold, alarm status, alarm counter, alarm flag, whether to enable traffic leveling alarm, whether to enable traffic mutation alarm, alarm masking flag, and collection time.

[0013] Step S2: (Based on Python and netsnmp framework) Actively poll the project traffic of all projects in the project monitoring table at a preset period;

[0014] Step S3: Compare the current project traffic value collected in step S2 with the alarm threshold, and execute the preset first alarm rule judgment. If the judgment results meet the alarm triggering conditions multiple times in a row, set the alarm flag to the valid state and record the corresponding alarm state type. The first alarm rule includes at least traffic leveling alarm and traffic mutation alarm calculated based on historical traffic data.

[0015] Step S4: When the alarm flag is in a valid state, execute the following sub-steps:

[0016] Determine whether the current time is within the alarm blocking period based on the alarm blocking flag. If yes, perform the current alarm blocking operation; otherwise, proceed to the next step.

[0017] By combining the newly added fields of sales notify person, project alarm level, and project-related technical department in the project monitoring table, as well as the pre-established WeChat notification personnel table, the target personnel list that needs to receive alarm messages is determined.

[0018] Based on the alarm level of the project and the alarm receiving level of the personnel in the WeChat notification personnel table, alarm information is pushed in a hierarchical manner.

[0019] Step S5: Through the WeChat Work interface, push alarm information containing project identifier and alarm status type to the designated target personnel list.

[0020] Preferably, as one possible implementation, while performing step S4, the following steps are also included:

[0021] Step S6: The monitoring platform polls the project monitoring table in real time and sets telephone alarm trigger conditions, determining whether at least one of the following telephone alarm trigger conditions is met:

[0022] First telephone alarm trigger condition: Within the most recent 5-minute time window, the total number of newly generated items with alarm flags becoming valid exceeds 12;

[0023] Second telephone alarm triggering conditions: Within the most recent 5-minute time window, the number of newly generated devices with building switch type and alarm flags turned valid exceeds 8;

[0024] Third telephone alarm triggering conditions: There is at least one project with an alarm flag bit that is valid and its project alarm level field value is greater than 5;

[0025] The fourth telephone alarm trigger condition is: there is a building switch with at least one alarm flag bit that is valid and its device alarm level field value is greater than 3;

[0026] Step S7: Once any of the conditions in step S6 is met, the system immediately queries the pre-established technician duty roster and obtains the contact number of the first responding technician on duty that day based on the current date and the technical department; the technician duty roster includes at least the fields of date, technical department, first responding technician, and second responding technician.

[0027] Step S8: The system automatically initiates a telephone call to the first response technician obtained in step S7 through the integrated external telephone gateway interface, and plays the preset emergency alarm notification content through voice synthesis technology. The content includes at least the triggering condition type and the number of alarm items.

[0028] Preferably, as one possible implementation, the first alarm rule in step S3 specifically includes:

[0029] Step S31a: Traffic flattening alarm judgment: When the project enables the flattening alarm, query the historical traffic table to obtain the average traffic of the project in the first time period of the most recent N times, calculate the change coefficient of the N average values, and if the change coefficient is less than the first threshold, it is determined that the traffic flattening alarm condition is met.

[0030] Step S31b: Traffic mutation alarm judgment: When the project enables mutation alarm, query the historical traffic table to obtain the average traffic of the project in the first time period of the most recent N times, calculate the percentage of the absolute difference between the current project traffic value and the average of the N average values, and if the percentage is greater than the second threshold, it is determined that the traffic mutation alarm condition is met.

[0031] Preferably, as one possible implementation, the alarm blocking flag in step S1 is associated with multiple preset time periods, and different flag values ​​correspond to different alarm blocking time rules, including alarm blocking during non-working hours on weekdays and / or alarm blocking throughout the day on holidays.

[0032] Preferably, as one possible implementation, in step S3, when the project returns to normal from the alarm state, only one normal traffic value needs to be collected, that is, the alarm counter is reset, the alarm flag position is set to invalid, and the alarm state type is cleared.

