Alarm information processing method and device, equipment and storage medium
By performing two-level filtering on alarm information, combining alarm type, time, keywords, and level, the problem of misjudgment of alarm information in existing technologies is solved, enabling rapid identification and location of the root cause of critical faults, improving fault recovery efficiency, and reducing business risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-26
- Publication Date
- 2026-07-14
AI Technical Summary
In existing technologies, the filtering methods for alarm information make it difficult to quickly identify and locate the root causes of critical failures, increasing delays in fault recovery and business risks.
By determining the comprehensive feature vector of the alarm information to be processed, including alarm type, alarm time, target keywords, alarm level and business coreness, and combining it with the reference feature vector in the alarm database, a two-level filtering is performed. First, it is determined whether the alarm information is the same, and then the similarity is determined according to the weight of the target keywords and the alarm level, so as to achieve accurate identification of the same or similar alarm information.
It enables accurate identification and location of critical alarm information, improves fault recovery efficiency, and reduces business risks.
Smart Images

Figure CN122387791A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, device, and storage medium for processing alarm information. Background Technology
[0002] In large-scale distributed systems and cloud computing environments, monitoring systems generate massive amounts of alarm information every day. These alarms are typically high-dimensional, real-time, and bursty, placing enormous processing pressure on operations and maintenance personnel. How to quickly and accurately identify the actual fault events from these alarms and suppress the interference of duplicate or similar alarms has become a key technical challenge for improving operational efficiency and system reliability.
[0003] In existing technologies, the similarity between newly arrived alarm information and historical alarm information is typically calculated, for example using cosine similarity or text similarity algorithms based on the bag-of-words model, to determine whether they describe the same alarm event. If the similarity exceeds a preset static threshold, they are determined to be similar alarms and are then merged or filtered.
[0004] However, the above-mentioned methods of filtering alarm information may result in some important alarm information being improperly merged or filtered out, making it difficult to quickly identify and locate the root cause of critical failures, thereby delaying fault recovery and increasing business risks. Summary of the Invention
[0005] This invention provides a method, apparatus, device, and storage medium for processing alarm information, which addresses the shortcomings of existing technologies where alarm information may be improperly merged or filtered, making it difficult to quickly identify and locate the root cause of critical faults, thus delaying fault recovery and increasing business risks. The invention achieves accurate identification of identical or similar alarm information, avoids the erroneous filtering of critical alarm information, and thus enables rapid identification and location of the root cause of critical faults, improving fault recovery efficiency and reducing business risks.
[0006] This invention provides a method for processing alarm information, including: Determine the comprehensive feature vector of the alarm information to be processed. The comprehensive feature vector includes alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the business corresponding to the alarm information to be processed. Based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, determine whether there is reference alarm information in the alarm database that is the same as the alarm information to be processed; If it is determined that there is no reference alarm information that is identical to the alarm information to be processed, the similarity between the alarm information to be processed and the target reference alarm information is determined based on the weight of the target keyword and the alarm level, wherein the alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed. If the alarm information to be processed is determined to be a similar alarm information based on the similarity, the alarm information to be processed is marked.
[0007] According to a method for processing alarm information provided by the present invention, determining whether there is reference alarm information in the alarm database that is identical to the alarm information to be processed, based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, includes: The feature values of each dimension in the comprehensive feature vector are compared with the corresponding feature values of each dimension in the reference feature vector. If all dimensional feature values match, then the alarm information to be processed is determined to be the same alarm information as the reference alarm information corresponding to the successfully matched reference feature vector.
[0008] According to a method for processing alarm information provided by the present invention, determining the similarity between the alarm information to be processed and the target reference alarm information based on the weight of the target keyword and the alarm level includes: Obtain the weight of each target keyword from the keyword library of the service corresponding to the alarm information to be processed; Based on the weight of each of the target keywords, the business weight factor of the alarm information to be processed is determined; Filter target reference alarm information from the alarm database that has the same alarm type as the alarm information to be processed within a preset historical time period; Based on the alarm time of the alarm information to be processed, the alarm time of each target reference alarm information, the business weight factor, and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information is determined.
[0009] According to a method for processing alarm information provided by the present invention, determining the similarity between the alarm information to be processed and the target reference alarm information based on the alarm time of the alarm information to be processed, the alarm time of each target reference alarm information, the service weight factor, and the alarm level includes: Based on the alarm time of the alarm information to be processed and the alarm time of each target reference alarm information, the number of alarm information occurring within each unit time is counted to obtain the first statistical sequence; Based on the first statistical sequence, determine the first fluctuation value; Based on the alarm time of the alarm information to be processed and the alarm time of each target reference alarm information, the number of alarm information occurring within each observation time window is counted to obtain a second statistical sequence, wherein the observation time window includes multiple unit time. Based on the second statistical sequence, determine the second fluctuation value; Based on the first fluctuation value, the second fluctuation value, the business weight factor, and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information is determined.
[0010] According to a method for processing alarm information provided by the present invention, determining the similarity between the alarm information to be processed and the target reference alarm information based on the first fluctuation value, the second fluctuation value, the business weight factor, and the alarm level includes: The similarity between the alarm information to be processed and the target reference alarm information is determined based on the following formulas (1) and (2): (1) (2) in, This represents the second statistical sequence obtained by counting the number of alarm messages according to the observation time window m. This represents the second fluctuation value. This represents the first statistical sequence. This represents the first fluctuation value. Indicates the slope. , This represents the business weighting factor. Indicates the alarm level, This indicates the similarity.
[0011] According to a method for processing alarm information provided by the present invention, the method further includes: If it is determined that the alarm information to be processed is the same or similar, the alarm information to be processed shall be deleted. If it is determined that the alarm information to be processed is a dissimilar alarm information, the alarm information to be processed is added to the alarm database.
[0012] According to a method for processing alarm information provided by the present invention, the reference alarm information is stored in the alarm database in a clustered form; The step of adding the alarm information to the alarm database when it is determined that the alarm information to be processed is a dissimilar alarm information includes: If it is determined that the alarm information to be processed is a dissimilar alarm information, the region to which the alarm information to be processed belongs and the device level corresponding to the alarm information to be processed are extracted from the alarm information to be processed; If the difference between the alarm time of the alarm to be processed and the alarm time corresponding to the candidate alarm cluster in the alarm database is less than a time threshold, the region to which the alarm belongs does not exceed the region corresponding to the candidate alarm cluster, and the device level is the same as the device level corresponding to the candidate alarm cluster, then the alarm to be processed is added to the candidate alarm cluster. The time threshold is determined based on the device level and the business core level.
