Cluster alarm information processing method and device

By generating cluster alarm information and performing silent or downgrade processing, the problem of low efficiency in cluster alarm information processing is solved, and processing efficiency and operation and maintenance response efficiency are improved.

CN122120098APending Publication Date: 2026-05-29BAIRONG ZHIXIN (BEIJING) TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BAIRONG ZHIXIN (BEIJING) TECH CO LTD
Filing Date
2026-01-20
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, the processing efficiency of cluster alarm information is low, resulting in low processing efficiency for operation and maintenance personnel when faced with a large number of device alarms.

Method used

By acquiring alarm information from devices, cluster alarm information is generated based on the correspondence between devices and the cluster, and then silenced or downgraded according to preset alarm handling rules, reducing unnecessary alarm analysis time.

Benefits of technology

It improves the processing efficiency of cluster alarm information, reduces the time spent by operation and maintenance personnel on analyzing unnecessary alarms, and optimizes the efficiency of operation and maintenance response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120098A_ABST
    Figure CN122120098A_ABST
Patent Text Reader

Abstract

The application discloses a cluster alarm information processing method and device, and relates to the technical field of computers. The method comprises the following steps: acquiring alarm information of at least one device, wherein the alarm information at least comprises device information; based on the device information, generating corresponding cluster alarm information by using a plurality of alarm information belonging to one cluster according to a corresponding relationship between the device and the cluster; and processing each cluster alarm information according to a preset alarm processing rule, wherein the preset alarm processing rule comprises a processing mode corresponding to each cluster alarm information; and the processing mode comprises a degradation processing and a silence processing. The application is used for realizing the cluster alarm information processing function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method and apparatus for processing cluster alarm information. Background Technology

[0002] During the use of computing devices such as servers, anomalies often occur due to various issues. Therefore, alerts are typically issued to indicate the existing problems. As computing demands increase, multiple servers are often clustered together. In this process, the number of alerts also increases due to the increased number of devices.

[0003] Currently, the conventional approach to handling cluster alarms requires operations and maintenance personnel to process each alarm individually. For example, when multiple devices in a cluster experience alarms, the current approach requires operations and maintenance personnel to process each alarm individually. However, in practical applications, a cluster may involve dozens or even hundreds of computing devices. This can lead to a large number of alarms occurring in a short period when multiple clusters exist. In such cases, the existing alarm processing methods will be found to have low processing efficiency. Summary of the Invention

[0004] This application provides a method and apparatus for processing cluster alarm information, the main purpose of which is to solve the problem of low processing efficiency in the current cluster alarm information processing process.

[0005] To address the aforementioned technical problems, this application provides the following technical solutions: Firstly, this application provides a method for processing cluster alarm information, the method comprising: Obtain alarm information from at least one device, wherein the alarm information includes at least device information; Based on the device information, according to the correspondence between devices and clusters, multiple alarm messages belonging to one cluster are generated into corresponding cluster alarm messages. According to the preset alarm processing rules, each cluster alarm information is processed. The preset alarm processing rules include the processing method for each cluster alarm information. The processing method includes degradation processing and silent processing.

[0006] Secondly, this application also provides a cluster alarm information processing device, comprising: An acquisition unit is configured to acquire alarm information of at least one device, wherein the alarm information includes at least device information; The generation unit is used to generate corresponding cluster alarm information from multiple alarm information belonging to a cluster based on the device information and according to the correspondence between the device and the cluster. The processing unit is used to process each cluster alarm information according to a preset alarm processing rule, wherein the preset alarm processing rule includes a processing method for each cluster alarm information; the processing method includes degradation processing and silent processing.

[0007] Thirdly, embodiments of this application provide a storage medium including a stored program, wherein, when the program is executed, it controls the device where the storage medium is located to execute the cluster alarm information processing method described in any one of the first aspects.

[0008] Fourthly, embodiments of this application provide a cluster alarm information processing apparatus, the apparatus including a storage medium; and one or more processors, the storage medium being coupled to the processors, the processors being configured to execute program instructions stored in the storage medium; the program instructions, when executed, perform the cluster alarm information processing method described in any one of the first aspects.

[0009] By employing the above-described technical solution, the technical solution provided in this application has at least the following advantages: This application provides a method and apparatus for processing cluster alarm information. The method first acquires alarm information from at least one device, the alarm information including at least device information. Then, based on the device information, multiple alarms belonging to a cluster are generated into corresponding cluster alarm information according to the correspondence between devices and clusters. Finally, each cluster alarm information is processed according to preset alarm processing rules, wherein the preset alarm processing rules include processing methods corresponding to each cluster alarm information; the processing methods include degradation processing and silent processing, thereby realizing the cluster alarm information processing function. Compared with existing technologies, in this application, alarm information from multiple devices can be generated into corresponding cluster alarm information during the cluster alarm information processing process, and processed using preset alarm processing rules in the form of cluster alarm information. This ensures that when faced with a large number of device alarm information, processing can be performed based on the cluster, eliminating the need to process device alarm information one by one, thereby improving the processing efficiency of alarm information. At the same time, since alarm information can be processed in a silent or downgraded manner during the alarm information processing process, it is not necessary for maintenance personnel to analyze the downgraded or silent alarm information during subsequent analysis. This helps maintenance personnel reduce the time spent analyzing unnecessary alarms, thereby further improving the overall processing efficiency of alarm information.

[0010] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0011] The above and other objects, features, and advantages of exemplary embodiments of this application will become readily understood by reading the following detailed description with reference to the accompanying drawings. In the drawings, several embodiments of this application are illustrated by way of example and not limitation, with the same or corresponding reference numerals denoteing the same or corresponding parts, wherein: Figure 1 A flowchart of a cluster alarm information processing method provided in an embodiment of this application is shown; Figure 2 This paper illustrates a flowchart of another cluster alarm information processing method provided in an embodiment of this application. Figure 3 This paper shows a block diagram of a cluster alarm information processing device provided in an embodiment of this application; Figure 4 This paper presents a block diagram of another cluster alarm information processing device provided in an embodiment of this application. Detailed Implementation

[0012] Exemplary embodiments of this application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of this application are shown in the drawings, it should be understood that this application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of this application and to fully convey the scope of this application to those skilled in the art.

[0013] It should be noted that, unless otherwise stated, the technical or scientific terms used in this application shall have the ordinary meaning as understood by one of ordinary skill in the art to which this application pertains.

[0014] This application provides a method for processing cluster alarm information. This method can be applied to data storage devices such as databases, specifically as follows: Figure 1 As shown, the method includes 101-103.

[0015] 101. Obtain alarm information from at least one device.

[0016] The alarm information should include at least device information.

[0017] In this embodiment, alarm information for each device can be generated and issued by monitoring or security software deployed in the cluster after detecting an anomaly. Each alarm message contains at least the device information corresponding to the device associated with the alarm. The device information can be a unique identifier assigned to the device at the factory (such as a serial number, MAC address, etc.), or a logical identifier assigned to the device during cluster deployment (such as a hostname, node ID, alias, etc.). This embodiment does not limit the specific form, content, or type of the device information, as long as it can uniquely distinguish between devices within the same cluster or between different clusters.

