Network change monitoring method and device, equipment and storage medium
By acquiring the correlation and contextual information between target change orders and network alarms, the system automatically analyzes the correlation between network alarms and target change orders, solving the problems of insufficient accuracy and timeliness in network change monitoring in existing technologies, and realizing timely identification and accurate judgment of network anomalies.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2026-03-27
AI Technical Summary
In existing technologies, relying on human judgment during network changes leads to low monitoring accuracy and poor timeliness, making it impossible to identify the causes of network anomalies in a timely manner.
By acquiring target change orders, scanning network alarms, analyzing the correlation between network alarms and target change orders, visually indicating whether network changes have caused network anomalies using indicator light colors, and obtaining contextual information of network alarms for correlation detection, the system automatically analyzes the correlation between network alarms and target change orders.
This improved the timeliness and accuracy of network change monitoring, reduced the false alarm rate of traffic lights, and ensured the timeliness and accuracy of anomaly identification during network change processes.
Smart Images

Figure CN121750518A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of Internet, in particular to the technical field of communication, and especially to a network change monitoring method and device, equipment and storage medium. BACKGROUND
[0002] In the technical field of communication, network change scenarios are very common, such as scenarios of upgrading the OS (network operating system) version of network equipment, scenarios of expanding the link bandwidth between two network equipments, and the like. Since network change can easily cause network anomalies, it is crucial to monitor whether the network anomaly is caused by network change. At present, the network change personnel usually obtains network monitoring results during network change, and then manually judges whether the network change causes network anomalies based on the network monitoring results. It can be seen that this method relies on the personal experience of network change personnel, and is prone to misjudgment, thereby resulting in low monitoring accuracy of network change, and also consuming a lot of time for manual judgment, thereby resulting in poor monitoring timeliness of network change. SUMMARY
[0003] The embodiments of the present application provide a network change monitoring method, device, equipment and storage medium, which can improve the monitoring timeliness and accuracy of network change.
[0004] In one aspect, the embodiments of the present application provide a network change monitoring method, which comprises:
[0005] Obtaining a target change order, the target change order corresponding to a signal lamp, the target change order being used to indicate a network equipment to be changed and a network monitoring configuration of the network equipment;
[0006] Scanning a network alarm while changing the network equipment indicated by the target change order, the network alarm being an alarm information generated in the case of monitoring a network anomaly;
[0007] If the network alarm is scanned, analyzing an association relationship between the network alarm and the target change order according to the network monitoring configuration of the network equipment, obtaining a relationship analysis result, and lighting the signal lamp corresponding to the target change order based on the relationship analysis result;
[0008] Obtaining context information of the network alarm, the context information being used to indicate at least one of the following: an abnormal cause corresponding to the network alarm, and whether the network alarm is assigned to the target change order;
[0009] detect a correlation between the network alarm and the target change order based on the context information, obtain a correlation detection result, and correct a display color of the signal lamp corresponding to the target change order based on the correlation detection result.
[0010] In another aspect, an embodiment of the present application provides a network change monitoring device, which comprises:
[0011] an obtaining unit configured to obtain a target change order, the target change order corresponding to a signal lamp, the target change order being used to indicate a network device to be changed and a network monitoring configuration of the network device;
[0012] a processing unit configured to scan a network alarm when the network device indicated by the target change order is changed, the network alarm being alarm information generated when a network exception is monitored;
[0013] The processing unit is further configured to, if the network alarm is scanned, analyze an association between the network alarm and the target change order according to the network monitoring configuration of the network device, obtain an association analysis result, and light up the signal lamp corresponding to the target change order based on the association analysis result.
[0014] The obtaining unit is further configured to obtain context information of the network alarm, the context information being used to indicate at least one of the following: a cause of an exception corresponding to the network alarm, and whether the network alarm is assigned to the target change order.
[0015] The processing unit is further configured to detect a correlation between the network alarm and the target change order based on the context information, obtain a correlation detection result, and correct a display color of the signal lamp corresponding to the target change order based on the correlation detection result.
[0016] In another aspect, an embodiment of the present application provides a computer device, which comprises an input interface and an output interface, and further comprises:
[0017] a processor and a computer storage medium;
[0018] The processor is adapted to implement one or more instructions, the computer storage medium stores one or more instructions, and the one or more instructions are adapted to be loaded by the processor and execute the network change monitoring method mentioned above.
[0019] In another aspect, an embodiment of the present application provides a computer storage medium, which stores one or more instructions, and the one or more instructions are adapted to be loaded by a processor and execute the network change monitoring method mentioned above.
[0020] In another aspect, embodiments of this application provide a computer program product comprising one or more instructions; when one or more instructions in the computer program product are executed by a processor, the aforementioned method for monitoring network changes is implemented.
[0021] This application embodiment can scan for network alarms when making network changes to the network devices indicated in the target change order. Upon detecting a network alarm, it automatically analyzes the correlation between the network alarm and the target change order based on the network monitoring configuration of the network devices in the target change order, obtaining a relationship analysis result. Based on this result, it quickly illuminates the indicator light corresponding to the target change order, allowing the color of the indicator light to promptly and intuitively indicate whether the current network change has caused a network anomaly, improving the timeliness of network change monitoring. Furthermore, it can obtain the contextual information of the network alarm, which indicates the cause of the anomaly and whether the network alarm was assigned to the target change order. Based on this contextual information, it can accurately perform a secondary analysis of the correlation between the network alarm and the target change order, obtaining a correlation detection result. The display color of the indicator light corresponding to the target change order is then corrected based on the correlation detection result, making the indicator light display more accurate and reducing the false alarm rate for network anomalies corresponding to that indicator light, thereby improving the accuracy of network change monitoring. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a system architecture diagram applicable to a network change monitoring method provided in the embodiments of this application;
[0024] Figure 2 This is a flowchart illustrating a network change monitoring method provided in an embodiment of this application;
[0025] Figure 3a This is a logical diagram illustrating a spatial association provided in an embodiment of this application;
[0026] Figure 3b This is a schematic diagram illustrating the analysis logic of an association relationship provided in an embodiment of this application;
[0027] Figure 3c This is a schematic diagram of a lighting logic provided in an embodiment of this application;
[0028] Figure 4 This is a flowchart illustrating a network change monitoring method provided in another embodiment of this application;
[0029] Figure 5a This is a logic diagram illustrating a batch lamp implementation provided in an embodiment of this application;
[0030] Figure 5b This is a schematic diagram of a task operation log acquisition process provided in an embodiment of this application;
[0031] Figure 5c This is a schematic diagram of the judgment logic provided in this application embodiment for determining whether a suspicious device and a network alarm are successfully associated in the time dimension;
[0032] Figure 6a This is an overall flowchart of network change and monitoring provided in an embodiment of this application;
[0033] Figure 6b This is a schematic diagram illustrating one of the various lighting modes provided in an embodiment of this application;
[0034] Figure 6c This is a schematic diagram of a signal light corrected by secondary correlation delay according to an embodiment of this application;
[0035] Figure 6d This is a schematic diagram of a signal light correction method using fuzzy illumination provided in an embodiment of this application;
[0036] Figure 6e This is a schematic diagram illustrating a method for correcting traffic lights through alarm diagnosis, as provided in an embodiment of this application.
[0037] Figure 7a This is a schematic diagram of a network monitoring configuration for a backbone network device provided in an embodiment of this application;
[0038] Figure 7b This is a schematic diagram of the association results of a device operation log provided in an embodiment of this application;
[0039] Figure 7c This is a schematic diagram of a signal light being illuminated according to an embodiment of this application;
[0040] Figure 7d This is a schematic diagram of an alarm diagnosis result provided in an embodiment of this application;
[0041] Figure 7e This is a schematic diagram of a modified traffic light provided in an embodiment of this application;
[0042] Figure 7f This is a schematic diagram of the alarm lighting history corresponding to a traffic light provided in an embodiment of this application;
[0043] Figure 8a This is a schematic diagram of a network monitoring configuration for an access layer network device provided in an embodiment of this application;
[0044] Figure 8b This is a schematic diagram of another alarm diagnosis result provided in an embodiment of this application;
[0045] Figure 8c This is a schematic diagram of a signal light illumination method based on fuzzy illumination provided in an embodiment of this application;
[0046] Figure 8d This is a schematic diagram of a fuzzy lamp-lighting log provided in an embodiment of this application;
[0047] Figure 9a This is a schematic diagram of a task execution log provided in an embodiment of this application;
[0048] Figure 9b This is a schematic diagram of another way to light up a signal light according to an embodiment of this application;
[0049] Figure 10a This application provides a network monitoring configuration for a change order.
[0050] Figure 10b This is a schematic diagram of the lighting result corresponding to a change order provided in an embodiment of this application;
[0051] Figure 11a This is another network monitoring configuration for a certain change order provided in the embodiments of this application;
[0052] Figure 11b This is a schematic diagram of another lighting result corresponding to a change order provided in an embodiment of this application;
[0053] Figure 12a This is a schematic diagram of batch configuration of a network device provided in an embodiment of this application;
[0054] Figure 12b This is a schematic diagram illustrating a batch-based device association operation for lighting, as provided in an embodiment of this application.
[0055] Figure 12c This is a schematic diagram illustrating another method of lighting lights by batch device association, provided in an embodiment of this application.
[0056] Figure 13a This is a schematic diagram of another alarm diagnosis result provided in another embodiment of this application;
[0057] Figure 13b This is a schematic diagram of another modified signal light provided in another embodiment of this application;
[0058] Figure 13cThis is a schematic diagram of a correction log provided in an embodiment of this application;
[0059] Figure 14 This is a schematic diagram of the structure of a network change monitoring device provided in an embodiment of this application;
[0060] Figure 15 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0061] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0062] This application proposes a method for monitoring network changes. During the process of making network changes to network devices according to a target change order, this method scans for network alarms. When a network alarm is detected, it automatically analyzes the correlation between the network alarm and the target change order based on the network monitoring configuration of the network device in the target change order. Based on the correlation analysis results, it quickly illuminates the indicator light corresponding to the target change order, allowing the color of the indicator light to promptly and intuitively indicate whether the current network change has caused a network anomaly, thus improving the timeliness of network change monitoring. Furthermore, it can obtain the context information of the network alarm and perform a secondary analysis of the correlation between the network alarm and the target change order based on this context information, obtaining a correlation detection result. Based on the correlation detection result, it corrects the display color of the indicator light corresponding to the target change order, making the indicator light display more accurate, reducing the missed detection rate in abnormal network change scenarios and the false detection rate in normal network change scenarios, thereby improving the accuracy of network change monitoring.
[0063] In specific implementation, the system architecture applicable to the network change monitoring method proposed in this application embodiment can be found in [reference needed]. Figure 1 As shown, the system architecture may include, but is not limited to: a traffic light system (a system for controlling traffic lights), a network monitoring system (a system for monitoring network quality), one or more network devices, etc. In practical applications, users can create and submit any network change order (hereinafter referred to as a change order) using any terminal to trigger network change personnel or a device (such as a terminal or a server) to make network changes to the corresponding network devices according to the change order. The network monitoring system is responsible for monitoring and processing network quality, and when a network anomaly is detected (i.e., an anomaly exists in network quality), it generates a network alarm and sends the network alarm to the traffic light system. This allows the traffic light system to illuminate the traffic light corresponding to the change order based on the network change monitoring method proposed in this application embodiment, so that the display color of the traffic light can intuitively indicate whether the network change corresponding to the change order has caused a network anomaly.
[0064] Understandably, Figure 1 This merely exemplifies a system architecture and is not intended to limit it; for example, in Figure 1 In this embodiment, the traffic light system and the network monitoring system are two independent systems. However, in other embodiments, the traffic light system and the network monitoring system can be integrated into one system. Furthermore, the aforementioned traffic light system may include a computer device, which can be a terminal or a server. In this case, the network change monitoring method proposed in this application embodiment can be executed by the computer device in the traffic light system. Alternatively, the aforementioned traffic light system may also include a terminal and a server. In this case, the network change monitoring method proposed in this application embodiment can be jointly executed by the terminal and the server in the traffic light system.
[0065] For example, the terminals mentioned above can be smartphones, computers (such as tablets, laptops, desktop computers, etc.), smart wearable devices (such as smartwatches, smart glasses), smart voice interaction devices, smart home appliances (such as smart TVs), vehicle terminals, or aircraft, etc.; the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms, etc.
[0066] It is worth emphasizing that in the embodiments of this application, data related to user information (such as change orders submitted by users) are collected with the user's permission or consent when any of the methods proposed in the embodiments of this application are applied to specific products or technologies, and the collection, use and processing of the relevant data comply with the relevant laws, regulations and standards of the relevant regions.
[0067] The following is combined with Figure 2 The flowchart shown illustrates the specific implementation process of the network change monitoring method proposed in this application embodiment; in this application embodiment, the network change monitoring method executed by a computer device is used as an example for explanation. Please refer to... Figure 2 As shown, the method for monitoring network changes can be roughly divided into the following steps S201-S206:
[0068] S201, Obtain the target change order.
[0069] The target change order can be any change order, serving as the basis for network changes. It may include, but is not limited to, the device identifier of the network device to be changed, and the network monitoring configuration of that device. Therefore, the target change order can include the network device to be changed and its network monitoring configuration. Specifically: ① Network devices can refer to dedicated hardware devices used to interconnect various servers, terminals, and application terminals to form an information communication network; for example, network devices can include switches, routers, optical transceivers, fiber optic transceivers, etc. ② The network monitoring configuration of the network device can include at least one monitoring item and the monitoring range (i.e., configuration item) under each monitoring item. Any monitoring range can include the network type of the network to be monitored and at least one network transmission direction. This network transmission direction can include a source area identifier (i.e., the identifier of the area from which the network probe originates, typically the identifier of the area where the network device to be changed is located) and a destination area identifier (i.e., the identifier of the area reached by the network probe).
[0070] It should be noted that: ① The number of network devices indicated in the target change order can be one or more. Optionally, when the target change order indicates multiple network devices, these multiple network devices can undergo network changes simultaneously or in batches; if network changes are performed in batches, the target change order may also include the batch number of each network device. ② The above is only an illustrative description of the contents of the target change order and is not exhaustive. For example, the target change order may also include: a network change time window, and instruction information indicating the network change operation to be performed. The network change operation refers to the operation used to implement the network change, such as upgrading the network device's OS version, expanding the link bandwidth, etc.