[0013] According to a method for processing alarm information provided by the present invention, the step of adding the alarm information to be processed to the candidate alarm cluster includes: The number of alarms, the corresponding business core coefficient, and the time decay coefficient in the target alarm cluster are determined. The time decay coefficient is related to the alarm level of the alarm information in the target alarm cluster. The target alarm cluster is a cluster obtained assuming that the alarm information to be processed has been added to the candidate alarm cluster. Based on the number of alarms, the business coreness coefficient, and the time decay coefficient, determine the aggregation effect value corresponding to the target alarm cluster; If the aggregation effect value is greater than or equal to the historical aggregation effect value corresponding to the candidate alarm cluster, it is determined that the alarm information to be processed will be added to the candidate alarm cluster.
[0014] According to a method for processing alarm information provided by the present invention, the method further includes: If the aggregation effect value is less than the historical aggregation effect value, the alarm information to be processed is stored as a new alarm cluster in the alarm database.
[0015] The present invention also provides an alarm information processing apparatus, comprising: The determination module is used to determine the comprehensive feature vector of the alarm information to be processed. The comprehensive feature vector includes alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the business corresponding to the alarm information to be processed. The determining module is further configured to determine, based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, whether there is reference alarm information in the alarm database that is the same as the alarm information to be processed; The determining module is further configured to, in the case that there is no reference alarm information identical to the alarm information to be processed, determine the similarity between the alarm information to be processed and the target reference alarm information based on the weight of the target keyword and the alarm level, wherein the alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed. The tagging module is used to tag the alarm information to be processed when the similarity is determined to be similar alarm information.
[0016] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the alarm information processing method as described above.
[0017] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the alarm information processing method as described above.
[0018] The present invention also provides a computer program product, including a computer program, which, when executed by a processor, implements the alarm information processing method as described above.
[0019] The alarm information processing method, apparatus, device, and storage medium provided by this invention determine a comprehensive feature vector of the alarm information to be processed. The comprehensive feature vector includes alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the business corresponding to the alarm information to be processed. Based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, it is determined whether there is any reference alarm information in the alarm database that is the same as the alarm information to be processed. If it is determined that there is no reference alarm information that is the same as the alarm information to be processed, the similarity between the alarm information to be processed and the target reference alarm information is determined based on the weight of the target keyword and the alarm level. The alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed. If the alarm information to be processed is determined to be similar based on the similarity, the alarm information to be processed is marked. Because this embodiment employs a two-level filtering process, it first determines whether the alarm information to be processed is the same as the previously processed reference alarm information in the alarm database, and then further determines whether they are similar alarm information. When determining similar alarm information, it also considers the differences in the core business involved in the alarm information to be processed and the alarm level, thus achieving accurate identification of the same or similar alarm information. This avoids the situation where key alarm information is incorrectly filtered out, thereby enabling rapid identification and location of the root cause of key faults, improving fault recovery efficiency, and reducing business risks. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0021] Figure 1 This is a schematic diagram of the alarm information processing flow provided in an embodiment of the present invention.
[0022] Figure 2 This is a flowchart illustrating the alarm information processing method provided in an embodiment of the present invention.
[0023] Figure 3 This is a schematic diagram of alarm information filtering provided in an embodiment of the present invention.
[0024] Figure 4 This is a similarity diagram of alarm information provided in an embodiment of the present invention.
[0025] Figure 5 This is a schematic diagram of the alarm information processing device provided in an embodiment of the present invention.
[0026] Figure 6 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0027] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0028] Currently, the handling of duplicate or similar alarms typically involves setting up a Redis in-memory database. This database stores multiple alarm messages, each associated with a status identifier, such as a network management synchronization identifier to indicate whether it has been synchronized to the network management system, and a save / clear alarm identifier to indicate whether it has been cleared. Upon receiving a new alarm message, the similarity between the new alarm message and the existing alarm messages in the Redis database is calculated based on its text content or basic characteristics. If the similarity exceeds a fixed threshold, it is considered a similar alarm and filtered out. However, this approach does not consider the differences in the core business implications of the alarm messages or the urgency reflected by the alarm levels. This leads to all alarm messages being treated equally during similarity comparisons, potentially misjudging high-impact, high-level critical alarm messages as redundant and clearing them. This severely hinders timely fault detection and accurate fault location, delaying fault recovery and increasing business risks.
[0029] In view of the above-mentioned problems, this invention proposes a method for processing alarm information. In this method, two-level filtering can be performed. First, it is determined whether the newly arrived alarm information is the same as the previously processed alarm information. Then, it is further determined whether the alarm information is similar. When determining similar alarm information, the differences in the core business involved in the alarm information and the alarm level are also considered. This achieves accurate identification of the same or similar alarm information, avoids the situation where key alarm information is incorrectly filtered out, and thus can quickly identify and locate the root cause of key faults, improve fault recovery efficiency, and reduce business risks.
[0030] The following is combined with Figures 1 to 4 The alarm information processing method provided in the embodiments of the present invention is described. The embodiments of the present invention are applicable to large-scale distributed system operation and maintenance or IoT device monitoring scenarios. The executing entity of this method can be an electronic device such as a terminal device, computer, server, server cluster, or specially designed alarm information processing device, or it can be an alarm information processing device installed in the electronic device. This alarm information processing device can be implemented through software, hardware, or a combination of both.
[0031] Figure 1 This is a schematic diagram of the alarm information processing flow provided in an embodiment of the present invention, such as... Figure 1 As shown, embodiments of the present invention can perform intelligent alarm processing by using mobile phone alarm information, reducing the redundancy of alarm information, and performing intelligent clustering analysis on the reduced alarm information. Figure 1 The process shown can automate and intelligently process and manage alarm information.
[0032] Figure 2This is a flowchart illustrating the alarm information processing method provided in an embodiment of the present invention, as shown below. Figure 2 As shown, the method includes: Step 201: Determine the comprehensive feature vector of the alarm information to be processed. The comprehensive feature vector includes alarm type, alarm time, at least one target keyword, alarm level, and the business coreness of the business corresponding to the alarm information to be processed.
[0033] In this step, alarm information collection is a crucial step in ensuring stable system operation within a modern, highly integrated, and automated Unified Messaging Service (UMS) alarm system. By collecting alarm information over a period of time from various third-party interface monitoring systems, this alarm information not only serves as an early warning system for assessing system health but also provides important clues for diagnosing system anomalies or malfunctions.