[0018] Furthermore, the execution entity of the cluster alarm information processing method provided in this embodiment can be a third-party processing device independent of the cluster, or it can be a processing module integrated within the cluster architecture. The specific deployment method of this execution entity can be flexibly selected according to the actual application scenario, and this embodiment does not impose any restrictions on it. In some embodiments of this application, the execution entity should be located on the transmission path of alarm information from the cluster device to the operation and maintenance personnel, and should be able to intercept and process the alarm information before it is pushed to the operation and maintenance personnel, thereby realizing the aggregation and intelligent handling of original device-level alarms.

[0019] 102. Based on device information, generate corresponding cluster alarm information from multiple alarm information belonging to a cluster according to the correspondence between devices and clusters.

[0020] In practical applications, computing devices are not used in isolation. For example, research institutions or enterprises need to use multiple devices in clusters. In addition, when computing power demand is high, there may be multiple different clusters, and the importance of different clusters also varies.

[0021] Therefore, in this embodiment, after obtaining some alarm information, since the devices corresponding to these alarm information may belong to different clusters, in this step, the alarm information of these devices can be used to generate corresponding cluster alarm information according to the cluster, thereby realizing the function of collecting and merging the alarm information of the devices. Of course, this process requires the use of the correspondence between devices and clusters, so as to ensure the accuracy of the function of merging and collecting alarm information of multiple devices into cluster alarm information.

[0022] Specifically, in this embodiment, the cluster alarm information can be a collection of all alarm information of the devices in the cluster, or it can be an alarm table or record generated after processing according to preset rules. Of course, the specific generation method is not specifically limited here, and can be done according to actual needs.

[0023] 103. Process the alarm information of each cluster according to the preset alarm processing rules.

[0024] The preset alarm handling rules include the handling methods for alarm information in each cluster; the handling methods include degradation handling and silent handling.

[0025] As described in the preceding steps, in practical applications, a computing system of an enterprise or research institution may involve multiple clusters, and the importance of different clusters may vary. Therefore, in this embodiment, after identifying the alarm information of multiple existing devices and processing them according to clusters in the preceding steps to obtain the cluster alarm information for each cluster, the next step is to process the cluster alarm information according to the method described in this step. The processing is based on preset alarm processing rules. These preset alarm processing rules can be understood as rules used to automatically silence or downgrade alarms involving clusters with lower importance. In other words, if cluster alarm information of a cluster with lower importance is identified, to avoid frequent interference from alarms of that cluster with subsequent alarm analysis by maintenance personnel, it can be processed automatically in this step. It should be noted that in this embodiment, the processing includes silencing and degradation. Silent processing can be understood as masking the cluster alarm information to prevent subsequent maintenance personnel from being disturbed and affecting the processing of other cluster alarm information. Degradation processing can be understood as lowering the alarm level of the cluster alarm information to prevent its excessively high alarm level from affecting the analysis order of other cluster alarm information.

[0026] This embodiment provides a cluster alarm information processing method. Compared with the prior art, in this application, alarm information from multiple devices can be generated into corresponding cluster alarm information according to the cluster during the cluster alarm information processing process, and processed using preset alarm processing rules in the form of cluster alarm information. This ensures that when faced with a large number of device alarm information, it can be processed based on the cluster, instead of processing each device alarm information individually, thereby improving the processing efficiency of alarm information. At the same time, since alarm information can be processed in a silent or downgraded manner during the alarm information processing process, it is no longer necessary for maintenance personnel to analyze the downgraded or silent alarm information during subsequent analysis. This helps maintenance personnel reduce the time spent analyzing unnecessary alarms, thereby further improving the overall processing efficiency of alarm information.

[0027] To provide a more detailed explanation, this application provides another method for processing cluster alarm information, applied to a database or a device equipped with a database. Specifically, as follows... Figure 2 As shown, the method includes 201-205.

[0028] 201. Obtain alarm information from at least one device.

[0029] The alarm information should include at least device information.

[0030] Since alarm information is used to alert users to device anomalies, it can include, in addition to device information, the cause of the anomaly, the anomaly code, the device's alarm level, and even its importance level. The specific content of the alarm information is not limited here; it can be determined based on the security software or system of the cluster to which the device belongs. Furthermore, device information can include not only the device's factory identifier, device code or name identifier when deployed in the cluster, but also specific address information, port information, and even the location information within the cluster. In other words, any one or more of the device's unique attributes are acceptable.

[0031] 202. Based on device information, generate corresponding cluster alarm information from multiple alarm information belonging to a cluster according to the correspondence between devices and clusters.

[0032] In this embodiment, when alarm information of a device is obtained, it indicates that there is a problem with a certain cluster. Since a large number of alarm information for different devices may be obtained at the same time, in order to facilitate the subsequent analysis and processing by maintenance personnel, in this step, the alarm information of a large number of devices can be integrated and collected into cluster alarm information for different clusters according to the device information and the correspondence between devices and clusters. Specifically, the process of processing alarm information of multiple devices into cluster alarm information is consistent with the description in the previous embodiment, and will not be repeated here.

[0033] 203. Process the alarm information of each cluster according to the preset alarm processing rules.

[0034] The preset alarm handling rules include the handling methods for alarm information in each cluster; the handling methods include degradation handling and silent handling.

[0035] In some embodiments, certain clusters are of low importance, or certain devices in certain clusters may experience alarms that cannot be resolved by maintenance personnel for a long time. In order to avoid the alarms of such clusters interfering with the maintenance personnel, in this embodiment, the alarms of such clusters can be processed by a pre-set rule based on a preset alarm processing rule. In this case, the preset alarm processing rule (i.e. the pre-set rule) can actually be divided according to the cluster. That is to say, the preset alarm processing rule is divided into grouping rules that include at least one corresponding cluster.

[0036] Based on this, the step "processing each cluster alarm information according to the preset alarm processing rules" can be executed as follows: 2031. Determine whether there is a grouping rule for the corresponding cluster alarm information in the preset alarm handling rules; 2032. When it is determined that there is a grouping rule for the corresponding cluster alarm information, the target operation is performed on the cluster alarm information. The target operation includes downgrading or silencing the cluster alarm information.

[0037] If a grouping rule corresponding to the cluster to which the current cluster alarm information belongs is matched in the preset alarm handling rules, it indicates that the alarm of the cluster has been pre-classified as a type that can be automatically handled by the system, without the need for manual attention or intervention by operation and maintenance personnel. In this case, the corresponding automated operation can be performed on the cluster alarm information according to the processing strategy configured in the grouping rule.

[0038] For example, the grouping rules include silent rules and degradation rules. Silent rules correspond to pre-configured silent policies, and degradation rules correspond to pre-configured degradation policies. Then, the current cluster alarm information can be processed according to the silent policy or the degradation policy.

[0039] The silencing strategy is an automated handling scheme corresponding to the silencing rules in the preset alarm handling rules. It is a strategy used to perform masking operations on cluster alarm information that matches the conditions (device information matching or alarm level matching). For example, according to the silencing strategy, cluster alarm information that meets the conditions can be directly masked, preventing the alarm information from being forwarded to the operation and maintenance interface or triggering subsequent alarm notification processes, thus reducing the interference of invalid alarms to operation and maintenance personnel.

