CN110445637B - Event monitoring method, system, computer device and storage medium - Google Patents

Event monitoring method, system, computer device and storage medium Download PDF

Info

Publication number
CN110445637B
CN110445637B CN201910604037.8A CN201910604037A CN110445637B CN 110445637 B CN110445637 B CN 110445637B CN 201910604037 A CN201910604037 A CN 201910604037A CN 110445637 B CN110445637 B CN 110445637B
Authority
CN
China
Prior art keywords
event
information
acquiring
abnormal
platform application
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201910604037.8A
Other languages
Chinese (zh)
Other versions
CN110445637A (en
Inventor
逯义东
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
OneConnect Financial Technology Co Ltd Shanghai
Original Assignee
OneConnect Financial Technology Co Ltd Shanghai
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by OneConnect Financial Technology Co Ltd Shanghai filed Critical OneConnect Financial Technology Co Ltd Shanghai
Priority to CN201910604037.8A priority Critical patent/CN110445637B/en
Publication of CN110445637A publication Critical patent/CN110445637A/en
Application granted granted Critical
Publication of CN110445637B publication Critical patent/CN110445637B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/14Network analysis or design
    • H04L41/145Network analysis or design involving simulating, designing, planning or modelling of a network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/16Threshold monitoring
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/55Push-based network services

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Debugging And Monitoring (AREA)
  • Computer And Data Communications (AREA)

Abstract

The application relates to an event monitoring method, an event monitoring system, computer equipment and a storage medium for anomaly monitoring. The method comprises the following steps: acquiring event processing information stored in an event library in a monitored server cluster, wherein the event processing information is generated by processing an event request based on an application server, analyzing the event processing information through an event analysis model to obtain an analysis result, and generating corresponding abnormal information and event record information according to an abnormal index value and the analysis result when a data index value exceeding a preset threshold value exists in the analysis result; acquiring a preset interface mapping table, and acquiring a bound platform application identifier according to a user identifier; and calling a corresponding platform application interface according to the platform application identifier, and pushing the abnormal information and the event record information to a user terminal corresponding to the event identifier through the platform application interface. By adopting the method, the event processing information can be accurately and effectively monitored and analyzed, so that the efficiency and the accuracy of event monitoring are effectively improved.

Description

Event monitoring method, system, computer device and storage medium
Technical Field
The present application relates to the field of computer technologies, and in particular, to an event monitoring method, system, computer device, and storage medium for anomaly monitoring.
Background
With the rapid development of internet technology, our lives, studies and works are more and more independent of the internet, a large number of data operations such as event requests, event processing and the like can be initiated in the internet, and a large number of events are generated in many network systems all the time. The real-time processing, capturing, real-time analyzing and monitoring of mass events in the internet environment becomes an important information technology research field at present.
In a conventional event monitoring method, a unified monitoring tool is usually used to monitor abnormal events, such as memory conditions, network conditions, service processing logic, port monitoring, and log monitoring. The recorded information content of the abnormal event contained in the event is less, and the warning information of the abnormal event is more general, so that the specific information of the abnormal event cannot be effectively obtained, and the monitoring efficiency of the event is lower.
Disclosure of Invention
In view of the above, there is a need to provide an event monitoring method, system, computer device and storage medium, which can accurately and effectively monitor and analyze event processing information to effectively improve the efficiency and accuracy of event monitoring.
A method of event monitoring, the method comprising:
acquiring event processing information stored in an event library in a monitored server cluster, wherein the event processing information is generated by processing an event request sent by a user terminal based on an application server, and comprises a user identifier and an event type;
acquiring a preset event analysis model according to the event type, and analyzing the event processing information through the event analysis model to obtain a corresponding analysis result, wherein the analysis result comprises a plurality of data index values;
when the data index value exceeding a preset threshold exists in the analysis result, determining the data index value exceeding the preset threshold as an abnormal index value, and generating corresponding abnormal information and event record information according to the abnormal index value and the analysis result;
acquiring a preset interface mapping table, and acquiring a bound platform application identifier according to the user identifier;
and calling a corresponding platform application interface according to the platform application identifier, and pushing the abnormal information and the event record information to a user terminal corresponding to the user identifier through the platform application interface.
