Methods, devices, media, and programs for field search based on time trend information

By acquiring and calculating the temporal feature correlation information of the target field, calculating the time trend pattern score of each field value and sorting them, the problem of ignoring the time trend in the sorting of field values ​​in the existing technology is solved, and the efficiency and accuracy of quickly locating and displaying the field values ​​with regular changes are improved.

CN122086979APending Publication Date: 2026-05-26BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING YOUTEJIE INFORMATION TECH
Filing Date
2026-01-30
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

In existing technologies, the sorting method of field values ​​ignores the dynamic trend of data changes over time and cannot reflect the changing trend of field value activity or importance. This makes it difficult to quickly identify the most active, fastest growing, or suddenly appearing problem entities, affecting the auxiliary role of performance analysis and capacity planning.

Method used

By obtaining the temporal feature correlation information of the target field, the time trend pattern score of each field value is calculated, and the values ​​are sorted according to the score. The sorting results are then displayed to highlight the field values ​​with significant time trends.

Benefits of technology

It improves the efficiency and accuracy of querying and searching field values ​​that change regularly, and can quickly locate field values ​​with significant time trends, supporting stable business operation, risk control and efficiency improvement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122086979A_ABST
    Figure CN122086979A_ABST
Patent Text Reader

Abstract

This invention discloses a field search method, device, medium, and program based on time trend information. The method includes: in response to a dropdown query list trigger request for a target field, obtaining time feature association information of the target field; calculating a time trend pattern score for each field value of the target field based on the time feature association information; sorting each field value of the target field according to the time trend pattern score; and displaying the sorting results of each field value in the dropdown query list of the target field. The technical solution of this invention can improve the efficiency and accuracy of querying and searching field values ​​with regular changes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the fields of computer software application and data processing technology, and in particular to a field search method, apparatus, electronic device, storage medium and program based on time trend information. Background Technology

[0002] In many types of data management systems, such as log management systems, database systems, and device security management systems, dashboard pages are typically provided to improve usability. Users can select fields from dropdown menus and filter the displayed data. In this scenario, the search values ​​in the dropdown menus are usually sorted in ascending or descending order according to the field values ​​of the corresponding query data source.

[0003] In the process of developing this invention, the inventors discovered the following shortcomings in existing technologies: The sorting of field values ​​in dropdown lists based on static attributes (alphabetical order) or global frequency (total frequency) completely ignores the dynamic trends of data over time, failing to reflect changes in the activity or importance of field values, such as growth, decline, and cyclical trends. In actual operation and maintenance and business analysis, the dynamic trends of data over time are often a key focus of data analysis. Traditional ascending / descending or frequency-based sorting of field values ​​cannot reflect these important time patterns, making it difficult to quickly identify the most active, fastest-growing, or suddenly appearing problem entities, thus limiting its auxiliary role in performance analysis and capacity planning scenarios. Summary of the Invention

[0004] This invention provides a field search method, apparatus, electronic device, storage medium, and program based on time trend information, which can improve the efficiency and accuracy of querying and searching field values ​​with regular changes.

[0005] According to one aspect of the present invention, a field search method based on time trend information is provided, comprising: In response to a dropdown query list trigger request for the target field, obtain the time feature association information of the target field; Calculate the time trend pattern score of each field value of the target field based on the time feature correlation information of the target field; The values ​​of each field in the target field are sorted according to the time trend pattern score of each field value; The drop-down query list of the target field displays the sorting results of the values ​​of each field.

[0006] According to another aspect of the present invention, a field search device based on time trend information is provided, comprising: The time feature association information acquisition module is used to acquire the time feature association information of the target field in response to the drop-down query list trigger request of the target field; The time trend pattern score acquisition module is used to calculate the time trend pattern score of each field value of the target field based on the time feature correlation information of the target field. The field value sorting module is used to sort the field values ​​of the target field according to the time trend pattern score of each field value of the target field; The field value sorting and display module is used to display the sorting result information of each field value in the drop-down query list of the target field.

[0007] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the field search method based on time trend information as described in any embodiment of the present invention.

[0008] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the field search method based on time trend information as described in any embodiment of the present invention.

[0009] According to another aspect of the present invention, a computer program product is also provided, comprising a computer program that, when executed by a processor, implements the field search method based on time trend information as described in any embodiment of the present invention.

[0010] This invention, in response to a dropdown query list trigger request for a target field, obtains the time-related information of the target field, calculates the time trend pattern score of each field value of the target field based on the time-related information, and then sorts the field values ​​of the target field according to the time trend pattern score, displaying the sorted results in the dropdown query list of the target field. This technical solution uses the time trend information of the field as the core sorting dimension, thereby quickly locating field values ​​with significant time trends when querying field values ​​in a list of field values. It solves the problem that existing methods of sorting field values ​​alphabetically or by indiscriminate frequency are insufficient for quickly locating regularly changing field values, thus improving the efficiency and accuracy of querying regularly changing field values.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart of a field search method based on time trend information provided in Embodiment 1 of the present invention; Figure 2 This is a flowchart of a field search method based on time trend information provided in Embodiment 2 of the present invention; Figure 3 This is a schematic diagram of a field search device based on time trend information provided in Embodiment 3 of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation

[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0015] It should be noted that the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product or device.