[0033] Preferably, as one possible implementation, the alarm status types include: low traffic: current traffic is below the minimum alarm threshold; high traffic: current traffic is above the maximum alarm threshold; SNMP read failure: no traffic value has been collected.

[0034] The flow leveling is defined as follows: read the average flow rate of the most recent 6 five-minute intervals from the historical flow table, calculate the average flow rate of the 6 intervals, and generate a flow leveling alarm when the extreme value change coefficient is less than 0.8; the extreme value change coefficient = (maximum value - minimum value) / average value * 100.

[0035] The surge / drop in traffic: Read the average traffic flow of the last 6 times in the historical traffic table over 5 minutes, and calculate the cumulative change in traffic flow deviation from the average traffic flow over the 6 times. When the cumulative change is greater than 65, a surge / drop alarm is generated; The cumulative change = absolute value (average value - current value) / average value * 100.

[0036] Accordingly, the present invention provides an alarm push system for an unattended monitoring platform, comprising:

[0037] The database module is used to store project monitoring tables, historical traffic tables, WeChat notification personnel tables, and technical personnel duty tables.

[0038] The data acquisition module is used to periodically collect traffic data from network devices based on the SNMP protocol and update the project monitoring table and historical traffic table.

[0039] The alarm analysis engine module is used to judge alarms based on the collected data, preset thresholds and first alarm rules, and update the alarm status in the project monitoring table.

[0040] The alarm routing decision module is used to determine the final target for pushing alarm information based on project attributes, alarm level, personnel information, and duty roster.

[0041] The message push execution module is used to push alarm information to the target personnel determined by the alarm routing decision module through the WeChat Work interface and the telephone interface.

[0042] Preferably, as one possible implementation, the project monitoring table in the database module includes at least the following fields: a sales notification field for associating with sales personnel, a project alarm level field for defining the importance of alarms, and a project-associated technical department field for associating with technical teams.

[0043] Preferably, as one possible implementation, the WeChat notification personnel table in the database module includes at least the following fields: personnel name, WeChat account, department, direct supervisor, and personnel alarm reception level. The personnel alarm reception level is used in conjunction with the project alarm level in the project monitoring table to achieve hierarchical filtering and push of alarm information.

[0044] Accordingly, a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the method.

[0045] Compared with the prior art, the embodiments of the present invention have at least the following technical advantages:

[0046] Analysis of the alarm push method and system for an unattended monitoring platform provided by the present invention shows that, in specific applications, the following steps are executed: Step S1: Construct and initialize a project monitoring table. The project monitoring table is used to store the status information of the monitored project, including at least: project name, project number, monitoring device IP, device SNMP read community name, device port OID, traffic in / out direction, current traffic, maximum alarm threshold, minimum alarm threshold, alarm status, alarm counter, alarm flag, whether to enable traffic leveling alarm, whether to enable traffic mutation alarm, alarm masking flag, and collection time. Step S2: (Based on Python and netsnmp framework) Actively poll the project traffic of all projects in the project monitoring table at a preset period; Step S3: Compare the current project traffic value collected in step S2 with the alarm threshold, and execute the preset first alarm rule judgment. If the judgment results meet the alarm triggering condition multiple times in a row, set the alarm flag to a valid state and record the corresponding alarm state type; The first alarm rule includes at least traffic leveling alarm and traffic mutation alarm calculated based on historical traffic data;

[0047] Step S4: When the alarm flag is valid, perform the following sub-steps: Determine whether the current time is within the alarm blocking period based on the alarm blocking flag. If so, block the current alarm; otherwise, proceed to the next step. Combine the newly added fields of sales notify person, project alarm level, and project-related technical department in the project monitoring table, as well as the pre-established WeChat notification personnel table, to determine the target personnel list that needs to receive alarm messages. Step S43: Based on the project alarm level and the personnel alarm receiving level in the WeChat notification personnel table, perform hierarchical push of alarm information.

