Indicator data monitoring method and related apparatus
Patent Information
- Application Number
- CN202610478766.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-13
- Publication Date
- 2026-09-11
AI Technical Summary
[0004]然而,在相关技术中,对指标数据监测时存在静态阈值无法适应数据波动、且多层级指标依赖人工逐层排查导致根因定位效率低的问题
[0012]从上面所述可以看出,本公开实施例提供的指标数据监测方法及相关装置,该方法包括:
Smart Images

Figure CN122736371A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data analysis and processing technology, and in particular to a method and related apparatus for monitoring indicator data. Background Technology
[0002] This section is intended to provide background or context for the embodiments of this disclosure as set forth in the claims. The description herein is not intended to be a prior art simply because it is included in this section.
[0003] Indicator data refers to massive amounts of heterogeneous data generated in business scenarios such as enterprise operation, finance, and production. It is constructed into a multi-level indicator system for monitoring. It is a time series data with correlation. The indicator values have natural seasonal fluctuations and long-term trend changes. Moreover, a complex correlation link is formed between indicators at each level, from micro-details to macro-cores. It is the basic data object for enterprises to carry out indicator monitoring and analysis.
[0004] However, in related technologies, there are problems with monitoring indicator data, such as static thresholds being unable to adapt to data fluctuations, and multi-level indicators relying on manual investigation layer by layer leading to low efficiency in root cause localization. Summary of the Invention
[0005] In view of this, the purpose of this disclosure is to propose a method and related device for monitoring indicator data, which at least to some extent solves one of the technical problems in the related technology.
[0006] To achieve the above objectives, the first aspect of this exemplary embodiment provides a method for monitoring indicator data, the method comprising:
[0007] Obtain historical time-series data of the target indicator, perform seasonal decomposition on the time-series data, and obtain the anomaly threshold; Based on the aforementioned anomaly threshold, irregularities in the historical time-series data are determined to obtain the anomaly status of the target indicator; wherein, the anomaly status includes an indicator without anomalies and an indicator with anomalies. Based on the target indicator, an indicator system model is constructed. In response to the abnormal state of the indicator, the indicator is considered to be in an abnormal state. Based on the indicator system model, root cause analysis is performed on the target indicator to obtain the root cause analysis results of the abnormality.
[0008] Based on the same inventive concept, a second aspect of the exemplary embodiments of this disclosure provides an indicator data monitoring device, comprising: The anomaly threshold determination module is configured to acquire historical time-series data of the target indicator, perform seasonal decomposition on the time-series data, and obtain the anomaly threshold. An abnormal state determination module is configured to determine irregular items in the historical time series data based on the abnormality threshold to obtain the abnormal state of the target indicator; wherein, the abnormal state of the indicator includes an indicator without abnormality and an indicator abnormality. The analysis result determination module is configured to construct an indicator system model based on the target indicator, and in response to the indicator's abnormal state, perform root cause analysis on the target indicator based on the indicator system model to obtain the abnormal root cause analysis results.
[0009] Based on the same inventive concept, a third aspect of the exemplary embodiments of this disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method as described in the first aspect.
[0010] Based on the same inventive concept, a fourth aspect of the exemplary embodiments of this disclosure provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the method as described in the first aspect.
[0011] Based on the same inventive concept, a fifth aspect of the exemplary embodiments of this disclosure provides a computer program product including computer program instructions that, when run on a computer, cause the computer to perform the method as described in the first aspect.
[0012] As can be seen from the above description, the indicator data monitoring method and related apparatus provided in this disclosure include: Historical time-series data of a target indicator is acquired, and the time-series data is seasonally decomposed to obtain an anomaly threshold. Based on the anomaly threshold, irregularities in the historical time-series data are determined to obtain the anomaly state of the target indicator. The anomaly state includes a state without anomalies and a state with anomalies. An indicator system model is constructed based on the target indicator. Responding to the anomaly state as an abnormal state, root cause analysis is performed on the target indicator based on the indicator system model to obtain the root cause analysis results. This disclosure can overcome seasonal fluctuation interference to improve the accuracy of anomaly determination and the efficiency of root cause localization. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in this disclosure or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 A schematic diagram illustrating an application scenario of the indicator data monitoring method provided in an exemplary embodiment of this disclosure; Figure 2 A flowchart illustrating an indicator data monitoring method provided for an exemplary embodiment of this disclosure; Figure 3 A schematic diagram of the structure of an indicator data monitoring device provided for an exemplary embodiment of this disclosure; Figure 4 A schematic diagram of the hardware structure of an electronic device provided for an exemplary embodiment of this disclosure. Detailed Implementation
[0015] It is understood that before using the technical solutions disclosed in the various embodiments of this application, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this application in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0016] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this application's technical solution, based on the prompt message.