In one embodiment, the event analysis model includes a plurality of decision nodes, and the step of analyzing the event processing information by the event analysis model further includes: traversing the processing node information of the event processing information through the event analysis model; respectively calculating multi-dimensional index values of the processing node information according to a plurality of decision nodes of the event analysis model; calculating an abnormal index value of the event processing information according to the multi-dimensional index value; and generating an analysis result corresponding to the event processing information according to the multi-dimensional index value and the abnormal index value.
In one embodiment, the method further comprises: acquiring a target sharing community corresponding to the user identifier, and acquiring a bound target platform application identifier according to the target sharing community; acquiring a preset interface mapping table, and acquiring a corresponding interface identifier according to the target platform application identifier; and calling a corresponding target platform application interface according to the interface identifier, and pushing the abnormal information to a user terminal corresponding to the user identifier through the target platform application interface.
In one embodiment, the method further comprises: acquiring a preset visual model, and converting the abnormal information and the event record information into corresponding visual abnormal data values through the visual model; acquiring a preset integration function according to an event type, and integrating the visual abnormal data value into corresponding view data through the integration function; and pushing the visual abnormal data to a corresponding user terminal through the target platform application interface.
A method of event monitoring, the method comprising:
receiving an event request sent by a user terminal, wherein the event request carries request information and an event type;
calling a corresponding service system according to the event type to process the event request;
acquiring event processing information of the event request processing process, and sending the event processing information to an event library of a monitored server cluster for storage according to the request information; and enabling the monitoring server to acquire event processing information from the event library, and performing event analysis and abnormity monitoring on the event processing information.
In one embodiment, the method further comprises: receiving a binding request sent by the user terminal, wherein the binding request carries user group information and a target sharing community; acquiring a platform application identifier of the target sharing community; and binding the user group information and the platform application identifier to generate a corresponding target sharing configuration table.
In one embodiment, the method further comprises: acquiring the target sharing configuration table, and acquiring corresponding platform application interface parameters according to the platform application identification; packaging the platform application interface according to the platform application interface parameters to obtain a packaged platform application interface; and binding association is carried out according to the community sharing configuration table and the packaged platform application interface, and an interface mapping table is generated.
An event monitoring system, the system comprising:
the system comprises a user terminal, a server and a server, wherein the user terminal is used for sending an event request to the application server, and the event request comprises request information and a request type; the request information comprises a user identification;
the application server is used for receiving an event request sent by the user terminal; calling a corresponding service system according to the event type to process the event request; acquiring event processing information of the event request processing process, and sending the event processing information to an event library of a monitored server cluster for storage according to the request information;
the monitored server cluster is used for acquiring event processing information in the application server through a preset monitoring interface and storing the event processing information to an event library according to the request information;
the monitoring server is used for acquiring event processing information stored in an event library in a monitored server cluster, wherein the event processing information comprises a user identifier and an event type; acquiring a preset event analysis model according to the event type, and analyzing the event processing information through the event analysis model to obtain a corresponding analysis result, wherein the analysis result comprises a plurality of data index values; when the data index value exceeding a preset threshold exists in the analysis result, determining the data index value exceeding the preset threshold as an abnormal index value, and generating corresponding abnormal information and event record information according to the abnormal index value and the analysis result; acquiring a preset interface mapping table, and acquiring a bound platform application identifier according to the user identifier; and calling a corresponding platform application interface according to the platform application identifier, and pushing the abnormal information and the event record information to a user terminal corresponding to the user identifier through the platform application interface.
A computer device comprising a memory storing a computer program and a processor implementing the steps of the event monitoring method provided in any one of the embodiments of the present application when executing the computer program.
A computer-readable storage medium, on which a computer program is stored which, when being executed by a processor, carries out the steps of the event monitoring method provided in any one of the embodiments of the present application.