[0040] A degradation strategy is an automated handling scheme corresponding to the degradation rules in the preset alarm handling rules. It is used to downgrade the alarm level of cluster alarm information that meets the matching conditions (device information matching or alarm level matching) before forwarding it. For example, according to the degradation strategy, the severity level of the cluster alarm information that meets the conditions is first reduced (e.g., from "urgent" to "general", from "important" to "alert"), and then the downgraded alarm information is forwarded to the designated channel or interface.

[0041] Furthermore, in some embodiments, taking the grouping rule containing a silencing rule and a degradation rule as an example, each of the silencing rule and the degradation rule contains at least one device information. Then, based on the matching relationship between this device information and the specific device involved in the cluster alarm information, it is determined whether the cluster alarm information needs to be silenced or degraded. Based on this, 2032 "When it is determined that a grouping rule corresponding to the cluster alarm information exists, perform the target operation on the cluster alarm information," specifically, during execution, is as follows: 20321. When it is determined that there is a grouping rule for the corresponding cluster alarm information, and it is determined that the device information in the cluster alarm information matches the device information in the silence rule in the grouping rule, the cluster alarm information is silenced. The silence is used to mask the cluster alarm information. 20322. When it is determined that there is a grouping rule for the corresponding cluster alarm information, and it is determined that the device information in the cluster alarm information matches the device information in the degradation rule in the grouping rule, the cluster alarm information is downgraded. The degradation process is used to downgrade the alarm level of the cluster alarm information before forwarding the cluster alarm information.

[0042] In this way, this example uses the specific devices involved in the cluster alarm information to determine whether to perform silent processing or degradation processing. This ensures that when alarms occur on different devices within the same cluster, they can be handled in a categorized manner. Specifically, alarms from devices that meet the silent rules are masked to avoid interference from invalid alarms; alarms from devices that meet the degradation rules are forwarded after their priority is reduced. This mechanism can implement fine-grained and categorized management of alarms from multiple devices within the same cluster without sacrificing the visibility of critical alarms. This significantly improves the flexibility and adaptability of alarm handling strategies, helps optimize operation and maintenance response efficiency, and reduces alarm noise.

[0043] Furthermore, in some embodiments, the generation of cluster alarm information may also involve a process of determining the alarm level of the cluster alarm information. In this case, the cluster alarm information may also include an alarm level; wherein, the alarm level of the cluster alarm information may be determined based on the alarm level of the device alarm information.

[0044] In addition, when the grouping rules include silencing rules and degradation rules, whether to silencing or degradation of cluster alarm information can be based on the alarm rules of the cluster alarm information. Therefore, silencing rules and degradation rules are divided according to alarm level; the alarm level involved in silencing rules is lower than the alarm level of degradation rules. Based on this, the specific execution of rule 2032, "When it is determined that there is a grouping rule corresponding to the cluster alarm information, perform the target operation on the cluster alarm information," is as follows: 20323. When it is determined that there is a grouping rule for the corresponding cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the downgrade rule in the grouping rule, the cluster alarm information is downgraded. The downgrade process is used to downgrade the alarm level of the cluster alarm information before forwarding the cluster alarm information. 20324. When it is determined that there is a grouping rule for the corresponding cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the silence rule in the grouping rule, the cluster alarm information is silenced. The silence is used to mask the cluster alarm information.

[0045] In this way, by matching the alarm level of the cluster alarm information with the degradation rules and silencing rules in the grouping rules according to the alarm level, a function is realized that can determine the processing method based on the alarm level involved in the cluster alarm information. This ensures that different processing methods can be adopted when the cluster alarm level is different, making the alarm information processing method of this embodiment more flexible.

[0046] Furthermore, in some embodiments, there are scenarios where some devices do not correspond to a single cluster but belong to multiple clusters (e.g., multiple clusters share the same device). In this case, a device can correspond to at least two clusters: one of which is the device's "direct cluster" (i.e., the normal operation of the cluster depends on the device's function), and the rest are "associated clusters" (i.e., device malfunctions only affect some functions of the cluster and will not cause the entire cluster to fail).

[0047] For example, in a "shared storage device" application scenario, there might be a device, described as: a distributed storage server, that stores product images and user order backup data for e-commerce operations, while also providing storage resources for multiple business clusters. Such a device would belong to two clusters, such as a data backup cluster (directly affiliated cluster) and a product display cluster (associated cluster).

[0048] The core function of a data backup cluster is to complete the backup, archiving, and recovery of all business data. This depends entirely on the storage capacity, read / write speed, and stability of the storage device. If the device fails, the data backup cluster will be unable to perform backup tasks, and the overall function will be paralyzed.

[0049] The product display cluster only needs to access the product image resources stored on the device. Device failure will only cause slow or failed loading of product images (and some functional abnormalities), but users can still browse product information and submit orders. Device failure does not affect real-time order generation and payment, only the historical order rollback function, and will not cause the entire cluster to fail.

[0050] Based on this scenario of devices belonging to multiple clusters, this example refines and supplements the alarm handling rules: the silencing rules are further divided into "ordinary silencing rules" and "related silencing rules," and the degradation rules are further divided into "ordinary degradation rules" and "related degradation rules," to adapt to the alarm handling needs under different cluster types. Therefore, in step 20321, "perform silencing processing on cluster alarm information," the refined execution logic of the silencing rules can also be provided as follows: When it is determined that a device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined. When it is determined that the direct cluster of the device is consistent with the cluster alarm information, and the device information of the cluster alarm information is consistent with the device information in the normal silencing rules, the cluster alarm information is subjected to normal silencing processing. When it is determined that the direct cluster of the device is inconsistent with the cluster alarm information, and it is determined that the device information in the cluster alarm information is consistent with the device information in the silent degradation rule, the cluster alarm information is subjected to associated silent processing.

[0051] Thus, this example provides the following refined logic for the silencing rules: If the cluster to which the alarm belongs is equal to the device's direct cluster, and the device information contained in the alarm matches the device information in the preset "normal silencing rules," then normal silencing processing is performed on the alarm information for that cluster; if the cluster to which the alarm belongs is not equal to the device's direct cluster (i.e., it belongs to its associated cluster), and the device information contained in the alarm matches the device information in the preset "associated silencing rules," then associated silencing processing is performed on the alarm information for that cluster. Through the above-mentioned hierarchical matching mechanism, the applicable silencing strategy can be dynamically selected based on the differences in the device's role in different clusters (such as criticality and scope of influence), realizing differentiated processing of alarms from shared devices in multiple clusters, and improving the accuracy of alarm management and business adaptability.

[0052] Specifically, taking the previously cited "shared storage device" application scenario as an example, the device is storage server S1, which belongs to two clusters: the data backup cluster (direct cluster) and the product display cluster (associated cluster). The detailed execution logic for performing silent processing will be explained in detail below.

