Alarm method, device, equipment, medium and program product

By performing dual security checks on host health and error log retrieval within the Linux operating system, combined with asymmetric encryption and dynamic scheduling, the system addresses the challenges of high technical barriers to service security checks and low functional integration, thereby improving disaster recovery stability and operational efficiency.

CN122293382APending Publication Date: 2026-06-26CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-24
Publication Date
2026-06-26

Smart Images

  • Figure CN122293382A_ABST
    Figure CN122293382A_ABST
Patent Text Reader

Abstract

This application provides an alarm method, apparatus, device, medium, and program product, relating to the field of computer security technology. It aims to lower the technical barriers to use and maintenance of service security checks on Linux operating systems and improve functional integration. The specific technical solution is as follows: After configuring a trust relationship between at least two hosts, based on a first preset startup time, the IP addresses of at least two hosts are traversed; during the traversal of the IP addresses of at least two hosts, a host health check operation and an error log retrieval operation are performed on the first host corresponding to the currently traversed first IP address, obtaining the first host health check operation result and the first error log retrieval operation result; based on the first host health check operation result and the first error log retrieval operation result, a first system alarm message is sent to the electronic equipment of the maintenance personnel. This application is applied to scenarios involving service security checks on Linux operating systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer security technology, and in particular to an alarm method, apparatus, device, medium and program product. Background Technology

[0002] As the scale and complexity of business operations across industries continue to increase, the Linux operating system, as a core business platform, requires routine and automated checks on its service and security status to ensure stable operation.

[0003] Currently, there are two main core implementation schemes in the field of service security inspection for Linux operating systems: one is a traditional centralized system built around Java, which relies on complex middleware and platforms and integrates functions such as vulnerability scanning and log auditing through modular design. The other is a lightweight toolchain based on shell scripts, which combines the Secure Shell (SSH) protocol with scheduled tasks to collect basic server metrics.

[0004] However, the traditional centralized systems built around Java have a highly centralized architecture and heavy dependencies, resulting in a high barrier to entry for both technical use and maintenance. Furthermore, the lightweight toolchains based on Shell scripts have limited functionality and lack deep integration. Consequently, service security checks on the Linux operating system face a high technical barrier to entry for use and maintenance, and have low functional integration. Summary of the Invention

[0005] This application provides an alarm method, apparatus, device, medium, and program product to reduce the technical barriers to use and maintenance of service security checks in the Linux operating system and improve functional integration.

[0006] In a first aspect, embodiments of this application provide an alarm method, which includes: after configuring a trust relationship between at least two hosts, traversing the Internet Protocol (IP) addresses of at least two hosts based on a first preset startup time; during the traversal of the IP addresses of at least two hosts, performing a host health check operation and an error log retrieval operation on the first host corresponding to the currently traversed first IP address, and obtaining the first host health check operation result and the first error log retrieval operation result; the host health check is used to determine whether the values ​​of the configuration parameters of at least two hosts are within or outside a first value range; the error log retrieval operation is used to retrieve the error logs of the default log files of at least two hosts; and based on the first host health check operation result and the first error log retrieval operation result, sending a first system alarm message to the electronic equipment of the maintenance personnel.

[0007] The technical solution provided in this application offers at least the following benefits: It allows for the traversal of various hosts via IP addresses, performing both health checks and error log retrieval on each host, and issuing alerts to operations and maintenance personnel based on the results of these operations. This eliminates the need for traditional centralized system architectures during system service security checks, enabling flexible deployment and lighter dependencies, thus lowering the technical barriers to use and maintenance. Furthermore, the dual-layer security checks allow for multi-dimensional security checks of system services, enriching the functionality of security checks. This reduces the technical barriers to use and maintenance of service security checks on Linux operating systems and improves functional integration.

[0008] One possible implementation is that the first system alarm information includes at least one of a first alarm information and a second alarm information; wherein, the first alarm information is used to alarm the abnormal result of the first host health inspection operation; and the second alarm information is used to alarm the abnormal result of the first error log retrieval operation.

[0009] Another possible implementation, after sending the first system alarm information to the electronic equipment of the maintenance personnel, further includes: determining a second preset startup time based on the alarm level weight corresponding to the first system alarm information; traversing the IP addresses of at least two hosts based on the second preset startup time; performing host health inspection and error log retrieval operations on the second host corresponding to the currently traversed second IP address during the traversal of the IP addresses of at least two hosts, obtaining the results of the second host health inspection and the second error log retrieval operations; and sending the second system alarm information to the electronic equipment of the maintenance personnel based on the results of the second host health inspection and the second error log retrieval operations.

[0010] Another possible implementation is that the first system alarm information includes first alarm information and second alarm information; the above-mentioned determination of the second preset start time based on the alarm level weight corresponding to the first system alarm information includes: determining a first weight range corresponding to the sum of the alarm level weights corresponding to the first alarm information and the alarm level weights corresponding to the second alarm information from at least one preset weight range; each weight range corresponds to a preset start time; and determining the preset start time corresponding to the first weight range as the second preset start time.

[0011] Another possible implementation involves, before traversing the IP addresses of at least two hosts, configuring a trust relationship between at least two hosts using an asymmetric encryption strategy.

[0012] Secondly, this application provides an alarm device, including: a traversal module, an operation module, and a sending module. The traversal module is used to traverse the IP addresses of at least two hosts based on a first preset startup time, after a trust relationship between at least two hosts has been configured. The operation module is used to perform a host health check and an error log retrieval operation on the first host corresponding to the currently traversed first IP address during the traversal of the IP addresses of the at least two hosts, obtaining the results of the first host health check and the first error log retrieval operation. The host health check is used to determine whether the values ​​of the configuration parameters of the at least two hosts are within or outside a first numerical range. The error log retrieval operation is used to retrieve error logs from the default log files of the at least two hosts. The sending module is used to send a first system alarm message to the electronic equipment of the maintenance personnel based on the results of the first host health check and the first error log retrieval operation.