[0016] Example 1 Figure 1This is a flowchart of a field search method based on time trend information provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where the values ​​of each field are sorted and queried based on the time trend analysis of the field. This method can be executed by a field search device based on time trend information. This device can be implemented in software and / or hardware, and is generally integrated into an electronic device. This electronic device can be a terminal device or a server device, as long as it can execute the field search method based on time trend information. The present invention does not limit the specific type of electronic device. Correspondingly, as... Figure 1 As shown, the method includes the following operations: S110. In response to the drop-down query list trigger request of the target field, obtain the time feature association information of the target field.

[0017] The target field can be the field from which the user needs to query a search result. The target field is also a field within the target system platform that provides a list of field value queries. Optionally, the target system platform can be a data management system platform capable of providing field value query and retrieval functions, such as, but not limited to, log management systems, database systems, and device security management systems. Correspondingly, different types of target system platforms may offer different types of fields for field value queries. For example, when the target system platform is a log management platform, the fields included in the dropdown query list could be source IP address, destination IP address, and host, etc. When the target system platform is a database system platform, the fields included in the dropdown query list could be number, region, and device, etc. Time feature association information can be information related to the time characteristics of the target field within a set query time range. The dropdown query list can be a list of all field values ​​corresponding to the target field, and may include all field values ​​of the target field. For example, when the target field is an IP address, its corresponding field value can be detailed IP address information; when the target field is a hostname, its corresponding field value can be detailed hostname or host identifier information; when the target field is a device, its corresponding field value can be detailed device name or device identifier information.

[0018] In various application scenarios such as data analysis, data processing, information retrieval, and database management, users often focus on field values ​​related to "trending hotspots" or "emerging issues" when querying search field values. These field values ​​can be called regularly changing field values, carrying predictable and inductive trends. They can serve as the core basis for data classification and clustering, the foundation for data prediction and trend analysis, and key indicators for data verification and anomaly detection. They are core elements supporting stable business operation, risk control, and efficiency / utilization improvement. For example, in log management applications, when querying IP address field values, users may pay more attention to which IP addresses (Internet Protocol Addresses) are experiencing rapid growth in access volume to initially filter out log information that may involve successful marketing campaigns or web crawler attacks. Alternatively, some users may pay more attention to which error codes have recently started appearing to determine if there are new version defects based on the search field values. Or, some users may pay more attention to which user accounts suddenly become active outside of working hours to determine if there is a risk of account theft based on the search field values. In the field of data clusters, it is necessary to monitor the changing patterns of cluster resource-related fields, identify load anomalies, and prevent system downtime. At the same time, it is also possible to monitor the dynamic changes of resource-related fields over time, so as to realize the dynamic allocation of cluster resources based on the dynamic changes of resource fields over time, improve the utilization rate of cluster resources, and ensure the stability of cluster operation.

[0019] To overcome the limitations of traditional field value sorting methods that only sort by letter or simple frequency, and to better meet the needs of quickly locating field values ​​with regular changes in field values, this invention introduces a time trend information dimension into the field value sorting strategy, thereby optimizing the sorting of the list of field values ​​that users need to query.

[0020] When a user needs to query the value of a specific target field within a target system platform, they can select to trigger a dropdown query list for that target field in the current field value query interface of the target system platform. Correspondingly, the target system platform can respond to the dropdown query list trigger request, obtain the time-related information of the target field, and analyze the time-varying trends and patterns of each field value based on this information. Furthermore, it can optimize the sorting method based on these time-varying trends and patterns.

[0021] S120. Calculate the time trend pattern score of each field value of the target field based on the time feature association information of the target field.

[0022] Among them, the time trend pattern score can be used to evaluate the trend and distribution pattern of a field value over time.

[0023] Specifically, the temporal feature correlation information of the target field can be parsed to obtain the distribution pattern and characteristics of each field value of the target field in the time dimension. Then, based on the parsed distribution pattern and characteristics of each field value of the target field in the time dimension, calculations and evaluations can be performed to obtain the time trend pattern score of each field value of the target field.

[0024] S130. Sort the values ​​of each field of the target field according to the time trend pattern score of each field value of the target field.