[0053] (1) Detailed execution of silent processing 1: If the device's direct cluster and the current cluster alarm are the same, execute normal silent processing: This detailed execution logic 1 is that the storage server S1 triggers an alarm due to "excessive temporary disk I / O usage". The cluster to which this alarm belongs is the "data backup cluster" (i.e., the device's direct cluster).

[0054] The determination process provided in this example includes: first, confirming that the device "Storage Server S1" corresponds to two clusters (directly affiliated: data backup cluster; associated: product display cluster), which meets the premise that "the device corresponds to at least two clusters"; determining that the cluster to which the current alarm belongs (data backup cluster) is consistent with the device's directly affiliated cluster; verifying that the device information (Storage Server S1) corresponding to the alarm completely matches the device information in the ordinary silent rule, and that the alarm reason (excessive temporary disk IO usage) meets the triggering conditions of the ordinary silent rule.

[0055] The corresponding execution result is: perform normal silent processing on the alarm information of the cluster, and directly block the alarm. The logical rationale of this embodiment is that: although the data backup cluster depends on the storage server S1, "excessive temporary disk IO usage" is a short-term fluctuation (usually self-healing in 1-2 minutes) and will not affect the core process of data backup (such as full backup and archiving). Silent processing can avoid the operation and maintenance personnel being disturbed by invalid alarms.

[0056] (2) Detailed execution logic of silent processing 2: The cluster directly under the device is inconsistent with the cluster alarmed by the current cluster → execute associated silent processing: The detailed execution logic 2 is as follows: Storage server S1 triggers an alarm due to "insufficient space in non-core partitions". The cluster to which this alarm belongs is the "product display cluster" (i.e., the associated cluster of the device).

[0057] The determination process provided in this example includes: confirming that the device "Storage Server S1" corresponds to two clusters, which meets the prerequisites; determining that the cluster to which the current alarm belongs (product display cluster) is inconsistent with the device's direct cluster (data backup cluster); verifying that the device information (Storage Server S1) corresponding to the alarm completely matches the device information in the associated silent rule, and that the alarm reason (insufficient space in non-core partitions) meets the triggering conditions of the associated silent rule.

[0058] The corresponding execution result is: the alarm information for this cluster is handled with a silent processing mechanism, directly masking the alarm. The logic of this example is reasonable because: the product display cluster only relies on the "product image storage partition" (core partition) of storage server S1, while "insufficient space in non-core partitions" (such as log storage partitions) will not affect the loading and display of product images, and the core services of the cluster are unaffected. Therefore, silently handling irrelevant alarms related to the cluster does not affect business operations and reduces redundant maintenance work.

[0059] Similarly, in step 20322, "perform downgrade processing on cluster alarm information," it can also be done in the following way: When it is determined that a device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined. When it is determined that the direct cluster of the device is consistent with the cluster of the cluster alarm information, and the device information of the cluster alarm information is consistent with the device information in the ordinary degradation rule, the cluster alarm information is downgraded. When it is determined that the direct cluster of the device is inconsistent with the cluster alarm information, and it is determined that the device information in the cluster alarm information is consistent with the device information in the associated degradation rules, the associated degradation processing is performed on the cluster alarm information.

[0060] Thus, this example provides the following detailed logic for degradation rules: If the cluster to which the alarm belongs is equal to the device's direct cluster, and the device information contained in the alarm matches the device information in the preset "normal degradation rule," then normal degradation processing is performed on the alarm information for that cluster; if the cluster to which the alarm belongs is not equal to the device's direct cluster (i.e., it belongs to its associated cluster), and the device information contained in the alarm matches the device information in the preset "associated degradation rule," then associated degradation processing is performed on the alarm information for that cluster. Through the above-mentioned hierarchical matching mechanism, the applicable degradation strategy can be dynamically selected based on the differences in the device's role in different clusters (such as criticality and scope of impact), realizing differentiated processing of alarms from shared devices in multiple clusters, and improving the accuracy of alarm management and business adaptability.

[0061] In summary, the detailed execution logic of steps 20321 "Perform silent processing of cluster alarm information" and 20322 "Perform degradation processing of cluster alarm information" is as follows: For the "silent processing" scenario, based on the device's affiliation to a "direct cluster" or "associated cluster," the corresponding "ordinary silent rule" or "associated silent rule" is matched; for the "degradation processing" scenario, similarly, based on the device's affiliation to a "direct cluster" or "associated cluster," the corresponding "ordinary degradation rule" or "associated degradation rule" is matched. This example fills the gaps in the details of cross-cluster device alarm processing through the dual matching logic of "cluster affiliation + rule type," making rule execution more accurate: it clarifies the triggering conditions of "ordinary / associated" rules, avoids rule misuse in cross-cluster scenarios, unifies the judgment process for degradation and silent processing, improves the feasibility and consistency of the solution, and thus optimizes cross-cluster alarm processing.

[0062] Furthermore, or as a supplement to the scenario and rule matching dimensions, based on the device information matching rules provided in the example above, an alarm level can be added as another dimension for rule matching. For example, the detailed execution logic obtained when executing the aforementioned steps 20323 and 20324 includes the following: Based on this, the further detailed execution logic of the aforementioned step 20323, "perform downgrade processing on cluster alarm information," includes: When it is determined that a device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined. When it is determined that the device's direct cluster is consistent with the cluster corresponding to the cluster alarm information, and when it is determined that the alarm level of the cluster alarm information matches the normal degradation rule, the cluster alarm information is downgraded. When it is determined that the direct cluster of the device is inconsistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the associated degradation rule, the associated degradation processing is performed on the cluster alarm information.

[0063] Thus, the refined logic for degradation processing is upgraded as follows: For cross-cluster devices (corresponding to at least two clusters), in addition to the "cluster affiliation" determination, the "alarm level matching" condition is superimposed: If the device's directly affiliated cluster is the same as the cluster that alarms in the current cluster, and the alarm level matches the ordinary degradation rule → execute the ordinary degradation processing; If the device's directly affiliated cluster is different from the cluster that alarms in the current cluster, and the alarm level matches the associated degradation rule → execute the associated degradation processing.

[0064] Furthermore, the detailed execution logic for step 20324, "perform silent processing of cluster alarm information," includes: When it is determined that a device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined. When it is determined that the device's direct cluster is consistent with the cluster alarm information, and the alarm level of the cluster alarm information matches the normal silencing rule, normal silencing processing is performed on the cluster alarm information. When it is determined that the direct cluster of the device is inconsistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the associated silencing rule, the associated silencing process is performed on the cluster alarm information.

[0065] Thus, corresponding to the degradation processing logic, the "alarm level matching" condition is also superimposed: if the device's directly affiliated cluster is the same as the cluster alarmed by the current cluster, and the alarm level matches the normal silencing rule → normal silencing processing is executed; if the device's directly affiliated cluster is different from the cluster alarmed by the current cluster, and the alarm level matches the associated silencing rule → associated silencing processing is executed.

[0066] In summary, the detailed execution logic of steps 20324 and 20324 above further improves the accuracy of rule execution by using the dual matching conditions of "cluster affiliation + alarm level": avoiding misjudgments that may occur when relying solely on device information to match rules, and making silent / downgrade processing more in line with the actual severity of alarms; improving the rule judgment dimensions in cross-cluster scenarios, making the solution more reasonable for differentiated processing of alarms of different levels.