[0013] One possible implementation is that the first system alarm information includes at least one of a first alarm information and a second alarm information; wherein, the first alarm information is used to alarm the abnormal result of the first host health inspection operation; and the second alarm information is used to alarm the abnormal result of the first error log retrieval operation.

[0014] In another possible implementation, the alarm device further includes a determining module. This determining module, after the sending module sends the first system alarm information to the maintenance personnel's electronic equipment, determines a second preset start time based on the alarm level weight corresponding to the first system alarm information. The traversal module is further configured to traverse the IP addresses of at least two hosts based on the second preset start time. The operation module is further configured to, during the traversal of the IP addresses of at least two hosts, perform a host health check operation and an error log retrieval operation on the second host corresponding to the currently traversed second IP address, obtaining the results of the second host health check operation and the second error log retrieval operation. The sending module is further configured to send the second system alarm information to the maintenance personnel's electronic equipment based on the results of the second host health check operation and the second error log retrieval operation.

[0015] Another possible implementation is that the first system alarm information includes first alarm information and second alarm information. The determining module is specifically used to determine, from at least one preset weight range, a first weight range corresponding to the sum of the alarm level weights corresponding to the first alarm information and the alarm level weights corresponding to the second alarm information; each weight range corresponds to a preset start time; and the preset start time corresponding to the first weight range is determined as the second preset start time.

[0016] Another possible implementation is that the alarm device also includes a configuration module; the configuration module is used to configure the IP addresses of at least two hosts using an asymmetric encryption strategy before the traversal module traverses the IP addresses of at least two hosts.

[0017] Thirdly, this application provides an electronic device comprising: a processor and a memory; the memory stores a program or instructions executable on the processor, wherein the program or instructions, when executed by the processor, implement the method of the first aspect described above.

[0018] Fourthly, this application provides a readable storage medium on which a program or instructions are stored, which, when executed by a computer, implement the method of the first aspect described above.

[0019] Fifthly, this application provides a computer program product stored in a storage medium, which, when executed by a computer, implements the method described in the first aspect.

[0020] In a sixth aspect, embodiments of this application provide a chip including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect.

[0021] The beneficial effects of the second to sixth aspects mentioned above are described in the corresponding description of the first aspect and will not be repeated here. Attached Figure Description

[0022] Figure 1 A schematic diagram of the network architecture for an alarm method application provided in this application embodiment;

[0023] Figure 2 A flowchart illustrating an alarm method provided in an embodiment of this application;

[0024] Figure 3 A flowchart illustrating another alarm method provided in an embodiment of this application;

[0025] Figure 4 A flowchart illustrating another alarm method provided in an embodiment of this application;

[0026] Figure 5 A flowchart illustrating another alarm method provided in an embodiment of this application;

[0027] Figure 6 A flowchart illustrating the implementation process of an alarm method provided in this application embodiment;

[0028] Figure 7 A schematic diagram of the weight calculation mechanism in an alarm method provided in an embodiment of this application;

[0029] Figure 8 A schematic diagram of the system structure for an alarm method application provided in this application embodiment;

[0030] Figure 9 This is a schematic diagram illustrating a trust configuration method in an alarm method provided in an embodiment of this application;

[0031] Figure 10 This is a schematic diagram illustrating a secondary service security check method in an alarm method provided in an embodiment of this application.

[0032] Figure 11 This is a schematic diagram of the structure of an alarm device provided in an embodiment of this application;

[0033] Figure 12 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0034] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0035] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0036] The terms "at least one," "at least one of," etc., used in the specification and claims of this application refer to any one, any two, or a combination of two or more of the included items. For example, at least one of a, b, and c can mean: "a," "b," "c," "a and b," "a and c," "b and c," and "a, b, and c," where a, b, and c can be single or multiple. Similarly, "at least two" refers to two or more items, and its meaning is similar to that of "at least one."

[0037] In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0038] The alarm method, apparatus, device, medium, and program product provided in this application embodiment can be applied in computer security scenarios.

[0039] Currently, there are two main types of core implementation solutions in the field of Linux operating system service security inspection. One type is the traditional security inspection system based on Java architecture. Its core relies on complex middleware and a centralized platform, embedding security functions into business logic through hard coding. It utilizes modular design to achieve functions such as vulnerability scanning and log analysis. However, this solution suffers from weak disaster recovery capabilities, dependence on external services, high learning and maintenance costs, and high server resource consumption. Furthermore, cross-cluster deployment requires large-scale modifications to the existing architecture, resulting in insufficient flexibility. The other type is lightweight automation tools, using shell scripts as the core to implement simple inspection functions. Some solutions combine passwordless SSH login and cron scheduling to complete basic indicator checks such as the server's central processing unit (CPU) and memory, without requiring additional hardware or commercial software purchases, resulting in lower deployment costs. However, this type of solution has limited functionality, focusing on single-dimensional checks and failing to form an integrated capability of "health inspection plus log retrieval." It also lacks optimization of cross-host access efficiency based on Linux trust relationships, lacks a dynamic weighted scheduling mechanism, and cannot adapt to the differentiated security inspection needs of large-scale clusters, limiting its applicability in complex business scenarios in the telecommunications industry.

