Abnormality detection method and device for processing flow, electronic equipment and storage medium

By receiving natural language text input from users, identifying object identifiers, and utilizing an automated detection and processing module based on a knowledge base, the problem of difficulty in locating anomalies in the existing processing flow is solved. This enables rapid and efficient anomaly detection and repair suggestions, improving the efficiency and ease of use of the processing flow.

CN122195706APending Publication Date: 2026-06-12北京中关村科金技术有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-09
Publication Date
2026-06-12

Smart Images

  • Figure CN122195706A_ABST
    Figure CN122195706A_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an exception detection method and device for a processing flow, electronic equipment and a storage medium. The method comprises: receiving a first text input by a user, the first text being used to query a first object in a database; identifying the first object in the first text to obtain an identifier of the first object; based on the identifier of the first object, obtaining, in the database, a plurality of first processing modules that execute the first object within a historical period and a historical execution order of the plurality of first processing modules; based on the historical execution order, detecting the plurality of first processing modules to obtain a first detection result of each first processing module, the first detection result being used to indicate whether the first processing module has an error when processing the first object; and displaying the first detection result of each first processing module. In the above method, full-link intelligentization from natural language inquiry to automatic positioning of processing flow exceptions is achieved, and the detection efficiency of complex processing flow exceptions is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and storage medium for detecting anomalies in a processing flow. Background Technology

[0002] When multiple highly coupled processing modules (i.e., those with complex dependencies) collaborate to handle a case or task, these dependencies often lead to errors influencing and accumulating each other. For example, an anomaly in the output of a preceding processing module may directly trigger a chain of errors in subsequent processing modules, complicating the anomaly and making it difficult to directly pinpoint the root cause of the error in the case's processing flow.

[0003] In related technologies, technicians need to have in-depth knowledge of computer technology. Based on human experience, they spend a lot of time checking the logs of each processing module when it processes cases, the database storing input and output data, the configuration center, and the interface status. This manual method of detecting anomalies in the processing flow usually takes several hours or even days, which is inefficient. Summary of the Invention

[0004] This application provides an anomaly detection method, apparatus, electronic device, and storage medium for a processing flow, which can improve the detection efficiency of anomalies in the processing flow.

[0005] In a first aspect, embodiments of this application provide an anomaly detection method for a processing flow, comprising:

[0006] Receive the first text input by the user, which is used to query the first object in the database;

[0007] Identify the first object in the first text and obtain the identifier of the first object;

[0008] Based on the identifier of the first object, retrieve from the database multiple first processing modules that executed the first object within a historical time period, as well as the historical execution order of the multiple first processing modules.

[0009] Based on the historical execution order, multiple first processing modules are detected to obtain the first detection result of each first processing module. The first detection result is used to indicate whether an error occurred when the first processing module processed the first object.

[0010] Displays the first detection results of each first processing module.

[0011] In some embodiments, identifying a first object in the first text to obtain an identifier of the first object includes:

[0012] Based on the pre-configured prompt word template, the first text is analyzed to obtain the user's query intent;

[0013] If the user's query intent indicates whether the first processing module for querying the first object has an error, then the first object in the first text is identified. If the identifier of the first object is identified, the identifier of the first object is obtained. If the identifier of the first object is not identified, the first prompt information is displayed. The first prompt information is used to prompt the user to enter the identifier of the first object.

[0014] If the user's query intent indicates that the first processing module is not querying the first object, then a second prompt message is displayed to guide the user to re-enter the first text.

[0015] In some embodiments, multiple first processing modules are detected based on their historical execution order to obtain a first detection result for each first processing module, including:

[0016] Obtain a preset knowledge base, which includes multiple second processing modules and a first detection action corresponding to each second processing module. The first detection action is associated with the exception type of the second processing module. The multiple second processing modules include multiple first processing modules.

[0017] Based on the historical execution order, the knowledge base is used to determine multiple first detection actions corresponding to each first processing module, as well as the first execution order of the multiple first detection actions.

[0018] Based on multiple first detection actions and multiple first execution sequences, the first detection result of each first processing module is determined.

[0019] In some embodiments, for any one first processing module, based on multiple first detection actions and multiple first execution sequences, the first detection result of each first processing module is determined, including:

[0020] According to the first execution order, multiple first detection actions are executed sequentially to obtain the second detection results of each first detection action;

[0021] Based on multiple second detection results, the first detection result of the first processing module is determined.

[0022] In some embodiments, determining the first detection result of the first processing module based on multiple second detection results includes:

[0023] When multiple second test results are all normal, the first test result is determined to be normal;

[0024] When any second detection result is abnormal, the cause of the abnormality and the repair suggestions are determined based on multiple second detection actions and multiple second detection results, and the first detection result is determined based on the cause of the abnormality and the repair suggestions.

[0025] In some embodiments, after displaying the first detection results of each first processing module, the method further includes:

[0026] Based on the first detection results of each first processing module, an anomaly report is generated, which includes text describing each first detection result;

[0027] Display an error report.

[0028] In some embodiments, after displaying the anomaly report, the method further includes:

[0029] Receive third text input from the user, which is used to query the first cause of the anomaly and / or the first repair suggestion in the anomaly report;

[0030] Based on the third text, a matching search is performed in the anomaly report to obtain the fourth text corresponding to the first anomaly cause and / or the first repair suggestion;

[0031] Display the fourth text.