[0034] Tables 1 and 2 show multiple alarm messages. Due to space limitations, different fields of the same alarm message are shown in two separate tables. For example, the information in the same row of Tables 1 and 2 represents different fields of the same alarm message. Table 1
[0035] Table 2
[0036] The alarm messages vary widely, but they all revolve around anomalies or malfunctions occurring in the system. For example, a 5XX alarm for multiple domains might indicate that certain critical business services are inaccessible; performance metrics exceeding thresholds could be a warning of system resource shortages or misconfiguration; and log upload interruptions could affect system maintenance personnel's ability to track and analyze system behavior. As shown in Tables 1 and 2, each alarm message records the source of the alarm, the affected business system, the alarm title, the specific content, and the time the alarm occurred.
[0037] However, due to the numerous sources of alarm information in the system, and the continuous generation of new alarms over time, a large number of duplicate or similar alarms will inevitably be encountered during the alarm information collection process. These duplicate or similar alarms not only increase the redundancy of the system's alarm information but also impose an additional burden on analysis and processing. Therefore, collecting this alarm information is not only for obtaining the current operating status of the system but also for subsequent redundancy reduction processing, so as to more efficiently and accurately locate and resolve problems in the system.
[0038] This involves redundancy reduction processing of the collected alarm information, identifying and filtering out duplicate, similar, or irrelevant alarm information to reduce the number of redundant alarm messages. Figure 3 This is a schematic diagram of alarm information filtering provided in an embodiment of the present invention, such as... Figure 3 As shown, multiple alarm messages are processed to reduce redundancy. By identifying and filtering out duplicate, similar, or irrelevant alarm data, the number of redundant alarms is reduced. The alarm messages after redundancy reduction should not only be highly general but also retain as much detailed information as possible.
[0039] Therefore, when reducing redundancy in newly collected alarm information, it is necessary to first determine at least one target keyword in the alarm information based on the preset core keyword library of the corresponding service. Different core keyword libraries can be pre-set for different services such as Content Delivery Network (CDN) and Domain Name System (DNS). For example, keywords for CDN services include "node caching" and "distribution delay," while keywords for DNS services include "domain name resolution."
[0040] In addition, alarm type, alarm time, alarm level, and the business coreness of the corresponding business can be extracted from the pending alarm information to form a comprehensive feature vector. For example, the comprehensive feature vector of a pending alarm information is: [Alarm type = CPU overload, alarm time = 16:00, keyword = {CDN, node cache}, alarm level = 1, business coreness = high].
[0041] By extracting alarm type, alarm time, at least one target keyword, alarm level, and business coreness, and determining a comprehensive feature vector based on these feature dimensions, the comprehensive feature vector is made to better fit the actual fault location needs.
[0042] Step 202: Based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, determine whether there is a reference alarm information in the alarm database that is the same as the alarm information to be processed.
[0043] In this step, the alarm database stores at least one reference alarm message and a reference feature vector for each reference alarm message. Each reference feature vector includes the alarm type, alarm time, at least one keyword, alarm level, and the business coreness of the corresponding service for the reference alarm message. The reference alarm messages stored in the alarm database are all previously filtered, distinct, and dissimilar alarm messages.
[0044] The values of each dimension in the comprehensive feature vector are compared with the corresponding values of each reference feature vector stored in the alarm database to determine whether there is a reference alarm in the alarm database that is identical to the alarm to be processed. For example, if each dimension value in the comprehensive feature vector is the same as the corresponding dimension value in a certain reference feature vector, it can be determined that the alarm to be processed is the same alarm as the reference alarm corresponding to the successfully matched reference feature vector; otherwise, there is no reference alarm in the alarm database that is identical to the alarm to be processed.
[0045] If a reference alarm message identical to the alarm message to be processed exists in the alarm database, the alarm message to be processed can be filtered out or marked, and the occurrence count of the successfully matched reference alarm message in the alarm database can be incremented by one to accurately reflect the frequency of occurrence of this type of alarm message.
[0046] By comparing feature vectors, duplicate alarm information can be quickly filtered out, which can greatly improve the processing efficiency of high-frequency duplicate alarms.
[0047] Step 203: If it is determined that there is no reference alarm information that is the same as the alarm information to be processed, the similarity between the alarm information to be processed and the target reference alarm information is determined based on the weight of the target keyword and the alarm level. The alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed.
[0048] In this step, after determining that no identical reference alarm information exists in the alarm database, it is necessary to further determine whether similar reference alarm information exists in the database. When determining similarity, in addition to considering the time series of the alarm information, the weight of the target keyword and the alarm level are also considered. The weight of the target keyword represents its importance or influence in the business context, thus determining the business core of the alarm information to be processed. The alarm level represents the severity and urgency of the fault indicated by the alarm information. Determining the similarity between the alarm information to be processed and the target reference alarm information through the weight of the target keyword and the alarm level allows for a quantitative assessment of the business value and urgency of the alarm information. This prioritizes high-value, high-urgency alarm information in the similarity judgment, improving the accuracy and business relevance of the filtering strategy.
[0049] Among them, the alarm types of the target reference alarm information are the same as the alarm types of the alarm information to be processed, such as CPU overload alarm or network link packet loss alarm.
[0050] Step 204: If the alarm information to be processed is determined to be similar alarm information based on similarity, mark the alarm information to be processed.
[0051] In this step, if the similarity between the alarm information to be processed and a certain target reference alarm information is greater than the preset similarity, it means that the alarm information to be processed is a similar alarm information to the target reference alarm information. In this case, the alarm information to be processed is deleted or marked, and the occurrence count of the target reference alarm information is incremented by one.
[0052] The alarm information processing method provided in this embodiment of the invention determines a comprehensive feature vector of the alarm information to be processed. The comprehensive feature vector includes alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the business corresponding to the alarm information to be processed. Based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, it is determined whether there is any reference alarm information in the alarm database that is the same as the alarm information to be processed. If it is determined that there is no reference alarm information that is the same as the alarm information to be processed, the similarity between the alarm information to be processed and the target reference alarm information is determined based on the weight of the target keyword and the alarm level. The alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed. If the alarm information to be processed is determined to be similar based on the similarity, the alarm information to be processed is marked. Because this embodiment employs a two-level filtering process, it first determines whether the alarm information to be processed is the same as the previously processed reference alarm information in the alarm database, and then further determines whether they are similar alarm information. When determining similar alarm information, it also considers the differences in the core business involved in the alarm information to be processed and the alarm level, thus achieving accurate identification of the same or similar alarm information. This avoids the situation where key alarm information is incorrectly filtered out, thereby enabling rapid identification and location of the root cause of key faults, improving fault recovery efficiency, and reducing business risks.