According to the event monitoring method, the system, the computer equipment and the storage medium, after the application server processes the time request sent by the user terminal and generates the corresponding event processing information, the monitoring server obtains the event processing information stored in the event library in the monitored server cluster, analyzes the event processing information through the event analysis model to obtain an analysis result comprising a plurality of data index values, analyzes the event processing information through the event analysis model, and can effectively analyze whether the event request is abnormal or not. And when the data index value exceeding the preset threshold exists in the analysis result, the data index value indicates that an abnormal index value exists in the event processing information, and the monitoring server further generates corresponding abnormal information and event record information according to the abnormal index value and the analysis result. The monitoring server further pushes the abnormal information and the event record information to the corresponding user terminal through the platform application pre-bound by the user, so that the user can timely and effectively acquire the abnormal information and the event record information. The event processing information is stored to the monitored server cluster in a centralized manner, and the monitoring server is used for monitoring and analyzing the event processing information, so that the pressure of the application server can be effectively relieved, and the analysis efficiency and the monitoring efficiency of the event processing information can be effectively improved.
Drawings
FIG. 1 is a diagram illustrating an exemplary scenario in which the event monitoring method is applied;
FIG. 2 is a flow diagram of a method for event monitoring in one embodiment;
FIG. 3 is a schematic flow chart diagram of a method for event monitoring in another embodiment;
FIG. 4 is a block diagram of an event monitoring system in one embodiment;
FIG. 5 is a diagram illustrating an internal structure of a computer device according to an embodiment.
Detailed Description
In order to make the objects, technical solutions and advantages of the present application more apparent, the present application is described in further detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the present application and are not intended to limit the present application.
The event monitoring method provided by the application can be applied to the application environment shown in fig. 1. The user terminal 102 communicates with the application server 104 through a network, the application server 104 communicates with the monitored server cluster 106 through the network, the monitored server cluster 106 communicates with the monitoring server 108 through the network, and the monitoring server 108 can also communicate with the user terminal 102 through the network. The user terminal 102 may be, but not limited to, various personal computers, notebook computers, smart phones, tablet computers, and portable wearable devices, and the application server 104 and the monitoring server cluster 108 may be implemented by independent servers or a server cluster formed by a plurality of servers.
In one embodiment, as shown in fig. 2, an event monitoring method is provided, which is described by taking the example that the method is applied to the monitoring server in fig. 1, and includes the following steps:
step 202, obtaining event processing information stored in an event library in the monitored server, wherein the event processing information is generated by processing an event request sent by a user terminal based on an application server, and the event processing information comprises a user identifier and an event type.
The multiple user terminals may send an event request to the application server, where the event request includes request information and a request type, where the event request may be a service request, the request information may include an event identifier and a user identifier, and the request type may include a specific service type. And the application server calls the corresponding service system to process the event request according to the event type of the event request. And after processing the event request, the application server generates corresponding event processing information, wherein the event processing information comprises a user identifier and an event type. And the application server sends the event processing information to an event library of the monitored server cluster for storage.
After the monitored server cluster obtains the event processing information, prompt information can be sent to the monitoring server, so that the monitoring server obtains the event processing information stored in the event library in the monitored server and analyzes the event processing information.
The monitoring server can monitor the event processing information stored in the event library of the monitored server cluster through a preset monitoring interface, and the monitoring server can acquire the event processing information stored in the event library of the monitored server in real time and also can acquire the event processing information stored in the event library of the monitored server according to a preset frequency so as to further analyze the event processing information. Wherein the event processing information comprises a user identification and an event type.
And 204, acquiring a preset event analysis model according to the event type, and analyzing the event processing information through the event analysis model to obtain a corresponding analysis result, wherein the analysis result comprises a plurality of data index values.