[0032] Secondly, embodiments of this application provide an anomaly detection device for a processing flow, comprising:

[0033] The first processing module is used to receive the first text input by the user, and the first text is used to query the first object in the database;

[0034] The second processing module is used to identify the first object in the first text and obtain the identifier of the first object;

[0035] The third processing module is used to retrieve, based on the identifier of the first object, multiple first processing modules that executed the first object within a historical time period and the historical execution order of the multiple first processing modules from the database.

[0036] The fourth processing module is used to detect multiple first processing modules based on the historical execution order and obtain the first detection result of each first processing module. The first detection result is used to indicate whether the first processing module has made an error when processing the first object.

[0037] The fifth processing module is used to display the first detection results of each of the first processing modules.

[0038] In some embodiments, the second processing module is specifically used for:

[0039] Based on the pre-configured prompt word template, the first text is analyzed to obtain the user's query intent;

[0040] If the user's query intent indicates whether the first processing module for querying the first object has an error, then the first object in the first text is identified. If the identifier of the first object is identified, the identifier of the first object is obtained. If the identifier of the first object is not identified, the first prompt information is displayed. The first prompt information is used to prompt the user to enter the identifier of the first object.

[0041] If the user's query intent indicates that the first processing module is not querying the first object, then a second prompt message is displayed to guide the user to re-enter the first text.

[0042] In some embodiments, the fourth processing module is specifically used for:

[0043] Obtain a preset knowledge base, which includes multiple second processing modules and a first detection action corresponding to each second processing module. The first detection action is associated with the exception type of the second processing module. The multiple second processing modules include multiple first processing modules.

[0044] Based on the historical execution order, the knowledge base is used to determine multiple first detection actions corresponding to each first processing module, as well as the first execution order of the multiple first detection actions.

[0045] Based on multiple first detection actions and multiple first execution sequences, the first detection result of each first processing module is determined.

[0046] In some embodiments, for any one of the first processing modules; the fourth processing module is specifically used for:

[0047] According to the first execution order, multiple first detection actions are executed sequentially to obtain the second detection results of each first detection action;

[0048] Based on multiple second detection results, the first detection result of the first processing module is determined.

[0049] In some embodiments, the fourth processing module is specifically used for:

[0050] When multiple second test results are all normal, the first test result is determined to be normal;

[0051] When any second detection result is abnormal, the cause of the abnormality and the repair suggestions are determined based on multiple second detection actions and multiple second detection results, and the first detection result is determined based on the cause of the abnormality and the repair suggestions.

[0052] In some embodiments, after displaying the first detection results of each of the first processing modules, the fifth processing module is further configured to:

[0053] Based on the first detection results of each first processing module, an anomaly report is generated, which includes text describing each first detection result;

[0054] Display an error report.

[0055] In some embodiments, after displaying the exception report, the fifth processing module is further configured to:

[0056] Receive third text input from the user, which is used to query the first cause of the anomaly and / or the first repair suggestion in the anomaly report;

[0057] Based on the third text, a matching search is performed in the anomaly report to obtain the fourth text corresponding to the first anomaly cause and / or the first repair suggestion;

[0058] Display the fourth text.

[0059] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0060] The memory stores instructions that the computer executes;

[0061] The processor executes computer execution instructions stored in memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0062] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0063] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0064] This application provides an anomaly detection method, apparatus, electronic device, and storage medium for a processing flow. The method includes: receiving first text input by a user, the first text being used to query a first object in a database; identifying the first object in the first text to obtain an identifier for the first object; based on the identifier of the first object, obtaining from the database multiple first processing modules that executed the first object within a historical time period, and the historical execution order of the multiple first processing modules; detecting the multiple first processing modules based on the historical execution order to obtain a first detection result for each first processing module, the first detection result being used to indicate whether an error occurred when the first processing module processed the first object; and displaying the first detection result for each first processing module. This method achieves end-to-end intelligentization from natural language querying to automatic location of processing flow anomalies, compressing the investigation process, which relies on human experience and takes hours or even days in related technologies, to minutes or even seconds, thus improving the efficiency of anomaly detection in complex processing flows. Attached Figure Description

[0065] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0066] Figure 1 A flowchart illustrating an anomaly detection method for a processing flow provided in an embodiment of this application;

[0067] Figure 2 A flowchart illustrating a method for determining a first detection result provided in an embodiment of this application;

[0068] Figure 3 A flowchart illustrating a method for displaying an anomaly report provided in an embodiment of this application;

[0069] Figure 4 A schematic diagram of the structure of an anomaly detection device for a processing flow provided in an embodiment of this application;

[0070] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0071] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0072] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0073] When multiple highly coupled processing modules (i.e., those with complex dependencies) collaborate to handle a case or task, these dependencies often lead to errors influencing and accumulating each other. For example, an anomaly in the output of a preceding processing module may directly trigger a chain of errors in subsequent processing modules, complicating the anomaly and making it difficult to directly pinpoint the root cause of the error in the case's processing flow.