[0053] For example, based on the above embodiments, when determining whether there is a reference alarm information in the alarm library that is the same as the alarm information to be processed, based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm library, it can be that the feature values of each dimension in the comprehensive feature vector are compared with the corresponding feature values of each dimension in each reference feature vector. If all feature values are consistent, it is determined that the alarm information to be processed and the reference alarm information corresponding to the successfully matched reference feature vector are the same alarm information.
[0054] Specifically, for each reference feature vector, the feature values of each dimension in the comprehensive feature vector can be extracted one by one and compared with the corresponding feature values of the reference feature vector. When all feature values of all dimensions are the same, it means that the two are the same alarm information.
[0055] In this embodiment, by comparing the feature values of each dimension as described above, it is determined whether there is an alarm message in the alarm database that is the same as the alarm message to be processed. This can accurately identify completely duplicate alarm messages, effectively avoid misjudgment caused by similar features, and ensure the accuracy of the first-level filtering.
[0056] For example, based on the above embodiments, when determining the similarity between the alarm information to be processed and the target reference alarm information based on the weight of the target keyword and the alarm level, it can be achieved in the following way: The weights of each target keyword are obtained from the keyword library of the business corresponding to the alarm information to be processed. Based on the weights of each target keyword, the business weight factor of the alarm information to be processed is determined. Target reference alarm information with the same alarm type as the alarm information to be processed within a preset historical time period is selected from the alarm library. Based on the alarm time of the alarm information to be processed, the alarm time of each target reference alarm information, the business weight factor, and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information is determined.
[0057] Specifically, the pre-defined keyword library for each business function also includes the weight of each keyword. This weight can be used to characterize the importance or influence of the corresponding target keyword in the business context, thereby determining the business core of the alarm information to be processed. After extracting at least one target keyword from the alarm information to be processed, the weight of each target keyword can be determined from the corresponding pre-defined keyword library.
[0058] When the pending alarm message includes only one target keyword, the weight of this target keyword can be determined as the business weight factor of the pending alarm message. When the pending alarm message includes two or more target keywords, the highest weight among these target keyword weights can be determined as the business weight factor of the pending alarm message, or the average weight of these target keyword weights can be determined as the business weight factor of the pending alarm message, or the lowest weight among these target keyword weights can be determined as the business weight factor of the pending alarm message.
[0059] Furthermore, based on the alarm type of the alarm information to be processed, target reference alarm information with the same alarm type within a preset historical time period can be filtered from the alarm database. The preset historical time period can be dynamically configured based on experience or actual conditions, such as configuring it according to business scenarios. For example, the preset historical time period can be set to the past 24 hours or the past 7 days to ensure that the target reference alarm information participating in the similarity calculation has timeliness and statistical significance.
[0060] After filtering out the target reference alarm information, the self-similarity of adding the alarm information to be processed to the target reference alarm information can be determined based on the alarm time of the alarm information to be processed, the alarm time of each target reference alarm information, as well as the business weight factor and alarm level. This determines the similarity between the alarm information to be processed and the target reference alarm information.
[0061] In this embodiment, by considering the business weight factor based on business keyword weights and integrating the alarm level that characterizes the urgency of the fault, the similarity between the alarm information to be processed and the target reference alarm information is determined. In the similarity judgment, alarms with high business impact and high level can be given higher distinguishability and priority. Thus, similarity judgment can be made based on business characteristics. While effectively compressing the total amount of alarm information, it ensures that key alarm information with high coreness and high urgency is accurately retained, which significantly improves the accuracy of alarm information reduction and the precision of fault location.
[0062] In one implementation, when determining the similarity between the alarm information to be processed and the target reference alarm information based on the alarm time of the alarm information to be processed, the alarm time of each target reference alarm information, the business weight factor, and the alarm level, it can be done in the following way: Based on the alarm time of the alarm information to be processed and the alarm time of each target reference alarm information, the number of alarm information occurring within each unit time is counted to obtain a first statistical sequence. Based on the first statistical sequence, a first fluctuation value is determined. Based on the alarm time of the alarm information to be processed and the alarm time of each target reference alarm information, the number of alarm information occurring within each observation time window is counted to obtain a second statistical sequence. The observation time window includes multiple unit time periods. Based on the second statistical sequence, a second fluctuation value is determined. Based on the first fluctuation value, the second fluctuation value, the business weight factor, and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information is determined.
[0063] Specifically, the unit of time can be the basic time granularity, such as 1 hour. The observation time window m can consist of at least one continuous unit of time, which can be set according to actual needs, such as 2 hours.
[0064] When constructing the first statistical sequence, the alarm information to be processed can be added to the target reference alarm information to obtain an alarm information set. Based on the alarm time of each alarm information in this alarm information set, the number of alarm information occurring in each unit of time is counted. For example, if the unit of time is 1 hour, the alarm time of the alarm information to be processed can be used as the benchmark, and each time we go back one hour, we count the number of alarm information occurring in every hour, thus forming the first statistical sequence X = {x1, x2, ..., x...}. n}, where x nThis represents the number of alarm messages that occur within the nth unit of time.
[0065] After obtaining the first statistical sequence, the variance can be calculated and determined as the first fluctuation value. Specifically, the average of all elements in the first statistical sequence can be calculated first, then the square of the difference between each element and the average can be determined, and the results can be averaged to obtain the first fluctuation value. This first fluctuation value can be used to determine the fluctuation of the alarm information in a unit time dimension after the alarm information to be processed is added.
[0066] Furthermore, the construction of the second statistical sequence follows the same method as the first, except that the unit time is replaced with an observation time window. That is, based on the alarm time of each alarm in the alarm information set, the number of alarms occurring within each observation time window is counted. For example, if the observation time window is 2 hours, the alarm time of the pending alarm information can be used as the baseline, and each time the alarm is traced back 2 hours, the number of alarms occurring within each 2-hour period is counted, thus forming the second statistical sequence. = {x (m) 1, x (m) 2..., x (m) n}, where x (m) n This indicates the number of alarm messages that occur within the nth observation time window.