[0071] Additionally, each target change order can correspond to a signal light. The color of this signal light can at least indicate whether the network change corresponding to the target change order (i.e., the network change based on the target change order) has caused a network anomaly. Optionally, the color of this signal light can also indicate the processing required for the network change (such as continuing the network change, pausing, or rolling back (i.e., reverting the network device's state to the most recent stable state, where the most recent stable state is the stable state closest to the rollback time (the time of executing the rollback operation), for example, it might be the state before executing the previous network change step, an isolated state, or the initial state before the network change, etc.). For ease of explanation, the following will use the following three colors as examples: a first color (e.g., red), a second color (e.g., yellow), and a third color (e.g., green). The first color indicates that the network change corresponding to the target change order has caused a network anomaly and needs to be rolled back; the second color indicates that the network change corresponding to the target change order has not caused a network anomaly and needs to be paused; the third color indicates that the network change corresponding to the target change order has not caused a network anomaly and needs to continue.
[0072] S202, When making network changes to the network devices indicated in the target change order, scan for network alarms.
[0073] Network alarms refer to alarm information generated when network anomalies are detected. Specifically, they can be generated based on each network transmission direction where anomalies are detected. In this case, network alarms are not converged; they directly include each network transmission direction with anomalies, and each transmission direction includes a source region identifier and a destination region identifier. Alternatively, to handle anomalies more clearly and efficiently, network alarms can be converged according to time and space dimensions. For example, if there are three network transmission directions with network anomalies, and these three network transmission directions are: region A -> region C, region B -> C, and region D -> region C, then the region identifier of region C, which is common to all three network transmission directions, can be used as the anomaly intersection point. Thus, these three network transmission directions can be converged into a single network alarm C -> A, B, D according to the anomaly intersection point. It can be seen that when network alarms are converged, the network alarm can include a source region identifier and at least one destination region identifier. The source region identifier included in the network alarm refers to the region identifier common to all network transmission directions with network anomalies. It may be the source region identifier in each network transmission direction or the destination region identifier in each network transmission direction.
[0074] S203. If a network alarm is detected, analyze the correlation between the network alarm and the target change order based on the network monitoring configuration of the network device to obtain the relationship analysis results.
[0075] In practical implementation, when the computer device analyzes the correlation between network alarms and target change orders based on the network monitoring configuration of the network devices and obtains the relationship analysis results, it can spatially associate the corresponding network devices with the network alarms according to the network monitoring configuration of each network device. If no network device and network alarm are successfully associated spatially, it is determined that there is no spatial correlation between the network alarm and the target change order, and a relationship analysis result is generated. In this case, the relationship analysis result can be used to indicate that there is no correlation between the network alarm and the target change order. If a network device and network alarm are successfully associated spatially, it is determined that there is a spatial correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial correlation. In this case, the relationship analysis result can be used to indicate that there is a spatial correlation between the network alarm and the target change order. Wherein:
[0076] (i) The specific implementation method for computer equipment to associate the corresponding network devices with network alarms in the spatial dimension according to the network monitoring configuration of each network device can be any of the following:
[0077] Implementation Method 1: Regardless of whether there are one or more source region identifiers and destination region identifiers in the network alarm, for the i-th network device (where i is a positive integer less than or equal to the number of network devices), it can be checked whether the network monitoring configuration and network alarm of the i-th network device meet the matching conditions. If the matching conditions are met, it can be determined that the i-th network device and the network alarm are successfully associated in the spatial dimension; if the matching conditions are not met, it can be determined that the i-th network device and the network alarm are not associated in the spatial dimension. The matching conditions include: a source region identifier in the network alarm is located within the source region identifiers included in the network monitoring configuration of the i-th network device (i.e., source-source matching), and a destination region identifier in the network alarm is located within the destination region identifiers included in the network monitoring configuration of the i-th network device (i.e., destination-destination matching); or, the matching conditions include: a source region identifier in the network alarm is located within the destination region identifiers included in the network monitoring configuration of the i-th network device (i.e., source-destination matching), and a destination region identifier in the network alarm is located within the source region identifiers included in the network monitoring configuration of the i-th network device (i.e., destination-source matching).
[0078] Implementation Method 2: When a network alarm includes one source region identifier and multiple destination region identifiers, the source region identifier in the network alarm is taken as the abnormal crossover point (i.e., the network failure point). In the network monitoring configuration of the i-th network device, the source region identifier that is the same as the abnormal crossover point is matched to obtain the first matching result. If the first matching result indicates a successful match (i.e., a source region identifier is matched), it can be determined that the abnormal crossover point is located in the source region identifiers included in the network monitoring configuration of the i-th network device. In this case, it can be determined that the i-th network device and the network alarm are successfully associated in the spatial dimension. If the first matching result indicates a failed match (i.e., no source region identifier is matched), it can be determined that the abnormal crossover point is not located in the source region identifiers included in the network monitoring configuration of the i-th network device. In this case, it can be determined that the i-th network device and the network alarm are not associated in the spatial dimension.
[0079] When a network alarm includes a source region identifier and a destination region identifier, the source region identifier in the network alarm is taken as the alarm source region identifier, and the destination region identifier in the network alarm is taken as the alarm destination region identifier. In the network monitoring configuration of the i-th network device, the source region identifier that is the same as the alarm source region identifier is matched to obtain a second matching result. In the network monitoring configuration of the i-th network device, the destination region identifier that is the same as the alarm destination region identifier is matched to obtain a third matching result. If both the second matching result and the third matching result indicate successful matching, it is determined that the i-th network device and the network alarm are successfully associated in the spatial dimension. If at least one of the second and third matching results indicates a matching failure, then in the network monitoring configuration of the i-th network device, a destination region identifier that is the same as the alarm source region identifier is matched to obtain a fourth matching result; in the network monitoring configuration of the i-th network device, a source region identifier that is the same as the alarm destination region identifier is matched to obtain a fifth matching result; if both the fourth and fifth matching results indicate a successful match, then it is determined that the i-th network device and the network alarm are successfully associated in the spatial dimension; if at least one of the fourth and fifth matching results indicates a matching failure, then it is determined that the i-th network device and the network alarm are not associated in the spatial dimension.
[0080] Based on the above description, the difference between Implementation Method 1 and Implementation Method 2 is as follows: When a network alarm contains multiple area identifiers, Implementation Method 1 does not distinguish directions. In order to hit abnormal changes as much as possible (i.e., to find the network changes that cause network anomalies as much as possible), it can assume that the areas indicated by each area identifier involved in the network alarm are all undergoing abnormal changes. Thus, spatial association is performed based on the corresponding areas to associate them with the target change order. However, in most cases, the areas indicated by some area identifiers involved in the network alarm may be false alarms. For example, for a network alarm from C to A, B, D, area C is an abnormal intersection point and is also very likely a network fault point. Implementation Method 1 can make changes in the four areas A, B, C, and D associated with this network alarm. However, in most cases, the three areas A, B, and D are false alarms. Therefore, in the second implementation method, for one-to-many network alarms, matching is strictly performed according to the alarm source, that is, the abnormal intersection point is strictly matched; for example, for network alarms C->A, B, D, spatial association is performed only based on the associated C region; for one-to-one network alarms, since the network fault point cannot be intuitively determined, both the source and destination can participate in the matching, for example, for network alarms D->A, both regions D and A are spatially associated.
[0081] In summary, see Figure 3a As shown: S is used respectively a and D a This represents the set of source region identifiers and the set of destination region identifiers in a network alarm, respectively represented by S. c and D c This represents the set of source region identifiers and the set of destination region identifiers in the network monitoring configuration. For one-to-one network alarms, the association rule for both Implementation Method 1 and Implementation Method 2 is: satisfying (S... a in S c )and(D a in D c ) or satisfy (S a in D c )and(D a in S c If the association is successful, then the association is successful; for one-to-many network alarms, the association rule in Implementation Method 1 above still satisfies (S a in S c )and(D a in D c ) or satisfy (S a in D c )and(D a in S c If the association is successful, then the association is successful; the association rule for the second implementation method described above is: satisfying (S) a in Sc )and(D a in D c If the connection is successful, then the association is complete. Where: (S) a in S c )and(D a in D c This indicates that each source region identifier in the network alarm is located within the source region identifiers included in the network monitoring configuration, and each destination region identifier in the network alarm is located within the destination region identifiers included in the network monitoring configuration; (S a in D c )and(D a in S c This indicates that each source region identifier in the network alarm is located in the target region identifier included in the network monitoring configuration, and each destination region identifier in the network alarm is located in the source region identifier included in the network monitoring configuration.
[0082] Based on this, assume the following two network monitoring configurations exist: Network monitoring configuration 1 is "Source: S c1 ={A} (used to indicate that network monitoring configuration 1 contains a source region identifier A), purpose: D c1 ={B, C, D, E} (used to indicate that network monitoring configuration 1 contains four destination area identifiers: B, C, D, and E); network monitoring configuration 2 is "Source: S c2 ={D} (used to indicate that network monitoring configuration 2 includes a source region identifier D), purpose: D c2 ={E, F, G} (used to indicate that network monitoring configuration 2 includes three destination area identifiers: E, F, and G)". Additionally, suppose network alarm 1 exists with the identifier "Source: S". a1 ={D} (used to indicate that network alarm 1 contains a source region identifier D), purpose: D a1 ={A} (used to indicate that network alarm 1 contains a destination area identifier A)”, then since network alarm 1 is a one-to-one network alarm, whether based on implementation method one or implementation method two, it can be determined that (S a1 in D c1 )and(D a1 in S c1 Therefore, it can be considered that network alarm 1 and the network device corresponding to network monitoring configuration 1 are successfully associated in the spatial dimension. Assume there is a network alarm 2 with the following information: "Source: S..." a2 ={C} (used to indicate that network alarm 2 contains the source region identifier C), purpose: D a2 ={A, B, D} (used to indicate that network alarm 1 contains three destination area identifiers A, B, and D)”, then since network alarm 2 is a one-to-many network alarm, based on implementation method one, it can be determined that (S) is satisfied.a2 in D c1 )and(D a2 inS c1 Therefore, based on Implementation Method 1, it can be assumed that network alarm 2 and the network device corresponding to network monitoring configuration 1 are successfully associated in the spatial dimension. However, based on Implementation Method 2, it can be determined that the (S) condition is not met. a2 in S c1 Therefore, based on Implementation Method 2, it can be considered that the network alarm 2 and the network device corresponding to the network monitoring configuration 1 have failed to be associated in the spatial dimension.
[0083] Since the source area identifier in the network monitoring configuration indicates the area where the network device performing the network change is located, and in most cases, the network anomaly area (network fault point) caused by the network change is the area where the network device performing the network change is located, the above-described implementation method can achieve fine-grained matching of alarm source and destination by matching the abnormal intersection point (area identifier used to indicate network fault point) and the source area identifier in the network monitoring configuration, thereby improving the accuracy of spatial association and avoiding false alarms of signal lights based on the results of spatial association.
[0084] (ii) The specific implementation method for generating relational analysis results based on spatial correlation of computer equipment can be any of the following:
[0085] The first implementation involves acquiring the device operation logs of each network device. These logs record executed device operations and their execution times. For example, the logs could be 3A operation logs (AAA operation logs), where AAA stands for Authentication, Authorization, and Accounting. Additionally, the reference time for network alarms is obtained. Based on the device operation logs and reference times for network alarms, the corresponding network devices and alarms are associated in a time dimension. Specifically, for any network device, a target device operation can be searched in its operation log. This target operation refers to a network change operation performed within a preset time period before the reference time of the network alarm. If the target operation is found in the operation log, the association between the corresponding network device and the network alarm is considered successful in a time dimension. If the target operation is not found in the operation log, the association between the corresponding network device and the network alarm is considered unsuccessful in a time dimension. Furthermore, if no network device and network alarm are successfully associated in the time dimension, it is determined that there is no time correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial correlation. In this case, the relationship analysis result indicates that there is a spatial correlation between the network alarm and the target change order, but no time correlation. If a network device and network alarm are successfully associated in the time dimension, it is determined that there is a time correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the time correlation and spatial correlation. In this case, the relationship analysis result indicates that there is both a spatial correlation and a time correlation between the network alarm and the target change order.
[0086] The second implementation method involves obtaining the device operation logs of the suspicious device and the reference time of the network alarm. Based on the device operation logs of the suspicious device and the reference time of the network alarm, the suspicious device and the network alarm are associated in the time dimension. Specifically, the target device operation can be searched in the device operation logs of the suspicious device. If the target device operation is found in the device operation logs, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension; if the target device operation is not found in the device operation logs, it is determined that the suspicious device and the network alarm are not associated in the time dimension. Furthermore, if the suspicious device fails to be associated with the network alarm in the time dimension, it can be determined that there is no temporal correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial correlation. In this case, the relationship analysis result indicates that there is a spatial correlation between the network alarm and the target change order, but no temporal correlation. If the suspicious device successfully associates with the network alarm in the time dimension, it can be determined that there is a temporal correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the temporal and spatial correlation. In this case, the relationship analysis result indicates that there are both spatial and temporal correlations between the network alarm and the target change order.
[0087] Based on the above, it should be noted that in the first or second implementation method described above, the specific implementation method for the computer device to obtain the reference time of the network alarm can be: obtaining the alarm generation time of the network alarm (i.e., the time when the network alarm started) as the reference time of the network alarm. In this case, the time correlation is based on the alarm generation time as the anchor point, and the target device operation is correlated backward to determine whether there is a time correlation between the network alarm and the target change order. Alternatively, considering that the alarm generation time is often some time after the network anomaly begins, the intermediate time delay may vary for different network alarms, and this difference may range from a few seconds to a few minutes. When the target device operation is correlated backward from the alarm generation time, the device operation after the network anomaly begins may be misjudged as the target device operation that caused the network anomaly, resulting in false alarms of the signal lights (such as false red light alarms). Based on this, the embodiments of this application can add an anomaly start time judgment to the underlying alarm, so that the specific implementation method for the computer device to obtain the reference time of the network alarm can be: obtaining the anomaly start time corresponding to the network alarm as the reference time of the network alarm, thereby realizing the correlation of the target device operation backward from the anomaly start time and solving the problem of inconsistency between the target device operation and the anomaly time. The anomaly start time refers to the time when the network anomaly corresponding to the network alarm occurs; that is, the anomaly start time is based on the first point in time when the network anomaly occurs. For example, if the network anomaly is that the packet loss rate exceeds the threshold, then the anomaly start time can be the earliest time when the packet loss rate exceeds the threshold.