[0025] Accordingly, after calculating the time trend pattern score of each field value of the target field based on the time characteristic correlation information, the field values ​​of the target field can be sorted according to the time trend pattern score. For example, the field values ​​of the target field can be sorted in descending order of time trend pattern score. Optionally, the higher the time trend pattern score, the more significant the regularity or high activity trend of the field value within the query time range, the higher its value for analysis, and the more conducive it is to supporting stable business operation, risk control, and improving efficiency and utilization.

[0026] S140. Display the sorting results of the values ​​of each field in the drop-down query list of the target field.

[0027] After sorting the values ​​of each field in the dropdown list of the target field based on time trend information, the sorted results can be displayed in the dropdown list. For example, assuming the target field is an IP address, time trend information can be used to sort the specific IP addresses in the dropdown list, prioritizing IP addresses with rapidly increasing access volume for faster user queries and responses. Similarly, assuming the target field is an error code, time trend information can be used to sort the error codes in the user's dropdown list, prioritizing newly appearing error codes for faster queries and responses. And if the target field is a user account, time trend information can be used to sort the user accounts in the user's dropdown list, prioritizing user accounts that suddenly become active outside of working hours for faster queries and responses.

[0028] Therefore, the above technical solution breaks through the limitations of traditional field value query methods that only sort by letter or simple frequency. It introduces time trend information into the field value sorting strategy to leverage time series analysis capabilities to automatically identify and highlight key entities that are "rising," "declining," or "periodicly emerging," determining the dynamic change patterns of field values ​​within the query time range and prioritizing the display of field values ​​with significant trends. This allows users to directly obtain regularly changing entity information (such as IPs and users) at the top of the field value list without scrolling through lengthy lists or making subjective guesses during data analysis. It transforms the field value query method from passive filtering to proactive risk guidance, greatly improving the efficiency of locating regularly changing field information and the accuracy of analysis. This is particularly helpful for performance capacity management, business effectiveness evaluation, and security attack detection, thereby displaying data that is undergoing significant changes in real time, enabling users to make more timely and forward-looking decisions.

[0029] This invention, in response to a dropdown query list trigger request for a target field, obtains the time-related information of the target field, calculates the time trend pattern score of each field value of the target field based on the time-related information, and then sorts the field values ​​of the target field according to the time trend pattern score, displaying the sorted results in the dropdown query list of the target field. This technical solution uses the time trend information of the field as the core sorting dimension, thereby quickly locating field values ​​with significant time trends when querying field values ​​in a list of field values. It solves the problem that existing methods of sorting field values ​​alphabetically or by indiscriminate frequency are insufficient for quickly locating regularly changing field values, thus improving the efficiency and accuracy of querying regularly changing field values.

[0030] Example 2 Figure 2 This is a flowchart of a field search method based on time trend information provided in Embodiment 2 of the present invention. This embodiment is a specific embodiment based on the above embodiment. In this embodiment, various specific optional implementation methods are given for obtaining the time feature association information of the target field, calculating the time trend pattern score of each field value of the target field, and sorting the field values ​​of the target field. Correspondingly, as Figure 2 As shown, the method in this embodiment may include: S210. In response to the drop-down query list trigger request of the target field, obtain the context information of the associated fields of the target field.

[0031] Among them, the context information of the associated field can be the context information related to the target field.

[0032] In this embodiment of the invention, when a user needs to query the value of a target field in a target system platform, they can select to trigger a drop-down query list for the target field in the current field value query interface of the target system platform. Correspondingly, the target system platform can respond to the drop-down query list trigger request for the target field, obtain the context information associated with the target field as the associated field context information, and analyze the query intent for the field value based on the associated field context information.

[0033] S220. Generate the current recommended field value sorting strategy for the target field based on the context information of the associated fields of the target field.

[0034] The field value sorting strategy refers to the strategy used to sort the field values. The currently recommended field value sorting strategy is the recommended field value sorting strategy currently provided for the target field.

[0035] Because different users and / or different fields have different query intentions for field values, various optional field value sorting strategies can be provided for different query intentions. For example, field value sorting strategies may include, but are not limited to, default field value sorting strategies, alarm correlation sorting strategies, rarity sorting strategies, time trend pattern sorting strategies, and business importance sorting strategies. The default field value sorting strategy can be an existing, commonly used field value sorting strategy, such as alphabetical sorting or field value frequency sorting. The alarm correlation sorting strategy can be a strategy that sorts field values ​​based on alarm information. The rarity sorting strategy can be a strategy that sorts field values ​​based on information about the rarity of field values. The time trend pattern sorting strategy can be a strategy that sorts field values ​​based on time and distribution pattern information. The business importance sorting strategy can be a strategy that sorts field values ​​based on information about their business relevance. It is understood that different field value sorting strategies emphasize different information dimensions and content when sorting field values.

[0036] Correspondingly, when a user queries the field value information of a target field based on the field query interface of the target system platform, after the target system platform detects the drop-down query list of the target field triggering a request, it obtains the information context information associated with the target field as the associated field context information of the target field, and generates the current recommended field value sorting strategy of the target field for display based on the associated field context information of the target field.