[0017] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0018] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this application. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this application.
[0019] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0020] To make the objectives, technical solutions, and advantages of this disclosure clearer, the principles and spirit of this disclosure will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are provided merely to enable those skilled in the art to better understand and implement this disclosure, and are not intended to limit the scope of this disclosure in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.
[0021] In this article, it is important to understand that any number of elements in the accompanying figures is for illustrative purposes and not for limitation, and any naming is for distinction only and has no limiting meaning.
[0022] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this disclosure should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar words used in the embodiments of this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly. The article "a" or "an" preceding an element does not exclude the existence of multiple such elements.
[0023] The principles and spirit of this disclosure will be explained in detail below with reference to several representative embodiments.
[0024] As described in the background section, related technologies suffer from several drawbacks when monitoring indicator data. Static thresholds cannot adapt to data fluctuations, and the reliance on manual, layer-by-layer investigation of multi-level indicators leads to low efficiency in root cause identification. Specifically, in the monitoring and analysis of indicator data in business scenarios such as enterprise operations, finance, and production, relevant technologies still exhibit significant technical deficiencies. When using static thresholds for monitoring, dynamic adaptation to historical time-series data of the indicators is not achieved. Because the seasonal fluctuation patterns of the data are not effectively decomposed, fixed thresholds cannot distinguish between normal periodic fluctuations and substantial anomalies, easily misinterpreting normal business fluctuations as abnormal signals. This results in distorted monitoring results, a high false alarm rate, and an inability to accurately identify indicator anomalies.
[0025] For root cause analysis of multi-level indicator systems, the relevant technologies lack systematic quantitative calculation models. After identifying indicator anomalies, it is difficult to objectively measure the contribution weight of child nodes relative to parent nodes. The analysis process relies excessively on human experience and subjective judgment, and cannot identify key driving nodes through data-driven methods, making it difficult to guarantee the accuracy and consistency of root cause localization.
[0026] Existing root cause localization processes lack automated recursive drill-down and path-locking mechanisms. When the indicator system is complex and has many levels, analysts must manually traverse each node to manually check and verify. The entire analysis process is lengthy and time-consuming, making it impossible to quickly trace from macroscopic anomalies to microscopic root causes, which seriously restricts the real-time performance and processing efficiency of indicator monitoring and analysis.
[0027] To address the aforementioned problems, this disclosure provides a method and related apparatus for monitoring indicator data. The method specifically includes: This invention involves acquiring historical time-series data of a target indicator, performing seasonal decomposition on the time-series data to obtain an anomaly threshold, and determining irregularities in the historical time-series data based on the anomaly threshold to obtain the anomaly state of the target indicator. The anomaly state includes a state of no anomaly and a state of anomaly. An indicator system model is constructed based on the target indicator. Responding to the anomaly state as an abnormal state, root cause analysis is performed on the target indicator based on the indicator system model to obtain the root cause analysis results. This invention obtains historical time-series data of a target indicator, decomposes the time-series data using a seasonal adjustment algorithm to obtain irregularities, and constructs an anomaly threshold based on the dynamic mean and dynamic standard deviation of the irregularities. This adaptively generates a dynamic confidence interval as the anomaly judgment standard, effectively eliminating interference from seasonal and trend factors, overcoming the problem of high false alarm rates caused by static thresholds failing to adapt to data fluctuations, and achieving accurate anomaly identification.
[0028] In terms of constructing the indicator system model, this solution determines multi-level indicator nodes and the parent-child relationship between each node based on the target indicator. It establishes a tree-like topology structure that includes indicator name, indicator ID, topic ID, indicator level, and aggregation rule attributes. The parent node value is derived from the child node value according to the aggregation rule, forming a structured indicator association model. This overcomes the problem of weak association analysis capability caused by the loose hierarchical structure of indicators in the existing technology.
[0029] When an indicator's abnormal state is determined to be an abnormal state, this solution obtains the target indicator as the set of all child nodes under the parent node based on the indicator system model, calculates the influence weight of each child node on the parent node's abnormal state, sorts them according to the abnormal state type, and locks the child node with the largest influence weight as the main driving node. Then, the main driving node is used as the new parent node for recursive drill-down until the leaf node is reached, forming an abnormality drill-down path as the root cause analysis result. This overcomes the problem of low efficiency and strong subjectivity in root cause location due to relying on manual experience to investigate layer by layer.
[0030] After introducing the basic principles of this disclosure, various non-limiting embodiments of this disclosure will be described in detail below.
[0031] refer to Figure 1 This is a schematic diagram illustrating an application scenario of the indicator data monitoring method provided in the exemplary embodiments of this disclosure.
[0032] This application scenario includes a terminal device 101 and a server 102. The terminal device 101 and the server 102 can be connected via a wired or wireless communication network to achieve data interaction.