[0088] Based on the above description, this application embodiment can support the network monitoring configuration of the target change order being calculated and summarized based on all network devices within the target change order. During the network change process, if a network alarm successfully matches the network monitoring configuration of a certain network device, the alarm range can be considered to belong to (∈) the change order monitoring configuration, thus confirming successful spatial association. If, at this time, any network device within the target change order is operating, the temporal association can be confirmed, potentially causing the indicator light to illuminate as the first color (e.g., red). Alternatively, considering that a target change order typically contains multiple network devices, and the network monitoring configuration of each device may be inconsistent, simply associating network alarms with the network monitoring configuration of the entire change order might result in a situation where a network alarm is generated in one area, but another area experiences target device operation, successfully associating with that network alarm and causing the indicator light to illuminate incorrectly. Therefore, this application embodiment can also support splitting the network monitoring configuration within the target change order according to the device dimension, such as... Figure 3b As shown, the target change order may include the network monitoring configurations of network device A, network device B, and network device C. During the network change process, network alarms can be sequentially associated with the network monitoring configurations of each network device within the target change order. If the association is successful, the corresponding network device is recorded as a suspicious device, thus enabling time-based correlation (e.g., ...) for suspicious devices. Figure 3b As shown, time correlation is performed on network device A. Non-suspicious devices are no longer used for time correlation, thereby resolving the inconsistency between network changes and the scope of network alarms.
[0089] Optional, based on Figure 3bAs shown, when generating relationship analysis results based on temporal and spatial correlations, computer equipment can directly generate the results based on these correlations. Alternatively, when generating relationship analysis results based on temporal and spatial correlations, computer equipment can further detect whether the operation command of the target device is located in the dangerous command set. If the operation command of the target device is located in the dangerous command set, then the operation command of the target device is determined to be a dangerous command, and the target device operation is determined to be a dangerous device operation (i.e., a dangerous network change operation). In this case, it can be determined that the corresponding network device and the network alarm are successfully associated in the content dimension, thereby determining that there is a content correlation between the network alarm and the target change order. Relationship analysis results are then generated based on temporal, spatial, and content correlations. In this case, the relationship analysis results indicate that there are spatial, temporal, and content correlations between the network alarm and the target change order. If the operation command of the target device is not in the dangerous command set, then the operation command of the target device is determined to be a safe command, and the target device operation is determined to be a safe device operation (i.e. a safe network change operation). In this case, it can be determined that the corresponding network device and the network alarm fail to be associated in terms of content, thus determining that there is no content association relationship between the network alarm and the target change order. Then, a relationship analysis result is generated based on the temporal and spatial association relationships. The relationship analysis result in this case is used to indicate that there is a spatial and temporal association relationship between the network alarm and the target change order, but no content association relationship.
[0090] S204, Based on the relationship analysis results, light up the signal light corresponding to the target change order.
[0091] In practical implementation, when the relationship analysis results indicate that there is a spatial, temporal, and content-based association between the network alarm and the target change order, the indicator light corresponding to the target change order can be illuminated in the first color (e.g., red). In this case, the indicator light is illuminated as the first color (e.g., red). When the relationship analysis results indicate that there is at least one of these three relationships between the network alarm and the target change order, the indicator light corresponding to the target change order can be illuminated in the second color (e.g., yellow). That is, when there is a spatial relationship but no temporal relationship between the network alarm and the target change order, or when there are both spatial and temporal relationships but no content-based relationship, the indicator light corresponding to the target change order can be illuminated as the second color (e.g., yellow). When the relationship analysis results indicate that there is no relationship between the network alarm and the target change order, the indicator light corresponding to the target change order can be illuminated in the third color (e.g., green).
[0092] For example, the lighting logic implemented based on the above specific implementation can be found in [reference needed]. Figure 3c As shown: For network alarms, the system determines whether the alarm has been successfully spatially correlated (i.e., successfully correlated with the network device in a spatial dimension). If spatial correlation fails, the indicator light turns green. If spatial correlation is successful, the system determines whether the alarm has been successfully temporally correlated (i.e., successfully correlated with the network device or a suspected device in a temporal dimension). If temporal correlation fails, the indicator light turns yellow. If temporal correlation is successful, the system determines whether the alarm has been successfully correlated content (i.e., successfully correlated with the network device or a suspected device in a content dimension). If content correlation is successful, the indicator light turns red; if content correlation fails, the indicator light turns yellow.
[0093] It is understood that the above is merely an illustrative description of the specific implementation of step S204 and is not intended to limit the scope of the invention. For example, in other embodiments, when there is a spatial and temporal correlation between the network alarm and the target change order, but no content correlation, the indicator light corresponding to the target change order can be illuminated using a first color (such as red). Furthermore, in other embodiments, if the analysis of the spatial correlation between the network alarm and the target change order does not further analyze the existence of temporal and content correlation, then the relationship analysis result in this case only indicates that there is a spatial correlation between the network alarm and the target change order. In this case, the indicator light corresponding to the target change order can be illuminated using a first color (such as red) or a second color (such as yellow).
[0094] S205, obtain the context information of the network alarm, and detect the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result.
[0095] The context information may include at least one of fault context (or alarm diagnosis result) and change context. The fault context is used to indicate the cause of the anomaly corresponding to the network alarm, and the change context is used to indicate whether the network alarm has been assigned to the target change order (i.e., whether the network alarm has been claimed by the target change order). Based on this, it can be seen that the context information can be used to indicate at least one of the following: the cause of the anomaly corresponding to the network alarm, and whether the network alarm has been assigned to the target change order.
[0096] In one specific implementation, when context information is used to indicate the cause of an anomaly corresponding to a network alarm, the specific implementation method for detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result is as follows:
[0097] (1) If the context information indicates that the cause of the anomaly is a network device anomaly, then the device correlation between the anomaly network device and the network change device can be detected. The network change device mentioned here refers to the network device that is undergoing network change as indicated by the target change order. If device correlation is detected, it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result indicating the existence of correlation is generated; if no device correlation is detected, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating the absence of correlation is generated.
[0098] The specific methods for detecting the device correlation between abnormal network devices and network-changed devices may include, but are not limited to: detecting whether the abnormal network device and the network-changed device are identical; if they are identical, it can be determined that a device correlation has been detected (i.e., the abnormal network device and the network-changed device are related); if they are inconsistent, it can be determined that no device correlation has been detected (i.e., the abnormal network device and the network-changed device are unrelated). Alternatively, detecting whether the abnormal network device and the network-changed device are directly connected; if they are directly connected, it can be determined that a device correlation has been detected; if they are not directly connected, it can be determined that no device correlation has been detected. Or, when the abnormal network device and the network-changed device are indirectly connected, determining the number of devices between them; if the number of devices is less than or equal to a preset number (e.g., one device), it can be determined that a device correlation has been detected; if the number of devices is greater than the preset number, it can be determined that no device correlation has been detected.
[0099] (2) If the context information indicates that the cause of the anomaly is server operation, then the network anomaly caused by the server operation is not related to the network change by default. Therefore, it can be determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is no correlation.
[0100] (3) If the context information indicates that the cause of the abnormality is main optical jitter (or backbone optical cable line jitter), then obtain the network change type. The network change type can be data communication change or wavelength division change. The so-called data communication change refers to the change of data communication equipment. The so-called data communication equipment refers to data communication equipment, including but not limited to switches, routers, etc. The so-called wavelength division change refers to the change of wavelength division equipment. The so-called wavelength division equipment refers to wavelength division transmission equipment, including but not limited to photonic racks, electronic racks, etc. Furthermore, when the network change type is a data communication change, it can be determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating that there is no correlation can be generated. When the network change type is a wavelength division multiplexing change, it can detect whether the jittered main light (backbone optical cable) is associated with the main light corresponding to the network change. If the jittered main light is associated with the main light corresponding to the network change, it can be determined that there is a correlation between the network alarm and the target change order, and a correlation detection result indicating that there is a correlation can be generated. If the jittered main light is not associated with the main light corresponding to the network change, it can be determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating that there is no correlation can be generated.
[0101] In another specific implementation, when the context information is used to indicate whether a network alarm is assigned to a target change order, the specific implementation method for detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result can be as follows: if the context information is used to indicate that the network alarm is assigned to the target change order, then it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result is generated; if the context information is used to indicate that the network alarm is not assigned to the target change order, then it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated. Furthermore, regarding the situation where context information is used to indicate that a network alarm has not been assigned to a target change order, it is worth emphasizing that: in one implementation, if context information is used to indicate that a network alarm has not been assigned to a target change order, it can be directly determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated; in another implementation, if context information is used to indicate that a network alarm has not been assigned to a target change order, it is determined based on the context information whether the network alarm has been assigned to another change order (i.e., whether the network alarm has been claimed by another change order). If so, it can be determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated; if not, it can be considered that it is impossible to determine whether the network alarm and the target change order are related. In this case, the display color of the indicator light corresponding to the target change order can be prohibited from being modified.
[0102] S206, Based on the correlation detection results, correct the display color of the signal light corresponding to the target change order.
[0103] In one specific implementation, when the display color of the indicator light corresponding to the target change order is a first color (e.g., red), the specific implementation of step S206 can be: if the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order is kept as the first color (e.g., red); if the correlation detection result indicates that there is no correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order is corrected to a second color (e.g., yellow).
[0104] In another specific implementation, when the indicator light corresponding to the target change order displays a second color (e.g., yellow), step S206 can be implemented as follows: if the correlation detection result indicates that there is no correlation between the network alarm and the target change order, then the indicator light corresponding to the target change order is kept at the second color (e.g., yellow); if the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the indicator light corresponding to the target change order is changed to the first color (e.g., red). Alternatively, if the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the device operation log is used to detect whether there is a network change operation within the target time period; if there is no network change operation within the target time period, then the indicator light corresponding to the target change order is kept at the second color (e.g., yellow); if there is a network change operation within the target preset time period, then the indicator light corresponding to the target change order is changed to the first color (e.g., red).
[0105] In another specific implementation, when the indicator light corresponding to the target change order displays a third color (e.g., green), and the context information indicates that the cause of the anomaly is a network device malfunction, step S206 can be implemented as follows: If the correlation detection result indicates that there is no correlation between the network alarm and the target change order (indicating that the abnormal network device is unrelated to the network change device), then the indicator light corresponding to the target change order is kept at the third color (e.g., green); if the correlation detection result indicates that there is a correlation between the network alarm and the target change order (indicating that the abnormal network device is related to the network change device), then the indicator light corresponding to the target change order is corrected to the first color (e.g., red). Alternatively, if the correlation detection result indicates that there is a correlation between the network alarm and the target change order (indicating that the abnormal network device is related to the network change device), then the device operation log is used to detect whether there is a network change operation within the target time period; if there is no network change operation within the target time period, then the indicator light corresponding to the target change order is kept at the third color (e.g., green); if there is a network change operation within the target preset time period, then the indicator light corresponding to the target change order is corrected to the first color (e.g., red).
[0106] It should be noted that the device operation logs mentioned above for detecting network change operations within the target time period can be the device operation logs of the aforementioned suspicious devices, the device operation logs of any network device, or the device operation logs of related devices. Here, related devices can be the intersection of the network device performing the network change (i.e., the network change device) and the alarm diagnosis device (a set of devices generated based on the connection relationships of abnormal network devices determined by alarm diagnosis), without limitation. Furthermore, the target time period mentioned here is obtained by extending a preset time period. Both the target time period and the preset time period are time periods calculated by extrapolating a certain duration from the reference time of the network alarm. The duration of the target time period is longer than the duration of the preset time period. For example, if the preset time period is 2 minutes before the reference time of the network alarm, then the target time period could be 10 minutes before the reference time of the network alarm, etc. Therefore, when the indicator light displays the second color and a correlation is detected between the network alarm and the target change order, the computer device can expand the detection range (query range) of network change operations in the device operation logs. Upon detecting a network change operation, the indicator light's display color can be corrected to the first color to improve the accuracy of the indicator light.
[0107] This application embodiment can scan for network alarms when making network changes to the network devices indicated in the target change order. Upon detecting a network alarm, it automatically analyzes the correlation between the network alarm and the target change order based on the network monitoring configuration of the network devices in the target change order, obtaining a relationship analysis result. Based on this result, it quickly illuminates the indicator light corresponding to the target change order, allowing the color of the indicator light to promptly and intuitively indicate whether the current network change has caused a network anomaly, improving the timeliness of network change monitoring. Furthermore, it can obtain the context information of the network alarm, which indicates the cause of the anomaly and whether the network alarm was assigned to the target change order. Based on this context information, it can accurately perform a secondary analysis of the correlation between the network alarm and the target change order, obtaining a correlation detection result. The display color of the indicator light corresponding to the target change order is then corrected based on the correlation detection result, making the indicator light display more accurate, reducing the missed detection rate in abnormal network change scenarios and the false detection rate in normal network change scenarios, thereby improving the accuracy of network change monitoring.
[0108] Based on the above Figure 2 The description of the method embodiments shown in this application further proposes a method for monitoring network changes; in this application embodiment, a computer device is still used as the execution subject for explanation. Please refer to... Figure 4 As shown, the method for monitoring network changes can be roughly divided into the following steps: S401-S413:
[0109] S401, Obtain the target change order. When making network changes to the network devices indicated in the target change order, scan for network alarms.
[0110] S402 If a network alarm is detected, the corresponding network device and the network alarm will be associated spatially according to the network monitoring configuration of each network device.
[0111] S403 If no network device and network alarm are successfully associated in the spatial dimension, it is determined that there is no spatial association between the network alarm and the target change order, and a relationship analysis result is generated; the relationship analysis result is used to indicate that the network alarm and the target change order are not associated.
[0112] S404 If a network device and a network alarm are successfully associated in a spatial dimension, then it is determined that there is a spatial association between the network alarm and the target change order.
[0113] S405 identifies network devices that are successfully associated in the spatial dimension as suspicious devices, obtains the device operation logs of the suspicious devices, and obtains the reference time of network alarms.
[0114] S406, based on the device operation logs of suspicious devices and the reference time of network alarms, associates suspicious devices with network alarms in the time dimension.
[0115] In practical implementation, after determining that there is a spatial correlation between the network alarm and the target change order, the computer device can directly execute steps S405-S406. Alternatively, considering that when there are many network devices to be changed, in order to control risks, the computer device usually splits multiple network devices into multiple batches for serial execution (i.e., serially performs network changes) according to certain principles. Based on this, if the target change order indicates multiple network devices, and the multiple network devices are changed in batches, after identifying the network devices that are successfully associated in the spatial dimension as suspicious devices, the computer device can determine the batch in which the network device currently undergoing network change is located as the current batch. Based on whether the batch number of the suspicious device and the batch number of the current batch are the same, it can determine whether the suspicious device is in the current batch. If the two batch numbers are the same, it is determined that the suspicious device is in the current batch; if the two batch numbers are different, it is determined that the suspicious device is not in the current batch. Furthermore, if the suspicious device is in the current batch, step S406 can be triggered; if the suspicious device is not in the current batch, a third color (such as green) can be used to light up the indicator light, and a second color (such as yellow) can be recorded in the storage space. When the batch in which the suspicious device is located begins to undergo network changes, it is checked whether the network alarm has been restored; if the network alarm has been restored, the display color of the indicator light is controlled to remain at the third color (such as green); if the network alarm has not been restored, the display color of the indicator light is controlled to switch from the third color (such as green) to the second color (such as yellow).