[0037] For example, when a user clicks on a dropdown list for a target field, such as the source IP address (src_ip), in the log query interface, the log management system captures this event and obtains the context information of the associated fields of the currently queried target field, particularly the specified query time range (e.g., "last 6 hours") and field type. Based on the context information of the associated fields of the target field, such as being in a performance monitoring view, the log management system intelligently determines whether the currently recommended field value sorting strategy is a time trend mode sorting strategy or a default field value sorting strategy, and recommends the aforementioned currently recommended field value sorting strategy to the user. Optionally, the default field value sorting strategy may include, but is not limited to, ascending order sorting strategies and descending order sorting strategies.

[0038] S230. If it is determined that the time trend pattern sorting strategy in the current recommended field value sorting strategy is triggered, obtain the time feature association information of the target field.

[0039] When a user triggers the selection of a time trend mode sorting strategy based on the current recommended field value sorting strategy recommended by the target system platform, the system can filter the content of each field value of the target field within a set time range from the stored full information, as well as the full information related to the time dimension, such as time and business indicators, user behavior, system status, space and event correlation information, as the time feature correlation information of the target field.

[0040] S240. Dynamically divide multiple continuously distributed time windows according to the time filtering range of the target field.

[0041] The time filter range refers to the time range set when querying the field value of the target field.

[0042] Specifically, the time range for the specified target field can be dynamically divided into multiple consecutive time windows. The length of the time window can be dynamically set according to the size of the time range and the specific application scenario. For example, the time window length can be slightly larger for periods of expected high-frequency access to reduce computational complexity. For periods of expected low-frequency access, the time window length can be slightly smaller to accurately capture subtle trends. Longer time ranges can have slightly larger time windows, while shorter time ranges can have slightly smaller time windows. For instance, a 6-hour time range can be divided into 12 consecutive 30-minute time windows.

[0043] S250. Calculate the frequency of occurrence of each field value of the target field within each time window to obtain the time series data of each field value of the target field.

[0044] After dividing the data into multiple time windows that generate a continuous distribution, the frequency of occurrence of each value in the target field can be counted within each time window, forming a time series data of the continuous distribution of each field value. In other words, the time series data of the field values ​​is sorted by time window.

[0045] S260. Calculate the time trend pattern score of each field value of the target field based on the time series data of each field value of the target field.

[0046] After processing the time series data for generating each field value, the time trend pattern score of each field value of the target field can be analyzed and calculated based on the time series data of each field value of the target field.

[0047] In an optional embodiment of the present invention, the step of calculating the time trend pattern score of each field value of the target field based on the time series data of each field value of the target field may include: calculating a single-dimensional time trend pattern score of each field value of the target field based on the time series data of each field value of the target field; wherein the single-dimensional time trend pattern score includes at least one of a growth trend score, a target activity score, and a cyclical volatility score; and performing a weighted calculation based on the single-dimensional time trend pattern score of each field value of the target field and the corresponding weight to obtain the time trend pattern score of each field value of the target field.

[0048] Among them, the single-dimensional time trend pattern score can be used to evaluate and calculate the time trend pattern from the perspective of a single-dimensional time characteristic. The growth trend score can evaluate the change pattern of field values ​​from the perspective of the growth pattern of field values ​​over time. The target activity score can evaluate the change pattern of field values ​​from the perspective of a specific time range of focus. The cyclical volatility score can evaluate the change pattern of field values ​​from the perspective of the cyclical change pattern of field values.

[0049] To improve the accuracy of time trend pattern scoring, the single-dimensional time trend pattern score corresponding to each value of the target field can be evaluated from multiple different dimensions based on the time series data of each field value. For example, the single-dimensional time trend pattern score can be evaluated from the perspectives of growth trend patterns, activity levels during specific periods of focus, and periodicity and volatility patterns, assessing the changes in the field value across multiple dimensions over time. Furthermore, the single-dimensional time trend pattern scores of the target field can be weighted and calculated using the weights configured for each single-dimensional time trend pattern score, resulting in a weighted average of the single-dimensional time trend pattern scores for each field value of the target field.

[0050] Optionally, the weights assigned to the single-dimensional time trend pattern scores can be dynamically configured. It's understandable that different fields focus on different dimensions when evaluating the time trend pattern scores. Therefore, the weights assigned to each single-dimensional time trend pattern score can be dynamically configured by comprehensively considering the type of the target field and the specific application scenario of the current query.

[0051] In an optional embodiment of the present invention, if the single-dimensional time trend pattern score includes a growth trend score, then calculating the single-dimensional time trend pattern score of each field value of the target field based on the time series data of each field value of the target field may include: performing linear regression on the time series data of each field value of the target field in each time window; calculating a slope parameter based on the linear regression result of the time series data; and calculating the growth trend score of each field value of the target field based on the value of the slope parameter.