Further, the monitoring server obtains a preset event analysis model according to the event type, wherein the event analysis model may be a decision tree-based event analysis model, and the monitoring server may pre-construct the event analysis model. Specifically, the event analysis model may include a plurality of business modules, and each business module has a corresponding business rule and an anomaly detection rule. The monitoring server may construct an event analysis model in a preset manner according to the service rules and the anomaly detection rules corresponding to the plurality of service modules in advance. Furthermore, after the monitoring server constructs the event anomaly analysis model according to the preset mode, a large amount of event processing information can be analyzed, so that the event anomaly analysis model is trained and parameters are adjusted, and the required event analysis model is obtained.
The method comprises the steps that after a monitoring server obtains event processing information stored in an event library, a preset event analysis model is obtained according to an event type, processing node information is subjected to traversal analysis through a plurality of decision nodes of the event analysis model, multi-dimensional index values corresponding to the event processing information are calculated through the decision nodes, the server further calculates abnormal index values in the event processing information according to the multi-dimensional index values, and corresponding analysis result information is obtained according to the multi-dimensional index values and the abnormal index values. And analyzing the multi-dimensional index value corresponding to the event processing information through the event anomaly analysis model, thereby accurately and effectively analyzing whether the event request is abnormal or not.
And step 206, when the data index value exceeding the preset threshold exists in the analysis result, determining the data index value exceeding the preset threshold as an abnormal index value, and generating corresponding abnormal information and event record information according to the abnormal index value and the analysis result.
When the analysis result has a data index value exceeding a preset threshold, determining the data index value exceeding the preset threshold as an abnormal index value to indicate that the event request is an abnormal event, generating corresponding abnormal information by the monitoring server according to the abnormal index value and the analysis result, generating event record information corresponding to the event request according to the request information and the event processing information, and adding the abnormal information and the event record information of the event request into an abnormal event library.
And step 208, acquiring a preset interface mapping table, and acquiring the bound platform application identifier according to the user identifier.
And step 210, calling a corresponding platform application interface according to the platform application identifier, and pushing the abnormal information and the event record information to a user terminal corresponding to the user identifier through the platform application interface.
Further, the monitoring server obtains a preset interface mapping table, and obtains a pre-bound platform application identifier according to the user identifier. The platform application identifier may be an identifier corresponding to a third-party platform application, and may be, for example, a third-party platform application such as an associated application program and a wechat application program.
The monitoring server calls a corresponding platform application interface according to the platform application identifier, and pushes the abnormal information and the event recording information to a corresponding user terminal through the platform application interface, for example, the abnormal information and the event recording information can be pushed to the user terminal corresponding to the user identifier through an interface of a WeChat platform in a WeChat message form. Therefore, the user can effectively acquire the abnormal information and the event record information.
Furthermore, the monitoring server can also push the abnormal information and the event record information to the corresponding operation and maintenance terminal through a preset operation and maintenance interface, so that operation and maintenance personnel can effectively know the abnormal information and the event record information. If the abnormal information is the problem of the service system, operation and maintenance personnel can perform operation and maintenance analysis on the service system according to the abnormal information and the event record information, so that the normal operation of the application server and the processing efficiency of the event are effectively guaranteed.
In the event monitoring method, after the application server processes the time request sent by the user terminal and generates corresponding event processing information, the monitoring server obtains the event processing information stored in the event library in the monitored server cluster, analyzes the event processing information through the event analysis model to obtain an analysis result comprising a plurality of data index values, analyzes the event processing information through the event analysis model, and can effectively analyze whether the event request is abnormal or not. And when the data index value exceeding the preset threshold exists in the analysis result, the data index value indicates that an abnormal index value exists in the event processing information, and the monitoring server further generates corresponding abnormal information and event record information according to the abnormal index value and the analysis result. The monitoring server further pushes the abnormal information and the event record information to the corresponding user terminal through the platform application pre-bound by the user, so that the user can timely and effectively acquire the abnormal information and the event record information. The event processing information is stored to the monitored server cluster in a centralized manner, and the monitoring server is used for monitoring and analyzing the event processing information, so that the pressure of the application server can be effectively relieved, and the analysis efficiency and the monitoring efficiency of the event processing information can be effectively improved.