[0116] Therefore, for batch changes, the embodiments of this application can further implement batch lighting by combining suspected devices. For example, see... Figure 5a As shown: If the suspicious device matched by the network alarm is included in the currently executing batch of devices, the system can continue to detect whether the suspicious device's operation includes the target device's operation and whether the target device's operation is a dangerous device operation. Based on the detection results, the system controls the indicator light to display either a first color (e.g., red) or a second color (e.g., yellow). If the suspicious device is not in the currently executing batch of devices, the computer can automatically suppress the network alarm, move it to storage space (e.g., a backend server), and record it as a second color (e.g., yellow). The indicator light on the front-end page will remain as a third color (e.g., green) until the batch to which the suspicious device belongs begins network changes. At this point, the computer can check whether the network alarm has been resolved. If it has, the indicator light on the front-end page will continue to display as a third color (e.g., green). If it has not been resolved, the recorded second color (e.g., yellow) will be synchronized to the indicator light on the front-end page, updating the indicator light's display color to the second color (e.g., yellow). As can be seen, this method can effectively reduce the number of second-color lights (such as yellow lights) or first-color lights (such as red lights) related to non-batch devices, thereby improving the accuracy of light changes, avoiding interference with the network change process, and improving the efficiency of network changes.
[0117] S407, if the suspicious device and the network alarm fail to be associated in the time dimension, it is determined that there is no time association between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial association. The relationship analysis result is used to indicate that there is a spatial association between the network alarm and the target change order, but no time association.
[0118] S408, if the suspicious device and the network alarm are successfully associated in the time dimension, it is determined that there is a time correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the time correlation and spatial correlation. The relationship analysis result is used to indicate that there is a spatial correlation and a time correlation between the network alarm and the target change order.
[0119] In one specific implementation, if a suspicious device and a network alarm are successfully correlated in the time dimension, it can be directly determined that there is a time correlation between the network alarm and the target change order.
[0120] In another specific implementation, considering that the same network device may be associated with multiple change orders within the same network change time window, relying solely on device operation logs to determine the target device's operation may lead to associating the same device operation log with network changes corresponding to multiple change orders. This could result in some network changes being mistakenly identified as being implemented even if they have not been executed, leading to false alarms from the first-color indicator light (e.g., red light). To address this issue, this application further introduces task operation logs to confirm the target device's operation; the method for obtaining task operation logs can be exemplarily described in [reference needed]. Figure 5b As shown:
[0121] The network change platform can utilize the change task workflow control system to call a public SDK (Software Development Kit). Using the task distribution interface provided by this public SDK, it can transmit the target change order number to the target network change task and then distribute the target network change task to the device management platform. The device management platform then distributes the target network change task to network devices via an agent. Upon receiving the target network change task from the device management platform, any network device can identify the target change order based on the task and perform network changes according to the instructions in the target change order. Furthermore, after distributing the target network change task, the device management platform can also receive (determine) the task execution logs (e.g., TNC logs, where TNC is a network...) corresponding to the target network change task reported by the agent. The device management platform records the various device operations performed by network devices based on the target network change task in the task execution log. That is, the task execution log and the corresponding change information are recorded and reported to the data subscription system. Based on this, the log operation monitoring service in the network change platform can obtain the task execution log corresponding to the specified target change order, network device and time window from the data subscription system, and provide the task execution log to the computer device in the traffic light system. This allows the computer device to detect whether the network change process corresponding to the target change order actually involves target device operations based on the task execution log, and further determine whether the traffic light corresponding to the target change order needs to be lit in the first color (such as red) or the second color (such as yellow).
[0122] Based on the above description, if the target device operation is found in the device operation log, the specific implementation method for determining that the suspicious device and the network alarm are successfully associated in the time dimension can be as follows: If the target device operation is found in the device operation log, the task execution log of the target network change task is obtained; if the task execution log records the target device operation, the suspicious device and the network alarm are successfully associated in the time dimension; if the task execution log does not record the target device operation, the suspicious device and the network alarm are not successfully associated in the time dimension.
[0123] If the task execution log records the target device's operations, the computer can directly determine that the suspicious device and the network alarm are successfully associated in the time dimension. Alternatively, considering that the device operation log also records the operation accounts of the executed device operations, the aforementioned method of combining task execution logs to detect whether a suspicious device and a network alarm are successfully associated in the time dimension is applicable to network changes triggered by network change tasks issued through the device management platform, but not to manually triggered network changes. Therefore, to improve the accuracy of the detection results, both device operation logs and task execution logs can be combined to jointly determine whether a suspicious device and a network alarm are successfully associated in the time dimension. Specifically, the judgment logic can be as follows:
[0124] If the task execution log records the operations of the target device, the computer device can obtain the operation account of the target device from the device operation log of the suspicious device;
[0125] If the operation account belongs to the platform account in the device management platform, the step of obtaining the task execution log corresponding to the target network change task will be triggered;
[0126] If the operating account is a personal account, a consistency check can be performed between the operating account and the implementer account corresponding to the target change order. The implementer account is the account of the object implementing the target change order. Implementing the target change order can be understood as making network changes to network devices based on the target change order. If the consistency check is successful (i.e., the operating account and the implementer account corresponding to the target change order are the same), it is determined that the suspicious device and the network alarm are successfully associated in the time dimension; if the consistency check fails (i.e., the operating account and the implementer account corresponding to the target change order are different), it is determined that the suspicious device and the network alarm are not associated in the time dimension.
[0127] If the operating account belongs to another account, it is confirmed that the suspicious device and the network alarm are successfully associated in terms of time; other accounts refer to accounts other than platform accounts and personal accounts.
[0128] Optionally, the computer equipment can also combine device operation logs and task execution logs to jointly determine whether the target device operation is a network change operation corresponding to the target change order. Based on the determination result of the target device operation, it can then determine whether the suspicious device and the network alarm are successfully associated in the time dimension. In this case, the judgment logic can be found in [reference needed]. Figure 5cAs shown: When a suspicious device is identified through spatial association, if the suspicious device's operation log contains an operation related to the target device, the operation account for that operation is identified. If the operation account is a platform account, the task execution log is further queried. If the target device operation is found in the task execution log, it is marked as a network change operation for the target change order, for example, marked as "this change operation". If the task execution log does not contain the target device operation, it is marked as a network change operation for another change order, for example, marked as "other change operation". If the device account is a personal account, the operation account is compared with the implementer account of the target change order. If they match, the target device operation is marked as a network change operation for the target change order, for example, marked as "this change operation". Otherwise, it is marked as a network change operation for another change order, for example, marked as "other change operation". If the operation account is another account, the target device operation is directly marked as a network change operation for the target change order, for example, marked as "this change operation". Furthermore, it can be determined whether the operation of the target device is marked as a network change operation of the target change order, such as marked as "this change operation"; if so, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension, and the indicator light corresponding to the target change order is lit up with the first color light (such as red light); if not, it is determined that the suspicious device and the network alarm are not associated in the time dimension, and the indicator light corresponding to the target change order is lit up with the second color light (such as yellow light).
[0129] Optionally, if the target device operation is not found in the device operation log, or if no device operation log exists, the indicator light corresponding to the target change order can be directly lit in the second color (e.g., yellow). Alternatively, considering that network devices may report abnormal device operation logs due to configuration issues, this embodiment can further associate the task execution log, i.e., obtain the task execution log of the target network change task corresponding to the target change order, and search for the target device operation in the task execution log; if the target device operation is found in the task execution log, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension, so that the indicator light corresponding to the target change order can be lit in the first color (e.g., red); if the target device operation is not found in the task execution log, the step of determining that the suspicious device and the network alarm are not associated in the time dimension is triggered, so that the indicator light corresponding to the target change order can be lit in the second color (e.g., yellow).
[0130] S409, based on the relationship analysis results, illuminate the signal light corresponding to the target change order.
[0131] S410 detects the correlation between network alarms and target change orders based on the context information of network alarms, obtains the correlation detection results, and corrects the display color of the signal light corresponding to the target change order based on the correlation detection results.
[0132] S411, when the indicator light corresponding to the target change order displays the third color, if the alarm duration of the network alarm is greater than the duration threshold and the network alarm is not assigned to any change order (i.e. no change order claims the network alarm), then the network abnormal area and the area where the network device indicated by the target change order is located are determined.
[0133] The network anomaly area can include the area indicated by any area identifier (such as the source area identifier) in the network alarm; that is, the area indicated by any area identifier (such as the source area identifier) in the network alarm can be considered as the network anomaly area. Furthermore, the network device indicated in the target change order is the network device indicated by the device identifier in the target change order, and the area where the network device is located can be understood as the geographical location of the network device.
[0134] S412, if the network anomaly area matches the area where the network device indicated by the target change order is located, then the display color of the indicator light corresponding to the target change order is corrected to the first color (such as red).
[0135] S413 If the network anomaly area does not match the area where the network device indicated by the target change order is located, the display color of the indicator light corresponding to the target change order will remain the third color (such as green).
[0136] In steps S412-S413, when the number of network devices indicated by the target change order is 1, the matching of the network abnormal area and the area where the network device indicated by the target change order is located can be understood as: the network abnormal area includes the area where the network device indicated by the target change order is located; correspondingly, the mismatch between the network abnormal area and the area where the network device indicated by the target change order is located can be understood as: the network abnormal area does not include the area where the network device indicated by the target change order is located. When the target change order indicates multiple network devices, these network devices may be located in one or more regions. Matching the network anomaly region and the region where the network device indicated by the target change order is located can be understood as: there is an intersection between the network anomaly region and the region where the network device indicated by the target change order is located. That is, at least one region in the region where the network device indicated by the target change order is located belongs to the network anomaly region. For example, the network anomaly region includes cities A and C, while the region where the network device indicated by the target change order is located includes cities A and B. In this case, there is an intersection between the network anomaly region and the region where the network device indicated by the target change order is located, and thus it can be determined that the network anomaly region and the region where the network device indicated by the target change order are matched.
[0137] It should be noted that the areas mentioned in steps S411-S413 above can be areas divided based on cities, that is, areas mentioned in steps S411-S413 above can be city-level areas. In this case, this embodiment of the application can perform fuzzy city-level traffic light adjustment through steps S411-S413, thereby bypassing the network monitoring configuration of network devices, expanding the search range to the city scope, and thus searching for change orders related to context information within the city scope, thereby correcting the traffic light of the change order from green to red. It is understood that the areas mentioned in steps S411-S413 above can be areas divided based on streets, that is, areas mentioned in steps S411-S413 above can be street-level areas, and this embodiment of the application does not limit this.
[0138] Furthermore, steps S411-S413 above exemplify one processing logic for fuzzy indicator lights and are not exhaustive. For example, in other embodiments, when the display color of the indicator light corresponding to the target change order is the third color, if the alarm duration of the network alarm exceeds the duration threshold and the network alarm is not assigned to any change order (i.e., no change order claims the network alarm), the computer device can also obtain various network monitoring configurations in the network monitoring system and match each network monitoring configuration in the network monitoring system with the network alarm. If at least one network monitoring configuration in the network monitoring system matches the network alarm, the display color of the indicator light corresponding to the target change order is corrected to the first color (e.g., red); if no network monitoring configuration in the network monitoring system matches the network alarm, the display color of the indicator light corresponding to the target change order remains the third color (e.g., green).
[0139] In the specific implementation of matching various network monitoring configurations with network alarms in the network monitoring system, for the p-th network monitoring configuration, where p is a positive integer less than or equal to the number of network monitoring configurations in the network monitoring system; when a network alarm includes one source region identifier and multiple destination region identifiers, the source region identifier in the network alarm is taken as an abnormal crossover point; in the p-th network monitoring configuration, a source region identifier that is the same as the abnormal crossover point is searched; if a source region identifier that is the same as the abnormal crossover point is found, it is determined that the p-th network monitoring configuration matches the network alarm; if no source region identifier that is the same as the abnormal crossover point is found, it is determined that the p-th network monitoring configuration does not match the network alarm. When a network alarm includes one source region identifier and one destination region identifier, it can be checked whether the p-th network monitoring configuration and the network alarm meet the target condition; if the target condition is met, it can be determined that the p-th network monitoring configuration matches the network alarm; if the matching condition is not met, it can be determined that the p-th network monitoring configuration does not match the network alarm. The target conditions include: a network alarm contains a source region identifier located in the source region identifier included in the p-th network monitoring configuration, and a network alarm contains a destination region identifier located in the destination region identifier included in the p-th network monitoring configuration; or, the target conditions include: a network alarm contains a source region identifier located in the destination region identifier included in the p-th network monitoring configuration, and a network alarm contains a destination region identifier located in the source region identifier included in the p-th network monitoring configuration.
[0140] Optionally, embodiments of this application may also support manual light activation to improve the accuracy of light activation. Specifically, if the computer device receives a light activation command, it determines at least one change order to be activated based on the command; if at least one change order includes a target change order, the signal light corresponding to the target change order is activated according to the command. The light activation command is generated by the implementer of any change order when they discover that a network change corresponding to that change order has caused a network anomaly; or, the light activation command is generated by the network administrator when they discover a network anomaly, by associating the list of currently implemented change orders based on the start time of the anomaly, filtering out change orders related to the network anomaly area from the list, and generating the command based on the filtered change orders; the change order being related to the network anomaly area means that the area where the network indicated by the change order is located belongs to the network anomaly area.
[0141] This application embodiment can scan for network alarms when making network changes to the network devices indicated in the target change order. Upon detecting a network alarm, it automatically analyzes the correlation between the network alarm and the target change order based on the network monitoring configuration of the network devices in the target change order, obtaining a relationship analysis result. Based on this result, it quickly illuminates the indicator light corresponding to the target change order, allowing the color of the indicator light to promptly and intuitively indicate whether the current network change has caused a network anomaly, improving the timeliness of network change monitoring. Furthermore, it can obtain the context information of the network alarm, which indicates the cause of the anomaly and whether the network alarm was assigned to the target change order. Based on this context information, it can accurately perform a secondary analysis of the correlation between the network alarm and the target change order, obtaining a correlation detection result. The display color of the indicator light corresponding to the target change order is then corrected based on the correlation detection result, making the indicator light display more accurate, reducing the missed detection rate in abnormal network change scenarios and the false detection rate in normal network change scenarios, thereby improving the accuracy of network change monitoring.
[0142] Based on the above Figure 2 and Figure 4 The description of the method embodiments shown in this application provides a method for network change and monitoring; see also... Figure 6a As shown, the overall flowchart for network changes and monitoring can be roughly as follows:
[0143] (1) Create a change order.