[0033] Terminal device 101 may be an electronic device located close to the user side, possessing data transmission and multimedia input / output functions, including but not limited to desktop computers, mobile phones, portable computers, tablet computers, media players, smart wearable devices, personal digital assistants (PDAs), or other electronic devices capable of performing the aforementioned functions. This electronic device may include a processor and a display screen with touch input functionality. The display screen is used to present a graphical user interface (GUI), which can display an application interface. The processor is used to process application data, generate the GUI, and control the display of the GUI on the screen.
[0034] Server 102 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0035] In some exemplary embodiments, the indicator data monitoring method may run on terminal device 101 or server 102.
[0036] When the indicator data monitoring method runs on server 102, server 102 is used to provide indicator data monitoring services to users of terminal device 101.
[0037] Server 102 acquires historical time-series data of the target indicator, and performs seasonal decomposition on the time-series data to obtain the anomaly threshold. Server 102 determines the irregularities in the historical time series data based on the anomaly threshold to obtain the anomaly status of the target indicator; wherein, the anomaly status includes an indicator without anomalies and an indicator with anomalies. Server 102 constructs an indicator system model based on the target indicator. In response to the indicator's abnormal state, server 102 performs root cause analysis on the target indicator based on the indicator system model. After obtaining the root cause analysis results, server 102 transmits the root cause analysis results to terminal device 101.
[0038] It should be noted that the above application scenarios are shown only to facilitate understanding of the spirit and principles of this disclosure, and the implementation of this disclosure is not limited in any way. On the contrary, the implementation of this disclosure can be applied to any applicable scenario.
[0039] refer to Figure 2 A method for monitoring indicator data, the method comprising the following steps: Step S210: Obtain historical time-series data of the target indicator, perform seasonal decomposition on the time-series data, and obtain the anomaly threshold.
[0040] In practice, target indicators refer to various time-series indicators that are included in the monitoring of a multi-level indicator system in business scenarios such as enterprise operation, finance, and production.
[0041] In practice, historical time-series data refers to the numerical data of the target indicator that are continuously collected and recorded in terms of time dimension within a historical period.
[0042] In practice, the historical time-series data of the target indicators are obtained in the following ways: Extract numerical records of a metric from past periods by metric ID and time dimension from a data warehouse or business system. For example, you can use 5 years of historical data as a sample to form a time-series sequence of data, thus obtaining historical time-series data. .
[0043] In some embodiments, seasonal decomposition is performed on the time-series data to obtain anomaly thresholds, including: The irregular items are obtained by decomposing the time-series data based on the seasonal adjustment algorithm. Based on the aforementioned irregularities, the dynamic mean and dynamic standard deviation are obtained; The dynamic mean and the dynamic standard deviation are constructed based on the confidence interval principle to obtain the anomaly threshold.
[0044] In practice, the irregular items are obtained by decomposing the time-series data based on a seasonal adjustment algorithm as follows: Using the X13-ARIMA seasonal adjustment algorithm, Using an additive model, the components are decomposed into a long-term trend cyclical element TC, a seasonal variation element S, and an irregularity element I, namely: ; in, For long-term trend cyclical terms, For seasonal variations, This is an irregular term.
[0045] In practice, the dynamic mean and dynamic standard deviation are obtained based on the aforementioned irregularities as follows: Based on irregularities after removing seasonality and trends Calculate the dynamic mean within the sliding window. With dynamic standard deviation .
[0046] In specific implementation, the dynamic mean and the dynamic standard deviation are constructed based on the confidence interval principle to obtain the anomaly threshold in the following way: In this embodiment, the abnormality threshold includes an upper limit for the abnormality threshold. and the lower limit of the abnormality threshold Using 5 years of historical data for each indicator as a sample, the upper and lower limits of the anomaly threshold for the current moment are dynamically generated based on the confidence interval principle. ; ; Here, k is the threshold coefficient. Based on the design principle of Shewhart control charts in Statistical Process Control (SPC) theory, the threshold coefficient k has a default value of 3. This setting corresponds to approximately 99.7% confidence level, assuming the process is under control and the data follows a normal distribution. In practical applications, the value can be appropriately modified by combining the historical fluctuation patterns of actual indicators and domain expert knowledge to adjust the sensitivity of the anomaly judgment rule to different indicators.
[0047] Step S220: Determine the irregular items of the historical time series data based on the anomaly threshold to obtain the anomaly status of the target indicator; wherein, the anomaly status includes an indicator without anomalies and an indicator with anomalies.
[0048] In some embodiments, abnormal indicator states include: abnormally low indicator state and abnormally high indicator state.