[0052] When analyzing and evaluating the growth trend scores of each value in a target field, linear regression can be performed on the time series data of each value in each time window to obtain a linear regression model for each value. Further, a slope parameter is calculated based on the linear regression model for each value, and the growth trend score for each value in the target field is calculated based on the value of the slope parameter. It can be understood that a positive slope indicates growth, a negative slope indicates decline, and the larger the absolute value of the slope, the stronger the growth trend and the higher the growth trend score.

[0053] In an optional embodiment of the present invention, if the single-dimensional time trend pattern score includes a target activity score, then calculating the single-dimensional time trend pattern score of each field value of the target field based on the time series data of each field value of the target field may include: determining the target attention time window of each field value of the target field from each time window; calculating the average value of the time series data in the target attention time window and the full time window; calculating the ratio between the average value of the time series data in the target attention time window and the average value of the time series data in the full time window to obtain the target activity score of each field value of the target field.

[0054] The target focus time window can be selected from various time windows, and it is the time window where the changing patterns of field values ​​need to be analyzed.

[0055] When analyzing and evaluating the target activity score of a field value, the first step is to filter the target field values ​​across different time windows to determine the target attention time window. For example, when the target field's time range is small, the most recent 1-2 time windows can be used as the target attention time window. When the target field's time range is large, such as nearly a year, the target attention time window can be intelligently determined based on the type of the target field and its historical analysis data. For instance, if the target field is a username, and historical query records show that username queries are often used to assess activity during specific time periods, such as weekday nights or non-weekdays, to identify potential abnormal login risks, then weekday nights (Monday to Friday, 5:30 PM to 9 AM the next day) can be designated as the first type of target attention time window, and the two days of each weekend can be designated as the second type. For each type of target attention time window, the corresponding target activity score can be calculated separately.

[0056] After determining the target attention time window for each value of the target field, the average value of the time series data within the target attention time window and the full time window can be calculated. Furthermore, the ratio between the average value of the time series data within the target attention time window and the average value of the time series data within the full time window can be calculated to obtain the target activity score for each value of the target field within the corresponding target attention time window. If there are multiple target attention time windows, the average value or a weighted average of the target activity scores calculated for each target attention time window can be calculated to obtain the final target activity score.

[0057] In an optional embodiment of the present invention, if the single-dimensional time trend pattern score includes a periodic volatility score, then calculating the single-dimensional time trend pattern score of each field value of the target field based on the time series data of each field value of the target field may include: calculating the single-dimensional periodic volatility score of each field value of the target field based on the time series data of each field value of the target field; wherein, the single-dimensional periodic volatility score includes a periodicity index score and / or a volatility index score; the periodicity index score includes at least one of a period length score, a seasonal index score, and a periodic volatility score; the volatility index score includes at least one of a standard deviation score, a variance score, a coefficient of variation score, and a range score; and performing a weighted calculation based on each single-dimensional periodic volatility score of each field value of the target field and its corresponding weight to obtain the periodic volatility score of each field value of the target field.

[0058] Among them, the single-dimensional periodic volatility score can calculate the periodic and volatility patterns of the evaluation field values ​​from a single dimension.

[0059] To improve the accuracy of the periodic volatility score when evaluating the calculated field value, multiple dimensions of periodicity and volatility patterns can be considered comprehensively. Specifically, time series data of each field value of the target field can be analyzed, and periodicity index scores and / or volatility index scores of each field value of the target field can be calculated based on the analysis results.

[0060] The periodic indicator score can include, but is not limited to, at least one of cycle length score, seasonal index score, and periodic fluctuation score. Optionally, the cycle length score can automatically analyze the distribution pattern of field values ​​across different time windows. The longer the period of the pattern, the higher the cycle length score. If the target field has a long time range, spanning multiple quarters (e.g., the last three years), the quarterly index of the field value across each time window can be calculated, and the seasonal index score can be determined based on the calculated quarterly index. For example, the time series data of each field value can be preprocessed and arranged by year-month to form a two-dimensional table. Then, a 12-period simple moving average and a centralized moving average can be calculated based on the preprocessed time series data, and the seasonal index can be calculated based on the simple moving average and the centralized moving average. Finally, the seasonal index score is calculated based on the calculated seasonal index. Optionally, the higher the seasonal index score, the higher the seasonal index score. Optionally, if the distribution of field values ​​across different time windows exhibits periodic fluctuations, a periodic fluctuation score can be calculated based on the significance of these fluctuations. The more significant the periodic fluctuation, the higher the score. Correspondingly, if the periodic indicator score includes two or more of the following: cycle length score, seasonal index score, and periodic fluctuation score, the scores can be weighted to obtain the final periodic indicator score.