[0144] (2) In the change order, fill in the device identifier of the network device and the network change time window.
[0145] (3) Create batch tasks according to the risk control principle (that is, process multiple network devices in batches and fill in the batch number of each network device in the change order).
[0146] (4) Calculate the network monitoring configuration for each network device, and add the network monitoring configuration for each network device to the change order.
[0147] (5) Scan for network alarms at the start of the network change time window.
[0148] (6) If a network alarm is detected, the precise indicator light mode can be activated within seconds. In precise indicator light mode, the correlation between change orders and network alarms can be analyzed through spatial correlation (i.e., correlation operation in the spatial dimension), temporal correlation (correlation operation in the temporal dimension), and content correlation (correlation operation in the content dimension). Based on the correlation analysis results, the indicator lights corresponding to the change orders can be quickly activated, such as turning the indicator lights yellow, red, or green. Furthermore, the display color of the indicator lights can be delayed and corrected based on spatial correlation and contextual correlation (i.e., using contextual information to detect the correlation between network alarms and change orders). Further, the fuzzy indicator light mode can be activated within minutes. In fuzzy indicator light mode, the indicator lights can be turned yellow, red, or green through contextual information correlation (such as fault context (i.e., alarm diagnosis result) correlation, change context correlation), temporal correlation, and content correlation. Further, the manual indicator light mode can be activated within minutes. In manual indicator light mode, the indicator lights can be turned yellow, red, or green through manual correlation.
[0149] (7) If no network alarm is detected, turn the indicator light green.
[0150] (8) If the signal light is green, the target change order is implemented normally (i.e., the network change is performed normally) until the network change is completed; if the signal light is yellow, the implementation of the target change order is suspended (i.e., the network change is suspended) until the network alarm is restored, the implementation of the target change order is resumed until the network change is completed; if the signal light is red, the network change process is automatically rolled back and the network change is confirmed to be completed.
[0151] In summary, the key points of the method for network change and monitoring proposed in this application are shown in Table 1:
[0152] Table 1
[0153]
[0154]
[0155] The method proposed in the embodiments of this application will be described in detail below:
[0156] (1) Combining multiple light patterns improves the recall rate of abnormal changes:
[0157] To ensure 100% illumination during abnormal changes, this application employs multiple illumination modes in a coordinated manner before, during, and after the event, such as... Figure 6b As shown:
[0158] 1) Focus on improving "precise lighting" in advance:
[0159] Precise alarm detection, which involves alarm correlation based on pre-configured monitoring content (i.e., network monitoring configuration of network devices) within the scope of change impact, is the primary mode for anomaly alarm detection. To improve the accuracy of correlation results, the "precise alarm detection" mode achieves this through two alarm activations:
[0160] ① Initial connection, quick light activation:
[0161] The initial association mechanism prioritizes speed, triggering immediately upon the generation of a network alarm. It primarily associates information based on three dimensions: time, location, and content. It can activate a red, yellow, or green light in as little as a few seconds. Practical experience has shown that this mode can detect 80% of abnormal change orders (i.e., change orders that triggered network anomalies).
[0162] ② Secondary association, delayed correction:
[0163] Secondary association, aiming for accuracy, needs to be triggered after collecting change or fault context information. Secondary association primarily utilizes context information for association, typically correcting the indicator signal activated during the initial association within minutes. Practical experience has shown that this mode can detect 10% of abnormal change orders. Specifically, the logic for delayed correction can include, but is not limited to:
[0164] A. Based on fault context: By using the fault context obtained from diagnosis to inversely correlate the cause of the anomaly with network devices, the indicator lights for change orders unrelated to the fault point (cause of the anomaly) are changed from red to yellow. This allows change orders mistakenly stopped by a red light to continue implementation after the alarm clears and turns green, ensuring the efficiency of network change implementation. Simultaneously, the indicator lights for change orders related to the fault point are changed from yellow to red or from green to red, triggering a red-light EOP (emergency operational procedure, i.e., rollback), facilitating rapid business recovery. See, for example... Figure 6c The change order 2-change order N (N is a positive integer) shown can change the traffic light corresponding to change order 2-change order N from red to yellow based on the fault context, so that after the network alarm is restored, the traffic light corresponding to change order 2-change order N can be changed back to green.
[0165] B. Based on Change Context: During network anomalies, abnormal change orders support user-initiated alarm claiming. This means that the indicator light for a change order implemented when a user claims a network alarm can be turned red, triggering a red EOP (Entry-Order Implementation). Conversely, for change orders whose indicator lights are illuminated based on the same network alarm but were not claimed through user claiming, the indicator light can be turned yellow, allowing implementation to continue after the alarm clears and turns green, thus avoiding impacting network change implementation efficiency. See, for example... Figure 6c The change order 1 shown can be modified from a yellow light to a red light based on the change context. This ensures that the traffic light corresponding to change order 1 remains red after the network alarm is restored, while the traffic lights corresponding to change orders 2-N are modified to green lights.
[0166] 2) Supplementing with "vague lighting" beforehand as a secondary measure:
[0167] Fuzzy indicator lighting primarily addresses the issue of incomplete monitoring scope in the pre-configured network monitoring settings of "Precise indicator lighting." In this mode, the network monitoring configuration of network devices may be skipped, and a search for context-related change orders is performed from all currently executing change orders. This allows the indicator light for that change order to be corrected from green to red. See also... Figure 6d As shown, the fuzzy lighting automatically starts if the anomaly persists for several minutes without any change claim alarm, indicating that the precise lighting failed to accurately locate the abnormal change, the estimated monitoring range is incomplete, and the search range needs to be expanded. Practical experience has shown that this lighting mode takes several minutes and can detect 6% of abnormal change orders.
[0168] 3) Post-event reinforcement with "manual lighting" as a backup:
[0169] While the "precise lighting" and "fuzzy lighting" automatic lighting modes can detect most abnormal changes, there is still a possibility of missed anomalies, such as scenarios not covered by the network monitoring system. In such cases, all network monitoring configurations connected to the network monitoring system fail to detect the anomaly, requiring manual monitoring or service / customer reports for discovery. To address this, this application provides "manual lighting" as a fallback function to illuminate specific areas or global changes, triggering an Expiration Operation (EOP) to restore services. Practical experience has shown that this mode takes an average of over ten minutes to light up and can cover 4% of abnormal changes. Specifically, this mode can include the following two approaches:
[0170] ① Global "Manual Ignition": "Manual Ignition" is mainly used by on-duty or management personnel. When a serious network anomaly occurs, users can automatically associate the list of ongoing change orders based on the start time of the anomaly, filter the scope of changes based on the anomaly area, and then trigger EOPs in batches.
[0171] ② Local "Manual Illumination": Local "Manual Illumination" is mainly used for personnel changes. When an anomaly is detected by manual monitoring, the personnel making the change can actively illuminate the red light for the current change and use "One-Click EOP" to trigger a change rollback to restore the business.
[0172] (2) Refined spatiotemporal correlation to reduce the false alarm rate of initial correlation:
[0173] Precise lighting is the primary mode of system lighting, and initial lighting is the most crucial step in precise lighting. Since initial lighting is mainly achieved through spatiotemporal correlation, improving the granularity of this correlation is key to reducing the false alarm rate. Specifically:
[0174] a) Refined time-related parameters:
[0175] ① Introduce more logs to confirm target device operations: Introduce task execution logs to confirm target device operations. Please refer to the previous section for details. Figure 4 The following is a description of the method embodiments shown.
[0176] ② Introduce an anomaly start time confirmation anchor point: Introduce the anomaly start time as an anchor point to correlate the target device operation backward in order to determine the correlation between network alarms and change orders.
[0177] b) Refinement of spatial association:
[0178] ① Fine-grained matching of alarm source and destination: For one-to-many network alarms, matching is strictly based on the alarm source, that is, strictly matching abnormal crossover points. For example, alarms from C to A, B, and D are only associated with changes in area C; for one-to-one alarms, since abnormal crossover points cannot be directly identified, both source and destination are involved in the matching. For example, alarms from D to A can be associated with changes in areas D and A.
[0179] c) Spatiotemporal collaborative association:
[0180] ① Associate operations with suspicious devices: During the change process, network alarms are sequentially associated with the network monitoring configurations of each network device in the change order. If the association is successful, the corresponding device is recorded as a suspicious device, and then time association is performed for the suspicious devices. Non-suspicious devices are not associated with time. This solves the problem of inconsistency between the change operation and the alarm scope.
[0181] ② Batch-based device association (batch lights): This further integrates batch lights with suspicious devices. Specifically, if a suspicious device matched by a network alarm is included in the currently executing batch, the target device operation continues, and a red or yellow light illuminates. If the suspicious device is not in the currently executing batch, the system automatically suppresses the network alarm, moving it to the backend for recording, while the main frontend light remains green. This continues until the suspicious device batch begins execution. At this point, the system checks if the backend alarm has recovered. If it has, the main frontend light remains green; if not, the backend alarm light status is synchronized to the main frontend light. This method effectively reduces the number of red and yellow lights associated with devices not in the executing batch, improving the accuracy of light changes.
[0182] (3) Context information calibration to reduce the false alarm rate of secondary association.
[0183] Besides improving anomaly detection rates, contextual information can also be used to correct initial false alarms and improve the accuracy of secondary correlation. Specifically, when each change order is independently correlated by time, space, and content, the impact scope (corresponding to network monitoring configurations) and network devices may overlap between changes. When change order A causes a network alarm, change orders B, C, and D may be falsely flagged by the same network alarm. Due to the lack of information exchange between change orders A, B, C, and D, they cannot confirm that the network alarm is unrelated to their own network changes and can only close the orders and reschedule. Furthermore, considering the increasing sophistication of alarm diagnostic tools, the cause of an anomaly can often be located within a short time (e.g., about one minute): network device malfunction, server malfunction, main light jitter, etc. This information is invaluable. Although it cannot be directly used for the initial light activation due to time constraints, it can be used as contextual information for secondary correlation calibration of light-up changes, thereby reducing false alarms. Specifically:
[0184] a) Alarm-based diagnosis and correction:
[0185] After obtaining the trace path (network transmission path) by detecting abnormal flows, alarm diagnosis can locate network fault information by combining path common points and key device indicators, including abnormal network devices, server operations, main optical jitter, etc. Different judgment rules can be set for different alarm diagnosis results (i.e., fault context) to correct the initial red light to a yellow light, such as... Figure 6e As shown. Examples are as follows:
[0186] ① The alarm diagnosis result indicates that the abnormality is caused by a network device malfunction:
[0187] Perform correlation analysis between diagnosed abnormal equipment and equipment undergoing operation changes. If the diagnosed abnormal equipment and the equipment undergoing operation changes are not directly related, they are considered unrelated, and the red light can be changed to a yellow light. Specific examples include equipment inconsistencies, lack of direct connection between equipment, and equipment connections separated by more than one device.
[0188] ② The alarm diagnosis results indicate that the abnormality was caused by server operation:
[0189] Anomaly alerts caused by server operations are not related to the changed operations by default and can be directly corrected to yellow alerts.
[0190] ③ The alarm diagnosis results indicate that the abnormality is caused by optical jitter:
[0191] If the network change method is a data communication change, the alarm caused by the main beam jitter can be considered to be unrelated to the change order by default, and the signal light can be directly corrected to yellow. If the network change method is a wavelength division change, it is necessary to further determine whether the main beam with the abnormality is related to the main beam of the network change operation. If there is no relationship, the signal light can be corrected to yellow.
[0192] b) Alarm-based correction:
[0193] If a network alarm is claimed by a specific change order implementer (i.e., the network alarm is assigned to a specific change order), the indicator lights of other change orders that are lit based on that network alarm can be corrected to yellow. Once the corrected yellow alarm lights turn green again, the corresponding change orders can continue to be implemented, thereby improving the success rate of network changes.
[0194] Practical experience has proven that this application's embodiments, by introducing more comprehensive lighting modes, richer contextual information, and more refined association logic, can reduce the false red light alarm rate from 5.4% to 0.5%, a reduction of over 90%, and increase the change anomaly hit rate from 88% to 99%. While ensuring the quality of network changes, it significantly saves change window resources and improves the success rate of network changes. The following is a detailed description of this application's embodiments using a set of practical examples:
[0195] (1) Combining multiple light modes improves the hit rate of abnormal changes:
[0196] a) Precise lighting: Based on alarm diagnosis and correction:
[0197] Figure 7a The issue concerns the network monitoring configuration of a backbone network device. During the modification process (02:47:34), a quality alarm occurred regarding network access from Shenzhen to Shanghai. The alarm source and monitoring configuration source match, but both the device operation logs and task execution logs indicate that the target device operation failed. Figure 7bThe device operation log shown has an empty association result, indicating that the associated target device operation failed. Therefore, the indicator light should be quickly turned on to yellow. Figure 7c As shown. At 02:48:36, the following was obtained: Figure 7d The alarm diagnosis result shown (i.e., fault context) indicates that the anomaly was caused by a network device malfunction, specifically network device 1. Since this malfunctioning device overlaps with the network device currently undergoing network changes, and expanding the scope of the device operation log query revealed target device operations that were deemed dangerous, the initially associated yellow light can be changed to a red light. Figure 7e As shown, this quickly triggers the EOP rollback to restore the service. In this case, the alarm lighting history of the corresponding indicator light can be found in [reference needed]. Figure 7f As shown.
[0198] b) Fuzzy LED illumination: Corrected based on alarm diagnosis.
[0199] Figure 8a The network monitoring configuration of network device A at the access layer in Guangzhou was changed during a restart. This configuration, by default, only monitors access layer quality alarms. However, during the change process, a Fullmesh (fully interconnected mode) packet loss anomaly alarm was generated, and [see...] Figure 8b The alarm diagnosis results show that the abnormal network device identified is network device A, which is consistent with the network device currently undergoing network changes. Furthermore, this network device had target device operations prior to the Fullmesh alarm, therefore it can be determined that the network alarm is related to the current change order. Although the network device's network monitoring configuration does not include Fullmesh, thus failing to trigger precise indicator lighting, fuzzy indicator lighting skips the network device's network monitoring configuration, thereby illuminating the red light (e.g., ...). Figure 8c (As shown), this quickly triggers EOP rollback to restore the service; in this case, the fuzzy light-up log can be found in... Figure 8d As shown.
[0200] (2) Refined spatiotemporal correlation to reduce the false alarm rate of initial correlation:
[0201] a) Introduce task execution logs to confirm operations on hazardous equipment:
[0202] Figure 9aThis is the task execution log for link debugging and changes between network device 1 and network device 2 in the Shanghai area. During the network change process, a network alarm occurs in the Beijing-Shanghai area. If a dangerous device operation is detected on a network device in Shanghai, resulting in a red light, the corresponding network change order will be mistakenly canceled. This embodiment of the application determines, by combining the task execution log, that the dangerous device operation was not issued by this change order (no task was issued by the network device management platform before or after the alarm). Therefore, it is considered that the network change corresponding to this change order does not involve dangerous device operation, and thus a yellow light is displayed, avoiding the mistaken cancellation due to a red light. Figure 9b As shown.