[0067] After obtaining the second statistical sequence, the variance can be calculated and determined as the second fluctuation value. The specific calculation method is similar to that used to calculate the first fluctuation value, and will not be repeated here. This second fluctuation value can be used to determine the fluctuation of the alarm information over the observation time window after the addition of alarm information to be processed.
[0068] Furthermore, the similarity between the alarm information to be processed and the target reference alarm information can be determined based on the first fluctuation value, the second fluctuation value, the business weight factor, and the alarm level.
[0069] By determining the variance at different time scales, the self-similarity of alarm information at different time scales can be determined based on the changes in variance. This allows for the determination of the similarity between the alarm information to be processed and the target reference alarm information. From the perspective of the inherent time distribution pattern of alarm information, its dynamic correlation characteristics can be accurately quantified, effectively identifying alarm information that has different surface features but is highly homogeneous in its occurrence pattern, thus improving the accuracy of similar alarm information determination.
[0070] For example, the similarity between the alarm information to be processed and the target reference alarm information can be determined based on the following formulas (1) and (2): (1) (2) in, This represents the second statistical sequence obtained by counting the number of alarm messages according to the observation time window m. This indicates the second fluctuation value. Represents the first statistical sequence. Indicates the first fluctuation value. Indicates the slope. , Indicates business weighting factors. This indicates the alarm level of the alarm information to be processed. The similarity is represented by Var(.), and the variance is represented by Var(.).
[0071] Figure 4 This is a similarity graph of alarm information provided in an embodiment of the present invention. Figure 4 The data in the middle is a weekly alarm information compiled and plotted on an hourly basis. The similarity graph shows that the similarity results approximate a line with a slope of A straight line.
[0072] In addition, Table 3 outputs the similarity coefficient data of alarm information for four consecutive weeks, proving that the generation of alarms exhibits obvious self-similarity characteristics. Among them, the similarity coefficient in Table 3 is the similarity H in formula (2).
[0073] Table 3
[0074] It should be noted that after determining the similarity between the alarm information to be processed and the target reference alarm information, if the similarity is greater than the preset similarity, it means that the alarm information to be processed and the target reference alarm information are similar. The preset similarity can be set according to actual conditions or experience, such as 0.8.
[0075] Analysis revealed that these similar alarm messages contained a large amount of redundant information, indicating that the generation of alarm messages has significant statistical characteristics. To gain a more comprehensive understanding of the behavioral patterns of alarm message generation and to discover the potential regularities of similar alarms, it is necessary to study and remove these similar alarms.
[0076] In this embodiment, based on the self-similarity definition of a stationary random process, time variance analysis can be used to analyze variance changes at different time scales. Furthermore, based on the first and second fluctuation values, business weighting factors are applied. and alarm level As a correction, the self-similarity of alarm time distribution can be combined with the business attributes and urgency of the alarm. This can more comprehensively and accurately quantify the overall correlation strength between the alarm information to be processed and the target reference alarm information in terms of time and business dimensions, thereby improving the accuracy of identifying similar alarm information.
[0077] For example, based on the above embodiments, if it is determined that the alarm information to be processed is the same alarm information or similar alarm information, the alarm information to be processed is deleted; if it is determined that the alarm information to be processed is dissimilar alarm information, the alarm information to be processed is added to the alarm library.
[0078] Specifically, after deleting pending alarm information, the occurrence count of identical or similar alarms can be incremented by one to accurately reflect the frequency of such alarms. Furthermore, only dissimilar alarm information will be stored in the alarm database.
[0079] In this embodiment, the two-level filtering method described above removes identical or similar alarm information, effectively eliminating massive amounts of redundant alarms and significantly reducing system storage and computing load. Furthermore, it ensures that the alarm database retains alarm information with independent semantics, providing a clean and high-fidelity data foundation for subsequent fault location, root cause analysis, and operational decisions.
[0080] Furthermore, the UMS alarm console generates 4,000 to 10,000 alarm messages daily. Although the methods described in the aforementioned embodiments were used to filter out identical and similar alarms, the remaining number of alarm messages is still between 3,000 and 6,000. This massive number makes it difficult for operations and maintenance personnel to conduct effective analysis.
[0081] In response to the above situation, in this embodiment of the invention, alarm information can be intelligently aggregated. By integrating regional distribution characteristics, dynamic time correlation rules, and device level and business coreness, alarm information is aggregated, so that the daily average number of alarms after aggregation is reduced to 10%-15% of the original data. The alarm information is also integrated and refined, thereby ensuring that the aggregated alarms provided to operation and maintenance personnel have higher reference value and decision-making basis.
[0082] For example, the reference alarm information included in the alarm database is stored in a clustered manner. When an alarm to be processed is determined to be a dissimilar alarm, it can be added to the alarm database in the following way: If it is determined that the alarm information to be processed is a dissimilar alarm information, the region to which the alarm information belongs and the device level corresponding to the alarm information are extracted from the alarm information to be processed. If it is determined that the difference between the alarm time of the alarm information to be processed and the alarm time corresponding to the candidate alarm cluster in the alarm database is less than the time threshold, the region to which the alarm belongs does not exceed the region corresponding to the candidate alarm cluster, and the device level is the same as the device level corresponding to the candidate alarm cluster, the alarm information to be processed is added to the candidate alarm cluster. The time threshold is determined based on the device level and the business coreness.
[0083] Specifically, alarm clustering can be understood as a data set formed by grouping together multiple alarm messages that are close in time, belong to the same region, have the same device level, and match the core business in the alarm database. Each cluster represents a potential, independent fault event or fault scenario.
[0084] The region to which the alarm information belongs can be understood as the physical or logical location where the alarm was generated, such as the province or city where the data center is located. Device level refers to the layer of the alarm source within the system architecture, such as a core switch, access layer server, or edge CDN node. Business coreness can be used to quantify the importance level of the business module or service associated with the alarm information.
[0085] Since an alarm growth period may contain multiple clusters of alarm sets (such as similar alarms from different devices in the same province, or related fault alarms across provinces), this embodiment can subdivide the time window according to business scenarios. Based on the distribution of alarm information, alarms that are relatively concentrated in the region and have the same device level are grouped into one alarm cluster. For example, not only based on the alarm occurrence timestamp, but also combined with the alarm's region (such as Shanxi, Chongqing, etc.) and device level (such as central node / edge node) for multi-dimensional division, alarms that are concentrated in the region and closely related in time are grouped into one alarm cluster. Specifically, after extracting the region and device level of the alarm information to be processed, the alarm database can be searched for matching candidate alarm clusters based on the alarm time, region, and device level.