[0048] Step S5: Through the WeChat Work interface, push alarm information containing project identifier and alarm status type to the designated target personnel list.

[0049] This invention constructs a tireless intelligent monitoring entity through end-to-end automation of "collection-analysis-routing-push." ​​It not only achieves uninterrupted and accurate data collection 24 / 7, but also significantly improves the accuracy and foresight of alarms by introducing intelligent judgment rules such as "traffic leveling," "mutation detection," and "alarm masking," effectively filtering false alarms and redundant information. Combined with multi-dimensional routing logic based on projects, departments, and levels, it ensures that every valuable alarm message is pushed to the single, correct responsible person in the first instance, through the most appropriate channel (WeChat / telephone), with 100% targeting. This completely solves the industry pain point of untimely fault notification during off-peak hours, achieving the highest operational goal of "zero omissions" in major faults.

[0050] Secondly, this solution, through a highly intelligent alarm distribution mechanism, accurately replicates and optimizes the information transmission function of manually monitored positions, enabling enterprises to completely eliminate the traditional 24 / 7 monitoring positions requiring at least four people working in shifts. This not only directly saves huge amounts of labor, management, and training costs, but also enhances organizational collaboration efficiency, ensuring that the command chain from frontline technical staff to management decision-makers remains clear and efficient in emergencies, achieving a perfect balance between cost reduction and efficiency improvement.

[0051] Ultimately, this invention ensures uninterrupted operation and maintenance capabilities during off-hours, early mornings, and holidays, providing customers with stable and reliable continuous services and significantly improving information delivery rates. Attached Figure Description

[0052] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0053] Figure 1 A flowchart illustrating the overall operation steps of an alarm push method for an unattended monitoring platform provided in this embodiment of the invention;

[0054] Figure 2 This is a schematic diagram of a process in an alarm push method for an unattended monitoring platform provided in an embodiment of the present invention;

[0055] Figure 3 This is a schematic diagram of an alarm push system for an unattended monitoring platform provided in an embodiment of the present invention;

[0056] Labels: Database module 10; Data acquisition module 20; Alarm analysis engine module 30; Alarm routing decision module 40; Message push execution module 50. Detailed Implementation

[0057] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0058] The present invention will now be described in further detail with reference to specific embodiments and accompanying drawings.

[0059] Example 1

[0060] like Figure 1 As shown, the present invention also proposes an alarm push method for an unattended monitoring platform, comprising the following steps:

[0061] This invention proposes an alarm push method for an unattended monitoring platform, comprising the following steps:

[0062] Step S1: Build and initialize the project monitoring table. The project monitoring table is used to store the status information of the monitored project, including at least: project name, project number, monitoring device IP, device SNMP read community name, device port OID, traffic in / out direction, current traffic, maximum alarm threshold, minimum alarm threshold, alarm status, alarm counter, alarm flag, whether to enable traffic leveling alarm, whether to enable traffic mutation alarm, alarm masking flag, and collection time.

[0063] Step S2: Based on Python and the netsnmp framework, actively poll the project traffic of all projects in the project monitoring table at a preset period;

[0064] Step S3: Compare the current project traffic value collected in step S2 with the alarm threshold, and execute the preset first alarm rule judgment. If the judgment results meet the alarm triggering conditions multiple times in a row, set the alarm flag to the valid state and record the corresponding alarm state type. The first alarm rule includes at least traffic leveling alarm and traffic mutation alarm calculated based on historical traffic data.

[0065] Step S4: When the alarm flag is in a valid state, execute the following sub-steps:

[0066] See Figure 2Step S41: Determine whether the current time is within the alarm blocking period based on the alarm blocking flag bit. If yes, perform the current alarm blocking operation; otherwise, proceed to the next step.