[0067] In addition, it should be noted that, besides the precise adaptation logic of the above scenarios and rules, if there are no matching rules in the "silent processing" and "downgrade processing" scenarios, this example also provides another optimization mechanism: by identifying and determining the alarm type of the cluster alarm information through a preset semantic template, and then forwarding the alarm information to the corresponding service terminal according to the pre-associated relationship of "alarm type - service terminal", so that relevant staff can carry out timely verification and processing.

[0068] In summary, this example iteratively upgrades the "degradation processing logic" and "silent processing logic," adding alarm level as a judgment dimension to the original cluster affiliation matching, making rule triggering more closely match the actual severity of alarms. Simultaneously, it incorporates a pre-defined optimization mechanism to fill processing gaps in scenarios where rules do not match, achieving full-dimensional coverage of "scenario and rule matching." From differentiated rule adaptation across cluster devices to precise responses to alarms of different levels, and optimization mechanisms for ruleless scenarios, this complete processing system optimizes aspects such as process accuracy and scenario coverage, ultimately achieving a dual improvement in cross-cluster alarm processing efficiency and reliability.

[0069] Furthermore, based on the detailed execution logic of steps 20321-20324 already defined, this example can also add an AI-driven machine learning model training module to replace the traditional static and fixed rule configuration mode, realizing intelligent automatic iteration of alarm processing rules. For example, the core implementation logic provided in this example includes the following: First, historical alarm data is structurally integrated, extracting multi-dimensional features such as device type, alarm level, fault handling results, and manual feedback from operations and maintenance personnel to construct a standardized data sample library. Then, a binary classification model is trained based on this sample library. The algorithm continuously learns the adaptation patterns between alarm scenarios and rules, accurately identifying two key issues: First, "high-false-judgment rules," which are redundant rules that are frequently triggered but verified by operations and maintenance personnel to require no handling (such as repetitive silent rules caused by normal fluctuations in specific devices); second, "missing rules," which are rule gaps that do not cover scenarios such as the access of new devices or changes in business processes (such as alarm handling rules corresponding to newly added cross-cluster linkage services). Finally, the model can automatically analyze the rule adaptation effect at preset cycles (such as daily / weekly), push visual optimization suggestions to operations and maintenance personnel, or directly update rules with authorization, forming a closed loop of "data collection - model learning - rule optimization." Specifically, taking the "silent handling" execution logic as an example, the following example scenario is provided for explanation.

[0070] For example, consider a cross-cluster device A (directly associated with the "Web Cluster" and related with the "Database Cluster"). The original silent rule was set to "when device A triggers an alarm, the database cluster performs associated silent processing." However, historical data shows that 80% of device A's alarms are temporary fluctuations in the Web service itself (such as cache timeouts), which do not affect the database cluster. This leads to a large amount of unnecessary silent processing and has even masked two alarms where device A actually affected the database.

[0071] Therefore, the binary classification model trained in this example can be applied to optimize the execution logic of "silent processing". For example, the model input features are: the alarm type of device A (such as "cache timeout" or "connection failure"), alarm duration, the occurrence rate of associated failures in the database cluster, and the manual rejection records of "silent processing" by maintenance personnel (marked as "false silence"). The binary classification model identifies that "the 'cache timeout' alarm of device A is not related to the database cluster failure", and automatically pushes rule optimization suggestions: refine the original rule to "when device A triggers a 'connection failure' alarm, the database cluster performs associated silent processing, and the 'cache timeout' alarm does not trigger associated silent processing"; or automatically update the rule to reduce false silence scenarios by 80%.

[0072] In this example, introducing an "AI-driven machine learning model training module" to train a "binary classification model" with the above functionality not only significantly reduces the operational costs of manually sorting and adjusting rules, and avoids the adaptation lag issues caused by traditional static rules due to business expansion, equipment iteration, and scenario changes, but also allows the rule matching accuracy to continuously improve with the accumulation of historical data, effectively reducing the false alarm rate and missed alarm rate. Simultaneously, the model is adaptive, dynamically adapting to changes in the cluster architecture, ensuring that alarm handling rules remain synchronized with the actual operational scenario, further enhancing the accuracy and efficiency of cross-cluster alarm handling, and driving the upgrade of the operational model from "human experience-driven" to "AI intelligent governance."

[0073] 204. After the cluster alarm information is silenced or downgraded, the alarm information of all devices corresponding to the cluster alarm information is recorded to obtain the alarm record, and the abnormal cause of the cluster alarm information is analyzed based on the alarm record.

[0074] After confirming that cluster alarm information has been silenced or downgraded, to facilitate subsequent analysis by maintenance personnel, the alarm information from multiple devices prior to each cluster alarm can be collected and recorded using the method described in this step, resulting in an alarm record. Since the alarm information in this record can show which specific devices were alarmed when the cluster alarm occurred, the cause of the anomaly involved in the current cluster alarm information can be analyzed based on this alarm record, thus obtaining preliminary analysis results. This allows maintenance personnel to directly provide relevant analysis results when they need to inspect silenced or downgraded alarms, simplifying the analysis and backtracking process for these alarms and further improving the efficiency of alarm information processing.

[0075] Furthermore, building upon existing silent and degradation handling mechanisms, this example can also add a security orchestration automation module to construct a closed-loop operation encompassing "alarm handling - fault repair." Its execution logic triggers a differentiated self-healing mechanism through the superposition and matching of alarm levels and alarm types, as detailed below: First, this embodiment classifies alarms into multiple levels based on the severity of their impact on business operations. For example, in order of priority from high to low, they are: "Urgent" level, used for serious faults such as core business interruption and system crash, which require immediate handling; "Important" level, used for critical function abnormalities and significant performance degradation that may affect business operations; "Warning" level, used for potential risks that have not yet affected current business operations but may cause subsequent faults; and "Notification" level, used for routine status notifications that are risk-free and require no intervention.

[0076] Furthermore, this embodiment categorizes alarm types into multiple classes based on the fault scenarios and the modules to which they belong, such as: resource class, used to represent scenarios like cache overflow, excessive memory / CPU usage, and insufficient disk space; service class, used to represent scenarios like abnormal core business services, database connection timeouts, and network link interruptions; security class, used to represent scenarios like unauthorized login attempts, address resolution protocol attacks, and abnormal traffic injection; and configuration class, used to represent scenarios like incorrect parameter configuration, protocol negotiation failures, and IP address pool exhaustion.

[0077] Then, this embodiment uses a dual dimension of "alarm level (severity) + alarm type (fault scenario)" to pre-define graded and categorized self-healing scripts, achieving precise matching and automated handling. The following scenario will be used as an example for explanation: Scenario 1: When the alarm level is "Warning / Notification" and the alarm type is "Resource" (such as temporary cache overflow, low disk space warning), a fully automatic self-healing mechanism is triggered. For example, without manual intervention, preset repair operations are directly executed (cleaning up redundant cache, releasing idle resources, expanding temporary storage, etc.), and a processing log is generated after the fault is resolved.