[0086] To ensure the real-time and accuracy of alarm information aggregation, a maximum alarm association time threshold can be dynamically set for each type of alarm (such as DNS resolution anomalies or CDN node failures). This time threshold can be adjusted in real time based on device level and business core importance (e.g., the threshold for core DNS nodes is higher than that for ordinary nodes). Additionally, the time threshold can be adjusted based on the alarm frequency of alarm information within the past 24 hours to ensure that alarms with the same root cause are aggregated within a short period.
[0087] For newly collected alarm information awaiting processing, the alarm time, region, and device level can be compared with the alarm time, region, and device level corresponding to each cluster in the alarm database. If the alarm time difference with a candidate alarm cluster exceeds a time threshold, or the region distribution exceeds the region corresponding to the candidate alarm cluster (e.g., across provinces and without business association), or the device level is different, then the alarm information awaiting processing is determined to be a new category and a new cluster is created. Otherwise, the alarm information awaiting processing is added to the candidate alarm cluster. In this way, alarm information from the same province, the same device level, and with a time difference less than the time threshold can be grouped into the same alarm cluster, avoiding the situation of "false aggregation of independent faults across provinces". The alarm time corresponding to the cluster can be the average alarm time of all alarm information in the cluster, the maximum value among all alarm times, or the minimum value among all alarm times.
[0088] In this embodiment, by adjusting the time threshold in real time based on device level and business coreness, and filtering the clusters to which the alarm information to be processed belongs through time correlation, regional adaptation, and device level matching, it ensures efficient aggregation of alarms with the same root cause (such as alarms from multiple provinces caused by nationwide CDN link failures can be classified into one category in real time), and avoids mis-aggregation of irrelevant alarms (such as the separate processing of independent DNS node failures in Shanxi and Chongqing). The resulting alarm clusters can accurately reflect the scope of the fault impact and related characteristics, providing more direct decision-making basis for operation and maintenance personnel and improving the efficiency of fault location.
[0089] To improve the accuracy and business value of alarm clustering, when adding alarm information to be processed to candidate alarm clusters, the number of alarms in the target alarm cluster, the corresponding business core coefficient, and the time decay coefficient can be determined. The time decay coefficient is related to the alarm level of the alarm information in the target alarm cluster. The target alarm cluster is the cluster obtained assuming that the alarm information to be processed has been added to the candidate alarm clusters. Based on the number of alarms, the business core coefficient, and the time decay coefficient, the aggregation effect value corresponding to the target alarm cluster is determined. If the aggregation effect value is greater than or equal to the historical aggregation effect value corresponding to the candidate alarm cluster, the alarm information to be processed is added to the candidate alarm cluster.
[0090] Specifically, it can be simulated that the current pending alarm information is incorporated into the candidate alarm cluster to form a target alarm cluster, and the number of alarms d, the corresponding business coreness coefficient p, and the time decay coefficient q in the target alarm cluster are determined. The time decay coefficient q is related to the alarm level of the alarm information in the target alarm cluster; for example, the time decay coefficient q for a level 1 alarm is 0.05 / minute, and the time decay coefficient q for a level 3 alarm is 0.02 / minute. The business coreness coefficient p is related to the business weight factor. Relevant factors can be directly applied to business weighting. It can be determined as the business coreness coefficient p, or it can be based on the business weight factor. Determine the business coreness coefficient p, such as by assigning business weight factors. Multiply by a preset coefficient to obtain the business coreness coefficient p. For example, the business coreness coefficient p is 1.5 for core businesses such as DNS root nodes, and 0.9 for non-core businesses such as ordinary servers.
[0091] Furthermore, the aggregation effect value corresponding to the target alarm cluster with added alarm information can be determined according to formula (3). : (3) Where t represents the time length of alarm aggregation, k represents the quantity gain index, and m represents the time decay coefficient. Both k and m are preset coefficients.
[0092] Since a corresponding aggregation effect value is calculated each time an alarm is added to a new cluster, historical aggregation effect values for candidate alarm clusters before any alarms to be processed were added can be obtained from the historical records. Comparing the calculated aggregation effect value with the historical aggregation effect value, if it is greater, it indicates that adding the alarm to be processed to the candidate alarm cluster can maintain or improve the overall information value and urgency of that cluster. Therefore, it can be determined whether to add the alarm to be processed to that candidate alarm cluster.
[0093] For example, if the aggregated effect value is less than the historical aggregated effect value, the alarm information to be processed will be stored as a new alarm cluster in the alarm database.
[0094] When the aggregation effect value is less than the historical aggregation effect value, it means that adding the alarm information to be processed to the candidate alarm cluster may dilute or distort the fault representation of the original candidate alarm cluster. Therefore, a new independent cluster can be created for the alarm information to be processed in the alarm library.
[0095] In this embodiment, by fusing the business coreness coefficient and the time decay coefficient to determine the aggregation effect value, it is possible to ensure that the aggregation result matches the fault location requirements. Furthermore, by using the aggregation effect value for a forward-looking aggregation utility evaluation, the effectiveness of alarm aggregation can be dynamically and quantitatively weighed, thereby achieving utility-based intelligent aggregation decision-making and improving the accuracy of each alarm cluster.
[0096] Furthermore, this invention can employ a distributed system architecture, distributing alarm synchronization, clearing, and dispatch functions across multiple nodes, reducing reliance on single components. By introducing mechanisms such as multi-replica replication, automatic failover, and load balancing, the system's fault tolerance and availability are improved. Additionally, since this invention does not rely on an external cloud computing platform, it avoids the risks of cloud service interruptions, delays, or data leaks, thus ensuring the stability and security of the alarm processing and dispatch process. Through its built-in high availability and fault-tolerant design, it can automatically perform fault recovery and data protection in the event of hardware failures, network problems, or software errors, ensuring business continuity and data integrity. This independence and self-controllability enable this invention to operate stably and reliably in complex and ever-changing network environments, providing users with more secure and efficient alarm processing and dispatch services.
[0097] The alarm information processing apparatus provided by the present invention will be described below. The alarm information processing apparatus described below can be referred to in correspondence with the alarm information processing method described above.