[0067] Step S42: Combine the newly added fields of sales notify person, project alarm level, and project-related technical department in the project monitoring table, as well as the pre-established WeChat notification personnel table, to determine the target personnel list that needs to receive alarm messages;

[0068] Step S43: Based on the project alarm level and the alarm reception level of the personnel in the WeChat notification personnel table, perform hierarchical push of alarm information;

[0069] Step S5: Through the WeChat Work interface, push alarm information containing project identifier and alarm status type to the target personnel list determined in step S42.

[0070] Preferably, as one possible implementation, while performing step S4, the following steps are also included:

[0071] Step S6: The monitoring platform polls the project monitoring table in real time and sets telephone alarm trigger conditions, determining whether at least one of the following telephone alarm trigger conditions is met:

[0072] First telephone alarm trigger condition: Within the most recent 5-minute time window, the total number of newly generated items with alarm flags becoming valid exceeds 12;

[0073] Second telephone alarm triggering conditions: Within the most recent 5-minute time window, the number of newly generated devices with building switch type and alarm flags turned valid exceeds 8;

[0074] Third telephone alarm triggering conditions: There is at least one project with an alarm flag bit that is valid and its project alarm level field value is greater than 5;

[0075] The fourth telephone alarm trigger condition is: there is a building switch with at least one alarm flag bit that is valid and its device alarm level field value is greater than 3;

[0076] Step S7: Once any of the conditions in step S6 is met, the system immediately queries the pre-established technician duty roster and obtains the contact number of the first responding technician on duty that day based on the current date and the technical department; the technician duty roster includes at least the fields of date, technical department, first responding technician, and second responding technician.

[0077] Step S8: The system automatically initiates a telephone call to the first response technician obtained in step S7 through the integrated external telephone gateway interface, and plays the preset emergency alarm notification content through voice synthesis technology. The content includes at least the triggering condition type and the number of alarm items.

[0078] During step S1 above, a project monitoring table is constructed and initialized. This project monitoring table is a MySQL relational database, including information such as project name, project number, monitoring device IP, device SNMP read community name, device port OID, traffic inbound / outbound direction, current traffic, maximum alarm threshold, minimum alarm threshold, alarm status, alarm counter, alarm flag, whether traffic leveling alarm is enabled, whether traffic surge alarm is enabled, alarm masking flag, and collection time. Simultaneously, the background uses a Python 3 + NetSNMP framework to collect project traffic at 15-second intervals. An alarm is generated when three consecutive traffic collections trigger the maximum / minimum alarm threshold or the leveling / surge condition.

[0079] The following is a partial content of a MySQL relational database project monitoring table:

[0080] Preferably, as one possible implementation, the first alarm rule in step S3 specifically includes:

[0081] Step S31a: Traffic flattening alarm judgment: When the project enables the flattening alarm, query the historical traffic table to obtain the average traffic of the project in the first time period of the most recent N times, calculate the change coefficient of the N average values, and if the change coefficient is less than the first threshold, it is determined that the traffic flattening alarm condition is met.

[0082] Step S31b: Traffic mutation alarm judgment: When the project enables mutation alarm, query the historical traffic table to obtain the average traffic of the project in the first time period of the most recent N times, calculate the percentage of the absolute difference between the current project traffic value and the average of the N average values, and if the percentage is greater than the second threshold, it is determined that the traffic mutation alarm condition is met.

[0083] Preferably, as one possible implementation, the alarm blocking flag in step S1 is associated with multiple preset time periods, and different flag values ​​correspond to different alarm blocking time rules, including alarm blocking during non-working hours on weekdays and / or alarm blocking throughout the day on holidays.

[0084] Preferably, as one possible implementation, in step S3, when the project returns to normal from the alarm state, only one normal traffic value needs to be collected, that is, the alarm counter is reset, the alarm flag position is set to invalid, and the alarm state type is cleared.

[0085] Preferably, as one possible implementation, the alarm status types include: low traffic: current traffic is below the minimum alarm threshold; high traffic: current traffic is above the maximum alarm threshold; SNMP read failure: no traffic value has been collected.