[0078] Scenario 2: When the alarm level is "Important" and the alarm type is "Service / Configuration" (such as non-core service response timeout, dynamic host configuration protocol address pool exhaustion), a semi-automatic self-healing mechanism is triggered. For example, basic repair operations are automatically performed first (restarting the target service, cleaning up dead connections, adjusting configuration parameters, etc.), and alarm notifications are pushed at the same time. If the repair fails, it is automatically upgraded to the manual intervention process, providing fault logs and troubleshooting suggestions.

[0079] Scenario 3: When the alarm level is "urgent" and the alarm type is "security / service" (such as core business downtime or brute-force attack), an emergency self-healing mechanism and a manual collaboration mechanism are triggered. For example, emergency measures (business degradation, traffic circuit breaking, blocking the attack source, etc.) are immediately implemented to reduce the scope of impact. At the same time, the highest priority manual approval and intervention process is triggered, and the operation and maintenance personnel can quickly find the root cause based on the complete operation trajectory retained by the system.

[0080] In this embodiment, such a "self-healing mechanism" ensures that all operation logs (including self-healing execution records, manual approval traces, original alarm information, etc.) are retained throughout the entire closed-loop operation for subsequent retrospective auditing. Through the superimposed logic of "priority based on level and handling plan based on type," it ensures rapid response to high-risk alarms while achieving automated closed-loop processing of routine alarms, reducing repetitive maintenance work and improving the efficiency of cluster alarm response and the standardization of fault handling.

[0081] To achieve the above objectives, according to another aspect of this application, an embodiment of this application also provides a storage medium, the storage medium including a stored program, wherein, when the program is running, it controls the device where the storage medium is located to execute the cluster alarm information processing method described above.

[0082] To achieve the above objectives, according to another aspect of this application, an embodiment of this application also provides a cluster alarm information processing apparatus, the apparatus including a storage medium; and one or more processors, the storage medium being coupled to the processors, the processors being configured to execute program instructions stored in the storage medium; the program instructions, when executed, perform the cluster alarm information processing method described above.

[0083] Furthermore, as a response to the above Figure 1 and Figure 2In addition to the implementation of the method shown, another embodiment of this application also provides a cluster alarm information processing device. This cluster alarm information processing device embodiment corresponds to the aforementioned method embodiment. For ease of reading, this cluster alarm information processing device embodiment will not repeat the details of the aforementioned method embodiments one by one, but it should be clear that the device in this embodiment can correspondingly implement all the contents of the aforementioned method embodiments. The main purpose of the cluster alarm information processing device is to solve the problem of poor timeliness in the current cluster alarm information processing process, specifically as follows... Figure 3 As shown, the cluster alarm information processing device includes: The acquisition unit 31 can be used to acquire alarm information of at least one device, wherein the alarm information includes at least device information; The generation unit 32 can be used to generate corresponding cluster alarm information from multiple alarm information belonging to a cluster based on the device information obtained by the acquisition unit 31 and according to the correspondence between the device and the cluster. The processing unit 33 can be used to process the cluster alarm information obtained by each generation unit 32 according to the preset alarm processing rules, wherein the preset alarm processing rules include the processing method corresponding to each cluster alarm information; the processing method includes degradation processing and silent processing.

[0084] Furthermore, such as Figure 4 As shown, the preset alarm processing rules are divided into grouping rules that include at least one corresponding cluster; The processing unit 33 can be specifically used to determine whether there is a grouping rule corresponding to the cluster alarm information in the preset alarm processing rules; and when it is determined that there is a grouping rule corresponding to the cluster alarm information, to perform a target operation on the cluster alarm information, the target operation including downgrading the cluster alarm information or silencing it.

[0085] Furthermore, such as Figure 4 As shown, the grouping rules include silent rules and degradation rules; each of the silent rules and degradation rules contains at least one piece of device information. The processing unit 33 includes: The first processing module 331 can be used to perform silencing processing on the cluster alarm information when it is determined that there is a grouping rule corresponding to the cluster alarm information and when it is determined that the device information in the cluster alarm information matches the device information in the silencing rule in the grouping rule. The silencing processing can be used to block the cluster alarm information. The second processing module 332 can be used to perform downgrade processing on the cluster alarm information when it is determined that there is a grouping rule corresponding to the cluster alarm information and it is determined that the device information in the cluster alarm information matches the device information in the downgrade rule in the grouping rule. The downgrade processing can be used to downgrade the alarm level of the cluster alarm information and then forward the cluster alarm information.

[0086] Furthermore, such as Figure 4 As shown, the cluster alarm information also includes an alarm level; the alarm level of the cluster alarm information is determined based on the alarm level of the device's alarm information; The grouping rules include silent rules and degradation rules; the silent rules and degradation rules are divided according to alarm levels; the alarm levels involved in the silent rules are lower than the alarm levels involved in the degradation rules. The processing unit 33 further includes: The third processing module 333 can be used to perform downgrade processing on the cluster alarm information when it is determined that there is a grouping rule corresponding to the cluster alarm information and the alarm level of the cluster alarm information matches the downgrade rule in the grouping rule. The downgrade processing can be used to downgrade the alarm level of the cluster alarm information and then forward the cluster alarm information. The fourth processing module 334 can be used to perform silencing processing on the cluster alarm information when it is determined that there is a grouping rule corresponding to the cluster alarm information and the alarm level of the cluster alarm information matches the silencing rule in the grouping rule. The silencing processing can be used to mask the cluster alarm information.

[0087] Furthermore, such as Figure 4 As shown, the silencing rules include ordinary silencing rules and associated silencing rules; the degradation rules include ordinary degradation rules and associated degradation rules. The second processing module 332 can also be specifically used to determine the direct cluster and associated cluster of the device when it is determined that the device corresponds to at least two clusters; and to perform degradation processing on the cluster alarm information when it is determined that the direct cluster of the device is consistent with the cluster of the cluster alarm information and the device information of the cluster alarm information is consistent with the device information in the ordinary degradation rule; and to perform associated degradation processing on the cluster alarm information when it is determined that the direct cluster of the device is inconsistent with the cluster of the cluster alarm information and the device information in the cluster alarm information is consistent with the device information in the associated degradation rule. The first processing module 331 can also be specifically used to determine the direct cluster and associated cluster of the device when it is determined that the device corresponds to at least two clusters; and to perform normal silencing processing on the cluster alarm information when it is determined that the direct cluster of the device is consistent with the cluster alarm information and the device information of the cluster alarm information is consistent with the device information in the normal silencing rule; and to perform associated silencing processing on the cluster alarm information when it is determined that the direct cluster of the device is inconsistent with the cluster alarm information and the device information in the cluster alarm information is consistent with the device information in the silencing degradation rule.