[0049] In practice, an abnormally low indicator status refers to the abnormal status of a target indicator when the value of an irregular item obtained by seasonal decomposition of the historical time series data of the target indicator is lower than the lower limit of the abnormality threshold constructed by the statistical characteristics of the irregular item.
[0050] In practice, an abnormally high indicator status refers to the abnormal status of a target indicator when the value of an irregular item obtained by seasonal decomposition of the historical time series data of the target indicator is higher than the upper limit of the abnormality threshold constructed from the statistical characteristics of the irregular item.
[0051] In some embodiments, the irregularity item is determined based on the anomaly threshold to obtain the anomaly status of the target indicator, including: The irregular item is determined based on the abnormality threshold. When the value of the irregular item is lower than the lower limit of the abnormality threshold, the abnormal state of the indicator is determined to be an abnormally low state of the indicator. When the value of the irregular item is higher than the upper limit of the abnormality threshold, the abnormal state of the indicator is determined to be an abnormal high-level state. When the value of the irregular item is between the upper and lower limits of the anomaly threshold, the value of the irregular item is equal to the lower limit of the anomaly threshold, or the value of the irregular item is equal to the upper limit of the anomaly threshold, the anomaly state of the indicator is determined to be an indicator without anomalies.
[0052] In specific implementation, the irregular item is determined based on the anomaly threshold. When the value of the irregular item is lower than the lower limit of the anomaly threshold, the abnormal state of the indicator is determined to be an abnormally low state as follows: When judging irregularities based on anomaly thresholds, if the value of an irregularity is lower than the lower limit of the anomaly threshold, the indicator is judged to be in an abnormally low state. Specifically, this is done by decomposing the resulting irregularities... Compared with the dynamically generated lower limit of the anomaly threshold If a comparison is made, The abnormal state of this indicator is then marked as an abnormally low state, indicating that the indicator value has fallen significantly below the normal fluctuation range. Status=1 at this time.
[0053] In specific implementation, when the value of the irregular item is higher than the upper limit of the anomaly threshold, the abnormal state of the indicator is determined to be a high-level abnormal state. The classification method is as follows: When the value of an irregularity item exceeds the upper limit of the anomaly threshold, the method for determining the abnormal state of the indicator as a high-level abnormal state is as follows: [The method involves] decomposing the irregularity items... With dynamically generated upper limit of anomaly threshold If a comparison is made, If the abnormal state of the indicator is marked as an abnormally high state, it indicates that the indicator value has significantly exceeded the normal fluctuation range. Status=2.
[0054] In specific implementation, when the value of the irregular item is between the upper and lower limits of the anomaly threshold, the value of the irregular item is equal to the lower limit of the anomaly threshold, or the value of the irregular item is equal to the upper limit of the anomaly threshold, the method for determining the indicator anomaly state as an indicator without anomalies is as follows: The method for determining the indicator's abnormal state as an indicator without anomalies when the value of the irregular item is between the upper and lower limits of the anomaly threshold, the value of the irregular item is equal to the lower limit of the anomaly threshold, or the value of the irregular item is equal to the upper limit of the anomaly threshold is as follows: The irregular items obtained after decomposition are... Compared with the dynamically generated lower limit of the anomaly threshold and upper limit If a comparison is made, If the indicator is within the normal fluctuation range, no abnormality alarm will be triggered, and the abnormality status of the indicator will be marked as an indicator without abnormality.
[0055] Step S230: Construct an indicator system model based on the target indicator. In response to the abnormal state of the indicator, perform root cause analysis on the target indicator based on the indicator system model to obtain the root cause analysis results of the abnormality.
[0056] In some embodiments, constructing an indicator system model based on the target indicator includes: Determine the multi-level indicator nodes corresponding to the target indicator and the parent-child relationship between each indicator node; wherein, the indicator node includes indicator name, indicator ID, topic ID, indicator level and aggregation rule attributes, the parent-child relationship includes parent node and child node, and the indicator value of the parent node is derived from the indicator value of the child node according to the aggregation rule; The indicator system model is constructed based on the multi-level indicator nodes and the parent-child hierarchical relationship.
[0057] In specific implementation, the method for determining the multi-level indicator nodes corresponding to the target indicator and the parent-child relationship between each indicator node is as follows: A tree-like topology is constructed based on business logic. Each indicator node is defined with attribute information including indicator name, indicator ID, topic ID, indicator level, and aggregation rules. The parent-child relationship between nodes is clarified by the logic that the indicator value of the parent node is derived from the indicator value of the child node according to the aggregation rules. An adjacency list data structure is used for storage to support fast traversal and recursive drill-down operations on the set of child nodes.
[0058] In practical implementation, the indicator name refers to the name identification attribute carried by each indicator node in the tree topology, which is used to uniquely distinguish and identify indicators with different business meanings, such as "total revenue" and "revenue of each product line". It is one of the basic attributes of the indicator node, which makes it easy to locate, call and display specific indicators in the indicator system.