[0061] Optionally, volatility index scores can be calculated and evaluated using standard deviation, variance, coefficient of variation, range score, and volatility clustering indicators. Specifically, volatility indices such as standard deviation, variance, coefficient of variation, and range can be calculated for time-series data of each field value as needed, and corresponding standard deviation scores, variance scores, coefficient of variation scores, and range scores can be calculated based on the calculated standard deviation, variance, and coefficient of variation. For example, larger standard deviation and variance values ​​indicate more unstable data, resulting in higher standard deviation and variance scores. If the volatility index score includes more than two of the following scores: standard deviation, variance, coefficient of variation, and range score, the scores can be weighted to obtain the final volatility index score.

[0062] Furthermore, a weighted calculation is performed based on the single-dimensional periodic volatility scores and corresponding weights of each field value of the target field to obtain the periodic volatility score of each field value of the target field. Optionally, the weights corresponding to each single-dimensional periodic volatility score can also be dynamically configured, and this embodiment of the invention does not limit this. Optionally, the weight value corresponding to the growth trend score can be greater than the weight value corresponding to the target activity score, and the weight value corresponding to the target activity score can be greater than the weight value corresponding to the periodic volatility score.

[0063] S270. Sort the values ​​of each field of the target field according to the time trend pattern score of each field value of the target field.

[0064] In an optional embodiment of the present invention, sorting the field values ​​of the target field according to the time trend pattern score of each field value of the target field may include: sorting the field values ​​of the target field in descending order according to the time trend pattern score of each field value of the target field; and sorting the target field values ​​according to field identification information when it is determined that the time trend pattern scores of multiple target field values ​​are the same.

[0065] The target field value can be multiple field values ​​that have the same time trend pattern score.

[0066] A higher time trend pattern score indicates a more significant growth or high activity trend in the field value during the query period. Therefore, when sorting the field values ​​of a target field based on their time trend pattern scores, if the scores are different, they can be sorted in descending order. If multiple target field values ​​have the same score, they can be further sorted by field identifier information, in addition to the descending order. For example, they can be sorted alphabetically in descending or ascending order. This embodiment does not limit the secondary sorting method for the target field values. The advantage of this approach is that the field values ​​with the most significant change patterns are placed at the top of the drop-down list. For field values ​​with similar or identical time trend pattern scores, a secondary sort can be performed using traditional ascending or descending alphabetical order, ensuring a clear and orderly drop-down list.

[0067] S280. Display the sorting results of the values ​​of each field in the drop-down query list of the target field.

[0068] To further improve the efficiency of field value queries, the dropdown query list can not only display sorted field values, but also attach trend icons to field values ​​with high trend scores, such as icons indicating increasing, decreasing, or periodic fluctuation trends. Field values ​​with trend icons can also have trend chart information configured synchronously. For example, when a hover operation is detected on a field value with a trend icon, or when a click operation is detected on the trend icon of a field value, a mini line chart of that field value can be displayed. Simultaneously, an authorization interface can be provided to users, allowing them to provide feedback on the field value sorting results, such as "This sorting is helpful," or to receive confirmation or rejection of the "time trend pattern score" marked by the system. This enables the target system platform to interact and iteratively learn, enhancing its understanding of user preferences for trend indicators in different scenarios (such as capacity alerts and attack detection). With user authorization, the target system platform needs to record user preferences for field values ​​to optimize subsequent field value sorting strategies. Specifically, the target system platform can provide an authorization interface to prompt users whether they wish to allow the recording of field value selection preferences. If a user triggers authorization based on a prompt message indicating their preference for recording field values, and then provides feedback to the target system platform allowing the recording of field value selection preferences, the target system platform can record the user's preference information for those field values.

[0069] The above technical solution provides a field search method based on time trend information. Upon responding to a dropdown query list trigger request for a target field, this method obtains the context information of related fields of the target field. Based on this context information, it generates a current recommended field value sorting strategy for the target field. If the time trend pattern sorting strategy within the current recommended field value sorting strategy is triggered, it obtains the time feature association information of the target field. Further, it dynamically divides the target field's time filtering range into multiple continuously distributed time windows, statistically analyzes the frequency of occurrence of each field value within each time window, and obtains the time series data of each field value. Then, it calculates the time trend pattern score for each field value of the target field based on this time series data. After obtaining the time trend pattern score, the target field values ​​are sorted according to these scores, and the sorting results are displayed in the target field's dropdown query list. This field search method based on time trend information can improve the efficiency and accuracy of searching for regularly changing field values.

[0070] It should be noted that all information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) disclosed herein are information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of such data comply with the relevant laws, regulations, and standards of the relevant regions. Furthermore, users may be provided with corresponding access points to choose whether to agree to or reject the automated decision-making results; if the user chooses to reject, the process will proceed to the expert decision-making stage.