[0088] Furthermore, such as Figure 4 As shown, the silencing rules include ordinary silencing rules and associated silencing rules; the degradation rules include ordinary degradation rules and associated degradation rules. The third processing module 333 can also be specifically used to determine the direct cluster and associated cluster of the device when it is determined that the device corresponds to at least two clusters; and to perform degradation processing on the cluster alarm information when it is determined that the direct cluster of the device is consistent with the cluster corresponding to the cluster alarm information and the alarm level of the cluster alarm information matches the ordinary degradation rule; and to perform associated degradation processing on the cluster alarm information when it is determined that the direct cluster of the device is inconsistent with the cluster corresponding to the cluster alarm information and the alarm level of the cluster alarm information matches the associated degradation rule. The fourth processing module 334 can also be specifically used to determine the direct cluster and associated cluster of the device when it is determined that the device corresponds to at least two clusters; and to perform normal silencing processing on the cluster alarm information when it is determined that the direct cluster of the device is consistent with the cluster corresponding to the cluster alarm information and the alarm level of the cluster alarm information matches the normal silencing rule; and to perform associated silencing processing on the cluster alarm information when it is determined that the direct cluster of the device is inconsistent with the cluster corresponding to the cluster alarm information and the alarm level of the cluster alarm information matches the associated silencing rule.

[0089] Furthermore, such as Figure 4 As shown, the device further includes: The analysis unit 34 can be used to record the alarm information of all the devices corresponding to the cluster alarm information after the cluster alarm information is silenced or downgraded by the processing unit 33, obtain alarm records, and analyze the abnormal reasons for the occurrence of the cluster alarm information based on the alarm records.

[0090] This application provides a cluster alarm information processing method and apparatus. Compared with the prior art, in this application, alarm information from multiple devices can be generated into corresponding cluster alarm information according to the cluster during the cluster alarm information processing process, and processed using preset alarm processing rules in the form of cluster alarm information. This ensures that when faced with a large number of device alarm information, it can be processed based on the cluster, instead of processing each device alarm information individually, thereby improving the processing efficiency of alarm information. At the same time, since alarm information can be processed in a silent or downgraded manner during the alarm information processing process, it is no longer necessary for maintenance personnel to analyze the downgraded or silent alarm information during subsequent analysis. This helps maintenance personnel reduce the time spent analyzing unnecessary alarms, thereby further improving the overall processing efficiency of alarm information.

[0091] This application provides a storage medium that includes a stored program, wherein the program controls the device where the storage medium is located to execute the cluster alarm information processing method described above when it is running.

[0092] Storage media may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0093] This application embodiment also provides a cluster alarm information processing device, the device including a storage medium; and one or more processors, the storage medium being coupled to the processors, the processors being configured to execute program instructions stored in the storage medium; the program instructions executing the cluster alarm information processing method described above.

[0094] This application provides a device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps: acquiring alarm information of at least one device, wherein the alarm information includes at least device information; based on the device information, generating corresponding cluster alarm information from multiple alarm information belonging to a cluster according to the correspondence between devices and clusters; and processing each cluster alarm information according to a preset alarm processing rule, wherein the preset alarm processing rule includes a processing method corresponding to each cluster alarm information; the processing method includes degradation processing and silent processing.

[0095] Furthermore, the preset alarm processing rules are divided into grouping rules that include at least one corresponding cluster; The process of processing each cluster alarm information according to preset alarm processing rules includes: Determine whether there is a grouping rule corresponding to the cluster alarm information in the preset alarm processing rules; When it is determined that there is a grouping rule corresponding to the cluster alarm information, a target operation is performed on the cluster alarm information, the target operation including downgrading or silencing the cluster alarm information.

[0096] Furthermore, the grouping rules include silent rules and degradation rules; each of the silent rules and degradation rules contains at least one piece of device information. When it is determined that a grouping rule corresponding to the cluster alarm information exists, the target operation is performed on the cluster alarm information, including: When it is determined that there is a grouping rule corresponding to the cluster alarm information, and it is determined that the device information in the cluster alarm information matches the device information in the silence rule of the grouping rule, the cluster alarm information is silenced, and the silence is used to block the cluster alarm information. When it is determined that there is a grouping rule corresponding to the cluster alarm information, and it is determined that the device information in the cluster alarm information matches the device information in the degradation rule of the grouping rule, degradation processing is performed on the cluster alarm information. The degradation processing is used to downgrade the alarm level of the cluster alarm information and then forward the cluster alarm information.

[0097] Furthermore, the cluster alarm information also includes an alarm level; the alarm level of the cluster alarm information is determined based on the alarm level of the device's alarm information. The grouping rules include silent rules and degradation rules; the silent rules and degradation rules are divided according to alarm levels; the alarm levels involved in the silent rules are lower than the alarm levels involved in the degradation rules. When it is determined that a grouping rule corresponding to the cluster alarm information exists, the target operation is performed on the cluster alarm information, including: When it is determined that there is a grouping rule corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the downgrade rule in the grouping rule, downgrade processing is performed on the cluster alarm information. The downgrade processing is used to downgrade the alarm level of the cluster alarm information and then forward the cluster alarm information. When it is determined that there is a grouping rule corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the silence rule in the grouping rule, the cluster alarm information is silenced, and the silence is used to mask the cluster alarm information.

[0098] Furthermore, the silencing rules include ordinary silencing rules and associated silencing rules; the degradation rules include ordinary degradation rules and associated degradation rules. The degradation processing of the cluster alarm information includes: When it is determined that the device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined; When it is determined that the direct cluster of the device is consistent with the cluster of the cluster alarm information, and when it is determined that the device information of the cluster alarm information is consistent with the device information in the ordinary degradation rule, degradation processing is performed on the cluster alarm information. When it is determined that the direct cluster of the device is inconsistent with the cluster of the cluster alarm information, and it is determined that the device information in the cluster alarm information is consistent with the device information in the associated degradation rule, the associated degradation processing is performed on the cluster alarm information. The step of performing silent processing on the cluster alarm information includes: When it is determined that the device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined; When it is determined that the direct cluster of the device is consistent with the cluster of the cluster alarm information, and it is determined that the device information of the cluster alarm information is consistent with the device information in the normal silencing rule, normal silencing processing is performed on the cluster alarm information. When it is determined that the direct cluster of the device is inconsistent with the cluster of the cluster alarm information, and it is determined that the device information in the cluster alarm information is consistent with the device information in the silent degradation rule, the cluster alarm information is subjected to associated silent processing.

[0099] Furthermore, the silencing rules include ordinary silencing rules and associated silencing rules; the degradation rules include ordinary degradation rules and associated degradation rules. The degradation processing of the cluster alarm information includes: When it is determined that the device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined; When it is determined that the direct cluster of the device is consistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the ordinary degradation rule, the cluster alarm information is downgraded. When it is determined that the direct cluster of the device is inconsistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the association degradation rule, the association degradation processing is performed on the cluster alarm information. The step of performing silent processing on the cluster alarm information includes: When it is determined that the device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined; When it is determined that the direct cluster of the device is consistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the normal silencing rule, normal silencing processing is performed on the cluster alarm information. When it is determined that the direct cluster of the device is inconsistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the associated silencing rule, the associated silencing process is performed on the cluster alarm information.

[0100] Furthermore, after processing each cluster alarm information according to the preset alarm processing rules, the method further includes: When it is determined that the cluster alarm information does not match the preset alarm processing rules, the alarm type of the cluster alarm information is determined, and the cluster alarm information is forwarded to the target end according to the alarm relationship based on the alarm type. The alarm relationship includes the target end corresponding to each alarm type.