[0040] Therefore, neither of the above two solutions addresses the core pain points of "low functional integration, poor disaster recovery stability, and insufficient deployment flexibility." Specifically, the related technologies have the following drawbacks: 1. Weak disaster recovery capabilities: Existing systems are centrally deployed on a single server, relying on external services and middleware. If the server crashes or the system goes offline during production deployment, security checks will fail, and operations personnel will be unable to retrieve logs and locate problems in a timely manner. 2. High learning and maintenance costs: The Java+SpringMVC architecture has a high learning curve for newcomers, and subsequent functional expansion requires architectural optimization, resulting in insufficient flexibility. 3. Significant security risks: The system relies on functional pages for interaction, making it vulnerable to being taken offline in scenarios with strict security access requirements. Furthermore, the page design itself introduces potential security vulnerabilities. 4. Limited functional coverage: Focusing only on log retrieval or basic indicator detection, it fails to form an integrated capability of "host health status check plus error log retrieval," thus unable to comprehensively support service security operations. 5. Insufficient adaptability and efficiency: The cross-host access process is not optimized by combining Linux trust relationships, lacks a dynamic scheduling mechanism, cannot flexibly adjust the inspection frequency according to cluster monitoring needs, and is difficult to adapt to the differentiated operation and maintenance scenarios of large-scale clusters.

[0041] To address the aforementioned technical issues, this application provides an alarm method, apparatus, device, medium, and program product. The alarm method provided in this application can traverse each host by IP address, performing two security checks on each host: health inspection and error log retrieval. Based on the results of these checks, alarms are sent to maintenance personnel. Therefore, when performing system service security checks, on the one hand, it eliminates the need for a traditional centralized system architecture, allowing for flexible deployment and lighter dependencies, thus lowering the technical barriers to use and maintenance; on the other hand, the two-stage security checks can examine system service security from multiple dimensions, enriching the functionality of the security check. This reduces the technical barriers to use and maintenance of service security checks on the Linux operating system and improves functional integration.

[0042] Specifically, the alarm method provided in this application embodiment can achieve the following effects: 1. Improve system disaster recovery stability: Ensure that even if some servers experience anomalies, the service security check function can still be carried out normally, avoiding function interruption due to single point of failure. 2. Lower the technical usage and maintenance threshold: Provide a simple and easy-to-use implementation solution, reduce the learning cost for new users, improve the flexibility of function expansion, and reduce the difficulty of subsequent maintenance. 3. Avoid unnecessary security risks: Adapt to strict security access requirements, abandon redundant page interaction design, and ensure the compliant and stable operation of the system. 4. Achieve integrated functional coverage: Simultaneously meet the core needs of host health inspection and error log retrieval, comprehensively protect service security, and fill the gaps in existing technical functions. 5. Optimize adaptability and operation and maintenance efficiency: By optimizing the cross-host access process and dynamic scheduling mechanism, adapt to the differentiated monitoring needs of large-scale clusters, improve the speed and accuracy of operation and maintenance response, and ensure production safety.

[0043] The alarm methods, apparatus, devices, media, and program products provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0044] Figure 1 The network architecture for an alarm method application provided in an embodiment of this application is illustrated. For example... Figure 1 As shown, the network architecture includes an alarm device 101 and a terminal device 102. The alarm device 101 and the terminal device 102 are interconnected.

[0045] In some embodiments, the alarm device 101 may be a server, a computer, or a processor or processing unit within a server or computer. The server may be a single server or a server cluster consisting of multiple servers. It should be noted that the embodiments of this application do not limit the specific device form of the alarm device 101. Figure 1 The alarm device 101 is used as an example of a single server.

[0046] In some embodiments, the terminal device may be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, personal computer (PC), ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc., and the embodiments of this application do not specifically limit it. Figure 1 The example shown is a mobile phone, with terminal device 102 as an example.

[0047] It should be noted that the network architecture described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As network architectures evolve, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0048] See Figure 2 This is a flowchart illustrating an alarm method provided in an embodiment of this application. Figure 2 As shown, the alarm method provided in this application embodiment can be implemented by the alarm device described above, specifically including the following steps 201 to 203.

[0049] Step 201: After configuring the trust relationship between at least two hosts, the alarm device traverses the IP addresses of at least two hosts based on the first preset startup time.

[0050] In some embodiments, the trust relationship described above is an authorization mechanism that allows hosts that have configured the trust relationship to access each other without a password.

[0051] It is understood that after the trust relationship between the above-mentioned at least two hosts is configured, the at least two hosts can access each other without password, thereby facilitating the execution of subsequent steps of the alarm method provided in the embodiments of this application.

[0052] In some embodiments, the first preset startup time can be a preset duration or a preset moment. After the trust relationship between the at least two hosts is configured, the alarm device begins to traverse the IP addresses of the at least two hosts after the preset duration or at the preset moment.

[0053] In some embodiments, the first preset startup time may be the system default or may be arbitrarily set by the user according to actual usage needs.

[0054] In some embodiments, the alarm device is based on a Shell script and uses the executable file "mysql" in the bin directory of the MyStructured Query Language (mysql) client in combination with an "embedded document" to establish a database connection. It reads the list of IP addresses under the service cluster through database table A and iterates through the IP addresses of at least two of the above hosts.

[0055] In some embodiments, the Shell script described above can be replaced with a Python script or a Perl script.

[0056] In some embodiments, the database table A above includes a list of service deployment host IP addresses configured for each service cluster, with the service cluster name as the key.

[0057] Step 202: During the process of traversing the IP addresses of at least two hosts, the alarm device performs a host health inspection operation and an error log retrieval operation on the first host corresponding to the first IP address currently being traversed, and obtains the results of the first host health inspection operation and the first error log retrieval operation.

[0058] The aforementioned host health inspection is used to determine whether the configuration parameter values ​​of at least two hosts are within or outside the first numerical range; the aforementioned error log retrieval operation is used to retrieve error logs from the default log files of at least two hosts.

[0059] In some embodiments, the first numerical range may be the range of host CPU utilization, the range of host memory usage, or the range of packet loss rate during network transmission.

[0060] In some embodiments, if the value of a host's configuration parameter is within a first numerical range, it can indicate that the configuration parameter is secure and does not need to be recorded; if the value of a host's configuration parameter is not within the first numerical range, it can indicate that the configuration parameter is insecure and needs to be recorded.