[0059] In practical implementation, the indicator ID refers to the unique identifier assigned to each indicator node in the tree topology. It is used to accurately distinguish and retrieve different indicator nodes in the indicator system, and supports the system to quickly locate indicators, maintain relationships, and perform recursive drill-down operations.
[0060] In practice, the topic ID refers to the topic classification identifier assigned to each indicator node in the tree topology, which is used to mark the business topic domain to which the indicator belongs, such as finance, sales, production, etc., so that the indicator system can be filtered, aggregated and cross-topic correlation analysis can be performed by topic.
[0061] In practical implementation, the indicator hierarchy refers to the hierarchical attribute assigned to each indicator node in the tree-like topology, which is used to identify the depth position of the node in the entire multi-level indicator system. For example, the root node is the first level, its child nodes are the second level, and so on, so as to clarify the vertical progression from macro core indicators to micro detailed indicators.
[0062] In practice, aggregation rules refer to the operational logic defined for each indicator node in the tree topology to calculate the indicator value of the parent node from the indicator value of the child node. This includes methods such as summation and weighted average, to ensure that the indicator value of the parent node can be automatically derived from the data of the lower-level child nodes according to unified rules.
[0063] In practice, the index value of the parent node is derived from the index value of the child node according to the aggregation rule in the following way: When constructing a tree-like topology, aggregation rule attributes are predefined for each indicator node, including calculation logic such as summation or weighted average. When it is necessary to calculate the indicator value of the parent node, the system traverses all direct child nodes under the parent node, calculates the indicator value of the child nodes according to the preset aggregation rules, and thus automatically derives the indicator value of the parent node.
[0064] In specific implementation, the indicator system model is constructed based on the multi-level indicator nodes and the parent-child hierarchical relationship, and the result is as follows: Each indicator node serves as the vertex of a tree structure. Each node is defined with an indicator name, indicator ID, topic ID, indicator level, and aggregation rule attributes. Parent-child relationships between nodes are established based on the logic of deriving child node indicator values from parent node indicator values according to aggregation rules. An adjacency list data structure is used to store the set of child nodes for each node, thus forming a complete tree-like topology model (i.e., an indicator system model). This model supports subsequent indicator traversal, anomaly propagation path locking, and recursive drill-down analysis. In some embodiments, root cause analysis is performed on the target indicators based on the indicator system model to obtain the root cause analysis results of the anomalies, including: In response to the target indicator's abnormal state being an abnormal indicator state, the target indicator is obtained as the set of all child nodes under the parent node; Determine the influence weight of each child node in the child node set on the anomaly of the parent node, sort the influence weights based on the abnormal state of the indicator, and lock the child node with the largest influence weight as the main driving node; The main driving node is used as the new parent node for recursive drilling down until the leaf node is reached, thus obtaining the anomaly drilling path, and the anomaly drilling path is used as the result of the anomaly root cause analysis.
[0065] In specific implementation, in response to the abnormal state of the target indicator, the method for obtaining the target indicator as the set of all child nodes under the parent node is as follows: When the parent node is determined to be abnormal, that is... When the value is 1 or 2, the automatic attribution algorithm is triggered. That is, when the target indicator's abnormal state is determined to be an abnormal state, based on the constructed tree-structured topology indicator system model, using the target indicator as the parent node, the algorithm retrieves and extracts all direct child nodes under the parent node by traversing the parent-child relationships in the model, forming a set of child nodes { This serves as the data foundation for subsequent contribution weight calculations and root cause analysis.
[0066] In specific implementation, the influence weight of each child node in the child node set on the anomaly of the parent node is determined. Based on the abnormal state of the indicator, the influence weights are sorted, and the child node with the largest influence weight is identified as the main driving node. First, based on the business characteristics, either the growth rate difference method or the pull rate method is selected to calculate the impact weight of each child node. The growth rate difference method calculates the weight by multiplying the difference between the growth rate of the child node and the growth rate of the parent node by the proportion of the child node. Specifically, the impact weight of each child node on the changes in the parent node is calculated. Each indicator is assigned different weighting logic based on its data characteristics, i.e., the different monitoring focuses. There are mainly two types: Growth rate difference method: ; in, For the growth rate of sub-indicators, For the growth rate of the parent node, This represents the proportion of the absolute value of the child indicator to the absolute value of the parent indicator.
[0067] Pull ratio method: ; in, This refers to the absolute value of the sub-indicator in the current period. The absolute value of the parent indicator in this period. The cumulative absolute value of the parent indicator at the end of last year.