[0071] It should be noted that any arrangement or combination of the technical features in the above embodiments also falls within the protection scope of this invention.

[0072] Example 3 Figure 3 This is a schematic diagram of a field search device based on time trend information provided in Embodiment 3 of the present invention, as shown below. Figure 3 As shown, the device includes: a time feature association information acquisition module 310, a time trend pattern scoring acquisition module 320, a field value sorting module 330, and a field value sorting display module 340, wherein: The time feature association information acquisition module 310 is used to acquire the time feature association information of the target field in response to a drop-down query list trigger request of the target field. The time trend pattern score acquisition module 320 is used to calculate the time trend pattern score of each field value of the target field based on the time feature association information of the target field. The field value sorting module 330 is used to sort the field values ​​of the target field according to the time trend pattern score of each field value of the target field; The field value sorting and display module 340 is used to display the sorting result information of each field value in the drop-down query list of the target field.

[0073] This invention, in response to a dropdown query list trigger request for a target field, obtains the time-related information of the target field, calculates the time trend pattern score of each field value of the target field based on the time-related information, and then sorts the field values ​​of the target field according to the time trend pattern score, displaying the sorted results in the dropdown query list of the target field. This technical solution uses the time trend information of the field as the core sorting dimension, thereby quickly locating field values ​​with significant time trends when querying field values ​​in a list of field values. It solves the problem that existing methods of sorting field values ​​alphabetically or by indiscriminate frequency are insufficient for quickly locating regularly changing field values, thus improving the efficiency and accuracy of querying regularly changing field values.

[0074] Optionally, the time feature association information acquisition module 310 is further configured to: in response to a drop-down query list trigger request of the target field, acquire the associated field context information of the target field; generate a current recommended field value sorting strategy for the target field based on the associated field context information of the target field; and acquire the time feature association information of the target field when it is determined that the time trend pattern sorting strategy in the current recommended field value sorting strategy is triggered.

[0075] Optionally, the time trend pattern score acquisition module 320 is further configured to: dynamically divide multiple continuously distributed time windows according to the time filtering range of the target field; count the frequency of occurrence of each field value of the target field within each time window to obtain time series data of each field value of the target field; and calculate the time trend pattern score of each field value of the target field based on the time series data of each field value of the target field.

[0076] Optionally, the time trend pattern score acquisition module 320 is further configured to: calculate a single-dimensional time trend pattern score for each field value of the target field based on the time series data of each field value of the target field; wherein the single-dimensional time trend pattern score includes at least one of growth trend score, target activity score, and periodic volatility score; and perform weighted calculation based on the single-dimensional time trend pattern score of each field value of the target field and the corresponding weight to obtain the time trend pattern score of each field value of the target field.

[0077] Optionally, if the single-dimensional time trend pattern score includes a growth trend score, the time trend pattern score acquisition module 320 is further configured to: perform linear regression on the time series data of each field value of the target field in each time window; calculate the slope parameter based on the linear regression result of the time series data; and calculate the growth trend score of each field value of the target field based on the value of the slope parameter.

[0078] Optionally, if the single-dimensional time trend pattern score includes a target activity score, the time trend pattern score acquisition module 320 is further configured to: determine the target attention time window for each field value of the target field from each field value of the target field in each time window; calculate the average value of the time series data in the target attention time window and the full time window; calculate the ratio between the average value of the time series data in the target attention time window and the average value of the time series data in the full time window to obtain the target activity score for each field value of the target field.

[0079] Optionally, if the single-dimensional time trend pattern score includes a periodic volatility score, the time trend pattern score acquisition module 320 is further configured to: calculate the single-dimensional periodic volatility score of each field value of the target field based on the time series data of each field value of the target field; wherein, the single-dimensional periodic volatility score includes a periodicity index score and / or a volatility index score; the periodicity index score includes at least one of a period length score, a seasonal index score, and a periodic volatility score; the volatility index score includes at least one of a standard deviation score, a variance score, a coefficient of variation score, and a range score; and perform a weighted calculation based on each single-dimensional periodic volatility score of each field value of the target field and its corresponding weight to obtain the periodic volatility score of each field value of the target field.

[0080] Optionally, the field value sorting module 330 is further configured to: sort the field values ​​of the target field in descending order according to the time trend pattern score of each field value of the target field; and sort the target field values ​​according to the field identification information when it is determined that the time trend pattern scores of multiple target field values ​​are the same.

[0081] The aforementioned field search device based on time trend information can execute the field search method based on time trend information provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method. Technical details not described in detail in this embodiment can be found in the field search method based on time trend information provided in any embodiment of the present invention.