[0061] For example, when the alarm device uses SSH to traverse the IP addresses of at least two hosts, it first obtains the standard data requirements configured in the server configuration file through database table B, checks whether the configuration of the first host corresponding to the first IP is within the first value range, and then obtains the host inspection command line string corresponding to the alarm level of high, middle or low when the first parameter is executed through database table D. Combined with the shell built-in command evaluation (Evaluate, eval) to execute the inspection command line string, and based on whether it exceeds the alarm threshold, obtains the health inspection operation result of the first host, and records the result in the log file under the . / log directory. Next, the default log file of the first host is obtained. The error, warning, or debug information corresponding to the second parameter when the script is executed is used as the default search string for this default log file. Then, the search string configuration of the service cluster is obtained through the database table E. The command line string is concatenated by the variable IFS="|" through a for loop to obtain "grep -E "aa|bb|cc|error" common.log". The result of the first error log search operation of the service cluster default log file common.log is then saved.

[0062] In some embodiments, the database table B mentioned above includes standard configuration data for configuring server configuration files, where the key is the file name to which the parameter belongs.

[0063] In some embodiments, the database table D includes a host inspection command line string, an alarm threshold, an alarm level configuration, and the keyword is the alarm level.

[0064] In some embodiments, the default log file refers to the log file that the system or application automatically generates and manages according to its preset rules without user-defined configuration.

[0065] In some embodiments, the database table E mentioned above includes log retrieval string configuration, where multiple strings are separated by a vertical bar "|", and the keyword is the service cluster name.

[0066] It should be noted that the above example of configuring the log retrieval string as aa|bb|cc is just that, and the actual log retrieval string configuration should prevail.

[0067] In some embodiments, grep -E is a pattern matching command, in the form of grep -E "pattern" filename, which searches for lines in the specified file that match the extended regular expression pattern and outputs those lines.

[0068] It should be noted that when using commands or strings in practice, for non-specific text, the double quotes in the commands or strings should be English double quotes. The same applies to commands or strings in the following text, and will not be repeated hereafter.

[0069] Step 203: Based on the results of the first host health inspection operation and the results of the first error log retrieval operation, the alarm device sends the first system alarm information to the electronic equipment of the maintenance personnel.

[0070] In some embodiments, the first system alarm information may be an alarm SMS, an alarm email, or an alarm phone call.

[0071] For example, taking the alarm information of the first system as an alarm SMS, the alarm device sends an alarm SMS to the electronic device of the maintenance personnel corresponding to the alarm level based on the health inspection operation results of the first host and the first error log retrieval operation results, through the data of database table C and by calling the SMS platform interface.

[0072] It should be noted that database table C includes the personnel who will be sent alarm SMS messages, their contact information, and the alarm level configuration, with the keyword being alarm level.

[0073] In some embodiments, the first system alarm information includes at least one of a first alarm information and a second alarm information.

[0074] The first alarm message is used to alert that the health inspection operation result of the first host is abnormal; the second alarm message is used to alert that the error log retrieval operation result is abnormal.

[0075] In some embodiments, abnormal results of the above-mentioned host health inspection operation may be due to the host CPU temperature exceeding 90 degrees Celsius, the memory usage exceeding 88%, or the packet loss rate of the host in network transmission exceeding 10%.

[0076] In some embodiments, the abnormal result of the above error log retrieval operation may be an error record in the log file that contains the A configuration, an error record with the error type of debug, an error record of the debug type that contains the A configuration, or an error record that contains all error types.

[0077] In some embodiments, since the first system alarm information includes a first alarm information and a second alarm information, and the first alarm information is used to alarm the abnormal result of the first host health inspection operation; the second alarm information is used to alarm the abnormal result of the first error log retrieval operation, the alarm information can be better classified, thereby improving the work efficiency of operation and maintenance personnel.

[0078] In some embodiments, the alarm device can traverse each host by IP address, performing two security checks on each host: health inspection and error log retrieval. Based on the results of these checks, it sends alarms to maintenance personnel. This eliminates the need for a traditional centralized system architecture during system service security checks, allowing for flexible deployment and lighter dependencies, thus lowering the technical barriers to use and maintenance. Furthermore, the two-stage security checks can examine system service security from multiple dimensions, enriching the functionality of the security checks. This approach lowers the technical barriers to use and maintenance of service security checks on the Linux operating system and improves functional integration.

[0079] In some embodiments, combined with Figure 2 ,like Figure 3 As shown, after step 203 above, the alarm method provided in this application embodiment may further include steps 204 to 207 as described below.

[0080] Step 204: The alarm device determines the second preset start time based on the alarm level weight corresponding to the alarm information of the first system.

[0081] In some embodiments, the alarm level weight can be any natural number.

[0082] For example, the alarm level weight can be 1, 16, or 88.

[0083] In some embodiments, the first system alarm information includes a first alarm information and a second alarm information; the alarm device adds the alarm level weight corresponding to the first alarm information and the alarm level weight corresponding to the second alarm information to obtain a target alarm level weight; then, according to the preset relationship between the preset alarm level weight and the preset start time, the preset start time corresponding to the target alarm level weight is determined as the second preset start time.

[0084] In some embodiments, the second preset startup time can be a preset duration or a preset moment. After the trust relationship between the at least two hosts is configured, the alarm device begins to traverse the IP addresses of the at least two hosts again after the preset duration or at the preset moment.

[0085] In some embodiments, the second preset startup time may be the system default or may be arbitrarily set by the user according to actual usage needs.

[0086] In some embodiments, the second preset startup time may be the same as or different from the first preset startup time.

[0087] In some embodiments, the first system alarm information includes first alarm information and second alarm information. For example, combining... Figure 3 ,like Figure 4As shown, step 204 can be implemented through steps 204a and 204b below.

[0088] Step 204a: The alarm device determines, from at least one preset weight range, the first weight range corresponding to the sum of the alarm level weights of the first alarm information and the alarm level weights of the second alarm information.

[0089] Each of the above-mentioned weight ranges corresponds to a preset start time.