[0068] Then, based on the abnormal state of the parent node's indicator, the child nodes are sorted. If the indicator is at a low abnormal position, all child nodes are sorted in ascending order of weight; if the indicator is at a high abnormal position, they are sorted in descending order. Finally, the child node at the top of the sorted list is extracted as the node with the greatest influence weight and identified as the primary driving force node. Specifically... In this case, sort the set of child nodes of the parent node in ascending order and find the child node with the largest weight that has an impact on the abnormal low point. The main driving force; In this case, sort the set of child nodes of the parent node in descending order and find the child node with the largest weight that has an impact on the abnormal high point. This is the main driving force.
[0069] In practice, the primary driving node is used as the new parent node for recursive drilling down until the leaf node is reached, thus obtaining the anomaly drilling path. This anomaly drilling path is then used as the result of the anomaly root cause analysis. Locking the main driving nodes As the new parent node, obtain the set of all child nodes under this parent node, recalculate the influence weight of each child node on the current parent node's anomaly, and sort the weights according to the abnormal state of the indicator. Then, lock the child node with the largest influence weight as the main driving node for the next layer. This process is recursively repeated layer by layer until the current node has no more child nodes (i.e., traversing to the finest granular leaf node). At this point, the main driving nodes locked in each layer are connected in order from macro to micro to form an anomaly drilling path. The path will be output as the result of the root cause analysis of the anomaly.
[0070] In some embodiments, the method disclosed herein further includes: The abnormality threshold, the abnormality status of the indicator, and the root cause analysis results of the abnormality are encapsulated into a structured data object, and the structured data object is visualized. In response to the abnormality status of the indicator being in an abnormal state, the abnormality drilling path and the influence weight of each node on the abnormality of the parent node are displayed simultaneously during the visualization. At the same time, the structured data object is pushed to the early warning interface to trigger an abnormality alarm. In response to the abnormal state of the indicator being normal, only the abnormal threshold and the normal state information of the target indicator are visualized.
[0071] In specific implementation, the anomaly threshold, the anomaly status of the indicator, and the root cause analysis results of the anomaly are encapsulated into structured data objects, and the structured data objects are visualized. Specifically, in response to the indicator anomaly status being an abnormal indicator state, the anomaly drilling path and the influence weight of each node on the parent node's anomaly are simultaneously displayed during visualization. The structured data object is then pushed to the early warning interface to trigger an anomaly alarm in the following manner: The dynamic threshold upper and lower limits, indicator anomaly status identifiers, information on each node in the anomaly drill-down path and their influence weights are assembled into a JSON or similar structured data object according to a predefined format, and then transmitted to the relevant module for front-end display. If the indicator anomaly status is an abnormal indicator status, the complete link of the anomaly drill-down path and the influence weight of each node on the parent node anomaly are displayed synchronously on the visualization interface. At the same time, the structured data object is pushed to the early warning interface to trigger anomaly alarm. If the indicator is in a normal abnormal status, only the anomaly threshold and normal status information of the target indicator are displayed.
[0072] In specific implementation, in response to the abnormal state of the indicator being in a normal state, the method of visually displaying only the abnormal threshold and the normal state information of the target indicator is as follows: After encapsulating the dynamic threshold upper and lower limits and the no-abnormality status identifier into structured data objects, the relevant modules displayed on the front end only extract the abnormal threshold range (lower and upper limits) corresponding to the target indicator and the identifier information of the indicator without abnormality status, and display it in the form of charts or text, without displaying any drill-down path or weight data.
[0073] It should be noted that the method of this disclosure embodiment can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of this disclosure embodiment, and the multiple devices will interact with each other to complete the method described.
[0074] It should be noted that the above description describes some embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0075] Based on the same inventive concept, corresponding to any of the above-described embodiments, this disclosure also provides an indicator data monitoring device.
[0076] refer to Figure 3 The indicator data monitoring device includes: The anomaly threshold determination module 310 is configured to acquire historical time-series data of the target indicator, perform seasonal decomposition on the time-series data, and obtain the anomaly threshold. The abnormal state determination module 320 is configured to determine the irregular items of the historical time series data based on the abnormality threshold to obtain the abnormal state of the target indicator; wherein, the abnormal state of the indicator includes an indicator without abnormality and an indicator abnormality. The analysis result determination module 330 is configured to construct an indicator system model based on the target indicator, and in response to the indicator's abnormal state being the indicator's abnormal state, perform root cause analysis on the target indicator based on the indicator system model to obtain the abnormal root cause analysis results.
[0077] In this exemplary embodiment, the anomaly threshold determination module 310 is specifically configured as follows: Historical time-series data of the target indicator is obtained, and the time-series data is decomposed based on a seasonal adjustment algorithm to obtain the irregularity term; based on the irregularity term, the dynamic mean and dynamic standard deviation are obtained; the dynamic mean and dynamic standard deviation are constructed based on the confidence interval principle to obtain the anomaly threshold.