[0101] Furthermore, after processing each cluster alarm information according to the preset alarm processing rules, the method further includes: After the cluster alarm information is silenced or downgraded, the alarm information of all the devices corresponding to the cluster alarm information is recorded to obtain alarm records, and the abnormal reasons for the occurrence of the cluster alarm information are analyzed based on the alarm records.

[0102] This application also provides a computer program product, which, when executed on a data processing device, is suitable for executing program code with the following initialization steps: acquiring alarm information of at least one device, the alarm information including at least device information; based on the device information, generating corresponding cluster alarm information from multiple alarm information belonging to a cluster according to the correspondence between devices and clusters; processing each cluster alarm information according to a preset alarm processing rule, wherein the preset alarm processing rule includes a processing method corresponding to each cluster alarm information; the processing method includes degradation processing and silent processing.

[0103] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0104] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0105] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0106] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0107] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0108] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0109] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0110] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0111] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0112] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for processing cluster alarm information, characterized in that, The method includes: Obtain alarm information from at least one device, wherein the alarm information includes at least device information; Based on the device information, according to the correspondence between devices and clusters, multiple alarm messages belonging to one cluster are generated into corresponding cluster alarm messages. According to the preset alarm processing rules, each cluster alarm information is processed. The preset alarm processing rules include the processing method for each cluster alarm information. The processing method includes degradation processing and silent processing.

2. The method according to claim 1, characterized in that, The preset alarm processing rules are divided into grouping rules that include at least one corresponding cluster; The process of processing each cluster alarm information according to preset alarm processing rules includes: Determine whether there is a grouping rule corresponding to the cluster alarm information in the preset alarm processing rules; When it is determined that there is a grouping rule corresponding to the cluster alarm information, a target operation is performed on the cluster alarm information, the target operation including downgrading or silencing the cluster alarm information.

3. The method according to claim 2, characterized in that, The grouping rules include silent rules and degradation rules; each of the silent rules and degradation rules contains at least one piece of device information. When it is determined that a grouping rule corresponding to the cluster alarm information exists, the target operation is performed on the cluster alarm information, including: When it is determined that there is a grouping rule corresponding to the cluster alarm information, and it is determined that the device information in the cluster alarm information matches the device information in the silence rule of the grouping rule, the cluster alarm information is silenced, and the silence is used to block the cluster alarm information. When it is determined that there is a grouping rule corresponding to the cluster alarm information, and it is determined that the device information in the cluster alarm information matches the device information in the degradation rule of the grouping rule, degradation processing is performed on the cluster alarm information. The degradation processing is used to downgrade the alarm level of the cluster alarm information and then forward the cluster alarm information.

4. The method according to claim 2, characterized in that, The cluster alarm information also includes alarm levels; the alarm levels of the cluster alarm information are determined based on the alarm levels of the device alarm information. The grouping rules include silent rules and degradation rules; the silent rules and degradation rules are divided according to alarm levels; the alarm levels involved in the silent rules are lower than the alarm levels involved in the degradation rules. When it is determined that a grouping rule corresponding to the cluster alarm information exists, the target operation is performed on the cluster alarm information, including: When it is determined that there is a grouping rule corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the downgrade rule in the grouping rule, downgrade processing is performed on the cluster alarm information. The downgrade processing is used to downgrade the alarm level of the cluster alarm information and then forward the cluster alarm information. When it is determined that there is a grouping rule corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the silence rule in the grouping rule, the cluster alarm information is silenced, and the silence is used to mask the cluster alarm information.

5. The method according to claim 3, characterized in that, The silence rules include ordinary silence rules and associated silence rules; the degradation rules include ordinary degradation rules and associated degradation rules. The degradation processing of the cluster alarm information includes: When it is determined that the device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined; When it is determined that the direct cluster of the device is consistent with the cluster of the cluster alarm information, and when it is determined that the device information of the cluster alarm information is consistent with the device information in the ordinary degradation rule, degradation processing is performed on the cluster alarm information. When it is determined that the direct cluster of the device is inconsistent with the cluster of the cluster alarm information, and it is determined that the device information in the cluster alarm information is consistent with the device information in the associated degradation rule, the associated degradation processing is performed on the cluster alarm information. The step of performing silent processing on the cluster alarm information includes: When it is determined that the device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined; When it is determined that the direct cluster of the device is consistent with the cluster of the cluster alarm information, and it is determined that the device information of the cluster alarm information is consistent with the device information in the normal silencing rule, normal silencing processing is performed on the cluster alarm information. When it is determined that the direct cluster of the device is inconsistent with the cluster of the cluster alarm information, and it is determined that the device information in the cluster alarm information is consistent with the device information in the silent degradation rule, the cluster alarm information is subjected to associated silent processing.

6. The method according to claim 4, characterized in that, The silence rules include ordinary silence rules and associated silence rules; the degradation rules include ordinary degradation rules and associated degradation rules. The degradation processing of the cluster alarm information includes: When it is determined that the device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined; When it is determined that the direct cluster of the device is consistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the ordinary degradation rule, the cluster alarm information is downgraded. When it is determined that the direct cluster of the device is inconsistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the association degradation rule, the association degradation processing is performed on the cluster alarm information. The step of performing silent processing on the cluster alarm information includes: When it is determined that the device corresponds to at least two clusters, the device's direct cluster and associated cluster are determined; When it is determined that the direct cluster of the device is consistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the normal silencing rule, normal silencing processing is performed on the cluster alarm information. When it is determined that the direct cluster of the device is inconsistent with the cluster corresponding to the cluster alarm information, and it is determined that the alarm level of the cluster alarm information matches the associated silencing rule, the associated silencing process is performed on the cluster alarm information.

7. The method according to claim 1, characterized in that, After processing each cluster alarm information according to the preset alarm processing rules, the method further includes: After the cluster alarm information is silenced or downgraded, the alarm information of all the devices corresponding to the cluster alarm information is recorded to obtain alarm records, and the abnormal reasons for the occurrence of the cluster alarm information are analyzed based on the alarm records.

8. A cluster alarm information processing device, characterized in that, include: An acquisition unit is configured to acquire alarm information of at least one device, wherein the alarm information includes at least device information; The generation unit is used to generate corresponding cluster alarm information from multiple alarm information belonging to a cluster based on the device information and according to the correspondence between the device and the cluster. The processing unit is used to process each cluster alarm information according to a preset alarm processing rule, wherein the preset alarm processing rule includes the processing method corresponding to each cluster alarm information; The processing methods include downgrade processing and silent processing.

9. A cluster alarm information processing device, characterized in that, The apparatus includes a storage medium; and one or more processors, the storage medium being coupled to the processors, the processors being configured to execute program instructions stored in the storage medium; the program instructions, when executed, perform the cluster alarm information processing method according to any one of claims 1 to 7.

10. A storage medium, characterized in that, The storage medium includes a stored program, wherein, when the program is running, it controls the device where the storage medium is located to execute the cluster alarm information processing method according to any one of claims 1-7.