In one embodiment, the event analysis model includes a plurality of decision nodes, and the step of analyzing the event processing information by the event analysis model further includes: traversing the processing node information of the event processing information through the event analysis model; respectively calculating multi-dimensional index values of processing node information according to a plurality of decision nodes of the event analysis model; calculating an abnormal index value of the event processing information according to the multi-dimensional index value; and generating an analysis result corresponding to the event processing information according to the multi-dimensional index value and the abnormal index value.
The event analysis model may be a decision tree-based event analysis model, and the monitoring server may construct the event analysis model in advance. Specifically, the event analysis model may include a plurality of business modules, and each business module has a corresponding business rule and an anomaly detection rule. The monitoring server may construct an event analysis model in a preset manner according to the service rules and the anomaly detection rules corresponding to the plurality of service modules in advance. Furthermore, after the monitoring server constructs the event anomaly analysis model according to the preset mode, a large amount of event processing information can be analyzed, so that the event anomaly analysis model is trained and parameters are adjusted, and the required event analysis model is obtained.
The event analysis model may include indexes corresponding to multiple dimensions, such as multidimensional indexes corresponding to a service layer, an application layer, a system layer, and a hardware layer, and may also monitor CPU load, memory usage, disk usage, network conditions, port monitoring, and log monitoring. The event analysis model can comprise a plurality of decision nodes, and the event processing information also comprises processing node information.
The method comprises the steps that after a monitoring server obtains event processing information stored in an event library, a preset event analysis model is obtained according to an event type, processing node information of the event processing information is subjected to traversal analysis through a plurality of decision nodes of the event analysis model, a multi-dimensional index value corresponding to the event processing information is calculated through the decision nodes, the server further calculates an abnormal index value in the event processing information according to the multi-dimensional index value, and corresponding analysis result information is obtained according to the multi-dimensional index value and the abnormal index value. And analyzing the multi-dimensional index value corresponding to the event processing information through the event anomaly analysis model, thereby accurately and effectively analyzing whether the event request is abnormal or not.
In one embodiment, the method further comprises: acquiring a target sharing community corresponding to a user identifier, and acquiring a bound target platform application identifier according to the target sharing community; acquiring a preset interface mapping table, and acquiring a corresponding interface identifier according to a target platform application identifier; and calling the corresponding target platform application interface according to the interface identifier, and pushing the abnormal information to the user terminal corresponding to the user identifier through the target platform application interface.
The monitoring server acquires event processing information stored in an event library in a monitored server cluster, acquires a preset event analysis model according to an event type, analyzes the event processing information through the event analysis model to obtain an analysis result comprising a plurality of data index values, analyzes the event processing information through the event analysis model, and can effectively analyze whether an event request is abnormal or not. And when the data index value exceeding the preset threshold exists in the analysis result, generating corresponding abnormal information and event record information according to the abnormal index value and the data index value.
And after the monitoring server analyzes that abnormal information exists in the event processing information, further acquiring a target sharing community corresponding to the user identification. The target sharing community may be registered and bound in advance by a user through a corresponding user terminal, for example, the target sharing community may include a third-party information sharing push platform such as a WeChat and a mailbox.
The monitoring server further acquires the bound target platform application identifier according to the target sharing community, acquires a pre-configured interface mapping table, acquires a corresponding interface identifier according to the target platform application identifier, calls a corresponding target platform application interface according to the interface identifier, and pushes the abnormal information to the user terminal corresponding to the user identifier through the target platform application interface, so that the user can effectively acquire the abnormal information and the event record information.
In one embodiment, the method further comprises: acquiring a preset visual model, and converting the abnormal information and the event record information into corresponding visual abnormal data values through the visual model; acquiring a preset integration function according to the event type, and integrating the visual abnormal data value into corresponding view data through the integration function; and pushing the visual abnormal data to the corresponding user terminal through the target platform application interface.
The monitoring server acquires event processing information stored in an event library in a monitored server cluster, acquires a preset event analysis model according to an event type, analyzes the event processing information through the event analysis model to obtain an analysis result comprising a plurality of data index values, analyzes the event processing information through the event analysis model, and can effectively analyze whether an event request is abnormal or not. And when the data index value exceeding the preset threshold exists in the analysis result, generating corresponding abnormal information and event record information according to the abnormal index value and the data index value.
