Data relationship display method and apparatus, and related device

By building a timeline based on event time points, displaying events, attributes and relationships, the problem of how to efficiently display and analyze network events is solved, and the efficiency of rapid positioning and query is improved.

WO2025092675A1PCT designated stage expired Publication Date: 2025-05-08HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/127874
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-30
Filing Date
2024-10-28
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

In the Internet era, how to effectively display different events and their related information to assist technicians in conducting abnormal detection has become a technical problem that needs to be solved urgently.

Method used

By building a timeline based on the time points in which events occur, users can quickly locate the time points that need to be queried and analyzed. The method includes displaying a timeline of multiple time points in the display area, and displaying the events that occur at that time point, the attributes corresponding to the event, and the relationship between the events and the attributes after the user selects a specific time point.

Benefits of technology

This method improves the efficiency of users when querying and analyzing events, can quickly locate the required time points, reduces the time cost of querying and analyzing, and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024127874_08052025_PF_FP_ABST
    Figure CN2024127874_08052025_PF_FP_ABST
Patent Text Reader

Abstract

A data relationship display method and apparatus, and a related device. The data relationship display method comprises: displaying in a display area a time axis comprising a plurality of discrete time points, and in response to at least one time point on the time axis that is selected by a user, displaying in the display area an event occurring at each time point among the at least one time point, an attribute corresponding to the event, and a relationship between the event occurring at each time point and the attribute corresponding to the event. Each time point comprised on the time axis corresponds to a real event, the time axis does not comprise a time point where no event occurs, and when the user selects a time point on the time axis, an event corresponding to the time point selected by the user, an attribute, and a relationship between the event and the attribute can be displayed in the display area.
Need to check novelty before this filing date? Find Prior Art

Description

A data relationship display method, device and related equipment

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on October 30, 2023, with application number 202311432744.6 and application name “A method, device and related equipment for displaying data relationships”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of computer technology, and in particular to a data relationship display method, apparatus, and related equipment. Background Art

[0003] In the internet age, various events are constantly occurring on the network, each of which is intricately interconnected. By analyzing these connections, we can promptly identify adverse factors and implement appropriate procedures to avoid unnecessary losses. Therefore, effectively displaying different events and other related information to assist technicians in anomaly detection is a pressing technical challenge.

[0004] Summary of the Invention

[0005] The present application provides a data relationship display method, device and related equipment. The method constructs a timeline based on the time point of an event, which enables users to quickly locate the time point that needs to be queried and analyzed through the timeline, thereby improving user efficiency.

[0006] In a first aspect, the present application provides a data relationship display method, comprising: displaying a timeline including multiple time points in a display area, and after obtaining at least one time point selected by a user on the timeline, displaying in the display area, in response to the at least one time point selected by the user, the events occurring at each time point in the at least one time point, the attributes corresponding to the events, and the relationship between the events occurring at each time point and the attributes corresponding to the events; wherein, the multiple time points on the timeline are discrete time points arranged in chronological order.

[0007] In the above solution, if the user selects a time point on the timeline, the computing device can display the events, attributes, and relationships between events and attributes corresponding to the time point selected by the user in the display area. Therefore, each time point on the timeline corresponds to an event and attributes associated with the event. That is, in this application, the device constructs a timeline based on the time point at which the event occurs. Each time point included in the timeline corresponds to a real event. The timeline constructed in this application does not include time points where no events occur. By constructing the above timeline, when the user needs to query or analyze the event corresponding to the time point, the user can quickly locate the time point that needs to be queried and analyzed, thereby improving efficiency.

[0008] In a possible implementation, before displaying, in the display area, the events that occur at each of the at least one time point selected by the user and the attributes associated with the events, the method further includes: obtaining a query request including a time interval input by the user, and then obtaining, according to the query request, multiple events and the attributes corresponding to each of the multiple events; wherein, each of the multiple events corresponds to a time point, and the time point corresponding to an event indicates the time when the event occurs; finally, mapping the time point corresponding to each event to the attribute corresponding to each event. Among them, the time point corresponding to each of the multiple events is included in the time interval input by the user, and the time range on the time axis belongs to the time interval input by the user.

[0009] The events saved in the database usually have time attributes, that is, an event corresponds to a time point indicating the time when the event occurs, but the attributes associated with the event do not have corresponding time points. After obtaining the above-mentioned multiple events and the attributes associated with each event, the computing device traverses each of the multiple events, and maps the time point corresponding to an event to the attribute associated with the event, so as to obtain one or more time points corresponding to each attribute. By endowing the attributes associated with the events with time attributes, each event and each attribute will correspond to a time set including time points. After the user selects a time point, the computing device searches for the time set including the time point, and according to the events and attributes corresponding to the found time set, the events and the attributes associated with the events corresponding to the time point selected by the user can be obtained, which can improve the efficiency of the computing device to search for the events and the attributes associated with the events corresponding to the time point selected by the user and improve the user experience.

[0010] In a possible implementation, when M events among the above-mentioned multiple events have the same attribute, the N time points at which the M events occur form a time set of the same attribute, where 1 < N <= M. That is, an attribute can be associated with one or more events, and the time point corresponding to an attribute is the set of the time points corresponding to the multiple events associated with the attribute.

[0011] In a possible implementation, before displaying, in the display area, the events that occur at each of the at least one time point and the attributes corresponding to the events, the method further includes: the computing device determines, according to the at least one time point selected by the user, the time point corresponding to each event, and the one or more time points corresponding to each attribute, the events that occur at each of the at least one time point and the attributes corresponding to the events.

[0012] Each event and its associated attributes correspond to a time set. After the user selects a time point, the computing device only needs to search the time set including that time point to obtain the events and attributes corresponding to that time point. This can improve the efficiency of the device in searching for events and attributes corresponding to the time point selected by the user and improve the user experience.

[0013] In one possible implementation, before displaying the events and attributes corresponding to each of the at least one time point selected by the user in the display area, the computing device configures display coordinates for each of the multiple events and each of the attributes when displayed in the display area; the display coordinates are used to indicate the position of the event or attribute when displayed in the display area. When the computing device displays the events and attributes corresponding to each of the at least one time point in the display area, the computing device displays the events and attributes corresponding to each of the at least one time point in the display area based on the display coordinates of the events and the display coordinates of the attributes corresponding to each of the at least one time point.