[0090] For example, taking the preset start time as the preset duration, the alarm device adds the alarm level weight corresponding to the first alarm information and the alarm level weight corresponding to the second alarm information. The duration is 10 minutes if the sum is greater than 4, 30 minutes if it is less than or equal to 4 but greater than 2, and 60 minutes if it is equal to 2.

[0091] Step 204b: The alarm device determines the preset start time corresponding to the first weight range as the second preset start time.

[0092] For example, taking the preset start time as the preset duration, if the duration corresponding to the first weight range is 10 minutes, the alarm device can determine 10 minutes as the second preset start time; if the duration corresponding to the first weight range is 1 hour, the alarm device can determine 1 hour as the second preset start time.

[0093] In some embodiments, the time interval for security checks is determined by the relationship between the preset alarm level weight and the preset start time, thus providing an accurate basis for the time interval for security checks, thereby accurately and dynamically controlling the time interval for security checks.

[0094] Step 205: The alarm device traverses the IP addresses of at least two hosts based on the second preset startup time.

[0095] For example, after the preset duration or preset time corresponding to the second preset start time is reached, the alarm device uses a Shell script to establish a database connection through the executable file "mysql" in the bin directory of the MySQL client and the "embedded document". It then reads the list of IP addresses under the service cluster through database table A and iterates through the IP addresses of at least two hosts.

[0096] Step 206: During the process of traversing the IP addresses of at least two hosts, the alarm device performs a host health inspection operation and an error log retrieval operation on the second host corresponding to the currently traversed second IP address, and obtains the results of the second host health inspection operation and the second error log retrieval operation.

[0097] For example, the alarm device uses SSH to traverse the IP addresses of at least two hosts. First, it retrieves the standard data requirements configured in the server configuration file through database table B, checks whether the configuration of the second host corresponding to the current second IP is within the second value range, and then retrieves the host inspection command line string corresponding to the alarm level of high, middle, or low as the first parameter value during script execution through database table D. It then executes the inspection command line string using the shell built-in command `eval`, and based on whether it exceeds the alarm threshold, obtains the health inspection operation result of the second host, and records the result in the log file under the `. / log` directory. Next, it retrieves the default log file of the second host, uses the error, warn, or debug value corresponding to the second parameter during script execution as the default search string for this default log file, and then retrieves the service cluster search string configuration through database table E. Using the variable `IFS="|"`, it iterates through the command line string using a for loop to obtain the second error log search result for the service cluster default log file `common.log`, and then saves the second error log search result.

[0098] Step 207: Based on the results of the second host health inspection and the second error log retrieval, the alarm device sends the second system alarm information to the electronic equipment of the maintenance personnel.

[0099] For example, based on the health inspection operation results and the second error log retrieval operation results of the second host, the alarm device sends an alarm SMS to the electronic device of the maintenance personnel corresponding to the alarm level through the data in database table C and by calling the SMS platform interface.

[0100] For other descriptions of steps 205 to 207 above, please refer to the relevant descriptions of steps 201 to 203 above. To avoid repetition, they will not be repeated here.

[0101] In some embodiments, by adjusting the time interval for the next security check based on system alarm information after each security check, the execution interval of security checks is dynamically controlled according to the content of the alarm information, thereby saving system resources while ensuring the availability of security checks.

[0102] In some embodiments, combined with Figure 2 ,like Figure 5 As shown, prior to step 201 above, the alarm method provided in this application embodiment may further include step 208 below.

[0103] Step 208: The alarm device uses an asymmetric encryption strategy to configure a trust relationship between at least two hosts.

[0104] In some embodiments, the asymmetric encryption strategy may be a digital signature strategy, an encrypted transmission strategy, a key exchange strategy, or an identity authentication strategy.

[0105] For example, select a host in the cluster as the server, go to the current user's root directory and use `ls -la` to show hidden directories, go to the `.ssh` directory, and use `ssh-keygen -t rsa` to generate a public and private key. Load the private key file, copy the public key to the host with which you want to establish a trust relationship (the client), log in to the target host using the `ssh` command, and redirect the output of the public key to the end of the authorized key file (`authorized_keys`), thereby configuring a trust relationship between at least two hosts.

[0106] In some embodiments, by configuring the trust relationship between hosts through an asymmetric encryption strategy, the number of password inputs is reduced while ensuring data security, thus facilitating the execution of script commands.

[0107] The alarm method of this application will be described below through specific embodiments.

[0108] like Figure 6 As shown, the implementation process of the alarm method provided in this application embodiment includes the following S1 to S7:

[0109] S1, crontab scheduling.

[0110] The crontab platform uses a time interval (i.e., the first preset start time) generated by a weighted secondary calculation mechanism to regularly schedule preset shell commands.

[0111] In some embodiments, the principle of the weighted secondary calculation mechanism is as follows: Figure 7 As shown, the security check system of this service sets alarm levels to high, middle, and low, respectively. The values ​​of the first parameter (host health inspection module) are high, middle, and low, and the values ​​of the second parameter (error log retrieval module) are error, warn, and debug. The corresponding level weights (i.e., alarm level weights) are 4, 2, and 1. The scheduling interval is 10 minutes (i.e., the second preset start time) when the sum of the weights of the first and second parameters is greater than 4, 30 minutes when the sum is less than or equal to 4 but greater than 2, and 60 minutes when the sum is equal to 2.

[0112] In some embodiments, the aforementioned weighted secondary calculation mechanism can also solve the problem of inflexible alarm level configuration for the two modules, allowing the service health monitoring system to configure parameters according to cluster monitoring needs. For example, if service cluster A only needs to focus on the debug level for error log retrieval, but has high requirements for host health and requires a high level, it will be scheduled according to the high alarm level to avoid system security issues. It will also prevent the recording of other non-debug level error log retrieval results in the . / log file, saving storage space and avoiding SMS disruptions to non-debug alarm level maintenance personnel.