[0203] b) Fine-grained matching of alarm sources and destinations:
[0204] By finely matching alarm sources and targets, the accuracy of lighting can be improved. For example... Figure 10a This is a network monitoring configuration change order in the Shanghai area. The corresponding indicator light display results can be found here. Figure 10b As shown.
[0205] ①Associate with suspicious devices
[0206] Figure 11a This refers to the network monitoring configuration of a change order. When implementing this configuration on network device VA-002, a leased line probe alarm occurs. If a red light illuminates after a dangerous device operation associated with network device VA-002, it could lead to a false positive on the change order. Therefore, this embodiment of the application can determine that the suspicious device is network device VA-001 if the leased line probe alarm matches the network monitoring configuration of network device VA-001. Since network device VA-001 did not perform any dangerous device operation, it is assumed that no dangerous device operation occurred within the alarm range, and thus a yellow light illuminates. Figure 11b .
[0207] ② Perform batch-based device association operations (batch lights)
[0208] Figure 12aThis involves the batch configuration of network devices, affecting multiple network devices in Qingyuan-Qingxin, Shenzhen-Ebu, Guiyang-Qixing, and Shenzhen-Shenyu Industrial Park. If a network alarm occurs in the Shenzhen-Ebu area when the network change is implemented for the batches of devices in the Qingyuan-Qingxin and Shenzhen-Shenyu regions, the corresponding network alarm can be stopped by displaying a yellow light after spatial association (based on the change order). Alternatively, it can be stopped by determining that the suspicious device is not part of the current batch, so that when the backend is pressed, the frontend only displays a green light, effectively avoiding false alarms caused by yellow lights and improving the success rate of the change. For example, when a network alarm occurs at 01:54:16 on December 27, 2023, network devices "Qingyuan-Qingxin" and "Shenzhen-Shenyu" are being operated based on a change order. This does not match the alarm source "Shenzhen-Ebu". Therefore, it can be determined that this network alarm is not a network alarm in the currently operated batch's associated area, and the suspected device is not a device in the current batch. Thus, this network alarm can be suppressed (moved to the backend monitoring status, and the indicator light on the frontend page will show as green, such as...). Figure 12b As shown), when the operation reaches the batch of network devices in "Shenzhen-Ebu", if the network alarm has not been resolved, the yellow light status will be released to the indicator light on the front-end page, causing it to light up yellow to remind the user to avoid the change operation (i.e., suspend the network change). Figure 12c As shown.
[0209] (3) Context information calibration to reduce the false alarm rate of secondary association:
[0210] Based on alarm diagnosis and correction: On December 29, 2023, during the expansion and modification process of the network equipment from Songjiang, Shanghai to Shanghai Baoxin's network equipment, other change orders within the same window triggered a quality anomaly alarm from Shanghai to multiple cities. If the network equipment associated with Shanghai Baoxin showed operation on the target device, and the target device's operation was deemed a dangerous operation that resulted in a red light, it would lead to a false positive on the change. However, if the change was corrected within 1 minute... Figure 13a The alarm diagnostic output shows that the anomaly was caused by a network device malfunction, specifically a network device in Shanghai Waigaoqiao. Comparing this malfunctioning device with the network device undergoing network modifications revealed that the malfunctioning device was unrelated to the modified device. Therefore, the red light was changed to a yellow light. Figure 13b As shown, its correction log can also be found here. Figure 13c As shown.
[0211] In summary, by introducing a more comprehensive lighting mode, richer contextual information, and more refined association logic, this application embodiment can significantly reduce the false alarm rate of change monitoring and improve the success rate of changes while effectively improving the hit rate of abnormal changes and ensuring network quality.
[0212] Based on the descriptions of the above method embodiments, this application also discloses a network change monitoring device; the network change monitoring device may be a computer program (including one or more instructions) running on a computer device, and the network change monitoring device may execute each step in any of the above method flows. Please refer to... Figure 14 The network change monitoring device can operate the following units:
[0213] The acquisition unit 1401 is used to acquire a target change order, the target change order corresponds to a signal light, and the target change order is used to indicate the network device to be changed and the network monitoring configuration of the network device.
[0214] Processing unit 1402 is used to scan for network alarms when making network changes to the network devices indicated in the target change order. The network alarms refer to alarm information generated when network anomalies are detected.
[0215] The processing unit 1402 is further configured to, if the network alarm is detected, analyze the correlation between the network alarm and the target change order according to the network monitoring configuration of the network device, obtain the relationship analysis result, and light up the signal light corresponding to the target change order based on the relationship analysis result;
[0216] The acquisition unit 1401 is further configured to acquire the context information of the network alarm, the context information being used to indicate at least one of the following: the cause of the anomaly corresponding to the network alarm, and whether the network alarm is assigned to the target change order;
[0217] The processing unit 1402 is further configured to detect the correlation between the network alarm and the target change order based on the context information, obtain the correlation detection result, and correct the display color of the signal light corresponding to the target change order based on the correlation detection result.
[0218] In one implementation, the context information is used to indicate the cause of the anomaly corresponding to the network alarm; correspondingly, when the processing unit 1402 detects the correlation between the network alarm and the target change order based on the context information and obtains the correlation detection result, it may specifically be used to:
[0219] If the context information indicates that the cause of the anomaly is a network device malfunction, then the device correlation between the malfunctioning network device and the network change device is detected; the network change device refers to the network device that is undergoing network change as indicated in the target change order.
[0220] If the device correlation is detected, it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result indicating the correlation is generated.
[0221] If no device correlation is detected, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating that there is no correlation is generated.
[0222] In another implementation, the context information is used to indicate the cause of the anomaly corresponding to the network alarm; correspondingly, when the processing unit 1402 is used to detect the correlation between the network alarm and the target change order based on the context information and obtain the correlation detection result, it can also be used to:
[0223] If the anomaly indicated by the context information is caused by server operation, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating that there is no correlation is generated.
[0224] In another implementation, the context information is used to indicate the cause of the anomaly corresponding to the network alarm;
[0225] The step of detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result further includes:
[0226] If the anomaly indicated by the context information is caused by main optical jitter, then obtain the network change type;
[0227] When the network change type is a data communication change, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is no correlation.
[0228] When the network change type is wavelength division multiplexing (WDM), if the jittered main light is associated with the main light corresponding to the network change, it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is a correlation; if the jittered main light is not associated with the main light corresponding to the network change, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is no correlation.
[0229] In another implementation, the context information is used to indicate whether the network alarm is assigned to the target change order; correspondingly, when the processing unit 1402 is used to detect the correlation between the network alarm and the target change order based on the context information and obtain the correlation detection result, it can also be used to:
[0230] If the context information is used to indicate that the network alarm is assigned to the target change order, then it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result is generated;
[0231] If the context information is used to indicate that the network alarm has not been assigned to the target change order, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated.
[0232] In another implementation, when the indicator light corresponding to the target change order displays a first color, the first color indicates that the network change corresponding to the target change order has caused a network anomaly and that the network change needs to be rolled back. Accordingly, when the processing unit 1402 corrects the display color of the indicator light corresponding to the target change order based on the correlation detection result, it can specifically be used to:
[0233] If the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order will be kept as the first color;
[0234] If the correlation detection result indicates that there is no correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order is corrected to the second color; the second color is used to indicate that the network change corresponding to the target change order has not caused a network anomaly and the network change needs to be suspended.
[0235] In another implementation, when the indicator light corresponding to the target change order displays a second color, the second color indicates that the network change corresponding to the target change order has not caused a network anomaly and the network change needs to be paused. Accordingly, when the processing unit 1402 corrects the display color of the indicator light corresponding to the target change order based on the correlation detection result, it can specifically be used to:
[0236] If the correlation detection result indicates that there is no correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order will be kept as the second color.
[0237] If the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the network change operation is detected in the device operation log within the target time period. The target time period is obtained by extending the duration of a preset time period.
[0238] If no network change operation occurs within the target time period, the display color of the traffic light corresponding to the target change order will remain the second color; if a network change operation occurs within the target time period, the display color of the traffic light corresponding to the target change order will be corrected to the first color.
[0239] In another implementation, when the indicator light corresponding to the target change order displays a third color, the third color indicates that the network change corresponding to the target change order has not caused a network anomaly, and the network change continues; the processing unit 1402 can also be used for:
[0240] If the alarm duration of the network alarm is greater than the duration threshold, and the network alarm is not assigned to any change order, then the network anomaly area and the area where the network device indicated by the target change order is located are determined; wherein, the network anomaly area includes: the area indicated by any area identifier in the network alarm;
[0241] If the network anomaly area matches the area where the network device indicated by the target change order is located, then the display color of the indicator light corresponding to the target change order will be corrected to the first color;
[0242] If the network anomaly area does not match the area where the network device indicated by the target change order is located, the display color of the indicator light corresponding to the target change order will remain the third color.
[0243] In another embodiment, the number of network devices is one or more; correspondingly, when the processing unit 1402 analyzes the correlation between the network alarm and the target change order based on the network monitoring configuration of the network devices to obtain the relationship analysis result, it can be specifically used for:
[0244] Based on the network monitoring configuration of each network device, the corresponding network device is associated with the network alarm in a spatial dimension;
[0245] If no network device is successfully associated with the network alarm in the spatial dimension, it is determined that there is no spatial association between the network alarm and the target change order, and a relationship analysis result is generated; the relationship analysis result is used to indicate that the network alarm and the target change order are not associated.
[0246] If a network device is successfully associated with the network alarm in a spatial dimension, it is determined that there is a spatial association between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial association.
[0247] In another implementation, each network monitoring configuration and the network alarm includes at least one source region identifier and at least one destination region identifier, with one source region identifier and one destination region identifier constituting a network transmission direction; correspondingly, when the processing unit 1402 associates the corresponding network device with the network alarm in the spatial dimension according to the network monitoring configuration of each network device, it can specifically be used to:
[0248] When the network alarm includes one source region identifier and multiple destination region identifiers, the source region identifier in the network alarm is regarded as an abnormal intersection point;
[0249] In the network monitoring configuration of the i-th network device, the source region identifier that is the same as the abnormal intersection point is matched to obtain the first matching result; where i is a positive integer and is less than or equal to the number of network devices;
[0250] If the first matching result indicates a successful match, then it is determined that the i-th network device and the network alarm are successfully associated in the spatial dimension.
[0251] If the first matching result indicates a matching failure, then it is determined that the i-th network device and the network alarm have failed to be associated in the spatial dimension.
[0252] In another embodiment, when the processing unit 1402 is used to generate relationship analysis results based on the spatial association, it may specifically be used to:
[0253] Network devices that are successfully associated in the spatial dimension are identified as suspicious devices. The device operation logs of the suspicious devices are obtained. The device operation logs are used to record the device operations that have been performed and the execution time of the corresponding device operations. The reference time of the network alarm is also obtained.
[0254] Based on the device operation logs of the suspicious device and the reference time of the network alarm, the suspicious device and the network alarm are associated in the time dimension;
[0255] If the suspicious device fails to be associated with the network alarm in the time dimension, it is determined that there is no time association between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial association. The relationship analysis result is used to indicate that there is a spatial association between the network alarm and the target change order, but no time association.
[0256] If the suspicious device is successfully associated with the network alarm in the time dimension, it is determined that there is a time correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the time correlation and the spatial correlation. The relationship analysis result is used to indicate that there is a spatial correlation and a time correlation between the network alarm and the target change order.
[0257] In another embodiment, when the processing unit 1402 is used to obtain the reference time of the network alarm, it may specifically be used to:
[0258] Obtain the anomaly start time corresponding to the network alarm, and use it as the reference time for the network alarm;
[0259] The anomaly start time refers to the time when the network anomaly corresponding to the network alarm occurs.
[0260] In another embodiment, when the processing unit 1402 associates the suspicious device with the network alarm in a time dimension based on the device operation log of the suspicious device and the reference time of the network alarm, it may specifically be used to:
[0261] Search the device operation log of the suspected device for target device operations, where the target device operations refer to network change operations performed within a preset time period before the reference time of the network alarm.
[0262] If the target device operation is found in the device operation log, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension.
[0263] If no operation of the target device is found in the device operation log, it is determined that the suspicious device and the network alarm are not associated in the time dimension.
[0264] In another implementation, any network device receives a target network change task from the device management platform, determines a target change order based on the target network change task, and performs network changes according to the instructions of the target change order; after issuing the target network change task, the device management platform determines the task execution log corresponding to the target network change task, and the task execution log records the various device operations performed by the network device based on the target network change task;
[0265] Accordingly, when processing unit 1402 determines that the suspicious device and the network alarm are successfully associated in the time dimension if the target device operation is found in the device operation log, it can specifically be used to:
[0266] If the target device operation is found in the device operation log, then the task execution log of the target network change task is obtained;
[0267] If the task execution log records the operation of the target device, then it is determined that the suspicious device and the network alarm are successfully associated in the time dimension.
[0268] If the task execution log does not record the operation of the target device, it is determined that the suspicious device and the network alarm are not associated in the time dimension.
[0269] In another embodiment, the device operation log is also used to record the operation accounts of the executed device operations; correspondingly, if the task execution log records the target device operation, the processing unit 1402 can also be used for:
[0270] Obtain the operation account for the target device from the device operation log of the suspicious device;
[0271] If the operation account belongs to the platform account in the device management platform, then the step of obtaining the task execution log corresponding to the target network change task is triggered;
[0272] If the operation account is a personal account, then the consistency between the operation account and the implementer account corresponding to the target change order shall be verified.
[0273] If the consistency check is successful, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension; if the consistency check fails, it is determined that the suspicious device and the network alarm are not successfully associated in the time dimension.
[0274] In another embodiment, the processing unit 1402 may also be used for:
[0275] If the operating account belongs to another account, then it is determined that the suspicious device and the network alarm are successfully associated in the time dimension;
[0276] The other accounts refer to accounts other than the platform account and the personal account.
[0277] In another embodiment, if no target device operation is found in the device operation log, the processing unit 1402 can also be used for:
[0278] Obtain the task execution log of the target network change task corresponding to the target change order, and search for the target device operation in the task execution log;
[0279] If the target device operation is found in the task execution log, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension.
[0280] If no target device operation is found in the task execution log, the step of determining that the suspicious device and the network alarm failed to be associated in the time dimension is triggered.