[0074] In related technologies, technicians need to have in-depth knowledge of computer technology. Based on human experience, they spend a lot of time checking the logs of each processing module when it processes cases, the database storing input and output data, the configuration center, and the interface status. This manual method of detecting anomalies in the processing flow usually takes several hours or even days, which is inefficient.

[0075] In view of this, this application provides an anomaly detection method for a processing flow. The method includes: receiving first text input by a user, the first text being used to query a first object in a database; identifying the first object in the first text to obtain an identifier for the first object; based on the identifier of the first object, obtaining from the database multiple first processing modules that executed the first object within a historical time period, and the historical execution order of the multiple first processing modules; based on the historical execution order, detecting the multiple first processing modules to obtain a first detection result for each first processing module, the first detection result being used to indicate whether an error occurred when the first processing module processed the first object; and displaying the first detection result for each first processing module. In the above method, end-to-end intelligent processing is achieved, from natural language query to automatic location of anomalies in the processing flow. This compresses the investigation process, which relies on human experience and takes hours or even days in related technologies, to minutes or even seconds, improving the efficiency of anomaly detection in complex processing flows.

[0076] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0077] Figure 1 A flowchart illustrating an anomaly detection method for a processing flow provided in this application embodiment is shown below. Figure 1 As shown, the method includes:

[0078] S101. Receive first text input by the user, wherein the first text is used to query a first object in the database.

[0079] In some embodiments, a text input box or voice input interface may be provided on the first page (e.g., an operation and maintenance monitoring panel or a dedicated query window), through which the user can input the first text.

[0080] The first text is a natural language query statement used to describe a first object to be queried. For example, the first text might be: "Where is the processing flow of case A1111 stuck?", "Can you help me find out which processing module is stuck on case ID A1112?", or "Why did the processing task with number B1112 fail?".

[0081] The first object is the business entity whose processing flow is to be queried, including but not limited to cases, processing tasks, business orders and other business-related objects with unique identifiers.

[0082] S102. Identify the first object in the first text to obtain the identifier of the first object.

[0083] The identifier of the first object is, for example, the case ID, task number, etc.

[0084] In some embodiments, identifying a first object in the first text to obtain an identifier of the first object includes:

[0085] Based on the pre-configured prompt word template, the first text is analyzed to obtain the user's query intent;

[0086] If the user's query intent indicates whether the first processing module for querying the first object has an error, then the first object in the first text is identified. If the identifier of the first object is identified, the identifier of the first object is obtained. If the identifier of the first object is not identified, the first prompt information is displayed. The first prompt information is used to prompt the user to enter the identifier of the first object.

[0087] If the user's query intent indicates that the first processing module is not querying the first object, then a second prompt message is displayed, which guides the user to re-enter the first text.

[0088] In some embodiments, a first object in the first text is identified using a Large Language Model (LLM) to obtain the identifier of the first object. Specifically, based on a pre-configured prompt word template, the first text is analyzed using LLM to obtain the user's query intent. If the user's query intent indicates whether the first processing module for querying the first object has encountered an error, the first object in the first text is identified using LLM. If the identifier of the first object is identified, the identifier of the first object is obtained; if the identifier of the first object is not identified, a first prompt message is displayed, which prompts the user to enter the identifier of the first object. If the user's query intent indicates whether the first processing module for not querying the first object has encountered an error, a second prompt message is displayed, which guides the user to re-enter the first text.

[0089] A pre-configured prompt template is a structured instruction text designed to guide the LLM in performing structured understanding and analysis of the user's natural language input. The prompt template defines the LLM's processing steps, intent classification rules, and output specifications, enabling the LLM to identify the user's query intent.

[0090] Optionally, the user query intent can be a binary classification identifier. For example, when the user query intent is True, it indicates whether the first processing module for querying the first object has encountered an error; when the user query intent is False, it indicates whether the first processing module for not querying the first object has encountered an error.

[0091] The following example illustrates how LLM (Local Language Management) analyzes the first text based on a pre-configured prompt template to obtain the user's query intent:

[0092] After the first text and the prompt word template are input into the large language model, the large language model performs semantic parsing on the first text and extracts the query elements according to the processing steps in the prompt word template.

[0093] The large language model will determine whether the query element belongs to the first processing module that indicates the first object of the query based on the predefined intent classification rules in the prompt word template;

[0094] If the query element belongs to the first processing module indicating the first object of the query, check for errors. The large language model determines that the user's query intent is True according to the output specification in the prompt word template.

[0095] If the query element does not belong to the first processing module indicating the first object of the query, the large language model determines that the user's query intent is False according to the output specifications in the prompt word template.

[0096] The first prompt message may be something like: "Please enter the case ID you want to query" or "Please enter the task ID you want to query".

[0097] The second prompt message is, for example: "Currently, we only provide fault query services for business processing procedures. Please enter the ID of the object to be queried (such as a case or task) and the fault query request."

[0098] For example, when the first text is, for instance, “Where is the processing flow of case A1111 stuck?”, the user’s query intent is determined to be True, the first object in the first text is identified, and the identifier of the first object is obtained as A1111.

[0099] For example, when the first text is, for example, “Why did the task processing fail?”, the user’s query intent is determined to be True. The first object in the first text is identified. If the identifier of the first object is not identified, the first prompt message is displayed as: “Please enter the case ID to be queried”.