[0014] After the computing device configures display coordinates for each event and attribute, when the time point selected by the user on the timeline changes, that is, when the event that the computing device needs to display in the display area and the attribute corresponding to the event change, the computing device does not need to recalculate the display coordinates of the event and attribute to be displayed. It only needs to obtain the display coordinates of the event and the attribute corresponding to the event after determining the event to be displayed, and then display it at the position indicated by the display coordinates in the display area. There is no need to rearrange the display positions of each event and the attribute corresponding to the event. In this way, the computing device can quickly respond to the user's selection and improve display efficiency and user experience.

[0015] In one possible implementation, the above-mentioned displaying in the display area the events occurring at each of at least one time point selected by the user and the attributes corresponding to the events includes: the computing device sequentially displays in the display area the events occurring at each of the at least one time point and the attributes corresponding to the time; wherein, when displaying the events occurring at the (i+1)th time point and the attributes corresponding to the events, the events occurring at the (i)th time point and the attributes corresponding to the events continue to be displayed, and the (i)th time point and the (i+1)th time point belong to the at least one time point mentioned above.

[0016] When a computing device displays events occurring at multiple time points and the attributes corresponding to the events, it uses the above-mentioned incremental display method to continue displaying the events occurring at the previous time node and the attributes corresponding to the events when displaying the events occurring at the next time point. This can intuitively show how events and event-related attributes change over time, making it easier for users to analyze data.

[0017] In a possible implementation, the method further includes: the computing device, in response to a play instruction triggered by the user, sequentially displays in the display area events and attributes corresponding to each time point after at least one time point selected by the user.

[0018] After the user triggers the play command, the computing device can display the events and corresponding attributes of each time point in at least one time point selected by the user, and then display the events and corresponding attributes of each time point after this at least one time point in sequence, so as to show the process of more events and event-related attributes changing over time.

[0019] In one possible implementation, the aforementioned events and attributes are displayed in the display area as graph data, comprising nodes and edges. Each node in the graph data represents an event or an attribute, and an event and its associated attribute are connected by edges, which represent the relationship between the event and the attribute. Representing events, attributes, and the relationships between events and attributes in the form of graph data allows for intuitive display of how events and attributes change over time when displaying events, attributes, and the relationships between events and attributes occurring at multiple time points selected by the user, facilitating data analysis.

[0020] In a second aspect, the present application provides a data relationship display device, which includes a module for implementing the method described in the first aspect or any possible implementation of the first aspect.

[0021] The data relationship display device includes a processing module and an input / output module. The processing module is used to generate a timeline and control the display of the timeline in the display area of ​​the device, wherein the timeline includes multiple discrete time points arranged in chronological order; the input / output module is used to obtain at least one time point on the timeline selected by the user; and the processing module is further used to respond to the at least one time point selected by the user and display in the display area the events and corresponding attributes of each time point, as well as the relationship between each event and the multiple attributes corresponding to each event.

[0022] In one possible implementation, the input / output module is further configured to obtain a query request input by a user that includes a time interval; the processing module is further configured to obtain multiple events and attributes corresponding to each of the multiple events based on the query request; wherein each of the multiple events corresponds to a time point, and the time point corresponding to an event indicates the time when the event occurred; and the processing module is further configured to map the time point corresponding to each event to the attribute corresponding to each event. wherein the time point corresponding to each of the multiple events is included in the time interval input by the user, and the time range on the time axis falls within the time interval input by the user.

[0023] In one possible implementation, the processing module is further used to determine the events occurring at each time point in at least one time point and the attributes corresponding to the events based on at least one time point selected by the user, the time point corresponding to each event, and one or more time points corresponding to each attribute.

[0024] In one possible implementation, the processing module is further configured to configure display coordinates for each event and each attribute in the plurality of events when displayed in the display area; the display coordinates indicate the position of the event or attribute when displayed in the display area. Based on the display coordinates of the event and the display coordinates of the attribute corresponding to each of the at least one time point, the event and the attribute corresponding to the event are displayed in the display area.

[0025] In one possible implementation, the processing module is also used to control the display of the events and attributes corresponding to the time occurring at each of the at least one time point in the display area in sequence; wherein, when displaying the events occurring at the i+1th time point and the attributes corresponding to the events, the events occurring at the i-th time point and the attributes corresponding to the events continue to be displayed, and the i-th time point and the i+1th time point belong to the at least one time point mentioned above.

[0026] In a third aspect, the present application provides a computing device comprising a processor and a memory, wherein the memory is used to store instructions and the processor is used to execute the instructions. When the processor executes the instructions, the method described in the first aspect or any possible implementation of the first aspect is implemented.

[0027] In a fourth aspect, a computer-readable storage medium comprises computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method as described in the first aspect or any possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0029] FIG1 is a schematic diagram of graph data provided by an embodiment of the present application;

[0030] FIG2 is a schematic diagram of another type of graph data provided in an embodiment of the present application;

[0031] FIG3 is a flow chart of a data relationship display method provided in an embodiment of the present application;

[0032] FIG4 is a schematic diagram of a time axis provided in an embodiment of the present application;

[0033] FIG5 is a schematic diagram of another time axis provided in an embodiment of the present application;

[0034] FIG6 is a schematic diagram of a display area display image data provided by an embodiment of the present application;

[0035] FIG7 is a schematic diagram of another display area display image data provided by an embodiment of the present application;

[0036] FIG8 is a schematic diagram of a display interface provided in an embodiment of the present application;

[0037] FIG9 is an interactive diagram of a data relationship display method provided in an embodiment of the present application;

[0038] FIG10 is a schematic diagram of a data relationship display device provided in an embodiment of the present application;

[0039] FIG11 is a schematic diagram of a data processing device provided in an embodiment of the present application;

[0040] FIG12 is a schematic diagram of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0041] The following describes the embodiment of the present application in conjunction with the accompanying drawings. First, the events, attributes and graph data in the embodiment of the present application are introduced.

[0042] An event refers to something that happens; for example, an event can be a transaction event, a business registration event, a transfer event, etc. Attributes are information associated with an event. Attributes include users, locations, contact information, Internet Protocol (IP) addresses, etc. It should be understood that in different scenarios, the attributes associated with events are different. For example, if the event is an online shopping transaction event, the attributes associated with the online shopping transaction event include account, store, delivery location, delivery location, contact information, IP address, etc.; if the event is a business registration event, the attributes include registration location, legal person, business type, etc. In an embodiment of the present application, an event can be associated with one or more attributes, and an attribute can be associated with one or more events. For example, an account can be associated with multiple online shopping transaction events.