[0086] The flow leveling is defined as follows: read the average flow rate of the most recent 6 five-minute intervals from the historical flow table, calculate the average flow rate of the 6 intervals, and generate a flow leveling alarm when the extreme value change coefficient is less than 0.8; the extreme value change coefficient = (maximum value - minimum value) / average value * 100.

[0087] The surge / drop in traffic: Read the average traffic flow of the last 6 times in the historical traffic table over 5 minutes, and calculate the cumulative change in traffic flow deviation from the average traffic flow over the 6 times. When the cumulative change is greater than 65, a surge / drop alarm is generated; The cumulative change = absolute value (average value - current value) / average value * 100.

[0088] In the above technical solution, an alarm flag of 1 indicates that an alarm has already occurred and will not be pushed again. When the project recovers from an alarm state, only one normal traffic collection is required. At this time, the alarm counter is set to empty, the alarm flag is set to 0, and the alarm status is set to empty. Whether to enable traffic leveling and traffic surge (sudden increase / decrease) depends on the project situation. If enabling it is meaningful, then it will be enabled.

[0089] Create a new historical traffic table to store the project's collected traffic over the past 24 hours, and calculate and store the average traffic over the past 5 minutes. The project monitoring table only stores the current traffic value and does not store historical traffic values.

[0090] Alarm status types: Low traffic: Current traffic is below the minimum alarm threshold; High traffic: Current traffic is above the maximum alarm threshold; SNMP read failure: No traffic value was collected.

[0091] The flow leveling is defined as follows: read the average flow rate of the most recent 6 five-minute intervals from the historical flow table, calculate the average flow rate of the 6 intervals, and generate a flow leveling alarm when the extreme value change coefficient is less than 0.8; the extreme value change coefficient = (maximum value - minimum value) / average value * 100.

[0092] The surge / drop in traffic: Read the average traffic flow of the last 6 times in the historical traffic table over 5 minutes, and calculate the cumulative change in traffic flow deviation from the average traffic flow over the 6 times. When the cumulative change is greater than 65, a surge / drop alarm is generated; The cumulative change = absolute value (average value - current value) / average value * 100.

[0093] Alarm masking flag. The default value is 0, meaning alarms are not masked; a value greater than or equal to 1 indicates that alarms will be masked for different time periods, and can be customized.

[0094] If some projects have no traffic or low traffic during non-working hours, it is not a fault and alarms should be disabled to avoid false alarms.

[0095] The alarm masking values ​​for different time periods are as follows. Other alarm masking time periods can be added according to the project traffic characteristics.

[0096] When the alarm masking flag is set to 1: alarms are masked during the early morning period (23:00-7:00 the next day);

[0097] When the alarm masking flag is set to 2: alarms are masked from 18:00 to 8:00 the next day;

[0098] When the alarm shielding flag is set to 3: alarms are shielded from 18:00 to 8:00 the next day, and all day on Saturdays and Sundays.

[0099] When the alarm shielding flag is set to 4: alarms are shielded from 17:30 to 7:30 the next day;

[0100] When the alarm shielding flag is set to 5: alarms are shielded from 21:00 to 9:00 the next day;

[0101] When the alarm shielding flag is set to 6: alarms are shielded from 17:30 to 7:30 the next day, and all day on Saturdays and Sundays.

[0102] When the alarm shielding flag is set to 7: alarms are shielded from 17:00 to 9:00 the next day, and all day on Saturdays and Sundays.

[0103] Backend traffic collection and monitoring script: If the earliest time of all items in the project monitoring table is more than 5 minutes slower than the current Internet time, it is judged that the backend collection program is abnormal and the maintenance personnel are notified.

[0104] The following fields have been added to the project monitoring items:

[0105] Added a "Sales Notification Person" field. This facilitates immediate notification to the sales personnel responsible for the project when a project alarm / alarm is triggered.

[0106] A new project alarm level field has been added. When a project alarm occurs, the alarm level will be used to select which level of leadership to push the alarm to.

[0107] When the alarm level is greater than 1, the alarm is pushed to the immediate supervisor.