[0100] For example, when the first text is, for example, “How is the weather today?”, it is determined that the user’s query intent is False. The first object in the first text is identified. If the identifier of the first object is not identified, the second prompt message is displayed: “Currently, only fault query services for business processing are provided. Please enter the relevant information of the object to be queried (such as a case or task) and the fault query request.”

[0101] S103. Based on the identifier of the first object, retrieve from the database multiple first processing modules that executed the first object during a historical period, as well as the historical execution order of the multiple first processing modules.

[0102] In some embodiments, the database includes a correspondence between the identifiers of multiple first objects and multiple processing flow records, so that the corresponding processing flow record can be retrieved from the database by using the identifier of the first object.

[0103] In some embodiments, the processing flow record includes multiple first processing modules of each first object executed within a historical time period, timestamps of the multiple first processing modules of each first object executed, and running logs of each first processing module of each first object executed.

[0104] Specifically, the database includes the identifier of each first object, the corresponding relationships of multiple first processing modules executed for each first object within a historical period, the timestamps of the multiple first processing modules executed for each first object, and the running logs of the execution of each first processing module for each first object. This allows the database to retrieve the multiple first processing modules executed for the first object within a historical period, the timestamps of the multiple first processing modules executed for the first object, and the running logs of the execution of each first processing module for the first object by using the identifier of the first object.

[0105] The runtime log of the first processing module includes relevant information about the first object processed by the first processing module.

[0106] For example, when the first processing module is a data query module, the relevant information in its operation log includes: Structured Query Language (SQL) statement ID, query execution parameters, database connection identifier, and query response time, etc.; when the first processing module is a configuration loading module, the relevant information in its operation log includes: dynamic service discovery, configuration and service management platform (Nacos) configuration key, configuration effective version, configuration loading time, and configuration verification result, etc.; when the first processing module is a third-party interface call module, the relevant information in its operation log includes: third-party interface Uniform Resource Locator (URL), request parameter set, signature verification identifier, and interface response status code, etc.; when the first processing module is a data flow module, the relevant information in its operation log includes: input data identifier, output data identifier, data format verification result, and flow node number, etc.

[0107] The following further explains how, based on the identifier of the first object, multiple first processing modules that execute the first object within a historical time period are retrieved from the database, along with the historical execution order of these multiple first processing modules:

[0108] Based on the identifier of the first object, a precise search is performed in the database to match the processing flow record corresponding to that identifier;

[0109] From the processing flow record, obtain the multiple first processing modules that executed the first object within the historical time period, as well as the timestamps of the multiple first processing modules that executed the first object;

[0110] Based on the timestamps of the execution of the first object's multiple first processing modules, the historical execution order of the multiple first processing modules is determined.

[0111] In some embodiments, while obtaining the timestamps of the execution of multiple first processing modules of the first object within a historical time period, the running logs corresponding to each first processing module can also be obtained simultaneously to provide data support for subsequent detection steps.

[0112] S104. Based on the historical execution order, multiple first processing modules are detected to obtain the first detection result of each first processing module. The first detection result is used to indicate whether an error occurred when the first processing module processed the first object.

[0113] Specifically, a preset knowledge base is obtained, which includes multiple second processing modules and a first detection action corresponding to each second processing module. The first detection action is associated with the exception type of the second processing module, and the multiple second processing modules include multiple first processing modules.

[0114] Based on the historical execution order, the knowledge base is used to determine multiple first detection actions corresponding to each first processing module, as well as the first execution order of the multiple first detection actions.

[0115] For any first processing module, multiple second detection actions are executed sequentially according to the first execution order to obtain the second detection result of each second detection action. When multiple second detection results are all normal, the first detection result is determined to be normal. When any second detection result is abnormal, the cause of the abnormality and the repair suggestions are determined based on the multiple second detection actions and the multiple second detection results, and the first detection result is determined based on the cause of the abnormality and the repair suggestions.

[0116] Understandably, the first detection result determined based on the cause of the anomaly and the repair suggestions is an anomaly, and at this time the first detection result includes the cause of the anomaly and the repair suggestions.

[0117] Understandably, if the first detection result is normal, it indicates that the first processing module did not encounter any errors when processing the first object; if the first detection result is abnormal, it indicates that the first processing module encountered an error when processing the first object.

[0118] S105. Display the first detection results of each first processing module.

[0119] In some embodiments, the first detection results of each first processing module can be displayed in a structured or visual process tracing view below the text input box provided on the first page. Specifically, according to the historical execution order, each first processing module and its first detection results are arranged and presented sequentially from top to bottom on the first interface.

[0120] For example, if the first detection result of the first processing module is normal, a normal status indicator (e.g., a green "√" or the word "Normal") is displayed on the left side of the first processing module. If the first detection result of the first processing module is abnormal, an abnormal status indicator (e.g., a red "×" or the word "Abnormal") is displayed on the left side of the first processing module, and the cause of the abnormality and repair suggestions included in the first detection result are displayed near the abnormal status indicator.

[0121] In some embodiments, the first detection result of a first processing module can be displayed on the first page when the first detection result of a first processing module is obtained, or the first detection result of each first processing module can be displayed on the first page after the first detection results of all first processing modules are obtained.