[0043] Graph data consists of nodes and edges. Graph data can be used to display the relationship between events and attributes. Nodes represent events and attributes, while edges connect an event to an attribute associated with it. That is, edges indicate whether an association exists between an event and an attribute. If an edge connects a node representing an event and a node representing an attribute, it indicates that the event and the attribute are associated.

[0044] As shown in Figure 1, Figure 1 is a schematic diagram of a graph data provided by an embodiment of the present application. Figure 1 takes the event as a transaction event as an example, and the node representing the transaction event is called a transaction node; the attributes include three attributes: account, IP and address, that is, the transaction event is associated with the three attributes of account, IP and address, and the node representing the attribute is called a non-transaction node, and the non-transaction node includes an account node, an IP node and an address node. Figure 1 is centered on the transaction node, and the transaction node is associated with three non-transaction nodes, which are an account node, an IP node and an address node. If the transaction node represents an online shopping transaction, the account node represents a buyer, the IP address represents the buyer's IP address, and the address node represents the delivery address. This graph data indicates that the buyer conducted a transaction through the IP address represented by the IP node, and the buyer used the delivery address represented by the address node.

[0045] As shown in Figure 2, Figure 2 is a schematic diagram of another graph data provided by an embodiment of the present application. The graph data includes multiple transaction nodes and multiple non-transaction nodes. Each non-transaction node can be associated with one or more transaction nodes. As shown in Figure 2, an account node can be associated with one or more transaction nodes, indicating that the buyer represented by the account node has conducted one or more online shopping transactions. For example, account node 1 is associated with transaction node 1 and transaction node 3, indicating that buyer 1 has conducted transactions 1 and 3, and buyer 1 conducted transaction 1 through IP address 1, and the selected delivery address is address 1; buyer 1 also conducted transaction 3 through IP address 2, and the selected delivery address is address 2. Among them, transaction a (a=1, 2, 3…, k1) refers to the transaction represented by transaction node a; account b (b=1, 2, 3…, k1) refers to the buyer represented by account node b; IP address c (c=1, 2, 3…, k3) refers to the IP address represented by IP node c; address d (c=1, 2, 3…, k4) refers to the delivery address represented by address node d.

[0046] An IP node can be associated with one or more transaction nodes, indicating that one or more buyers conducted one or more transactions through the IP address represented by the IP node. For example, IP node 1 is associated with transaction nodes 1 and 2, indicating that buyers conducted transactions 1 and 2 through IP address 1, and that buyer 1 conducted transaction 1 through IP address 1, and buyer 2 conducted transaction 2 through IP address 2.

[0047] An address node can be associated with one or more transaction nodes, indicating that a buyer has set the delivery address for one or more transactions to the address represented by the address node. For example, address 1 is associated with transactions 1 and 4, indicating that buyer 1 received the goods of transaction 1 through address 1, and buyer 3 received the goods of transaction 4 through address 1.

[0048] It should be understood that the graph data shown in Figures 1 and 2 above is an example of graph data used in scenarios involving transactions, such as financial activities, e-commerce risk control, and the like. Graph data can also take other forms, and there can also be graph data for other scenarios. For example, in an enterprise context scenario, the event is an enterprise registration event, and the attributes include the registration location, legal person, enterprise type, etc., then the graph data can include an enterprise node, a registration address node, a legal person node, and a type node. An enterprise node represents an enterprise registration event, a registration location node represents the registered address of the enterprise, a legal person node represents the legal person of the enterprise, and a type node represents the type of the enterprise.

[0049] The present application provides a data relationship display solution that can establish a timeline including multiple discrete time points. If the user selects at least one time point through the timeline, the computing device can display the events that occurred at the at least one time point and the attributes corresponding to the events in the display area, as well as the relationship between each event and the attributes associated with each event, to assist technicians in improving the efficiency of detecting anomalies. The data relationship display solution provided by the embodiment of the present application is described below in conjunction with the accompanying drawings. As shown in Figure 3, Figure 3 is a flow chart of a data relationship display method provided by an embodiment of the present application.

[0050] S301. Obtain a query request input by a user, and obtain multiple events, attributes corresponding to each event, and the relationship between each event and the corresponding attribute according to the query request.

[0051] In an embodiment of the present application, events stored in the database have corresponding time points, and the time point corresponding to each event indicates the time when the event occurred. If a user wishes to view events that occurred within a period of time and data such as attributes associated with each event, the user can enter a query request through the user interface, where the query request includes a time interval. The query request instructs the computing device to retrieve multiple events that occurred within the time interval, the attributes corresponding to each of these multiple events, and the relationship between each event and the corresponding attributes.

[0052] After the computing device obtains the query request input by the user, the computing device obtains the above-mentioned multiple events, the attributes corresponding to each event in the multiple events, and the relationship between each event and the corresponding attribute according to the query request and the data in the database. Each event in the database corresponds to a time point, and the time point corresponding to each event is used to indicate the time when the event occurs. After the computing device obtains the time interval in the above-mentioned query request, it traverses each event in the database. If the time point corresponding to an event belongs to the above-mentioned time interval, it obtains the event, the attributes corresponding to the event, and the relationship between the event and the corresponding attribute. After the computing device traverses the events in the database, it obtains the above-mentioned multiple events, the attributes corresponding to each event, and the relationship between each event and the attributes corresponding to each event. That is, it obtains multiple events, multiple attributes, and the corresponding relationship between the multiple events and the multiple attributes. Among them, an event can have an association relationship with one or more attributes, and an attribute can be associated with one or more events.

[0053] Optionally, the above-mentioned query request may further include other query conditions in addition to the above-mentioned time interval. For example, if the user wants to view the data of multiple accounts within a period of time, the above-mentioned query request further includes the account identifiers of the multiple accounts. Another example is that if the user wants to view the data of a certain city within a period of time, the above-mentioned query request further includes the city identifier.

[0054] S302. Map the time point corresponding to each event in the above-mentioned multiple events to the attribute corresponding to each event, and obtain one or more time points corresponding to each attribute.