[0082] Since the field search device based on time trend information described above is capable of executing the field search method based on time trend information in the embodiments of the present invention, those skilled in the art can understand the specific implementation and various variations of the field search device based on time trend information in this embodiment based on the field search method based on time trend information described in the embodiments of the present invention. Therefore, how the field search device based on time trend information implements the field search method based on time trend information in the embodiments of the present invention will not be described in detail here. Any device used by those skilled in the art to implement the field search method based on time trend information in the embodiments of the present invention falls within the scope of protection of this application.

[0083] Example 4 Figure 4 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0084] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0085] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0086] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as field search methods based on time trend information.

[0087] Optionally, the field search method based on time trend information may include: in response to a drop-down query list trigger request for a target field, obtaining the time feature association information of the target field; calculating the time trend pattern score of each field value of the target field based on the time feature association information of the target field; sorting each field value of the target field based on the time trend pattern score of each field value of the target field; and displaying the sorting result information of each field value in the drop-down query list of the target field.

[0088] In some embodiments, the field search method based on time trend information can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the field search method based on time trend information described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the field search method based on time trend information by any other suitable means (e.g., by means of firmware).

[0089] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0090] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0091] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0092] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0093] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0094] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0095] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0096] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A field search method based on time trend information, characterized by, include: In response to a dropdown query list trigger request for the target field, obtain the time feature association information of the target field; Calculate the time trend pattern score of each field value of the target field based on the time feature correlation information of the target field; The values ​​of each field in the target field are sorted according to the time trend pattern score of each field value; The drop-down query list of the target field displays the sorting results of the values ​​of each field.

2. The method of claim 1, wherein, The process of responding to a dropdown query list trigger request for the target field and obtaining the time feature association information of the target field includes: In response to a dropdown query list trigger request for the target field, obtain the context information of the associated fields of the target field; The current recommended field value sorting strategy for the target field is generated based on the context information of the associated fields of the target field; If it is determined that the time trend pattern sorting strategy in the current recommended field value sorting strategy is triggered, the time feature association information of the target field is obtained.

3. The method of claim 1, wherein, The step of calculating the time trend pattern score of each field value of the target field based on the time feature correlation information of the target field includes: The target field is dynamically divided into multiple continuously distributed time windows based on its time filtering range. The frequency of occurrence of each field value of the target field within each time window is statistically analyzed to obtain the time series data of each field value of the target field; Calculate the time trend pattern score of each field value of the target field based on the time series data of each field value of the target field.

4. The method of claim 3, wherein, The step of calculating the time trend pattern score of each field value of the target field based on the time series data of each field value of the target field includes: Calculate a one-dimensional time trend pattern score for each field value of the target field based on the time series data of each field value of the target field; wherein the one-dimensional time trend pattern score includes at least one of growth trend score, target activity score, and cyclical volatility score; The time trend pattern score of each field value of the target field is obtained by weighting the single-dimensional time trend pattern score of each field value and the corresponding weight.

5. The method according to claim 4, characterized in that, If the single-dimensional time trend pattern score includes a growth trend score, then the single-dimensional time trend pattern score of each field value of the target field is calculated based on the time series data of each field value of the target field, including: Linear regression is performed on the time series data of each field value of the target field in each time window; Calculate the slope parameter based on the linear regression results of the time series data; The growth trend score of each field value of the target field is calculated based on the value of the slope parameter.

6. The method according to claim 4, characterized in that, If the single-dimensional time trend pattern score includes a target activity score, then the single-dimensional time trend pattern score of each field value of the target field is calculated based on the time series data of each field value of the target field, including: The target attention time window for each field value of the target field is determined from each field value of the target field within each time window; Calculate the average value of the time series data within the target focus time window and the full time window; The target activity score is obtained by calculating the ratio between the average value of the time series data in the target attention time window and the average value of the time series data in the full time window.

7. The method according to claim 4, characterized in that, If the single-dimensional time trend pattern score includes a periodic volatility score, then the single-dimensional time trend pattern score of each field value of the target field is calculated based on the time series data of each field value of the target field, including: Calculate a one-dimensional periodic volatility score for each field value of the target field based on the time series data of each field value of the target field; wherein the one-dimensional periodic volatility score includes a periodicity index score and / or a volatility index score; the periodicity index score includes at least one of a period length score, a seasonality index score, and a periodic volatility score; the volatility index score includes at least one of a standard deviation score, a variance score, a coefficient of variation score, and a range score; The periodic volatility score of each field value of the target field is obtained by weighting the single-dimensional periodic volatility score of each field value and the corresponding weight.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that is executed by the at least one processor, such that the at least one processor is able to perform the field search method based on time trend information as described in any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the field search method based on time trend information as described in any one of claims 1-7.

10. A computer program product, characterized in that, Includes a computer program / instruction, wherein when the computer program / instruction is executed by a processor, it implements the field search method based on time trend information as described in any one of claims 1-7.