[0122] In this embodiment, a first text input by a user is received, which is used to query a first object in a database. The first object in the first text is identified to obtain an identifier for the first object. Based on the identifier of the first object, multiple first processing modules that execute the first object within a historical time period and the historical execution order of the multiple first processing modules are obtained from the database. Based on the historical execution order, the multiple first processing modules are detected to obtain a first detection result for each first processing module. The first detection result is used to indicate whether an error occurred when the first processing module processed the first object. The first detection result of each first processing module is displayed. In the above method, the entire chain of intelligent detection, from natural language query to automatic location of abnormalities in the processing flow, is realized. The investigation process, which relies on human experience and takes hours or even days in related technologies, is compressed to minutes or even seconds, improving the detection efficiency of abnormalities in complex processing flows.

[0123] In addition, this application supports querying anomalies in the processing flow using natural language (i.e., first text), enabling implementation or maintenance personnel who are not directly involved in code development to quickly locate faulty links in complex business processes through intuitive language descriptions, thereby lowering the technical threshold and improving the ease of use and accessibility of maintenance.

[0124] Hereinafter, based on any of the above embodiments, by... Figure 2 Further explanation is given regarding the detection of multiple first processing modules based on historical execution order, and the first detection results of each first processing module.

[0125] Figure 2 A flowchart illustrating a method for determining a first detection result provided in an embodiment of this application is shown below. Figure 2 As shown, the method includes:

[0126] S201. Obtain a preset knowledge base, wherein the knowledge base includes multiple second processing modules and a first detection action corresponding to each second processing module. The first detection action is associated with the exception type of the second processing module, and the multiple second processing modules include multiple first processing modules.

[0127] Specifically, the knowledge base includes multiple second processing modules, each of which is associated with one or more exception types, and each exception type is associated with one or more first detection actions.

[0128] For example, when the second processing module is a third-party investigation module, the associated exception type includes no callback. The first detection action corresponding to this exception type includes: querying the callback log table, checking the thirdparty.callback.url configuration in Nacos, and calling the third-party health check interface.

[0129] For example, when the second processing module is an Optical Character Recognition (OCR) module, the associated anomaly type includes recognition as empty. The first detection action corresponding to this anomaly type includes: checking whether the original image exists, querying the OCR service log, and verifying whether the model version matches.

[0130] Understandably, the first detection action is usually encapsulated as an independently executable operation unit, which can be implemented as a pre-defined executable script (such as a Shell script) or a pre-defined Application Programming Interface (API) call.

[0131] S202. Based on the historical execution order, determine the multiple first detection actions corresponding to each first processing module and the first execution order of the multiple first detection actions in the knowledge base.

[0132] In some embodiments, based on the historical execution order, multiple first detection actions corresponding to each first processing module and the first execution order of the multiple first detection actions are determined in the knowledge base, including:

[0133] Based on the historical execution order, multiple first detection actions corresponding to each first processing module are determined in the knowledge base;

[0134] For any first processing module, based on the multiple first detection actions corresponding to the first processing module, the first execution order of the multiple first detection actions corresponding to the first processing module is generated through LLM.

[0135] Based on the historical execution order, multiple first detection actions corresponding to each first processing module are determined in the knowledge base. This can be understood as: according to the historical execution order, for each first processing module, the corresponding second processing module is matched in the preset knowledge base, thereby obtaining multiple first detection actions corresponding to the second processing module (i.e., multiple first detection actions corresponding to the first processing module).

[0136] The total number of the second processing modules is greater than the total number of the first processing modules.

[0137] S203. Based on multiple first detection actions and multiple first execution sequences, determine the first detection result of each first processing module.

[0138] In some embodiments, determining the first detection result of each first processing module based on multiple first detection actions and multiple first execution sequences includes:

[0139] For any one of the first processing modules;

[0140] According to the first execution order, multiple first detection actions are executed sequentially to obtain the second detection results of each first detection action;

[0141] Based on multiple second detection results, the first detection result of the first processing module is determined.

[0142] According to the first execution order, multiple first detection actions are executed sequentially to obtain the second detection result of each first detection action. Specifically, according to the first execution order, multiple first detection actions are executed sequentially to obtain the feedback information of each first detection action; based on the feedback information of each first detection action, the second detection result of each first detection action is determined.

[0143] In some embodiments, determining the second detection result of each first detection action based on the feedback information of each first detection action can be as follows: for each first detection action, the feedback information obtained after its execution is compared with the preset feedback standard corresponding to the first detection action in the knowledge base. If the feedback information meets the feedback standard, the second detection result of the first detection action is determined to be normal; if the feedback information does not meet the feedback standard or the feedback information is missing, the second detection result of the first detection action is determined to be abnormal.

[0144] For example, when the first detection action is to query the callback log table, if the feedback information obtained from the first detection action is, for example, that there is a callback record of the first object in the callback log table, the feedback information meets the feedback standard, and the second detection result of the first detection action is normal; if the feedback information obtained from the first detection action is, for example, that there is no callback record of the first object in the callback log table, the feedback information does not meet the feedback standard, and the second detection result of the first detection action is abnormal.