[0108] When the alarm level is greater than or equal to 3, the alarm is pushed to the leader of the first-level department.

[0109] When the alarm level is greater than or equal to 4, the alarm is pushed to the technical director and sales director.

[0110] A new field has been added indicating the technical department to which a project belongs, making it easier to push information to personnel in different technical departments.

[0111] Project monitoring table - data model - 2 is as follows:

[0112] Regarding the creation of the database table – the WeChat notification personnel table – information such as personnel name, WeChat account, contact number, department, direct supervisor, alarm level received by the personnel, and personnel status (employed / resigned) should be entered. When a project alarm occurs, WeChat Work will push the alarm information to the sales and technical managers.

[0113] The innovative logic behind the WeChat notification personnel list lies in its integration with the project monitoring list. This allows for multi-dimensional segmentation of project alerts and personnel, enabling customized alert pushes that highlight key information and avoid redundant pushes.

[0114] The data model for the WeChat notification personnel table is as follows:

[0115] Other supplementary execution methods are as follows - Example of alarm tiered push:

[0116] The company CEO's personnel alarm level is 9, and they only receive project alarms with an alarm level of 7 or higher.

[0117] The technical director and sales director are required to receive alarms at level 6, and only receive project alarms at level 4 or higher.

[0118] The head of a first-level department is authorized to receive alarms at level 5, and will only receive alarms from projects with an alarm level of 3 or higher.

[0119] All personnel in technical department A will only receive project alerts for projects whose technical department is A.

[0120] Regarding the creation of a database table - Technical Personnel Duty Roster, on a weekly basis, information such as date, technical department, first response technology, second response technology, and third response technology should be entered.

[0121] When the conditions for setting up automatic phone calls are met, the program will notify the on-duty technical personnel by phone when a project alarm is triggered.

[0122] The number of alarms for a given item within 5 minutes exceeds 12.

[0123] The number of alarms on the building switch is greater than 8;

[0124] The alarm level field value of the building switch is greater than 3;

[0125] The alarm level field value is greater than 5.

[0126] The automatic dialing function, combined with the project monitoring table, filters project alarm scenarios, focuses on important project alarms and concurrent alarms during non-working hours, and achieves automation.

[0127] Example 2

[0128] like Figure 3 As shown, correspondingly, Embodiment 2 of the present invention provides an alarm push system for an unattended monitoring platform, comprising:

[0129] Database module 10 is used to store project monitoring tables, historical traffic tables, WeChat notification personnel tables, and technical personnel duty tables;

[0130] The data acquisition module 20 is used to periodically collect traffic data from network devices based on the SNMP protocol and update the project monitoring table and historical traffic table.

[0131] The alarm analysis engine module 30 is used to make alarm judgments based on the collected data, preset thresholds and first alarm rules, and update the alarm status in the project monitoring table.

[0132] The alarm routing decision module 40 is used to determine the final target for pushing alarm information based on project attributes, alarm level, personnel information and duty roster;

[0133] The message push execution module 50 is used to push alarm information to the target personnel determined by the alarm routing decision module through the enterprise WeChat interface and the telephone interface.

[0134] Preferably, as one possible implementation, the project monitoring table in the database module includes at least the following fields: a sales notification field for associating with sales personnel, a project alarm level field for defining the importance of alarms, and a project-associated technical department field for associating with technical teams.

[0135] Preferably, as one possible implementation, the WeChat notification personnel table in the database module includes at least the following fields: personnel name, WeChat account, department, direct supervisor, and personnel alarm reception level. The personnel alarm reception level is used in conjunction with the project alarm level in the project monitoring table to achieve hierarchical filtering and push of alarm information.

[0136] Example 3

[0137] Accordingly, a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the method.

[0138] In summary, the alarm push method and system for an unattended monitoring platform proposed in this invention fundamentally reconstructs the response mode of traditional network operation and maintenance, upgrading the passive, lagging, and high-cost manual monitoring system into a proactive, intelligent, and intensive unattended ecosystem. The resulting technical benefits and commercial value are comprehensive and far-reaching.