After the monitoring server analyzes that the abnormal information exists in the event processing information, the monitoring server can also perform visual processing on the abnormal information and the event record information. Specifically, the monitoring server acquires a preset visual model, converts the abnormal information and the event record information of the event request into corresponding visual abnormal data values through the visual model, acquires a preset integration function according to the event type, and integrates the visual abnormal data values into corresponding view data through the integration function. For example, the monitoring server may obtain a python visualization function, integrate the plurality of visualization abnormal data values into corresponding view data, for example, embed the integrated corresponding view data using a histogram visualization function, a distribution density, a heat map, and other visualization functions, and draw a corresponding visualization image using a nested function.
And after integrating the visual abnormal data values into the corresponding view data, the monitoring server further adds event type identification and corresponding interface calling parameters to the view data, and integrates the corresponding classes for storage.
The monitoring server pushes the visual abnormal data to the corresponding terminal through a preset interface, so that a user can quickly and effectively know the abnormal event and perform the next operation according to the prompt. Furthermore, the monitoring server can also push the abnormal information and the event record information to the corresponding operation and maintenance terminal through a preset operation and maintenance interface, perform abnormal analysis on the event request through the event abnormal analysis model, accurately and effectively monitor the abnormal event request, convert the abnormal event request into visual abnormal analysis data and warn, so that the operation and maintenance personnel can quickly and effectively know the abnormal event. And operation and maintenance personnel can carry out operation and maintenance analysis on the service system according to the abnormal information and the event record information so as to effectively ensure the normal operation of the application server and the processing efficiency of the event.
In one embodiment, the monitoring server may be a monitoring server cluster, and the monitoring server cluster may include a plurality of nodes, including a master node and a plurality of slave nodes. After the monitoring server acquires event processing information corresponding to a plurality of event requests sent by a plurality of user terminals, a master node in the monitoring server can send the event processing information to a plurality of slave nodes respectively for analysis and processing. Specifically, the master node polls the current load weights of a plurality of slave nodes in the cluster to obtain the current load weight of each slave node. And the master node selects a corresponding slave node identifier for the event request according to the current load weight of each slave node in the cluster. And the master node performs smoothing processing on the current load weight corresponding to the selected slave node identifier, and selects the slave node identifier corresponding to the next event request by using the smoothed result until the corresponding slave node identifier is selected for the plurality of event requests. And the master node sequentially sends the event requests to the corresponding slave nodes according to the selected slave node identification. The resource consumption of the slave node of the currently distributed event request can be offset through smoothing processing, and the load weight of the slave node is prevented from being repeatedly calculated, so that the load balance of a plurality of slave nodes in the cluster is achieved. Therefore, the plurality of slave nodes in the cluster can respectively perform parallel monitoring processing on the event processing information corresponding to the plurality of event requests, and the analysis processing efficiency of the event processing information is effectively improved.
In one embodiment, as shown in fig. 3, an event monitoring method is provided, which is described by taking the application server in fig. 1 as an example, and includes the following steps:
step 302, receiving an event request sent by a user terminal, where the event request carries request information and an event type.
And step 304, calling a corresponding service system according to the event type to process the event request.
Step 306, acquiring event processing information of the event request processing process, and sending the event processing information to an event library of the monitored server cluster for storage according to the request information; and the monitoring server acquires the event processing information from the event library, and performs event analysis and anomaly monitoring on the event processing information.
The plurality of user terminals may send an event request to the application server, where the event request includes request information and a request type, where the request information may include a user identifier and a request identifier, the event request may be a service request, and the request type may include a specific service type.
And after receiving the event request sent by the user terminal, the application server calls a corresponding service system to process the event request according to the event type of the event request. And after processing the event request, the application server generates corresponding event processing information, wherein the event processing information comprises a user identifier and an event type.