[0145] For example, when the first detection action is to check whether the original image exists, if the first detection action is performed and the feedback information obtained is, for example, that the original image exists, the feedback information meets the feedback standard, then the second detection result of the first detection action is normal; if the first detection action is performed and the feedback information obtained is, for example, that the original image does not exist, the feedback information does not meet the feedback standard, then the second detection result of the first detection action is abnormal.

[0146] In some embodiments, determining the first detection result of the first processing module based on multiple second detection results includes:

[0147] When multiple second test results are all normal, the first test result is determined to be normal;

[0148] When any second detection result is abnormal, the cause of the abnormality and the repair suggestions are determined based on multiple second detection actions and multiple second detection results, and the first detection result is determined based on the cause of the abnormality and the repair suggestions.

[0149] Understandably, the first detection result determined based on the cause of the anomaly and the repair suggestions is an anomaly, and at this time the first detection result includes the cause of the anomaly and the repair suggestions.

[0150] The following is an example of determining the cause of the anomaly and providing remediation suggestions based on multiple second detection actions and results:

[0151] When the second detection action corresponding to any of the first processing modules is abnormal;

[0152] The second detection action of the anomaly is matched with the anomaly type associated with that action in the knowledge base to obtain the anomaly type;

[0153] By combining the feedback information from the second detection action of the anomaly, the cause of the error in the first processing module (i.e. the cause of the anomaly) is determined. At the same time, the mapping relationship between the preset anomaly types and repair suggestions in the knowledge base is linked to generate targeted repair suggestions.

[0154] For example, for the third-party investigation module, if the second detection result of "querying the callback log table" is abnormal (the feedback information is "no first object callback record"), and the second detection result of "checking the thirdparty.callback.url configuration in Nacos" is abnormal (the feedback information is "the configuration value is empty"), then the cause of the abnormality is determined to be "the third-party investigation module has no callback because the callback address configuration in Nacos is missing, which causes the callback request to fail to be sent". The corresponding repair suggestions are "1. Add the correct callback address of thirdparty.callback.url in the Nacos configuration center; 2. Manually trigger the callback resending operation for the first object; 3. Verify the connectivity of the callback address after configuration".

[0155] For example, for the OCR recognition module, if its second detection result of "checking whether the original image exists" is normal (feedback information is "image exists"), but the second detection result of "verifying whether the model version matches" is abnormal (feedback information is "current model version v2.0 does not match the required version v3.1"), then the cause of the abnormality is determined to be "OCR recognition is empty because the model version is incompatible, causing the image recognition logic to fail". The corresponding repair suggestions are "1. upgrade the OCR service model version to v3.1; 2. re-perform OCR recognition on the original image of the first object; 3. configure an automatic model version verification mechanism to avoid the reproduction of version inconsistency issues".

[0156] In this embodiment, a preset knowledge base is obtained. The knowledge base includes multiple second processing modules and first detection actions corresponding to each second processing module. The first detection actions are associated with the exception types of the second processing modules, and the multiple second processing modules include multiple first processing modules. Based on the historical execution order, multiple first detection actions corresponding to each first processing module and the first execution order of the multiple first detection actions are determined in the knowledge base. For any one first processing module, multiple second detection actions are executed sequentially according to the first execution order to obtain the second detection results of each second detection action. When all multiple second detection results are normal, the first detection result is determined to be normal. When any second detection result is abnormal, the cause of the abnormality and repair suggestions are determined based on the multiple second detection actions and multiple second detection results, and the first detection result is determined based on the cause of the abnormality and the repair suggestions. In the above method, the abnormality investigation mode of relying on experience and trial and error in related technologies is transformed into an automated and structured diagnostic process based on a knowledge base, which improves the accuracy of abnormality analysis and realizes a closed-loop processing from abnormality location to abnormality cause and repair suggestions, providing efficient, intelligent and reusable operation and maintenance diagnostic capabilities for complex processing processes.

[0157] In some embodiments, after displaying the first detection results of each first processing module, an anomaly report can be generated based on the detection results of all first processing modules and displayed on the first page.

[0158] Hereinafter, based on any of the above embodiments, by... Figure 3 Further explanation is provided regarding the display method for anomaly reports.

[0159] Figure 3 A flowchart illustrating a method for displaying an anomaly report provided in an embodiment of this application is shown below. Figure 3 As shown, the method includes:

[0160] S301. Based on the first detection results of each first processing module, generate an anomaly report, wherein the anomaly report includes text describing each first detection result.

[0161] Specifically, the detection results of each first processing module are summarized and structured to obtain an anomaly report in natural language format.

[0162] Optionally, the anomaly report is presented in a coherent narrative text, which may include: a brief overview explaining the first object and the overall detection conclusion; a main description of the detection results, describing the detection status of each first processing module, and providing detailed remediation suggestions for the causes of anomalies in the first processing modules; and a summary section summarizing the core issues and subsequent remediation suggestions.

[0163] For example, an anomaly report might read: "Anomaly detection report for Case ID: A1111. The detection results show that an anomaly occurred in the [Third-Party Investigation Module] of the case processing flow. The cause of the anomaly is: the callback address is missing in the Nacos configuration; the suggested solution is to log in to the Nacos configuration center, add the correct value for 'thirdparty.callback.url', and resubmit the processing request. The remaining modules of the process (including the [Data Query Module], [Configuration Loading Module], and [Data Flow Module]) have all been tested and are running normally. Technical personnel should prioritize addressing the above configuration issue."