[0139] First, this invention constructs a tireless intelligent monitoring entity through end-to-end automation of "collection-analysis-routing-push." ​​It not only achieves uninterrupted and accurate data collection 24 / 7, but also significantly improves the accuracy and foresight of alarms by introducing intelligent judgment rules such as "traffic leveling," "mutation detection," and "alarm masking," effectively filtering false alarms and redundant information. Combined with multi-dimensional routing logic based on projects, departments, and levels, it ensures that every valuable alarm message is pushed to the single, correct responsible person in the first instance, through the most appropriate channel (WeChat / telephone), with 100% targeting. This completely solves the industry pain point of untimely fault notification during off-peak hours, achieving the highest operational goal of "zero omissions" in major faults.

[0140] Secondly, this solution, through a highly intelligent alarm distribution mechanism, accurately replicates and optimizes the information transmission function of manually monitored positions, enabling enterprises to completely eliminate the traditional 24 / 7 monitoring positions requiring at least four people working in shifts. This not only directly saves huge amounts of labor, management, and training costs, but also enhances organizational collaboration efficiency, ensuring that the command chain from frontline technical staff to management decision-makers remains clear and efficient in emergencies, achieving a perfect balance between cost reduction and efficiency improvement.

[0141] Ultimately, this invention ensures uninterrupted operation and maintenance capabilities during off-hours, early mornings, and holidays, providing customers with stable and reliable continuous services and significantly improving information delivery rates.

[0142] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; those skilled in the art can modify the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for sending alarms to an unattended monitoring platform, comprising the following steps: Step S1: Construct and initialize the project monitoring table, which is used to store the status information of the monitored project, including at least: Project name, project number, monitoring device IP, device SNMP read community name, device port OID, traffic in / out direction, current traffic, maximum alarm threshold, minimum alarm threshold, alarm status, alarm counter, alarm flag, whether to enable traffic flattening alarm, whether to enable traffic surge alarm, alarm masking flag, collection time; Step S2: Actively poll the project traffic of all projects in the project monitoring table at a preset period; Step S3: Compare the current project traffic value collected in step S2 with the alarm threshold, and execute the preset first alarm rule judgment. If the judgment results meet the alarm triggering conditions multiple times in a row, set the alarm flag position to the valid state and record the corresponding alarm state type. The first alarm rule includes at least traffic leveling alarms and traffic mutation alarms calculated based on historical traffic data; Step S4: When the alarm flag is in a valid state, execute the following sub-steps: Determine whether the current time is within the alarm blocking period based on the alarm blocking flag. If yes, perform the current alarm blocking operation; otherwise, proceed to the next step. By combining the newly added fields of sales notify person, project alarm level, and project-related technical department in the project monitoring table, as well as the pre-established WeChat notification personnel table, the target personnel list that needs to receive alarm messages is determined. Based on the alarm level of the project and the alarm receiving level of the personnel in the WeChat notification personnel table, alarm information is pushed in a hierarchical manner. Step S5: Through the WeChat Work interface, push alarm information containing project identifier and alarm status type to the designated target personnel list.

2. The method according to claim 1, characterized in that, While step S4 is being executed, the following steps are also included: Step S6: The monitoring platform polls the project monitoring table in real time and sets telephone alarm trigger conditions, determining whether at least one of the following telephone alarm trigger conditions is met: First telephone alarm trigger condition: Within the most recent 5-minute time window, the total number of newly generated items with alarm flags becoming valid exceeds 12; Second telephone alarm triggering conditions: Within the most recent 5-minute time window, the number of newly generated devices with building switch type and alarm flags turned valid exceeds 8; Third telephone alarm triggering conditions: There is at least one project with an alarm flag bit that is valid and its project alarm level field value is greater than 5; The fourth telephone alarm trigger condition is: there is a building switch with at least one alarm flag bit that is valid and its device alarm level field value is greater than 3; Step S7: Once any of the conditions in step S6 is met, the system immediately queries the pre-established technician duty roster and obtains the contact number of the first responding technician on duty that day based on the current date and the technical department. The technical personnel duty roster shall include at least the fields of date, technical department, first-response technical personnel, and second-response technical personnel; Step S8: The system automatically initiates a telephone call to the first response technician obtained in step S7 through the integrated external telephone gateway interface, and plays the preset emergency alarm notification content through voice synthesis technology. The content includes at least the triggering condition type and the number of alarm items.