[0055] In the embodiment of the present application, the events stored in the database have corresponding time points, but the attributes associated with the events do not have corresponding time points. In the embodiment of the present application, after the computing device obtains the above-mentioned multiple events, the computing device traverses each event in the multiple events, maps the time point corresponding to an event to the attribute associated with the event, and assigns a time point to the attribute associated with each event, so as to obtain one or more time points corresponding to each attribute. Among them, each attribute can be associated with one or more events, so the time point corresponding to each attribute can be one or more. For example, if M events in the above-mentioned multiple events are associated with the same attribute, the N time points when these M events occur form the time set of the attribute, 1 < N <= M. That is, an attribute can be associated with one or more events, and the time point corresponding to an attribute is the set of the time points corresponding to the multiple events associated with the attribute, and there are no duplicate time points in the time set.

[0056] If an event 1 corresponds to a time point T2, and event 1 is associated with three attributes, then mapping time point T2 to these three attributes will make the time points corresponding to these three attributes include T2. If an event 2 corresponds to a time point T3, and event 2 is associated with two attributes, then mapping time point T3 to these two attributes will make the time points corresponding to these two attributes include T3. Following this method, traverse all events and map the time points corresponding to an event to the attributes associated with the event.

[0057] For example, using Figure 2 above as an example, if transaction node 1 corresponds to a time point T2, and transaction node 1 is associated with three non-transaction nodes: account node 1, address node 1, and IP node 1, mapping time point T2 to these three non-transaction nodes means that account node 1, address node 1, and IP node 1 correspond to time point T2. If transaction node 2 corresponds to a time point T3, and transaction node 2 is associated with two non-transaction nodes: account node 2 and IP node 1, mapping time point T3 to these two non-transaction nodes means that the time points corresponding to account node 2 include T3, and the time points corresponding to IP node 1 include T2 and T3. Following the above method, all transaction nodes are traversed, and the time points corresponding to a transaction node are mapped to the non-transaction nodes associated with that transaction node.

[0058] S303. Construct a timeline according to the time point corresponding to each of the multiple events.

[0059] After receiving the multiple events, the computing device obtains the time points corresponding to each of the multiple events, obtaining multiple time points, and then generates a timeline based on the multiple time points. It should be understood that the multiple time points corresponding to the multiple events are not continuous time points, and therefore the timeline includes multiple discrete time points arranged in chronological order.

[0060] It should be understood that there are no duplicate time points on the timeline. The time points corresponding to the multiple events described above may contain duplicate time points. After obtaining the time points corresponding to each of the multiple events described above, the computing device will perform deduplication processing on the obtained multiple time points to obtain multiple time points that do not contain the same time point.

[0061] In a possible implementation, before generating the timeline, the computing device also needs to perform precision conversion on the time points corresponding to the above-mentioned multiple events. For example, if the time precision selected by the user is different from the precision of the time point corresponding to the event, or if there are many time points used to construct the timeline, it is necessary to perform precision conversion on the time points. For example, the precision of the time point corresponding to the event is milliseconds (ms). If the number of time points is large, by converting the precision of the time point from milliseconds to seconds (s), the number of time points can be reduced and the timeline can be avoided from being too long. In the process of performing precision conversion, the computing device can directly delete the part representing milliseconds in each time point. For example, the time at which an event occurs is 12:25:36:215 milliseconds. After performing precision conversion, the time at which the event occurs can be expressed as 12:25:36:00. The computing device can also perform precision conversion on the time point according to other methods, and the embodiments of the present application are not specifically limited.

[0062] If the time points corresponding to these multiple events have a high precision, for example, millisecond precision, even after deduplication, the number of time points used to construct the timeline is still large. This results in a long timeline, making it difficult to display on the device and making it difficult for users to quickly locate the desired time point through the timeline. By converting the time point precision, the number of time points used to construct the timeline can be reduced, creating a timeline that is more user-friendly and improves the user experience.

[0063] S304. Display the above time axis in the display area.

[0064] As shown in Figure 4, Figure 4 is a schematic diagram of the time axis provided in an embodiment of the present application. Figure 4 provides schematic diagrams of two types of time axes, each rectangular box or dot in the figure represents a time point. For ease of description, the rectangular boxes or dots representing time points in the embodiment of the present application are referred to as region points.

[0065] The time points on the time axis are arranged in chronological order. Multiple time points on the time axis are discrete, non-continuous time points. As shown in Figure 4, the time axis in Figure 4 has a precision of 1 second. The time points represented by two adjacent area points are not necessarily adjacent to each other. In other words, two adjacent area points can be adjacent to each other or not.

[0066] Alternatively, as shown in FIG5 , which is a schematic diagram of another timeline provided in an embodiment of the present application, toggle controls are also included on the left and right sides of the timeline. If there are many time points and the display area cannot display the entire timeline, that is, cannot display all the time points included in the timeline, the user can switch the time points displayed in the display area using the toggle controls.

[0067] Optionally, when the computing device displays a timeline in a display area, it displays the time point represented by the leftmost region point and the rightmost region point of the currently displayed timeline, and may also display a time point every first number of region points. For example, a time point represented by a region point may be displayed every 10 region points. For a region point that does not display a time point, the user can select the region point to cause the computing device to display the time point represented by the region point. For example, the user can hover the mouse over a region point to cause the computing device to display the time point represented by the region point.

[0068] If the time point selected by the user belongs to the time point included in the time axis, or the user selects the time point included in the time axis through the time axis, the computing device can display the events corresponding to the time point selected by the user and the attributes corresponding to each event in the display area. Therefore, each time point on the time axis corresponds to an event and the attributes associated with the event. That is, in this application, the computing device constructs the time axis based on the time point when the event occurs. Each time point included in the time axis corresponds to a real event. The time axis constructed in this application does not include time points where no event occurs. By constructing the above time axis, users can quickly locate the time point that needs to be queried and analyzed, thereby improving efficiency and user experience.

[0069] S305. Obtain at least one time point on the timeline selected by the user.

[0070] If a user wishes to view events, attributes associated with events, and relationships between events and attributes corresponding to at least one time point on the timeline, the user can select a region corresponding to the desired time point on the timeline. The region corresponding to the selected time point will be rendered in a different color than other unselected regions. After the user selects the region corresponding to the desired time point on the timeline, the computing device can retrieve the time point corresponding to the selected region.