[0164] S302, Display an anomaly report.

[0165] In some embodiments, an anomaly report may be displayed on the first page below or to the side of the first detection result display area of ​​all first processing modules, in the form of an independent window, an expandable / collapseable panel, or a pop-up modal.

[0166] In some embodiments, after displaying the anomaly report, the following may also be included:

[0167] Receive third text input from the user, which is used to query the first cause of the anomaly and / or the first repair suggestion in the anomaly report;

[0168] Based on the third text, a matching search is performed in the anomaly report to obtain the fourth text corresponding to the first anomaly cause and / or the first repair suggestion;

[0169] Display the fourth text.

[0170] In some embodiments, users can enter third text in the text input box or voice input interface provided on the first page.

[0171] The third text is, for example: What to do if the image recognition logic fails?

[0172] In some embodiments, text matching or lightweight semantic understanding technology is used to perform matching retrieval in the anomaly report based on the third text to obtain the fourth text corresponding to the first anomaly cause and / or the first repair suggestion.

[0173] In some embodiments, the fourth text may be displayed next to the exception report on the first page or within a floating tooltip.

[0174] In some embodiments, the first cause of the anomaly and / or the first repair suggestion corresponding to the fourth text may also be highlighted in the anomaly report.

[0175] In this embodiment, after displaying the first detection results of each first processing module, an anomaly report is generated based on the first detection results of each first processing module. The anomaly report includes text describing each first detection result; the anomaly report is then displayed. This method achieves automated integration and visualization of the first detection results, transforming the originally scattered first detection results of the first processing modules into a highly readable report, further improving the efficiency of anomaly handling.

[0176] Furthermore, after displaying the anomaly report, the system receives third text input from the user. This third text is used to query the first cause of the anomaly and / or the first repair suggestion within the anomaly report. Based on the third text, a matching search is performed within the anomaly report to obtain a fourth text corresponding to the first cause of the anomaly and / or the first repair suggestion. The fourth text is then displayed. This method provides users with interactive query capabilities for the content of the anomaly report, allowing them to quickly focus on the cause of the anomaly and / or the repair suggestion through natural language (i.e., the third text). This enhances the usability and ease of operation of the report, further lowers the technical threshold for repairing anomalies in the processing flow, and increases the average repair time for anomalies.

[0177] Figure 4 This is a schematic diagram of the structure of an anomaly detection device for a processing flow provided in an embodiment of this application, as shown below. Figure 4 As shown, the anomaly detection device 400 for the processing flow provided in this embodiment includes:

[0178] The first processing module 401 is used to receive first text input by the user, and the first text is used to query the first object in the database;

[0179] The second processing module 402 is used to identify the first object in the first text and obtain the identifier of the first object;

[0180] The third processing module 403 is used to retrieve, based on the identifier of the first object, multiple first processing modules that execute the first object within a historical period and the historical execution order of the multiple first processing modules from the database.

[0181] The fourth processing module 404 is used to detect multiple first processing modules based on the historical execution order and obtain the first detection result of each first processing module. The first detection result is used to indicate whether the first processing module has made an error when processing the first object.

[0182] The fifth processing module 405 is used to display the first detection results of each of the first processing modules.

[0183] The anomaly detection device 400 in the processing flow provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0184] In some embodiments, the second processing module 402 is specifically used for:

[0185] Based on the pre-configured prompt word template, the first text is analyzed to obtain the user's query intent;

[0186] If the user's query intent indicates whether the first processing module for querying the first object has an error, then the first object in the first text is identified. If the identifier of the first object is identified, the identifier of the first object is obtained. If the identifier of the first object is not identified, the first prompt information is displayed. The first prompt information is used to prompt the user to enter the identifier of the first object.

[0187] If the user's query intent indicates that the first processing module is not querying the first object, then a second prompt message is displayed to guide the user to re-enter the first text.

[0188] In some embodiments, the fourth processing module 404 is specifically used for:

[0189] Obtain a preset knowledge base, which includes multiple second processing modules and a first detection action corresponding to each second processing module. The first detection action is associated with the exception type of the second processing module. The multiple second processing modules include multiple first processing modules.

[0190] Based on the historical execution order, the knowledge base is used to determine multiple first detection actions corresponding to each first processing module, as well as the first execution order of the multiple first detection actions.

[0191] Based on multiple first detection actions and multiple first execution sequences, the first detection result of each first processing module is determined.

[0192] In some embodiments, for any one of the first processing modules; the fourth processing module 404 is specifically used for:

[0193] According to the first execution order, multiple first detection actions are executed sequentially to obtain the second detection results of each first detection action;

[0194] Based on multiple second detection results, the first detection result of the first processing module is determined.

[0195] In some embodiments, the fourth processing module 404 is specifically used for:

[0196] When multiple second test results are all normal, the first test result is determined to be normal;

[0197] When any second detection result is abnormal, the cause of the abnormality and the repair suggestions are determined based on multiple second detection actions and multiple second detection results, and the first detection result is determined based on the cause of the abnormality and the repair suggestions.