[0113] In some embodiments, when using crontab, the first step is to determine when the script will run. The scheduling interval is determined using a weighted secondary calculation method. A crontab command consists of the scheduling interval plus an action. The time can be minute, hour, day, month, or week, and the action for a shell script is the script startup method. It is recommended that all scripts be deployed in the background without suspending (nohup) to avoid data unreliability caused by abnormal process activity. Furthermore, shell scripts have advantages such as portability, ease of deployment, and low resource consumption, allowing for full cluster deployment. This deployment method can perform host health checks even if one or more servers are down.

[0114] In some embodiments, the systemd timer or at command of the Linux system, or a third-party lightweight scheduling tool (such as Jenkins Simple Task Scheduler) can be used to replace crontab. By configuring task triggering conditions and interval rules, and combining weight calculation logic, the execution frequency can be dynamically adjusted to achieve a differentiated scheduling effect consistent with the original scheduling platform.

[0115] In some embodiments, the system architecture is as follows Figure 8 As shown, the service security inspection system includes functions such as a data support platform, an application platform, and a scheduling platform. The application platform includes two main modules: host health inspection and error log retrieval.

[0116] In some embodiments, Python or Perl scripts can be used instead of Shell scripts. Both are lightweight and compatible with Linux distributions. They can read data through database connection libraries (such as Python's pymysql), and complete cross-host SSH access with the help of the paramiko module. They can also develop host health inspection and log retrieval functions, meeting the core requirements of easy deployment and low resource consumption.

[0117] S2. The health check service system is activated.

[0118] If the target has no trust relationship between at least two hosts, such as Figure 9As shown, the following actions are combined to complete the trust relationship configuration between hosts.

[0119] Configuring trust relationships can reduce the number of password entries, and this step is a prerequisite for facilitating script execution.

[0120] Configuring trust relationships between Linux hosts mainly involves the following actions: Select a host within the cluster as the server, navigate to the current user's root directory, use `ls -la` to display hidden directories, and enter the `.ssh` directory; in this directory, use `ssh-keygen -t rsa` to generate a public and private key; load the private key file; copy the public key to the host with which you want to establish a trust relationship (i.e., the client); log in to the target host using the `ssh` command, and redirect the output of the public key to the end of the `authorized_keys` file (i.e., using an asymmetric encryption strategy to configure a trust relationship between at least two of the hosts).

[0121] In some embodiments, the Linux SSH key trust relationship can be replaced by the Kerberos protocol or a lightweight proxy service (such as Ansible). Kerberos enables passwordless access through centralized authentication, while Ansible can manage host authentication permissions in batches. Both can avoid re-entering passwords and ensure efficient execution of cross-host checks.

[0122] S3, SSH to the target IP address.

[0123] This service security check system uses the host IP address as a unique index to perform host health checks and error log retrieval around the IP address. Failure of any module's health check will have a significant impact on the security and stability of the service cluster application. Both modules serve the same purpose: poor host health will definitely affect service health, and frequent error log occurrences will also impact service health. Without wasting resources, secondary service security checks are performed sequentially within the same traversal logic. Older log search systems only provide error log retrieval functionality; the shell script-based secondary service security checks better ensure the stable and secure operation of the service cluster. The secondary service security check method is as follows: Figure 10 Specifically, the shell script uses the executable file "mysql" in the bin directory of the MySQL client, combined with an "embedded document," to establish a database connection. It reads the list of IP addresses under the service cluster through database table A, iterates through all host IP addresses under the service cluster, and uses the ssh command to perform inspection actions (i.e., host health inspection operations) at each IP address.

[0124] In some embodiments, Table A above includes a list of service deployment host IP addresses configured for each service cluster, with the key being the service cluster name.

[0125] S4. Host health check.

[0126] Based on the host health inspection module, the standard data requirements configured in the server configuration file are obtained through data table B. It checks whether the configuration of each host is within a reasonable value range (i.e., the first value range). The host inspection command line string corresponding to the alarm level with the first parameter value of high, middle or low is obtained through data table D. The inspection command line string is executed in combination with the shell built-in command eval. If the alarm threshold is exceeded (i.e., the result of the first host health inspection operation), the alarm information is recorded in the log file under the . / log directory. The log file is kept for 1 month and is automatically cleaned up by the auxiliary script.

[0127] In some embodiments, for the host health inspection module, due to the separation of the platform and the application, production managers such as developers and production operations personnel can only rely on the platform's monitoring data to judge the health status of the host. Of course, the mature monitoring methods are timely, but at the same time, they will gradually reduce the subjective initiative of the managers in checking Linux health. The platform's monitoring results will make the troubleshooting of production problems too passive, and there have been cases where the platform's feedback results do not match the actual situation, causing the troubleshooting work to reach a deadlock. At this time, the host health self-check using scripts becomes particularly important.

[0128] In some embodiments, Table B above includes standard configuration data for configuring server configuration files, where the keyword is the file name to which the parameter belongs.

[0129] In some embodiments, Table D above includes a host inspection command line string, an alarm threshold, an alarm level configuration, and the keyword is the alarm level.

[0130] S5, Host health check alarm triggered.

[0131] The alarm level is determined by using data from table C in the database and calling the SMS platform interface to send alarm SMS messages (i.e., first system alarm information) to the corresponding alarm level operation and maintenance personnel, notifying them to intervene in production safety operation and maintenance.

[0132] In some embodiments, Table C includes the configuration of personnel to whom alarm SMS messages are sent, their contact information, and alarm level configuration, with the keyword being alarm level.

[0133] S6. Error log retrieval.