[0071] As shown in Figure 5, Figure 5 is a schematic diagram of a selected time point provided by an embodiment of the present application. In the figure, the user selects 5 time points as an example, and the colors of the 5 selected time points are different from those of other area points. Optionally, the computing device can be a desktop computer, a laptop computer, a tablet computer or other computing device. If the user operates the computing device with a mouse, the user can select a time point by clicking on an area point on the timeline. If the user needs to select two or more time points, such as the 5 time points mentioned above, the user can click on the area points corresponding to the 5 time points to select the 5 time points respectively, or after clicking to select one of the time points, select the other 4 time points by dragging the mouse. It should be understood that based on the different computing devices used, the user can select the time point to be viewed by different methods, and the embodiment of the present application does not impose specific restrictions.

[0072] S306. In response to at least one time point selected by the user, the event occurring at each of the at least one time point, the attribute corresponding to each event, and the relationship between each event and the corresponding attribute are displayed in the display area.

[0073] After obtaining at least one time point selected by the user, the computing device determines the event occurring at each time point in the at least one time point selected by the user, and the attributes corresponding to the event occurring at each time point based on the at least one time point selected by the user, the time point corresponding to each event, and the one or more time points corresponding to each attribute.

[0074] The multiple events obtained according to the query request and the multiple attributes corresponding to these multiple events; for these multiple events, since each event corresponds to a time point, if the time point corresponding to an event belongs to at least one time point selected by the user, then the event is regarded as the event corresponding to the at least one time point selected by the user. For the multiple attributes corresponding to the multiple events obtained according to the query request, if an attribute corresponds to one or more time points, and if the one or more time points corresponding to an attribute include any time point selected by the user, then the attribute is regarded as the attribute corresponding to the at least one time point selected by the user.

[0075] For example, if there are m events and attributes obtained according to a query request, and each event and attribute corresponds to a time set, the time set corresponding to an event includes the time point corresponding to the event, and the time set corresponding to an attribute includes the time point corresponding to the attribute. For any time point t1 selected by the user, the computing device determines k time sets in the m time sets that include the first time point t1, and uses the k events and attributes corresponding to these k time sets as the events and attributes corresponding to the first time point t1. That is, for any time set, if the time set includes t1 and the time set corresponds to an event, the event corresponding to the time set is used as the event corresponding to the first time point t1; if the time set includes t1 and the time set corresponds to an attribute, the attribute corresponding to the time set is used as the attribute corresponding to the first time point t1. The computing device traverses the m time sets and determines k time sets that include the first time point t1. The k events and attributes corresponding to these k time sets are the multiple events and multiple attributes corresponding to the first time point t1. Here, m is an integer greater than or equal to 2, and k is less than or equal to m.

[0076] The computing device can determine the events and attributes corresponding to each other time point respectively according to the same method as the above-mentioned determination of the first time point t1, and then display multiple events, multiple attributes and the relationship between multiple events and multiple attributes corresponding to this at least one time point in the display area.

[0077] In a possible implementation, the computing device can simultaneously display the multiple events, multiple attributes, and the relationships between the multiple events and the multiple attributes corresponding to the at least one time point in the display area at one time.

[0078] In another possible implementation, if the user selects two or more time points, the computing device can sequentially display the events, attributes, and relationships between events and attributes corresponding to each time point in the display area. That is, the computing device first displays the events and attributes corresponding to the i-th time point, and after a first time interval, displays the events and attributes corresponding to the i+1-th time point; and after another first time interval, displays the events and attributes corresponding to the i+2-th time point, until all the events and attributes corresponding to the time points selected by the user are displayed. When displaying the events and attributes corresponding to the i+1-th time point, the events and attributes corresponding to the i-th time point continue to be displayed; when displaying the events and attributes corresponding to the i+2-th time point, the events and attributes corresponding to the i-th time point and the events and attributes corresponding to the i+1-th time point continue to be displayed; that is, in the process of displaying the events and attributes corresponding to two or more time points, the events and attributes corresponding to the already displayed time points remain displayed in the display area.

[0079] In embodiments of the present application, events, attributes, and the relationships between events and attributes can be represented using the aforementioned graph data. For ease of description, the multiple events obtained based on the query request, the multiple attributes corresponding to these multiple events, and the relationships between these multiple events and the multiple attributes are referred to as first graph data. The first graph data includes m nodes, each corresponding to a time set. The following describes the process of using graph data to display the events and attributes corresponding to each of the at least one node.

[0080] If the user selects a time point, such as the first time point t1, after obtaining the first time point t1 selected by the user, the computing device determines, for the m time sets corresponding to the m nodes included in the first graph data, the k time sets that include the first time point t1, and uses the k nodes corresponding to these k time sets as the nodes corresponding to the first time point t1. That is, for any time set that includes t1, the node corresponding to the time set is used as the node corresponding to the first time point t1. The computing device traverses the time sets corresponding to the m nodes included in the first graph data and determines the k time sets that include the first time point t1. Where m is an integer greater than or equal to 2, and k is less than or equal to m.

[0081] After obtaining the k nodes corresponding to the first time point t1, the computing device uses these k nodes and the edges representing the association relationship between these k nodes as the graph data corresponding to the first time point t1, and then displays the graph data corresponding to the first time point t1 in the display area.

[0082] For example, as shown in Figure 6, Figure 6 is a schematic diagram of a display area displaying graph data provided by an embodiment of the present application. As shown in the figure, after a user selects a time point t1, the color of the area dot representing that time point on the time axis will be different from that of other time points, and the nodes and edges included in the graph data corresponding to the first time point will be displayed in the display area. In Figure 6, for example, eight nodes corresponding to the first time point t1 are used, including three transaction nodes: transaction node 1, transaction node 2, and transaction node 4, as well as five non-transaction nodes associated with these three transaction nodes.

[0083] Optionally, the computing device can also display the specific time of the time point selected by the user in the area above or below the timeline.

[0084] If the user selects multiple time points, the computing device determines the node corresponding to each of the multiple time points selected by the user according to the above method of determining the node corresponding to the first time point t1, and then displays the corresponding graph data of the multiple time points selected by the user in the display area.

[0085] In one possible implementation, the computing device can simultaneously display graph data corresponding to multiple time points selected by the user in a display area. For example, if the multiple time points selected by the user correspond to n nodes, the computing device can display all n nodes in the display area at once.