[0098] Figure 5 This is a schematic diagram of the structure of the alarm information processing device provided in an embodiment of the present invention, as shown below. Figure 5 As shown, the alarm information processing device 500 includes: The determination module 11 is used to determine the comprehensive feature vector of the alarm information to be processed. The comprehensive feature vector includes alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the business corresponding to the alarm information to be processed. The determining module 11 is further configured to determine, based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, whether there is reference alarm information in the alarm database that is the same as the alarm information to be processed. The determining module 11 is further configured to, in the case that there is no reference alarm information identical to the alarm information to be processed, determine the similarity between the alarm information to be processed and the target reference alarm information based on the weight of the target keyword and the alarm level, wherein the alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed. The tagging module 12 is used to tag the alarm information to be processed when the alarm information to be processed is determined to be similar alarm information based on the similarity.
[0099] In one example embodiment, the determining module 11 is specifically used for: The feature values of each dimension in the comprehensive feature vector are compared with the corresponding feature values of each dimension in the reference feature vector. If all dimensional feature values match, then the alarm information to be processed is determined to be the same alarm information as the reference alarm information corresponding to the successfully matched reference feature vector.
[0100] In one example embodiment, the determining module 11 is specifically used for: Obtain the weight of each target keyword from the keyword library of the service corresponding to the alarm information to be processed; Based on the weight of each of the target keywords, the business weight factor of the alarm information to be processed is determined; Filter target reference alarm information from the alarm database that has the same alarm type as the alarm information to be processed within a preset historical time period; Based on the alarm time of the alarm information to be processed, the alarm time of each target reference alarm information, the business weight factor, and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information is determined.
[0101] In one example embodiment, the determining module 11 is specifically used for: Based on the alarm time of the alarm information to be processed and the alarm time of each target reference alarm information, the number of alarm information occurring within each unit time is counted to obtain the first statistical sequence; Based on the first statistical sequence, determine the first fluctuation value; Based on the alarm time of the alarm information to be processed and the alarm time of each target reference alarm information, the number of alarm information occurring within each observation time window is counted to obtain a second statistical sequence, wherein the observation time window includes multiple unit time. Based on the second statistical sequence, determine the second fluctuation value; Based on the first fluctuation value, the second fluctuation value, the business weight factor, and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information is determined.
[0102] In one example embodiment, the determining module 11 is specifically used for: The similarity between the alarm information to be processed and the target reference alarm information is determined based on the following formulas (1) and (2): (1) (2) in, This represents the second statistical sequence obtained by counting the number of alarm messages according to the observation time window m. This represents the second fluctuation value. This represents the first statistical sequence. This represents the first fluctuation value. Indicates the slope. , This represents the business weighting factor. Indicates the alarm level, This indicates the similarity.
[0103] In one example embodiment, the device further includes a deletion module and an addition module, wherein: The deletion module is used to delete the alarm information to be processed when it is determined that the alarm information to be processed is the same alarm information or similar alarm information; An add module is used to add the alarm information to the alarm library when it is determined that the alarm information to be processed is a dissimilar alarm information.
[0104] In one example embodiment, the reference alarm information is stored in the alarm database in a clustered manner; the added module is specifically used for: If it is determined that the alarm information to be processed is a dissimilar alarm information, the region to which the alarm information to be processed belongs and the device level corresponding to the alarm information to be processed are extracted from the alarm information to be processed; If the difference between the alarm time of the alarm to be processed and the alarm time corresponding to the candidate alarm cluster in the alarm database is less than a time threshold, the region to which the alarm belongs does not exceed the region corresponding to the candidate alarm cluster, and the device level is the same as the device level corresponding to the candidate alarm cluster, then the alarm to be processed is added to the candidate alarm cluster. The time threshold is determined based on the device level and the business core level.
[0105] In one example embodiment, a module is added specifically for: The number of alarms, the corresponding business core coefficient, and the time decay coefficient in the target alarm cluster are determined. The time decay coefficient is related to the alarm level of the alarm information in the target alarm cluster. The target alarm cluster is a cluster obtained assuming that the alarm information to be processed has been added to the candidate alarm cluster. Based on the number of alarms, the business coreness coefficient, and the time decay coefficient, determine the aggregation effect value corresponding to the target alarm cluster; If the aggregation effect value is greater than or equal to the historical aggregation effect value corresponding to the candidate alarm cluster, it is determined that the alarm information to be processed will be added to the candidate alarm cluster.
[0106] In one example embodiment, the device module further includes a storage module, wherein: The storage module is used to store the alarm information to be processed as a new alarm cluster in the alarm library when the aggregation effect value is less than the historical aggregation effect value.
[0107] The apparatus of this embodiment can be used in any of the methods in the alarm information processing method side embodiment. Its specific implementation process and technical effects are similar to those in the alarm information processing method side embodiment. For details, please refer to the detailed description in the alarm information processing method side embodiment, which will not be repeated here.
[0108] Figure 6 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention, such as... Figure 6 As shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communications bus 640, wherein the processor 610, the communications interface 620, and the memory 630 communicate with each other through the communications bus 640. The processor 610 can call logical instructions in the memory 630 to execute a method for processing alarm information. This method includes: determining a comprehensive feature vector of the alarm information to be processed, the comprehensive feature vector including alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the service corresponding to the alarm information to be processed; determining, based on the comprehensive feature vector and a reference feature vector of at least one reference alarm information stored in the alarm database, whether there is any reference alarm information in the alarm database that is identical to the alarm information to be processed; if no reference alarm information is found to be identical to the alarm information to be processed, determining, based on the weight of the target keyword and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information, wherein the alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed; and marking the alarm information to be processed as similar alarm information based on the similarity.
[0109] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0110] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the alarm information processing method provided by the above methods. The method includes: determining a comprehensive feature vector of the alarm information to be processed, the comprehensive feature vector including alarm type, alarm time, at least one target keyword, alarm level, and business core degree of the business corresponding to the alarm information to be processed; determining, based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, whether there is reference alarm information in the alarm database that is the same as the alarm information to be processed; if it is determined that there is no reference alarm information that is the same as the alarm information to be processed, determining the similarity between the alarm information to be processed and the target reference alarm information based on the weight of the target keyword and the alarm level, wherein the alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed; and marking the alarm information to be processed if it is determined that the alarm information to be processed is similar based on the similarity.
[0111] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a method for processing alarm information provided by the methods described above. This method includes: determining a comprehensive feature vector of an alarm information to be processed, the comprehensive feature vector including alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the service corresponding to the alarm information to be processed; determining, based on the comprehensive feature vector and a reference feature vector of at least one reference alarm information stored in an alarm database, whether there is any reference alarm information in the alarm database identical to the alarm information to be processed; if no reference alarm information identical to the alarm information to be processed is determined, determining a similarity between the alarm information to be processed and the target reference alarm information based on the weight of the target keyword and the alarm level, wherein the alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed; and marking the alarm information to be processed if it is determined to be a similar alarm information based on the similarity.