[0281] In another implementation, the target change order indicates multiple network devices, and the multiple network devices undergo network changes in batches; after determining that network devices successfully associated in the spatial dimension are suspicious devices, the processing unit 1402 can also be used for:
[0282] The batch to which the network device currently undergoing network changes belongs is determined as the current batch;
[0283] If the suspicious device is in the current batch, then the step of associating the suspicious device with the network alarm in the time dimension based on the reference time of the device operation log of the suspicious device and the network alarm is triggered.
[0284] If the suspicious device is not in the current batch, the signal light is illuminated with the third color, and the second color is recorded in the storage space. When the batch in which the suspicious device is located begins to undergo network changes, if the network alarm has been resolved, the display color of the signal light is controlled to remain at the third color. If the network alarm has not been resolved, the display color of the signal light is controlled to switch from the third color to the second color.
[0285] According to another embodiment of this application, Figure 14 The network change monitoring device shown can be composed of individual or combined units into one or more other units, or some of the units can be further divided into multiple functionally smaller units. This achieves the same operation without affecting the technical effects of the embodiments of this application. The above units are based on logical function division. In practical applications, the function of one unit can be implemented by multiple units, or the function of multiple units can be implemented by one unit. In other embodiments of this application, the network change monitoring device may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented collaboratively by multiple units.
[0286] According to another embodiment of this application, a method such as [example method] can be constructed by running a computer program (including one or more instructions) capable of executing the steps involved in the various methods on a general-purpose computing device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM). Figure 14The network change monitoring device shown herein, and the network change monitoring method for implementing the embodiments of this application, are described. The computer program may be recorded on, for example, a computer-readable storage medium, loaded onto the aforementioned computing device via the computer-readable storage medium, and run therein.
[0287] It is worth noting that, in the embodiments of this application, the terms "module" or "unit" refer to a computer program or part of a computer program with a predetermined function, which works together with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can contain a portion of the overall module or unit's functionality.
[0288] This application embodiment can scan for network alarms when making network changes to the network devices indicated in the target change order. Upon detecting a network alarm, it automatically analyzes the correlation between the network alarm and the target change order based on the network monitoring configuration of the network devices in the target change order, obtaining a relationship analysis result. Based on this result, it quickly illuminates the indicator light corresponding to the target change order, allowing the color of the indicator light to promptly and intuitively indicate whether the current network change has caused a network anomaly, improving the timeliness of network change monitoring. Furthermore, it can obtain the contextual information of the network alarm, which indicates the cause of the anomaly and whether the network alarm was assigned to the target change order. Based on this contextual information, it can accurately perform a secondary analysis of the correlation between the network alarm and the target change order, obtaining a correlation detection result. The display color of the indicator light corresponding to the target change order is then corrected based on the correlation detection result, making the indicator light display more accurate and reducing the false alarm rate for network anomalies corresponding to that indicator light, thereby improving the accuracy of network change monitoring.
[0289] Based on the description of the above method and apparatus embodiments, this application also provides a computer device. Please refer to... Figure 15The computer device includes at least a processor 1501, an input interface 1502, an output interface 1503, and a computer storage medium 1504. The processor 1501, input interface 1502, output interface 1503, and computer storage medium 1504 within the computer device can be connected via a bus or other means. The computer storage medium 1504 can be stored in the computer device's memory. The computer storage medium 1504 is used to store a computer program, which includes one or more instructions. The processor 1501 is used to execute one or more instructions from the computer program stored in the computer storage medium 1504. The processor 1501 (or CPU (Central Processing Unit)) is the computing and control core of the computer device, adapted to implement one or more instructions, specifically adapted to load and execute one or more instructions to achieve a corresponding method flow or function.
[0290] In one embodiment, the processor 1501 described in this application can be used to perform a series of monitoring processes on network changes, specifically including: obtaining a target change order, the target change order corresponding to a signal light, the target change order being used to indicate the network device to be changed and the network monitoring configuration of the network device; when making network changes to the network device indicated by the target change order, scanning for network alarms, the network alarms referring to alarm information generated when network anomalies are detected; if the network alarm is detected, analyzing the correlation between the network alarm and the target change order according to the network monitoring configuration of the network device, obtaining a relationship analysis result, and lighting up the signal light corresponding to the target change order based on the relationship analysis result; obtaining the context information of the network alarm, the context information being used to indicate at least one of the following: the cause of the anomaly corresponding to the network alarm, and whether the network alarm is assigned to the target change order; detecting the correlation between the network alarm and the target change order based on the context information, obtaining a correlation detection result, and correcting the display color of the signal light corresponding to the target change order based on the correlation detection result, etc.
[0291] This application embodiment also provides a computer storage medium (Memory), which is a memory device in a computer device used to store computer programs and data. It is understood that the computer storage medium here can include both the built-in storage medium in the computer device and extended storage media supported by the computer device. The computer storage medium provides storage space that stores the operating system of the computer device. Furthermore, the storage space also stores a computer program, which includes one or more instructions suitable for loading and execution by the processor 1501. These instructions can be one or more program codes. It should be noted that the computer storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device; optionally, it can also be at least one computer storage medium located remotely from the aforementioned processor.
[0292] In one embodiment, a processor may load and execute one or more instructions stored in a computer storage medium to implement the corresponding steps in the above method embodiments; specifically, one or more instructions in the computer storage medium may be loaded and executed by the processor in the following steps:
[0293] Obtain a target change order, which corresponds to a signal light. The target change order is used to indicate the network device to be changed and the network monitoring configuration of the network device.
[0294] When making network changes to the network devices indicated in the target change order, scan for network alarms. The network alarms refer to alarm information generated when network anomalies are detected.
[0295] If the network alarm is detected, the correlation between the network alarm and the target change order is analyzed according to the network monitoring configuration of the network device to obtain the relationship analysis result, and the signal light corresponding to the target change order is lit based on the relationship analysis result.
[0296] Obtain the context information of the network alarm, the context information being used to indicate at least one of the following: the cause of the anomaly corresponding to the network alarm, and whether the network alarm is assigned to the target change order;
[0297] Based on the context information, the correlation between the network alarm and the target change order is detected to obtain the correlation detection result, and the display color of the signal light corresponding to the target change order is corrected based on the correlation detection result.
[0298] In one implementation, the context information is used to indicate the cause of the anomaly corresponding to the network alarm; correspondingly, when detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result, the one or more instructions can be loaded and executed by the processor:
[0299] If the context information indicates that the cause of the anomaly is a network device malfunction, then the device correlation between the malfunctioning network device and the network change device is detected; the network change device refers to the network device that is undergoing network change as indicated in the target change order.
[0300] If the device correlation is detected, it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result indicating the correlation is generated.
[0301] If no device correlation is detected, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating that there is no correlation is generated.
[0302] In another implementation, the context information is used to indicate the cause of the anomaly corresponding to the network alarm; correspondingly, when detecting the correlation between the network alarm and the target change order based on the context information and obtaining the correlation detection result, one or more instructions can be loaded and executed by the processor:
[0303] If the anomaly indicated by the context information is caused by server operation, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating that there is no correlation is generated.
[0304] In another implementation, the context information is used to indicate the cause of the anomaly corresponding to the network alarm;
[0305] The step of detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result further includes:
[0306] If the anomaly indicated by the context information is caused by main optical jitter, then obtain the network change type;
[0307] When the network change type is a data communication change, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is no correlation.
[0308] When the network change type is wavelength division multiplexing (WDM), if the jittered main light is associated with the main light corresponding to the network change, it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is a correlation; if the jittered main light is not associated with the main light corresponding to the network change, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is no correlation.
[0309] In another implementation, the context information is used to indicate whether the network alarm is assigned to the target change order; correspondingly, when detecting the correlation between the network alarm and the target change order based on the context information and obtaining the correlation detection result, the one or more instructions can be loaded and executed by the processor:
[0310] If the context information is used to indicate that the network alarm is assigned to the target change order, then it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result is generated;
[0311] If the context information is used to indicate that the network alarm has not been assigned to the target change order, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated.
[0312] In another implementation, when the indicator light corresponding to the target change order displays a first color, the first color indicates that the network change corresponding to the target change order has caused a network anomaly and needs to be rolled back. Correspondingly, when correcting the display color of the indicator light corresponding to the target change order based on the correlation detection result, one or more instructions can be loaded and executed by the processor.
[0313] If the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order will be kept as the first color;
[0314] If the correlation detection result indicates that there is no correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order is corrected to the second color; the second color is used to indicate that the network change corresponding to the target change order has not caused a network anomaly and the network change needs to be suspended.
[0315] In another implementation, when the indicator light corresponding to the target change order displays a second color, the second color indicates that the network change corresponding to the target change order has not caused a network anomaly and the network change needs to be paused. Correspondingly, when correcting the display color of the indicator light corresponding to the target change order based on the correlation detection result, one or more instructions can be loaded and executed by the processor.
[0316] If the correlation detection result indicates that there is no correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order will be kept as the second color.
[0317] If the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the network change operation is detected in the device operation log within the target time period. The target time period is obtained by extending the duration of a preset time period.
[0318] If no network change operation occurs within the target time period, the display color of the traffic light corresponding to the target change order will remain the second color; if a network change operation occurs within the target time period, the display color of the traffic light corresponding to the target change order will be corrected to the first color.
[0319] In another implementation, when the indicator light corresponding to the target change order displays a third color, the third color indicates that the network change corresponding to the target change order has not caused a network anomaly, and the network change continues; the one or more instructions can be loaded and executed by the processor.
[0320] If the alarm duration of the network alarm is greater than the duration threshold, and the network alarm is not assigned to any change order, then the network anomaly area and the area where the network device indicated by the target change order is located are determined; wherein, the network anomaly area includes: the area indicated by any area identifier in the network alarm;
[0321] If the network anomaly area matches the area where the network device indicated by the target change order is located, then the display color of the indicator light corresponding to the target change order will be corrected to the first color;
[0322] If the network anomaly area does not match the area where the network device indicated by the target change order is located, the display color of the indicator light corresponding to the target change order will remain the third color.
[0323] In another implementation, the number of network devices is one or more; correspondingly, when analyzing the correlation between the network alarms and the target change order based on the network monitoring configuration of the network devices to obtain the relationship analysis results, the one or more instructions can be loaded and executed by the processor:
[0324] Based on the network monitoring configuration of each network device, the corresponding network device is associated with the network alarm in a spatial dimension;
[0325] If no network device is successfully associated with the network alarm in the spatial dimension, it is determined that there is no spatial association between the network alarm and the target change order, and a relationship analysis result is generated; the relationship analysis result is used to indicate that the network alarm and the target change order are not associated.
[0326] If a network device is successfully associated with the network alarm in a spatial dimension, it is determined that there is a spatial association between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial association.
[0327] In another implementation, both the network monitoring configuration and the network alarm include at least one source region identifier and at least one destination region identifier, with one source region identifier and one destination region identifier constituting a network transmission direction. Correspondingly, when associating the corresponding network device with the network alarm in a spatial dimension according to the network monitoring configuration of each network device, the one or more instructions can be loaded and executed by the processor.
[0328] When the network alarm includes one source region identifier and multiple destination region identifiers, the source region identifier in the network alarm is regarded as an abnormal intersection point;
[0329] In the network monitoring configuration of the i-th network device, the source region identifier that is the same as the abnormal intersection point is matched to obtain the first matching result; where i is a positive integer and is less than or equal to the number of network devices;
[0330] If the first matching result indicates a successful match, then it is determined that the i-th network device and the network alarm are successfully associated in the spatial dimension.
[0331] If the first matching result indicates a matching failure, then it is determined that the i-th network device and the network alarm have failed to be associated in the spatial dimension.
[0332] In another implementation, when generating relationship analysis results based on the spatial association, the one or more instructions can be loaded and executed by the processor:
[0333] Network devices that are successfully associated in the spatial dimension are identified as suspicious devices. The device operation logs of the suspicious devices are obtained. The device operation logs are used to record the device operations that have been performed and the execution time of the corresponding device operations. The reference time of the network alarm is also obtained.
[0334] Based on the device operation logs of the suspicious device and the reference time of the network alarm, the suspicious device and the network alarm are associated in the time dimension;
[0335] If the suspicious device fails to be associated with the network alarm in the time dimension, it is determined that there is no time association between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial association. The relationship analysis result is used to indicate that there is a spatial association between the network alarm and the target change order, but no time association.
[0336] If the suspicious device is successfully associated with the network alarm in the time dimension, it is determined that there is a time correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the time correlation and the spatial correlation. The relationship analysis result is used to indicate that there is a spatial correlation and a time correlation between the network alarm and the target change order.
[0337] In another implementation, when obtaining the reference time of the network alarm, the one or more instructions can be loaded and executed by the processor:
[0338] Obtain the anomaly start time corresponding to the network alarm, and use it as the reference time for the network alarm;
[0339] The anomaly start time refers to the time when the network anomaly corresponding to the network alarm occurs.
[0340] In another implementation, when associating the suspicious device with the network alarm in a time dimension based on the device operation log of the suspicious device and the reference time of the network alarm, the one or more instructions can be loaded and executed by the processor:
[0341] Search the device operation log of the suspected device for target device operations, where the target device operations refer to network change operations performed within a preset time period before the reference time of the network alarm.
[0342] If the target device operation is found in the device operation log, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension.
[0343] If no operation of the target device is found in the device operation log, it is determined that the suspicious device and the network alarm are not associated in the time dimension.
[0344] In another implementation, any network device receives a target network change task from the device management platform, determines a target change order based on the target network change task, and performs network changes according to the instructions of the target change order; after issuing the target network change task, the device management platform determines the task execution log corresponding to the target network change task, and the task execution log records the various device operations performed by the network device based on the target network change task;
[0345] Accordingly, if the target device operation is found in the device operation log, and it is determined that the suspicious device and the network alarm are successfully associated in the time dimension, the one or more instructions can be loaded and executed by the processor:
[0346] If the target device operation is found in the device operation log, then the task execution log of the target network change task is obtained;
[0347] If the task execution log records the operation of the target device, then it is determined that the suspicious device and the network alarm are successfully associated in the time dimension.
[0348] If the task execution log does not record the operation of the target device, it is determined that the suspicious device and the network alarm are not associated in the time dimension.
[0349] In another implementation, the device operation log is also used to record the operation accounts of the executed device operations; correspondingly, if the task execution log records the target device operation, then the one or more instructions can be loaded and executed by the processor.
[0350] Obtain the operation account for the target device from the device operation log of the suspicious device;
[0351] If the operation account belongs to the platform account in the device management platform, then the step of obtaining the task execution log corresponding to the target network change task is triggered;
[0352] If the operation account is a personal account, then the consistency between the operation account and the implementer account corresponding to the target change order shall be verified.