[0078] In this exemplary embodiment, the abnormal state determination module 320 is specifically configured as follows: Based on the anomaly threshold, irregularities in the historical time-series data are determined to obtain the anomaly state of the target indicator. The anomaly state includes a no-anomaly state and an abnormal state, with the abnormal state further including an abnormally low state and an abnormally high state. When the value of the irregularity is below the lower limit of the anomaly threshold, the abnormal state is determined to be an abnormally low state. When the value of the irregularity is above the upper limit of the anomaly threshold, the abnormal state is determined to be an abnormally high state. When the value of the irregularity is between the upper and lower limits of the anomaly threshold, equal to the lower limit of the anomaly threshold, or equal to the upper limit of the anomaly threshold, the anomaly state is determined to be a no-anomaly state.
[0079] In this exemplary embodiment, the analysis result determination module 330 is specifically configured as follows: The process involves determining the multi-level indicator nodes corresponding to the target indicator and the parent-child relationships between these nodes. Each indicator node includes an indicator name, indicator ID, topic ID, indicator level, and aggregation rule attributes. The parent-child relationship includes a parent node and child nodes, with the indicator value of the parent node derived from the indicator value of the child node according to the aggregation rule. Based on the multi-level indicator nodes and the parent-child relationships, an indicator system model is constructed. Responding to the indicator anomaly state of the target indicator, a set of all child nodes under the parent node is obtained. The influence weight of each child node in the set on the anomaly of the parent node is determined. Based on the indicator anomaly state, the influence weights are sorted, and the child node with the largest influence weight is identified as the primary driving node. The primary driving node is used as the new parent node for recursive drill-down until a leaf node is reached, obtaining the anomaly drill-down path. This path is then used as the root cause analysis result.
[0080] For ease of description, the above apparatus is described in terms of its functions, divided into various modules. Of course, in implementing this disclosure, the functions of each module can be implemented in one or more software and / or hardware.
[0081] The apparatus described above is used to implement the corresponding indicator data monitoring method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0082] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the indicator data monitoring method described in any of the above embodiments.
[0083] Figure 4 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.
[0084] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0085] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0086] The input / output interface 1030 is used to connect input / output modules to realize information input and output. The input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touch screens, microphones, various sensors, etc., and output devices may include displays, speakers, vibrators, indicator lights, etc.
[0087] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0088] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.
[0089] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.
[0090] The electronic devices described above are used to implement the corresponding indicator data monitoring methods in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0091] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the indicator data monitoring method as described in any of the above embodiments.
[0092] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0093] The aforementioned non-transitory computer-readable storage media can be any available medium or data storage device that a computer can access, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MOs), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).
[0094] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the indicator data monitoring method as described in any of the embodiments in the exemplary method section above, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0095] Based on the same inventive concept, corresponding to the indicator data monitoring method described in any of the above embodiments, this disclosure also provides a computer program product, which includes computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of a computer to cause the computer and / or the processor to perform the indicator data monitoring method. Corresponding to the execution entity for each step in each embodiment of the indicator data monitoring method, the processor executing the corresponding step can belong to the corresponding execution entity.
[0096] The computer program product of the above embodiments is used to cause the computer and / or the processor to execute the indicator data monitoring method as described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0097] Those skilled in the art will recognize that embodiments of this disclosure can be implemented as a system, method, or computer program product. Therefore, this disclosure can be implemented as entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as a "circuit," "module," or "system." Furthermore, in some embodiments, this disclosure can also be implemented as a computer program product contained in one or more computer-readable media, which includes computer-readable program code.
[0098] Any combination of one or more computer-readable media may be used. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium can be, for example,, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (not exhaustive) of a computer-readable storage medium may include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device.
[0099] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.
[0100] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0101] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0102] It should be understood that each block of a flowchart and / or block diagram, as well as combinations of blocks in a flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine that, when executed by a computer or other programmable data processing device, creates means for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.
[0103] These computer program instructions may also be stored in a computer-readable medium that enables a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable medium produce a product comprising an instruction apparatus that implements the functions / operations specified in the boxes of a flowchart and / or block diagram.
[0104] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, such that the instructions that execute on the computer or other programmable apparatus can provide a process for implementing the functions / operations specified in the boxes of a flowchart and / or block diagram.
[0105] Furthermore, although the operations of the methods of this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the operations shown must be performed to achieve the desired result. Rather, the steps depicted in the flowcharts may be executed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0106] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0107] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0108] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application (including the claims) is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in the details for the sake of brevity.
[0109] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of the implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0110] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0111] The embodiments of this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this application should be included within the protection scope of this application.