[0086] In another possible implementation, the computing device can also display the graphical data corresponding to these multiple time points in sequence in the display area. The computing device first displays the graphical data corresponding to the i-th time point, and after an interval of the first time length, displays the graphical data corresponding to the i+1-th time point; and after another interval of the first time length, displays the graphical data corresponding to the i+2-th time point; until all the graphical data corresponding to these multiple time points are displayed. When displaying the graphical data corresponding to the i+1-th time point, the graphical data corresponding to the i-th time point continues to be displayed; when displaying the graphical data corresponding to the i+2-th time point, the graphical data corresponding to the i-th time point and the graphical data corresponding to the i+1-th time point continue to be displayed; that is, in the process of displaying the graphical data corresponding to these multiple time points, the graphical data corresponding to the time points that have been displayed remain displayed in the display area.

[0087] For example, as shown in FIG7 , FIG7 is a schematic diagram of another display area displaying graph data provided by an embodiment of the present application. FIG7 takes the user selecting three time points (t1, t2, t3) as an example, illustrating the process of a computing device displaying graph data corresponding to the three time points in the display area. At time T1, the computing device first displays the graph data corresponding to time point t1, including three transaction nodes, transaction node 1, transaction node 2, and transaction node 4, and five non-transaction nodes associated with these three transaction nodes. Then, at time T1+ΔT, the graph data corresponding to time point t2 is displayed; the graph data corresponding to time point t2 is based on the graph data corresponding to time point t1, with the addition of two transaction nodes, transaction node 3 and transaction node 5, and the non-transaction nodes associated with these two transaction nodes. Finally, at time T1+2ΔT, the graph data corresponding to time point t3 is displayed; the graph data corresponding to time point t3 is based on the graph data corresponding to time point t2, with the addition of two transaction nodes, transaction node 6 and transaction node 9, and the non-transaction nodes associated with these two transaction nodes. Optionally, the computing device can display the nodes corresponding to different time points in different colors.

[0088] Through the above-mentioned incremental display method, when displaying the node corresponding to the next time point, the node corresponding to the previous time point continues to be displayed, which can intuitively show the process of events and event-related attributes changing over time, making it easier for users to analyze data. In addition, by also assigning time attributes to the attributes associated with each event, after the user selects a time point, the computing device only needs to find the time set that includes the time point, and can obtain the event and attribute corresponding to the time point based on the found time set. The computing device does not need to first find the event based on a time point, and then determine the attribute corresponding to the time point based on the association relationship between the event and the attribute. This can improve the efficiency of the computing device in finding the event and attribute corresponding to the time point selected by the user, and after obtaining the time point selected by the user, improve the response speed and thus improve the user experience.

[0089] In an embodiment of the present application, after the computing device obtains the above-mentioned multiple events, the attributes corresponding to the multiple events, and the relationship between the multiple events and the corresponding attributes, the computing device can configure the display coordinates of each event and each attribute when displayed in the display area according to the display area, the total number of the above-mentioned multiple events and the multiple attributes. The display coordinates are used to indicate the position where the event or attribute is displayed in the display area. After the computing device configures the display coordinates for each event and each attribute, after the user selects the above-mentioned at least one time point on the timeline, the computing device displays the event and attribute corresponding to each time point in the display area according to the display coordinates of the event corresponding to each time point in the at least one time point and the display coordinates of the attribute corresponding to each time point.

[0090] For example, when representing events, attributes, and the relationship between events and attributes in the form of the above-mentioned graph data, the computing device can use the two mutually perpendicular sides of the display area as coordinate axes, and configure display coordinates for each node according to the total number of nodes representing events and attributes. After the computing device configures the display coordinates for each node, when the time point selected by the user on the timeline changes, that is, when the node to be displayed in the display area changes, the computing device does not need to recalculate the display coordinates of the node to be displayed. It only needs to obtain the display coordinates of the node to be displayed after determining the node to be displayed, and display the node at the position indicated by the display coordinates in the display area. Therefore, it can quickly respond to the user's selection and improve display efficiency and user experience.

[0091] In one possible implementation, as shown in FIG8 , FIG8 is a schematic diagram of a display interface provided by an embodiment of the present application. The display interface includes a display area, a timeline, and a control area. Among them, the control area includes a “play / pause control”, and the user can trigger the “play / pause control” after selecting at least one time point on the timeline. When the user triggers the “play / pause control”, after the computing device displays the events and attributes corresponding to each time point in at least one time point selected by the user, the computing device sequentially displays the events and attributes corresponding to each time point after the at least one time point. In the process of the computing device sequentially displaying the events and attributes corresponding to each time point after the at least one time point, if the user triggers the “play / pause control” again, the computing device pauses displaying the time and attributes corresponding to the next time point.

[0092] Optionally, if the user has only selected one time point t1, when the computing device sequentially displays the time and attributes corresponding to each time point after time point t1 on the timeline, the computing device can continue to display the event and attributes corresponding to the previous time point in the display area when displaying the event and attributes corresponding to the next time point, or can stop displaying the event and attributes corresponding to the previous time point in the display area when displaying the event and attributes corresponding to the next time point. If the user has selected multiple time points, when the computing device displays the time and attributes corresponding to each time point after the multiple time points selected by the user on the timeline, it can still display the events and attributes corresponding to the multiple time points selected by the user in the display area, and continue to display the events and attributes corresponding to the previous time point in the display area when displaying the event and attributes corresponding to the next time point.

[0093] In one possible implementation, the control area further includes a "previous control" and a "next control." After the user selects at least one time point on the timeline and the computing device displays the events and attributes corresponding to each of the at least one time point selected by the user, if the user does not trigger the "play / pause control" but instead triggers the "next control," the computing device displays the events and attributes corresponding to a time point after the at least one time point selected by the user. If the user continues to trigger the "next control," the computing device displays the events and attributes corresponding to the next time point. If the user triggers the "previous control," the computing device deletes the events and attributes corresponding to the last time point in the display area, where the last time point refers to the latest time point among the time points corresponding to the events currently displayed in the display area.

[0094] In a possible implementation, the user can also set the display speed, that is, set the speed at which the computing device sequentially displays events and attributes corresponding to different time points.

[0095] The present application also provides a data relationship display system, which includes a first device and a second device, as shown in FIG9 , which is an interactive diagram of a data relationship display method provided by an embodiment of the present application. As shown in FIG9 , when a user needs to query events within a certain time range and attribute information associated with the events, the user inputs a query request through the first device. The query request includes a time interval, and the query request is used to instruct the computing device to obtain all events included in the time interval and the attributes of each event; the query request may also include other query conditions, such as location information, for example, the user wants to view events that occurred in a city within the above time interval and the attributes of each event.