[0353] If the consistency check is successful, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension; if the consistency check fails, it is determined that the suspicious device and the network alarm are not successfully associated in the time dimension.
[0354] In another implementation, the one or more instructions may be loaded and executed by the processor:
[0355] If the operating account belongs to another account, then it is determined that the suspicious device and the network alarm are successfully associated in the time dimension;
[0356] The other accounts refer to accounts other than the platform account and the personal account.
[0357] In another implementation, if no target device operation is found in the device operation log, the one or more instructions can be loaded and executed by the processor:
[0358] Obtain the task execution log of the target network change task corresponding to the target change order, and search for the target device operation in the task execution log;
[0359] If the target device operation is found in the task execution log, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension.
[0360] If no target device operation is found in the task execution log, the step of determining that the suspicious device and the network alarm failed to be associated in the time dimension is triggered.
[0361] In another implementation, the target change order indicates multiple network devices, and these network devices undergo network changes in batches; after identifying network devices that are successfully associated in the spatial dimension as suspicious devices, the one or more instructions can be loaded and executed by the processor:
[0362] The batch to which the network device currently undergoing network changes belongs is determined as the current batch;
[0363] If the suspicious device is in the current batch, then the step of associating the suspicious device with the network alarm in the time dimension based on the reference time of the device operation log of the suspicious device and the network alarm is triggered.
[0364] If the suspicious device is not in the current batch, the signal light is illuminated with the third color, and the second color is recorded in the storage space. When the batch in which the suspicious device is located begins to undergo network changes, if the network alarm has been resolved, the display color of the signal light is controlled to remain at the third color. If the network alarm has not been resolved, the display color of the signal light is controlled to switch from the third color to the second color.
[0365] This application embodiment can scan for network alarms when making network changes to the network devices indicated in the target change order. Upon detecting a network alarm, it automatically analyzes the correlation between the network alarm and the target change order based on the network monitoring configuration of the network devices in the target change order, obtaining a relationship analysis result. Based on this result, it quickly illuminates the indicator light corresponding to the target change order, allowing the color of the indicator light to promptly and intuitively indicate whether the current network change has caused a network anomaly, improving the timeliness of network change monitoring. Furthermore, it can obtain the contextual information of the network alarm, which indicates the cause of the anomaly and whether the network alarm was assigned to the target change order. Based on this contextual information, it can accurately perform a secondary analysis of the correlation between the network alarm and the target change order, obtaining a correlation detection result. The display color of the indicator light corresponding to the target change order is then corrected based on the correlation detection result, making the indicator light display more accurate and reducing the false alarm rate for network anomalies corresponding to that indicator light, thereby improving the accuracy of network change monitoring.
[0366] It should be noted that, according to one aspect of this application, a computer program product or computer program is also provided, comprising one or more instructions stored in a computer storage medium. A processor of a computer device reads one or more instructions from the computer storage medium and executes the one or more instructions, causing the computer device to perform the methods provided in the various optional embodiments of the above-described methods. It should be understood that the above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, equivalent variations made according to the claims of this application are still within the scope of this application.
Claims
1. A method for monitoring network changes, characterized in that, Obtain a target change order, which corresponds to a signal light. The target change order is used to indicate the network device to be changed and the network monitoring configuration of the network device. When making network changes to the network devices indicated in the target change order, scan for network alarms. The network alarms refer to alarm information generated when network anomalies are detected. If the network alarm is detected, the correlation between the network alarm and the target change order is analyzed according to the network monitoring configuration of the network device to obtain the relationship analysis result, and the signal light corresponding to the target change order is lit based on the relationship analysis result. Obtain the context information of the network alarm, the context information being used to indicate at least one of the following: the cause of the anomaly corresponding to the network alarm, and whether the network alarm is assigned to the target change order; Based on the context information, the correlation between the network alarm and the target change order is detected to obtain the correlation detection result, and the display color of the signal light corresponding to the target change order is corrected based on the correlation detection result.
2. The method as described in claim 1, characterized in that, The context information is used to indicate the cause of the anomaly corresponding to the network alarm; The step of detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result includes: If the context information indicates that the cause of the anomaly is a network device malfunction, then the device correlation between the malfunctioning network device and the network change device is detected; the network change device refers to the network device that is undergoing network change as indicated in the target change order. If the device correlation is detected, it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result indicating the correlation is generated. If no device correlation is detected, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating that there is no correlation is generated.
3. The method as described in claim 1, characterized in that, The context information is used to indicate the cause of the anomaly corresponding to the network alarm; The step of detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result further includes: If the anomaly indicated by the context information is caused by server operation, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result indicating that there is no correlation is generated.
4. The method as described in claim 1, characterized in that, The context information is used to indicate the cause of the anomaly corresponding to the network alarm; The step of detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result further includes: If the anomaly indicated by the context information is caused by main optical jitter, then obtain the network change type; When the network change type is a data communication change, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is no correlation. When the network change type is wavelength division multiplexing (WDM), if the jittered main light is associated with the main light corresponding to the network change, it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is a correlation; if the jittered main light is not associated with the main light corresponding to the network change, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated to indicate that there is no correlation.
5. The method as described in claim 1, characterized in that, The context information is used to indicate whether the network alarm is assigned to the target change order; The step of detecting the correlation between the network alarm and the target change order based on the context information to obtain the correlation detection result further includes: If the context information is used to indicate that the network alarm is assigned to the target change order, then it is determined that there is a correlation between the network alarm and the target change order, and a correlation detection result is generated; If the context information is used to indicate that the network alarm has not been assigned to the target change order, it is determined that there is no correlation between the network alarm and the target change order, and a correlation detection result is generated.
6. The method according to any one of claims 1-5, characterized in that, When the indicator light corresponding to the target change order displays the first color, the first color indicates that the network change corresponding to the target change order has caused a network anomaly and the network change needs to be rolled back. The step of correcting the display color of the traffic light corresponding to the target change order based on the correlation detection result includes: If the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order will be kept as the first color; If the correlation detection result indicates that there is no correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order is corrected to the second color; the second color is used to indicate that the network change corresponding to the target change order has not caused a network anomaly and the network change needs to be suspended.
7. The method according to any one of claims 1-5, characterized in that, When the indicator light corresponding to the target change order displays the second color, the second color indicates that the network change corresponding to the target change order has not caused a network anomaly and the network change needs to be paused. The step of correcting the display color of the traffic light corresponding to the target change order based on the correlation detection result includes: If the correlation detection result indicates that there is no correlation between the network alarm and the target change order, then the display color of the indicator light corresponding to the target change order will be kept as the second color. If the correlation detection result indicates that there is a correlation between the network alarm and the target change order, then the network change operation is detected in the device operation log within the target time period. The target time period is obtained by extending the duration of a preset time period. If no network change operation occurs within the target time period, the display color of the traffic light corresponding to the target change order will remain the second color; if a network change operation occurs within the target time period, the display color of the traffic light corresponding to the target change order will be corrected to the first color.
8. The method as described in claim 1, characterized in that, When the indicator light corresponding to the target change order displays the third color, the third color indicates that the network change corresponding to the target change order has not caused a network anomaly, and the network change continues. The method further includes: If the alarm duration of the network alarm is greater than the duration threshold, and the network alarm is not assigned to any change order, then the network anomaly area and the area where the network device indicated by the target change order is located are determined; wherein, the network anomaly area includes: the area indicated by any area identifier in the network alarm; If the network anomaly area matches the area where the network device indicated by the target change order is located, then the display color of the indicator light corresponding to the target change order will be corrected to the first color; If the network anomaly area does not match the area where the network device indicated by the target change order is located, the display color of the indicator light corresponding to the target change order will remain the third color.
9. The method as described in claim 1, characterized in that, The number of network devices is one or more; the step of analyzing the correlation between the network alarms and the target change order based on the network monitoring configuration of the network devices to obtain the relationship analysis results includes: Based on the network monitoring configuration of each network device, the corresponding network device is associated with the network alarm in a spatial dimension; If no network device is successfully associated with the network alarm in the spatial dimension, it is determined that there is no spatial association between the network alarm and the target change order, and a relationship analysis result is generated; the relationship analysis result is used to indicate that the network alarm and the target change order are not associated. If a network device is successfully associated with the network alarm in a spatial dimension, it is determined that there is a spatial association between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial association.
10. The method as described in claim 9, characterized in that, Each network monitoring configuration and the network alarm includes at least one source region identifier and at least one destination region identifier, and one source region identifier and one destination region identifier are used to constitute a network transmission direction; The step of associating the corresponding network devices with the network alarms spatially based on the network monitoring configuration of each network device includes: When the network alarm includes a source region identifier and multiple destination region identifiers, the source region identifier in the network alarm is regarded as an abnormal intersection point; In the network monitoring configuration of the i-th network device, the source region identifier that is the same as the abnormal intersection point is matched to obtain the first matching result; where i is a positive integer and is less than or equal to the number of network devices; If the first matching result indicates a successful match, then it is determined that the i-th network device and the network alarm are successfully associated in the spatial dimension. If the first matching result indicates a matching failure, then it is determined that the i-th network device and the network alarm have failed to be associated in the spatial dimension.
11. The method as described in claim 9, characterized in that, The relationship analysis results generated based on the spatial association include: Network devices that are successfully associated in the spatial dimension are identified as suspicious devices. The device operation logs of the suspicious devices are obtained. The device operation logs are used to record the device operations that have been performed and the execution time of the corresponding device operations. The reference time of the network alarm is also obtained. Based on the device operation logs of the suspicious device and the reference time of the network alarm, the suspicious device and the network alarm are associated in the time dimension; If the suspicious device fails to be associated with the network alarm in the time dimension, it is determined that there is no time association between the network alarm and the target change order, and a relationship analysis result is generated based on the spatial association. The relationship analysis result is used to indicate that there is a spatial association between the network alarm and the target change order, but no time association. If the suspicious device is successfully associated with the network alarm in the time dimension, it is determined that there is a time correlation between the network alarm and the target change order, and a relationship analysis result is generated based on the time correlation and the spatial correlation. The relationship analysis result is used to indicate that there is a spatial correlation and a time correlation between the network alarm and the target change order.
12. The method as described in claim 11, characterized in that, The reference time for obtaining the network alarm includes: Obtain the anomaly start time corresponding to the network alarm, and use it as the reference time for the network alarm; The anomaly start time refers to the time when the network anomaly corresponding to the network alarm occurs.
13. The method as described in claim 11, characterized in that, The method of associating the suspicious device with the network alarm in a time dimension based on the device operation log of the suspicious device and the reference time of the network alarm includes: Search the device operation log of the suspected device for target device operations, where the target device operations refer to network change operations performed within a preset time period before the reference time of the network alarm. If the target device operation is found in the device operation log, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension. If no operation of the target device is found in the device operation log, it is determined that the suspicious device and the network alarm are not associated in the time dimension.
14. The method as described in claim 13, characterized in that, Any network device receives a target network change task from the device management platform, determines a target change order based on the target network change task, and performs network changes according to the instructions of the target change order; after issuing the target network change task, the device management platform determines the task execution log corresponding to the target network change task, and the task execution log records the various device operations performed by the network device based on the target network change task; If the target device operation is found in the device operation log, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension, including: If the target device operation is found in the device operation log, then the task execution log of the target network change task is obtained; If the task execution log records the operation of the target device, then it is determined that the suspicious device and the network alarm are successfully associated in the time dimension. If the task execution log does not record the operation of the target device, it is determined that the suspicious device and the network alarm are not associated in the time dimension.
15. The method as described in claim 14, characterized in that, The device operation log is also used to record the operation accounts of the device operations that have been performed. If the task execution log records the operation of the target device, the method further includes: Obtain the operation account for the target device from the device operation log of the suspicious device; If the operation account belongs to the platform account in the device management platform, then the step of obtaining the task execution log corresponding to the target network change task is triggered; If the operation account is a personal account, then the consistency between the operation account and the implementer account corresponding to the target change order shall be verified. If the consistency check is successful, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension; if the consistency check fails, it is determined that the suspicious device and the network alarm are not successfully associated in the time dimension.
16. The method as described in claim 15, characterized in that, The method further includes: If the operating account belongs to another account, then it is determined that the suspicious device and the network alarm are successfully associated in the time dimension; The other accounts refer to accounts other than the platform account and the personal account.
17. The method according to any one of claims 13-16, characterized in that, If no target device operation is found in the device operation log, the method further includes: Obtain the task execution log of the target network change task corresponding to the target change order, and search for the target device operation in the task execution log; If the target device operation is found in the task execution log, it is determined that the suspicious device and the network alarm are successfully associated in the time dimension. If no target device operation is found in the task execution log, the step of determining that the suspicious device and the network alarm failed to be associated in the time dimension is triggered.
18. The method according to any one of claims 11-16, characterized in that, The target change order indicates multiple network devices, and these network devices undergo network changes in batches; after identifying network devices successfully associated in the spatial dimension as suspicious devices, the method further includes: The batch to which the network device currently undergoing network changes belongs is determined as the current batch; If the suspicious device is in the current batch, then the step of associating the suspicious device with the network alarm in the time dimension based on the reference time of the device operation log of the suspicious device and the network alarm is triggered. If the suspicious device is not in the current batch, the signal light is illuminated with the third color, and the second color is recorded in the storage space. When the batch in which the suspicious device is located begins to undergo network changes, if the network alarm has been resolved, the display color of the signal light is controlled to remain at the third color. If the network alarm has not been resolved, the display color of the signal light is controlled to switch from the third color to the second color.
19. A network change monitoring device, characterized in that, An acquisition unit is used to acquire a target change order, wherein the target change order corresponds to a signal light, and the target change order is used to indicate the network device to be changed and the network monitoring configuration of the network device. The processing unit is used to scan for network alarms when making network changes to the network devices indicated in the target change order. The network alarms refer to alarm information generated when network anomalies are detected. The processing unit is further configured to, if the network alarm is detected, analyze the correlation between the network alarm and the target change order according to the network monitoring configuration of the network device, obtain the relationship analysis result, and light up the signal light corresponding to the target change order based on the relationship analysis result; The acquisition unit is further configured to acquire the context information of the network alarm, the context information being used to indicate at least one of the following: the cause of the anomaly corresponding to the network alarm, and whether the network alarm is assigned to the target change order; The processing unit is further configured to detect the correlation between the network alarm and the target change order based on the context information, obtain the correlation detection result, and correct the display color of the signal light corresponding to the target change order based on the correlation detection result.
20. A computer device, comprising an input interface and an output interface, characterized in that, Also includes: Processor and computer storage media; The processor is adapted to implement one or more instructions, the computer storage medium stores one or more instructions, and the one or more instructions are adapted to be loaded by the processor and executed as described in any one of claims 1-18 for monitoring network changes.