3. The method according to claim 1, characterized in that, The first alarm rule in step S3 specifically includes: Step S31a: Traffic flattening alarm judgment: When the project enables the flattening alarm, query the historical traffic table to obtain the average traffic of the project in the first time period of the most recent N times, calculate the change coefficient of the N average values, and if the change coefficient is less than the first threshold, it is determined that the traffic flattening alarm condition is met. Step S31b: Traffic mutation alarm judgment: When the project enables mutation alarm, query the historical traffic table to obtain the average traffic of the project in the first time period of the most recent N times, calculate the percentage of the absolute difference between the current project traffic value and the average of the N average values, and if the percentage is greater than the second threshold, it is determined that the traffic mutation alarm condition is met.

4. The method according to claim 3, characterized in that, The alarm blocking flag in step S1 is associated with multiple preset time periods. Different flag values ​​correspond to different alarm blocking time rules. The alarm blocking time rules include alarm blocking during non-working hours on weekdays and / or all day on holidays.

5. The method according to claim 4, characterized in that, In step S3, when the project returns to normal from the alarm state, it only needs to collect a normal traffic value once, that is, reset the alarm counter, set the alarm flag position to invalid state, and clear the alarm state type.

6. The method according to claim 4, characterized in that, The alarm status types include: Low traffic: Current traffic is below the minimum alarm threshold; High traffic: Current traffic is above the maximum alarm threshold; SNMP read failure: No traffic value has been collected. The flow leveling is defined as follows: read the average flow rate of the most recent 6 five-minute intervals from the historical flow table, calculate the average flow rate of the 6 intervals, and generate a flow leveling alarm when the extreme value change coefficient is less than 0.8; the extreme value change coefficient = (maximum value - minimum value) / average value * 100. The surge / drop in traffic: Read the average traffic flow of the last 6 times in the historical traffic table over 5 minutes, and calculate the cumulative change in traffic flow deviation from the average traffic flow over the 6 times. When the cumulative change is greater than 65, a surge / drop alarm is generated; The cumulative change = absolute value (average value - current value) / average value * 100.

7. An alarm push system for an unattended monitoring platform for implementing the method of any one of claims 1-6, comprising: The database module is used to store project monitoring tables, historical traffic tables, WeChat notification personnel tables, and technical personnel duty tables. The data acquisition module is used to periodically collect traffic data from network devices based on the SNMP protocol and update the project monitoring table and historical traffic table. The alarm analysis engine module is used to judge alarms based on the collected data, preset thresholds and first alarm rules, and update the alarm status in the project monitoring table. The alarm routing decision module is used to determine the final target for pushing alarm information based on project attributes, alarm level, personnel information, and duty roster. The message push execution module is used to push alarm information to the target personnel determined by the alarm routing decision module through the WeChat Work interface and the telephone interface.

8. The system according to claim 8, characterized in that, The project monitoring table in the database module contains at least the following fields: a sales notification field for associating with sales personnel, a project alarm level field for defining the importance of alarms, and a technical department field for associating with the project team.

9. The system according to claim 6, characterized in that, The WeChat notification personnel table in the database module contains at least the following fields: personnel name, WeChat account, department, direct supervisor, and personnel alarm reception level. The personnel alarm reception level is used in conjunction with the project alarm level in the project monitoring table to achieve hierarchical filtering and push of alarm information.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the method as described in any one of claims 1 to 5.