[0096] After receiving the user's query request, the first device generates a request based on the query request and then sends the request to the second device. The request includes the aforementioned time interval; if the user's query request also includes other query conditions, the request also includes the other query conditions. The second device can be an instance for managing a database, such as a service, virtual machine, or container.

[0097] After receiving the above-mentioned acquisition request, the second device parses the acquisition request and obtains the first event set that meets the acquisition request from the database based on the acquisition request. The first event set includes multiple events, attributes corresponding to these multiple events, and the relationship between these multiple events and the corresponding attributes, and the time point corresponding to each of these multiple events belongs to the above-mentioned time interval. The method for the second device to obtain multiple events that meet the acquisition request, the attributes corresponding to these multiple events, and the relationship between these multiple events and the corresponding attributes from the database according to the acquisition request can refer to the method for the computing device to obtain multiple events, the attributes corresponding to each event, and the relationship between each event and the corresponding attributes according to the query request in S301 above, which will not be repeated here.

[0098] After obtaining the multiple events, the attributes corresponding to each event, and the relationship between each event and the corresponding attributes, the second device maps the time points corresponding to each event in the first event set to the attributes associated with each event, thereby obtaining one or more time points corresponding to each attribute in the attributes corresponding to the multiple events. The method for mapping the time points corresponding to an event to the attributes associated with the event can be referred to the method in S302 above and is not further described here.

[0099] The second device sends a first event set to the first device, wherein the first event set includes the above-mentioned multiple events, attributes corresponding to these multiple events, and the relationship between these multiple events and the corresponding attributes; and the attributes corresponding to each event in these multiple events correspond to one or more time points.

[0100] After receiving the first event set, the first device obtains the time points corresponding to all events in the first event set, and then performs deduplication and precision conversion operations on all time points to obtain multiple time points for constructing the timeline. The method for deduplication and precision conversion of the time points by the first device can be referred to the description of S303 above and is not repeated here.

[0101] After obtaining the multiple time points for constructing the timeline, the first device constructs the timeline based on the multiple time points for constructing the timeline, wherein the time points on the timeline are arranged in chronological order, and the multiple time points on the timeline are discrete, non-continuous time points. The timeline constructed by the first device can refer to the relevant description of Figure 4 or Figure 5 above, and will not be repeated here.

[0102] After constructing the timeline, the first device displays the timeline in the display area and obtains at least one time point selected by the user. Then, in response to the at least one time point selected by the user, the first device displays in the display area the events corresponding to each of the at least one time point, the attributes corresponding to the events, and the relationships between the events and the attributes. The operations of the first device displaying the timeline in the display area, obtaining at least one time point selected by the user, and displaying the events and attributes corresponding to each of the at least one time point in the display area can be referred to the descriptions of S304 to S306 above and are not further described here.

[0103] For the above method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should know that the present invention is not limited by the order of the actions described. For example, the execution order of S302 and S303 above can be that S303 is executed before S302, or it can be executed after S302. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the present invention. Other reasonable step combinations that those skilled in the art can think of based on the above description also fall within the scope of protection of the present invention.

[0104] The embodiment of the present application also provides a data relationship display device, as shown in FIG10 , which is a schematic diagram of a data relationship display device provided by the embodiment of the present application. The data relationship display device 100 includes a processing module 101 and an input / output module 102. The processing module 101 is used to control the display of the timeline in the display area of ​​the device after generating the timeline, wherein the timeline includes a plurality of discrete time points arranged in chronological order; the input / output module 102 is used to obtain at least one time point on the timeline selected by the user; the processing module 101 is also used to display, in response to the at least one time point selected by the user, the events and the attributes corresponding to the events at each time point in the display area, as well as the relationship between each event and the multiple attributes corresponding to each event.

[0105] In one possible implementation, the input / output module 102 is further configured to obtain a query request input by a user that includes a time interval; the processing module 101 is further configured to obtain multiple events and attributes corresponding to each of the multiple events based on the query request; wherein each of the multiple events corresponds to a time point, and the time point corresponding to an event indicates the time when the event occurred; and the processing module 101 is further configured to map the time point corresponding to each event to the attribute corresponding to each event. wherein the time point corresponding to each of the multiple events is included in the time interval input by the user, and the time range on the time axis falls within the time interval input by the user.

[0106] Optionally, the data relationship display apparatus 100 further includes a communication module 103, and the communication module 103 is configured to send the acquisition request to the second device and receive the first event set sent by the second device.

[0107] The above-mentioned data relationship display device 100 is used to implement the operations implemented by the computing device in the embodiment shown in Figure 3 above. The operations implemented by each module of the data relationship display device 100 can refer to the corresponding operations implemented by the above-mentioned computing device or first device, and will not be repeated here.

[0108] An embodiment of the present application further provides a data processing device, as shown in FIG11 . FIG11 is a schematic diagram of a data processing device provided in an embodiment of the present application. The data processing device 110 includes a processing module 111 and a communication module 112 .

[0109] The communication module 112 is used to receive an acquisition request sent by other devices, the acquisition request including the above time interval. If the query request input by the user in the other device also includes other query conditions, the acquisition request also includes the other query conditions input by the user.

[0110] Processing module 111 is configured to traverse each event in the database based on the acquisition request and the time point corresponding to each event in the database, and retrieve, from the database, multiple events that satisfy the acquisition request, the attributes corresponding to the multiple events, and the relationships between the multiple events and the corresponding attributes based on the acquisition request. The method by which processing module 111 obtains events that satisfy the acquisition request can refer to the method by which the second device obtains multiple events, the attributes corresponding to each event, and the relationships between each event and the corresponding attributes based on the acquisition request, and is not further described here.

[0111] The data processing device 110 is used to implement the operations implemented by the second device in the method embodiment shown in FIG. 9 , and will not be described in detail here.

[0112] The present application also provides a computing device, as shown in FIG12 , which is a schematic diagram of a computing device provided in an embodiment of the present application. The computing device 120 includes one or more processors 121, a communication interface 122, a memory 123, a bus 124, and a display unit 125. The one or more processors 121, the communication interface 122, the memory 123, and the display unit 125 are interconnected via the bus 124. The processor 121 can be used to implement the operations performed by the computing device in the method embodiment corresponding to FIG3 . The method implemented by the processor 121 can refer to the introduction in the above method embodiment and will not be repeated here.