[0134] Based on the error log retrieval module, the system iterates through all service deployment host IP addresses in the service cluster. After performing host health checks via SSH commands to each IP address, it immediately performs log retrieval (i.e., error log retrieval). This ensures that each host completes a two-stage check mechanism—host health checks and error log retrieval—within a single iteration. The key string for log retrieval is the default retrieval string, corresponding to the second parameter (error, warn, or debug) during script execution. The system then retrieves the retrieval string configuration for the service cluster from the database table E. For example, if the configuration is "aa|bb|cc" and the parameter is "error", the variable IFS = "|" is used to construct the command line string using a for loop, resulting in "grep -E "aa|bb|cc|error" common.log". This completes the error log check of the service cluster's default log file common.log and outputs the result (i.e., the result of the first error log retrieval operation).

[0135] In some embodiments, the error log retrieval module can indeed retrieve logs from different hosts under the application deployment simply by entering keywords, compared to the existing service security check system for SIM cards. However, due to various reasons such as the service security check system host crashing or security access forcing the service to go offline, developers cannot quickly retrieve logs immediately without the service security check system. The shell script deployment method continues the function of keyword log retrieval by passing parameters through the script, and does not need to rely on the health status of services outside the application cluster.

[0136] S7, Error log retrieval alarm triggered.

[0137] The alarm level is determined by using data from table C in the database and calling the SMS platform interface to send alarm SMS messages (i.e., first system alarm information) to the corresponding alarm level operation and maintenance personnel, notifying them to intervene in production safety operation and maintenance.

[0138] It should be noted that S4 and S6 can be executed in parallel. S5 only needs to be executed after S4, and S7 only needs to be executed after S6.

[0139] In this way, each host can be traversed by IP address, performing two security checks: health inspection and error log retrieval. Based on the results of these checks, alerts are sent to operations and maintenance personnel. Therefore, when performing system service security checks, on the one hand, there is no need to use the traditional centralized system architecture, allowing for flexible deployment and lighter dependencies, lowering the technical barriers to use and maintenance; on the other hand, the two-stage security checks can examine system service security from multiple dimensions, enriching the functionality of security checks. This lowers the technical barriers to use and maintenance of service security checks on the Linux operating system and improves functional integration.

[0140] It should be noted that the descriptions of each step S1 to S7 in this embodiment can be found in the descriptions in the above embodiments, and will not be repeated here.

[0141] It should be noted that the above-described method embodiments, or the various possible implementations of the method embodiments, can be executed individually, or, provided there is no conflict, they can be combined with each other. The specific implementation can be determined according to actual usage requirements, and this application embodiment does not impose any restrictions on this.

[0142] As can be seen, the above mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, the embodiments of this application provide corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the modules and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0143] This application embodiment can divide the alarm device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into a single sending module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0144] In some embodiments, this application also provides an alarm device. The alarm device may include one or more functional modules for implementing the alarm methods of the above method embodiments.

[0145] For example, Figure 11 This is a schematic diagram of an alarm device provided in an embodiment of this application. Figure 11 As shown, the alarm device 900 includes: a traversal module 901, an operation module 902, and a sending module 903.

[0146] The traversal module 901 is used to traverse the IP addresses of at least two hosts based on a first preset startup time, after the trust relationship between at least two hosts has been configured. The operation module 902 is used to perform host health inspection and error log retrieval operations on the first host corresponding to the first IP address being traversed during the process of traversing the IP addresses of at least two hosts, and obtain the results of the first host health inspection and the first error log retrieval operation. The host health inspection is used to determine whether the values ​​of the configuration parameters of at least two hosts are within or outside a first value range. The error log retrieval operation is used to retrieve the error logs of the default log files of at least two hosts. The sending module 903 is used to send the first system alarm information to the electronic equipment of the operation and maintenance personnel based on the results of the first host health inspection and the first error log retrieval operation.

[0147] The alarm device provided in this application can traverse each host by IP address, performing two security checks on each host: health inspection and error log retrieval. Based on the results of these checks, it sends alarms to operations and maintenance personnel. Therefore, when performing system service security checks, on the one hand, it eliminates the need for a traditional centralized system architecture, allowing for flexible deployment and lighter dependencies, thus lowering the technical barriers to use and maintenance; on the other hand, the two-stage security checks can examine system service security from multiple dimensions, enriching the functionality of the security checks. This reduces the technical barriers to use and maintenance of service security checks on the Linux operating system and improves functional integration.

[0148] In some embodiments, the first system alarm information includes at least one of a first alarm information and a second alarm information; wherein, the first alarm information is used to alarm the abnormal result of the first host health inspection operation; and the second alarm information is used to alarm the abnormal result of the first error log retrieval operation.

[0149] In some embodiments, the alarm device 900 further includes a determining module. The determining module is configured to determine a second preset start time based on the alarm level weight corresponding to the first system alarm information after the sending module 903 sends the first system alarm information to the electronic equipment of the maintenance personnel. The traversal module 901 is further configured to traverse the IP addresses of at least two hosts based on the second preset start time. The operation module 902 is further configured to perform a host health check operation and an error log retrieval operation on the second host corresponding to the currently traversed second IP address during the process of traversing the IP addresses of at least two hosts, obtaining the second host health check operation result and the second error log retrieval operation result. The sending module 903 is further configured to send the second system alarm information to the electronic equipment of the maintenance personnel based on the second host health check operation result and the second error log retrieval operation result.

[0150] In some other embodiments, the first system alarm information includes first alarm information and second alarm information. Specifically, the determining module is configured to determine, from at least one preset weight range, a first weight range corresponding to the sum of the alarm level weights corresponding to the first alarm information and the alarm level weights corresponding to the second alarm information; each weight range corresponds to a preset start time; and the preset start time corresponding to the first weight range is determined as a second preset start time.

[0151] In some other embodiments, the alarm device 900 further includes a configuration module. The configuration module is used to configure the IP addresses of at least two hosts using an asymmetric encryption strategy before the traversal module 901 traverses the IP addresses of at least two hosts.

[0152] It should be noted that the alarm device can implement all the processes implemented in the above method embodiments and achieve the same beneficial effects. To avoid repetition, it will not be described again here.