[0112] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0113] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0114] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for processing alarm information, characterized in that, include: Determine the comprehensive feature vector of the alarm information to be processed. The comprehensive feature vector includes alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the business corresponding to the alarm information to be processed. Based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, determine whether there is reference alarm information in the alarm database that is the same as the alarm information to be processed; If it is determined that there is no reference alarm information that is identical to the alarm information to be processed, the similarity between the alarm information to be processed and the target reference alarm information is determined based on the weight of the target keyword and the alarm level, wherein the alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed. If the alarm information to be processed is determined to be a similar alarm information based on the similarity, the alarm information to be processed is marked.
2. The alarm information processing method according to claim 1, characterized in that, The step of determining whether there is reference alarm information in the alarm database that is identical to the alarm information to be processed, based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, includes: The feature values of each dimension in the comprehensive feature vector are compared with the corresponding feature values of each dimension in the reference feature vector. If all dimensional feature values match, then the alarm information to be processed is determined to be the same alarm information as the reference alarm information corresponding to the successfully matched reference feature vector.
3. The alarm information processing method according to claim 1, characterized in that, The process of determining the similarity between the alarm information to be processed and the target reference alarm information based on the weight of the target keyword and the alarm level includes: Obtain the weight of each target keyword from the keyword library of the service corresponding to the alarm information to be processed; Based on the weight of each of the target keywords, the business weight factor of the alarm information to be processed is determined; Filter target reference alarm information from the alarm database that has the same alarm type as the alarm information to be processed within a preset historical time period; Based on the alarm time of the alarm information to be processed, the alarm time of each target reference alarm information, the business weight factor, and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information is determined.
4. The alarm information processing method according to claim 3, characterized in that, The determination of the similarity between the alarm information to be processed and the target reference alarm information based on the alarm time of the alarm information to be processed, the alarm time of each target reference alarm information, the business weight factor, and the alarm level includes: Based on the alarm time of the alarm information to be processed and the alarm time of each target reference alarm information, the number of alarm information occurring within each unit time is counted to obtain the first statistical sequence; Based on the first statistical sequence, determine the first fluctuation value; Based on the alarm time of the alarm information to be processed and the alarm time of each target reference alarm information, the number of alarm information occurring within each observation time window is counted to obtain a second statistical sequence, wherein the observation time window includes multiple unit time. Based on the second statistical sequence, determine the second fluctuation value; Based on the first fluctuation value, the second fluctuation value, the business weight factor, and the alarm level, the similarity between the alarm information to be processed and the target reference alarm information is determined.
5. The alarm information processing method according to claim 4, characterized in that, The step of determining the similarity between the alarm information to be processed and the target reference alarm information based on the first fluctuation value, the second fluctuation value, the business weight factor, and the alarm level includes: The similarity between the alarm information to be processed and the target reference alarm information is determined based on the following formulas (1) and (2): (1) (2) in, This represents the second statistical sequence obtained by counting the number of alarm messages according to the observation time window m. This represents the second fluctuation value. This represents the first statistical sequence. This represents the first fluctuation value. Indicates the slope. , This represents the business weighting factor. Indicates the alarm level, This indicates the similarity.
6. The method for processing alarm information according to any one of claims 1-5, characterized in that, The method further includes: If it is determined that the alarm information to be processed is the same or similar, the alarm information to be processed shall be deleted. If it is determined that the alarm information to be processed is a dissimilar alarm information, the alarm information to be processed is added to the alarm database.
7. The alarm information processing method according to claim 6, characterized in that, The reference alarm information is stored in the alarm database in a clustered manner; The step of adding the alarm information to the alarm database when it is determined that the alarm information to be processed is a dissimilar alarm information includes: If it is determined that the alarm information to be processed is a dissimilar alarm information, the region to which the alarm information to be processed belongs and the device level corresponding to the alarm information to be processed are extracted from the alarm information to be processed; If the difference between the alarm time of the alarm to be processed and the alarm time corresponding to the candidate alarm cluster in the alarm database is less than a time threshold, the region to which the alarm belongs does not exceed the region corresponding to the candidate alarm cluster, and the device level is the same as the device level corresponding to the candidate alarm cluster, then the alarm to be processed is added to the candidate alarm cluster. The time threshold is determined based on the device level and the business core level.
8. The alarm information processing method according to claim 7, characterized in that, Adding the alarm information to be processed to the candidate alarm cluster includes: The number of alarms, the corresponding business core coefficient, and the time decay coefficient in the target alarm cluster are determined. The time decay coefficient is related to the alarm level of the alarm information in the target alarm cluster. The target alarm cluster is a cluster obtained assuming that the alarm information to be processed has been added to the candidate alarm cluster. Based on the number of alarms, the business coreness coefficient, and the time decay coefficient, determine the aggregation effect value corresponding to the target alarm cluster; If the aggregation effect value is greater than or equal to the historical aggregation effect value corresponding to the candidate alarm cluster, it is determined that the alarm information to be processed will be added to the candidate alarm cluster.
9. The alarm information processing method according to claim 8, characterized in that, The method further includes: If the aggregation effect value is less than the historical aggregation effect value, the alarm information to be processed is stored as a new alarm cluster in the alarm database.
10. An alarm information processing device, characterized in that, include: The determination module is used to determine the comprehensive feature vector of the alarm information to be processed. The comprehensive feature vector includes alarm type, alarm time, at least one target keyword, alarm level, and the business core degree of the business corresponding to the alarm information to be processed. The determining module is further configured to determine, based on the comprehensive feature vector and the reference feature vector of at least one reference alarm information stored in the alarm database, whether there is reference alarm information in the alarm database that is the same as the alarm information to be processed; The determining module is further configured to, in the case that there is no reference alarm information identical to the alarm information to be processed, determine the similarity between the alarm information to be processed and the target reference alarm information based on the weight of the target keyword and the alarm level, wherein the alarm type of the target reference alarm information is the same as the alarm type of the alarm information to be processed. The tagging module is used to tag the alarm information to be processed when the similarity is determined to be similar alarm information.
11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the alarm information processing method as described in any one of claims 1 to 9.
12. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the alarm information processing method as described in any one of claims 1 to 9.
13. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the alarm information processing method as described in any one of claims 1 to 9.