[0113] The communication interface 122 can be a wired or wireless interface and is used to communicate with other modules or devices to enable the computing device to receive and send data. For example, it can send a request to the second device and receive multiple events and attributes associated with the events from the second device. The wired interface can be an Ethernet interface, a local interconnect network (LIN), etc. The wireless interface can be a cellular network interface or a wireless local area network interface.

[0114] Memory 123 may be a non-volatile memory, such as a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. Memory 123 may also be a volatile memory, which may be a random access memory (RAM) used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0115] The memory 123 can also be used to store program instructions and data, so that the processor 121 can call the program instructions stored in the memory 123 to execute the operating steps of the computing device in the method embodiment shown in Figure 3. In addition, the computing device 120 may include more or fewer components than those shown in Figure 12, or have different component configurations.

[0116] Bus 124 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. Bus 124 may be classified as an address bus, a data bus, a control bus, etc. For ease of illustration, FIG12 shows only one thick line, but this does not indicate that there is only one bus or only one type of bus.

[0117] The display unit 125 is used to display the above-mentioned time axis, display area, play / pause control, etc. For example, the display unit 125 can be a display with a display function such as a touch screen.

[0118] It should be noted that the above-mentioned processor 121 can be a central processing unit (CPU), or it can include a CPU and other hardware chips. The above-mentioned hardware chips can be of various types. For example, it can be a co-processing unit including a graphics processing unit (GPU), a tensor processing unit (TPU), a programmable logic device (PLD), a complex programmable logic device (CPLD), a field programmable gate array (FPGA) or a digital signal processor (DSP). Any one of the chips, the computing device 120 can include one or more hardware chips of any of the above types, or can include multiple types of the above hardware chips, which is not specifically limited in the embodiments of the present application.

[0119] Specifically, the specific implementation of various operations performed by the computing device 120 can refer to the specific operations performed by the computing device in the above method embodiment, which will not be repeated here.

[0120] An embodiment of the present application also provides another computing device, the structural diagram of which is the same as the structural diagram of the computing device 120 shown in Figure 12 above. The computing device is used to execute the operations completed by the above-mentioned second device, which will not be repeated here.

[0121] An embodiment of the present application also provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is executed on a processor, it can implement the method steps implemented by the computing device in the above method embodiment. The specific implementation of the processor of the computer-readable storage medium in executing the above method steps can refer to the specific operations of the above method embodiment, which will not be repeated here.

[0122] An embodiment of the present application also provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is executed on a processor, it can implement the method steps implemented by the second device in the above method embodiment. The specific implementation of the processor of the computer-readable storage medium in executing the above method steps can refer to the specific operations of the above method embodiment, which will not be repeated here.

[0123] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0124] The above embodiments can be implemented in whole or in part through software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium, or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0125] The steps in the method of the embodiment of the present application can be adjusted in order, combined or deleted according to actual needs; the modules in the device of the embodiment of the present application can be divided, combined or deleted according to actual needs.

[0126] The above is a detailed introduction to the embodiments of the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of ​​the present application. At the same time, for those skilled in the art, according to the idea of ​​the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A data relationship display method, characterized in that: include: Displaying a time axis in the display area, the time axis comprising a plurality of discrete time points arranged in chronological order; In response to at least one time point on the timeline selected by a user, the display area displays events occurring at each of the at least one time point and attributes corresponding to the events, as well as the relationship between multiple events occurring at the at least one time point and multiple attributes corresponding to the multiple events.

2. The method according to claim 1, characterized in that Before the display area displays the event occurring at each of the at least one time point and the attribute corresponding to the event, the method further includes: Acquire a query request input by a user; wherein the query request includes a time interval, and the time range on the time axis belongs to the time interval; Acquire multiple events and attributes corresponding to each of the multiple events according to the query request; wherein each of the multiple events corresponds to a time point, and the time point corresponding to each event belongs to the time interval; The time point corresponding to each event is mapped to the attribute corresponding to each event to obtain one or more time points corresponding to each attribute.

3. The method according to claim 2, characterized in that When M events among the multiple events have the same attribute, the N time points at which the M events occur constitute a time set with the same attribute, 1 <N<=M。 4. The method according to claim 2 or 3, characterized in that: Before displaying the event occurring at each of the at least one time point and the attribute corresponding to the event in the display area, the method further includes: According to at least one time point selected by the user, the time point corresponding to each event, and one or more time points corresponding to each attribute, the event and attribute corresponding to each time point in the at least one time point are determined, and the acquired events and attributes are not repeated.

5. The method according to any one of claims 1 to 4, characterized in that: Before displaying the event occurring at each of the at least one time point and the attribute corresponding to the event in the display area, the method further includes: Configuring display coordinates of the multiple events and the attributes corresponding to each of the multiple events when displayed in the display area; the display coordinates are used to indicate the position where the event or attribute is displayed in the display area; The displaying in the display area an event occurring at each of the at least one time point and an attribute corresponding to the event includes: The event occurring at each of the at least one time point and the attribute corresponding to the event are displayed in the display area according to the display coordinates of the event occurring at each of the at least one time point and the display coordinates of the attribute corresponding to the event.

6. The method according to any one of claims 1 to 5, characterized in that: The displaying in the display area an event occurring at each of the at least one time point and an attribute corresponding to the event includes: The events occurring at each of the at least one time point and the attributes corresponding to the events are displayed in sequence in the display area; wherein, when displaying the events occurring at the (i+1)th time point and the attributes corresponding to the events, the events occurring at the (i)th time point and the attributes corresponding to the events continue to be displayed, and the (i)th time point and the (i+1)th time point belong to the at least one time point.

7. The method according to any one of claims 1 to 6, characterized in that: The event and the attribute corresponding to the event are displayed in the display area in the form of graph data, and the graph data includes nodes and edges; wherein each node in the graph data represents an event or an attribute, and an event and the associated attribute are connected by an edge.

8. A data relationship display device, characterized in that: The data relationship display device includes a module for implementing the method as described in any one of claims 1-7.

9. A computing device, characterized in that The method comprises a processor and a memory, wherein the memory is used to store instructions, and the processor is used to execute the instructions. When the processor executes the instructions, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device, the computing device performs the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Display method and device for enterprise graph, and electronic equipment

    CN108133047A

  • Event information display method, device and equipment

    CN116304247A

  • Data relationship display method and device and related equipment

    CN117573936A

  • Systems and interactive user interfaces for automatic generation of temporal representation of data objects

    US20180095621A1

  • Displaying a series of events along a time axis in enterprise threat detection

    US20190190935A1