[0153] In the case where the functions of the integrated modules described above are implemented in hardware, this application provides a possible structural schematic diagram of the electronic device involved in the above embodiments. For example... Figure 12 As shown, the electronic device 90 includes: a processor 92, a communication interface 93, and a bus 94. Optionally, the electronic device 90 may also include a memory 91.

[0154] Processor 92 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 92 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 92 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0155] Communication interface 93 is used to connect with other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.

[0156] The memory 91 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0157] As one possible implementation, the memory 91 can exist independently of the processor 92. The memory 91 can be connected to the processor 92 via a bus 94 and is used to store instructions or program code. When the processor 92 calls and executes the instructions or program code stored in the memory 91, it can implement the alarm method provided in the embodiments of this application.

[0158] In another possible implementation, memory 91 can also be integrated with processor 92.

[0159] Bus 94 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 94 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 12 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0160] Through the above description of the implementation methods, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the service calling device can be divided into different functional modules to complete all or part of the functions described above.

[0161] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above alarm method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0162] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0163] This application also provides a readable storage medium storing a program or instructions that, when executed by a computer, implement the alarm method provided in the above embodiments. It is understood that all or part of the processes in the above method embodiments can be executed by computer instructions instructing related hardware; the readable storage medium can be any of the foregoing embodiments or memory; the readable storage medium can also be an external storage device of the service invocation device, such as a pluggable hard drive, Smart Media Card (SMC), Secure Digital (SD) card, flash card, etc., equipped on the service invocation device. Further, the readable storage medium can include both internal storage units of the service invocation device and external storage devices. The readable storage medium is used to store the computer program and other programs and data required by the service invocation device. The readable storage medium can also be used to temporarily store data that has been output or will be output.

[0164] This application also provides a computer program product, which is stored in a storage medium and implements the alarm method provided in the above embodiments when the computer program product is executed by a computer.

[0165] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0166] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0167] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. An alarm method, characterized in that, include: Once the trust relationship between at least two hosts is configured, the Internet Protocol IP addresses of the at least two hosts are traversed based on the first preset startup time. During the process of traversing the IP addresses of the at least two hosts, a host health inspection operation and an error log retrieval operation are performed on the first host corresponding to the first IP address currently being traversed, and the results of the first host health inspection operation and the first error log retrieval operation are obtained. The host health check is used to determine whether the values ​​of the configuration parameters of the at least two hosts are within or outside a first value range; the error log retrieval operation is used to retrieve the error logs of the default log files of the at least two hosts; Based on the results of the first host health inspection and the first error log retrieval, a first system alarm message is sent to the electronic equipment of the maintenance personnel.

2. The alarm method according to claim 1, characterized in that, The first system alarm information includes at least one of the first alarm information and the second alarm information; The first alarm message is used to alert that the health inspection operation result of the first host is abnormal; the second alarm message is used to alert that the error log retrieval operation result is abnormal.

3. The alarm method according to claim 1 or 2, characterized in that, After sending the first system alarm information to the electronic equipment of the maintenance personnel, the method further includes: Based on the alarm level weights corresponding to the alarm information of the first system, a second preset start time is determined; Based on the second preset startup time, traverse the IP addresses of the at least two hosts; During the process of traversing the IP addresses of the at least two hosts, a host health inspection operation and an error log retrieval operation are performed on the second host corresponding to the currently traversed second IP address to obtain the results of the second host health inspection operation and the second error log retrieval operation. Based on the results of the second host health inspection and the second error log retrieval, a second system alarm message is sent to the electronic equipment of the maintenance personnel.

4. The alarm method according to claim 3, characterized in that, The first system alarm information includes the first alarm information and the second alarm information; The step of determining the second preset start time based on the alarm level weight corresponding to the alarm information of the first system includes: From at least one preset weight range, a first weight range is determined corresponding to the sum of the alarm level weight corresponding to the first alarm information and the alarm level weight corresponding to the second alarm information; each weight range corresponds to a preset start time; The preset startup time corresponding to the first weight range is determined as the second preset startup time.

5. The alarm method according to claim 1, characterized in that, Before traversing the IP addresses of the at least two hosts, the method further includes: Use an asymmetric encryption strategy to configure a trust relationship between the at least two hosts.

6. An alarm device, characterized in that, The device includes: a traversal module, an operation module, and a sending module; The traversal module is used to traverse the IP addresses of at least two hosts based on a first preset startup time, after the trust relationship between at least two hosts has been configured. The operation module is used to perform a host health check and an error log retrieval operation on the first host corresponding to the currently traversed first IP address during the process of traversing the IP addresses of the at least two hosts, and to obtain the first host health check operation result and the first error log retrieval operation result; the host health check is used to determine whether the values ​​of the configuration parameters of the at least two hosts are within or outside a first value range; the error log retrieval operation is used to retrieve the error logs of the default log files of the at least two hosts; The sending module is used to send a first system alarm message to the electronic equipment of the operation and maintenance personnel based on the first host health inspection operation result and the first error log retrieval operation result.

7. The alarm device according to claim 6, characterized in that, The first system alarm information includes at least one of the first alarm information and the second alarm information; The first alarm message is used to alert that the health inspection operation result of the first host is abnormal; the second alarm message is used to alert that the error log retrieval operation result is abnormal.

8. The alarm device according to claim 6, characterized in that, The device also includes a configuration module; The configuration module is used to configure the IP addresses of the at least two hosts using an asymmetric encryption strategy before the traversal module traverses the IP addresses of the at least two hosts.

9. An electronic device, characterized in that, It includes a processor and a memory, the memory storing a program or instructions that can run on the processor, the program or instructions being executed by the processor to implement the alarm method as described in any one of claims 1-5.

10. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a computer, implement the alarm method as described in any one of claims 1-5.

11. A computer program product, characterized in that, The computer program product is stored in a storage medium, and when executed by a computer, the computer program product implements the alarm method as described in any one of claims 1-5.