[0112] While the spirit and principles of this disclosure have been described with reference to several specific embodiments, it should be understood that this disclosure is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for convenience of expression. This disclosure is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims. The scope of the appended claims is to be interpreted in the broadest sense, thereby encompassing all such modifications and equivalent structures and functions.
Claims
1. A method for monitoring indicator data, characterized in that, include: Obtain historical time-series data of the target indicator, perform seasonal decomposition on the time-series data, and obtain the anomaly threshold; Based on the aforementioned anomaly threshold, irregularities in the historical time-series data are determined to obtain the anomaly status of the target indicator; wherein, the anomaly status includes an indicator without anomalies and an indicator with anomalies. Based on the target indicator, an indicator system model is constructed. In response to the abnormal state of the indicator, the indicator is considered to be in an abnormal state. Based on the indicator system model, root cause analysis is performed on the target indicator to obtain the root cause analysis results of the abnormality.
2. The method according to claim 1, characterized in that, The step of performing seasonal decomposition on the time-series data to obtain the anomaly threshold includes: The irregular items are obtained by decomposing the time-series data based on the seasonal adjustment algorithm. Based on the aforementioned irregularities, the dynamic mean and dynamic standard deviation are obtained; The dynamic mean and the dynamic standard deviation are constructed based on the confidence interval principle to obtain the anomaly threshold.
3. The method according to claim 1, characterized in that, The abnormal states of the indicators include: abnormally low indicator states and abnormally high indicator states. The step of determining the irregularity based on the anomaly threshold to obtain the anomaly status of the target indicator includes: The irregular item is determined based on the abnormality threshold. When the value of the irregular item is lower than the lower limit of the abnormality threshold, the abnormal state of the indicator is determined to be an abnormally low state of the indicator. When the value of the irregular item is higher than the upper limit of the abnormality threshold, the abnormal state of the indicator is determined to be an abnormal high-level state. When the value of the irregular item is between the upper and lower limits of the anomaly threshold, the value of the irregular item is equal to the lower limit of the anomaly threshold, or the value of the irregular item is equal to the upper limit of the anomaly threshold, the anomaly state of the indicator is determined to be an indicator without anomalies.
4. The method according to claim 1, characterized in that, The construction of the indicator system model based on the target indicator includes: Determine the multi-level indicator nodes corresponding to the target indicator and the parent-child relationship between each indicator node; wherein, the indicator node includes indicator name, indicator ID, topic ID, indicator level and aggregation rule attributes, the parent-child relationship includes parent node and child node, and the indicator value of the parent node is derived from the indicator value of the child node according to the aggregation rule; The indicator system model is constructed based on the multi-level indicator nodes and the parent-child hierarchical relationship.
5. The method according to claim 4, characterized in that, The root cause analysis of the target indicators based on the indicator system model, to obtain the root cause analysis results of the anomalies, includes: In response to the target indicator's abnormal state being an abnormal indicator state, the target indicator is obtained as the set of all child nodes under the parent node; Determine the influence weight of each child node in the child node set on the anomaly of the parent node, sort the influence weights based on the abnormal state of the indicator, and lock the child node with the largest influence weight as the main driving node; The main driving node is used as the new parent node for recursive drilling down until the leaf node is reached, thus obtaining the anomaly drilling path, and the anomaly drilling path is used as the result of the anomaly root cause analysis.
6. The method according to claim 5, characterized in that, The method further includes: The abnormality threshold, the abnormality status of the indicator, and the root cause analysis results of the abnormality are encapsulated into a structured data object, and the structured data object is visualized. In response to the abnormality status of the indicator being in an abnormal state, the abnormality drilling path and the influence weight of each node on the abnormality of the parent node are displayed simultaneously during the visualization. At the same time, the structured data object is pushed to the early warning interface to trigger an abnormality alarm. In response to the abnormal state of the indicator being normal, only the abnormal threshold and the normal state information of the target indicator are visualized.
7. A device for monitoring indicator data, characterized in that, include: The anomaly threshold determination module is configured to acquire historical time-series data of the target indicator, perform seasonal decomposition on the time-series data, and obtain the anomaly threshold. An abnormal state determination module is configured to determine irregular items in the historical time series data based on the abnormality threshold to obtain the abnormal state of the target indicator; wherein, the abnormal state of the indicator includes an indicator without abnormality and an indicator abnormality. The analysis result determination module is configured to construct an indicator system model based on the target indicator, and in response to the indicator's abnormal state, perform root cause analysis on the target indicator based on the indicator system model to obtain the abnormal root cause analysis results.
8. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as claimed in any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions for causing the computer to perform the method according to claims 1 to 6.
10. A computer program product, characterized in that, It includes computer program instructions that, when run on a computer, cause the computer to perform the method as described in any one of claims 1 to 6.