[0198] In some embodiments, after displaying the first detection results of each of the first processing modules, the fifth processing module 405 is further configured to:

[0199] Based on the first detection results of each first processing module, an anomaly report is generated, which includes text describing each first detection result;

[0200] Display an error report.

[0201] In some embodiments, after displaying the exception report, the fifth processing module 405 is further configured to:

[0202] Receive third text input from the user, which is used to query the first cause of the anomaly and / or the first repair suggestion in the anomaly report;

[0203] Based on the third text, a matching search is performed in the anomaly report to obtain the fourth text corresponding to the first anomaly cause and / or the first repair suggestion;

[0204] Display the fourth text.

[0205] The anomaly detection device 400 in the processing flow provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0206] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 5 As shown, the electronic device 50 includes a processor 501 and a memory 502. The processor 501 is communicatively connected to the memory 502, which stores computer execution instructions. The processor 501 is configured to execute the technical solutions in any of the aforementioned method embodiments by executing the computer execution instructions stored in the memory 502.

[0207] Optionally, the memory 502 can be either independent or integrated with the processor 501. Optionally, when the memory 502 is a device independent of the processor 501, the electronic device 50 may further include a bus 503 for connecting the aforementioned devices.

[0208] The electronic device is used to execute the technical solutions in any of the foregoing method embodiments. Its implementation principle and technical effect are similar, and will not be repeated here.

[0209] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0210] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0211] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0212] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0213] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0214] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0215] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0216] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0217] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0218] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0219] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0220] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0221] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. An anomaly detection method for a processing flow, characterized in that, include: Receive first text input by the user, the first text being used to query a first object in the database; Identify the first object in the first text to obtain the identifier of the first object; Based on the identifier of the first object, the database is used to obtain multiple first processing modules that executed the first object within a historical time period, as well as the historical execution order of the multiple first processing modules. Based on the historical execution order, the plurality of first processing modules are detected to obtain a first detection result for each first processing module. The first detection result is used to indicate whether an error occurred when the first processing module processed the first object. Display the first detection results of each of the first processing modules.

2. The method according to claim 1, characterized in that, The step of identifying the first object in the first text to obtain the identifier of the first object includes: Based on the pre-configured prompt word template, the first text is analyzed to obtain the user's query intent; If the user's query intent indicates whether the first processing module for querying the first object has made an error, then the first object in the first text is identified. When the identifier of the first object is identified, the identifier of the first object is obtained. When the identifier of the first object is not identified, a first prompt message is displayed. The first prompt message is used to prompt the user to enter the identifier of the first object. If the user's query intent indicates that the first processing module is not querying the first object, then a second prompt message is displayed to guide the user to re-enter the first text.

3. The method according to claim 1, characterized in that, The step of detecting the plurality of first processing modules based on the historical execution order to obtain a first detection result for each first processing module includes: A preset knowledge base is obtained, the knowledge base includes multiple second processing modules and a first detection action corresponding to each second processing module, the first detection action is associated with the exception type of the second processing module, and the multiple second processing modules include the multiple first processing modules; Based on the historical execution order, in the knowledge base, multiple first detection actions corresponding to each first processing module and the first execution order of the multiple first detection actions are determined; Based on the plurality of first detection actions and the plurality of first execution sequences, the first detection result of each first processing module is determined.

4. The method according to claim 3, characterized in that, For any one of the first processing modules; Based on the plurality of first detection actions and the plurality of first execution sequences, the first detection result of each first processing module is determined, including: According to the first execution order, multiple first detection actions are executed sequentially to obtain the second detection result of each first detection action; Based on multiple second detection results, the first detection result of the first processing module is determined.

5. The method according to claim 4, characterized in that, The determination of the first detection result of the first processing module based on multiple second detection results includes: When all of the second test results are normal, the first test result is determined to be normal; When any second detection result is abnormal, the cause of the abnormality and the repair suggestions are determined based on multiple second detection actions and multiple second detection results, and the first detection result is determined based on the cause of the abnormality and the repair suggestions.

6. The method according to any one of claims 1-5, characterized in that, After displaying the first detection results of each of the first processing modules, the method further includes: Based on the first detection results of each of the first processing modules, an anomaly report is generated, and the anomaly report includes text describing each of the first detection results; Display the aforementioned anomaly report.

7. The method according to claim 6, characterized in that, After displaying the anomaly report, the method further includes: Receive third text input by the user, the third text being used to query the first cause of the anomaly and / or the first repair suggestion in the anomaly report; Based on the third text, a matching search is performed in the anomaly report to obtain the fourth text corresponding to the first anomaly cause and / or the first repair suggestion; The fourth text is displayed.

8. An anomaly detection device for a processing flow, characterized in that, include: The first processing module is used to receive first text input by the user, and the first text is used to query a first object in the database; The second processing module is used to identify the first object in the first text and obtain the identifier of the first object; The third processing module is used to obtain, based on the identifier of the first object, multiple first processing modules that executed the first object within a historical time period and the historical execution order of the multiple first processing modules from the database. The fourth processing module is used to detect the plurality of first processing modules based on the historical execution order and obtain a first detection result for each first processing module. The first detection result is used to indicate whether the first processing module has made an error when processing the first object. The fifth processing module is used to display the first detection results of each of the first processing modules.

9. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-7.