And the application server sends the event processing information to an event library of the monitored server cluster for storage. And then the monitoring server acquires event processing information stored in an event library in the monitored server cluster, wherein the event processing information comprises user identification and event type. The monitoring server acquires a preset event analysis model according to the event type, analyzes the event processing information through the event analysis model to obtain an analysis result comprising a plurality of data index values, analyzes the event processing information through the event analysis model, and can effectively analyze whether the event request is abnormal or not. And when the data index value exceeding the preset threshold exists in the analysis result, generating corresponding abnormal information and event record information according to the abnormal index value and the data index value. The monitoring server obtains a preset interface mapping table, obtains a bound platform application identifier according to the user identifier, calls a corresponding platform application interface according to the platform application identifier, and pushes the abnormal information and the event record information to a corresponding user terminal through the platform application interface, so that a user can effectively obtain the abnormal information and the event record information. The event processing information is stored to the monitored server cluster in a centralized manner, and the monitoring server is used for monitoring and analyzing the event processing information, so that the pressure of the application server can be relieved effectively, and the analysis efficiency of the event processing information can be improved effectively.
In the event monitoring method, after receiving an event request sent by a user terminal, an application server calls a corresponding service system to process the event request according to the event type of the event request. And after processing the event request, the application server generates corresponding event processing information, wherein the event processing information comprises a user identifier and an event type. And the application server sends the event processing information to an event library of the monitored server cluster for storage. The event processing information is stored to the monitored server cluster in a centralized manner, and the monitoring server is used for monitoring and analyzing the event processing information, so that the pressure of the application server can be relieved effectively, and the analysis efficiency of the event processing information can be improved effectively.
In one embodiment, the method further comprises: receiving a binding request sent by a user terminal, wherein the binding request carries user group information and a target sharing community; acquiring a platform application identifier of a target sharing community; and binding according to the user group information and the platform application identifier to generate a corresponding target sharing configuration table.
The receiving user terminal can also bind a target sharing community in advance in the application server. The target sharing community may refer to a platform application for pushing a message, for example, a third-party platform application such as a WeChat and a mail may be used.
The user terminal may send a binding request to the application server before sending the event request to the application server, and further, the user terminal may send the binding request to the application server while sending the event request to the application server, where the binding request includes user group information, the user group information may include identification information, account information, and the like of a user, and the target sharing community may be one or more target sharing communities selected by the user through a corresponding user terminal. After receiving a binding request sent by a user terminal, the application server acquires a platform application identifier of the target sharing community, and binds the platform application identifier according to user group information to generate a corresponding target sharing configuration table. By means of pre-binding and producing the target sharing configuration table, the target sharing configuration table can be effectively called when the event record information is pushed, and therefore information pushing can be effectively carried out.
In one embodiment, the application server includes a corresponding application server identification, the method further comprising: acquiring a target sharing configuration table, and acquiring corresponding platform application interface parameters according to the platform application identification; packaging the platform application interface according to the platform application interface parameters to obtain a packaged platform application interface; and binding association is carried out according to the community sharing configuration table and the packaged platform application interface, and an interface mapping table is generated.
The user terminal may also manage the plurality of application servers and the interface of the third party platform before sending the event request to the application server. Wherein the application server comprises a corresponding application server identification.
The application server obtains a target sharing configuration table, wherein the target sharing configuration table comprises user group information and a platform application identifier of a target sharing community. And the application server further acquires corresponding platform application interface parameters according to the platform application identification, encapsulates the platform application interface according to the interface parameters, and generates corresponding encapsulation information after encapsulation. The package information includes a plurality of attribute information of the platform application interface. And the application server stores the encapsulated platform application interface and the corresponding encapsulation information, and further performs binding association according to the community sharing configuration table and the encapsulated platform application interface and generates an interface mapping table. The application server can store the interface mapping table in a local database, and can also send the interface mapping table to a monitored server cluster for storage, so that the monitoring server can simultaneously acquire corresponding packaging information when calling the platform application interface. By packaging the platform application interface, the platform application interface can be effectively normalized, and the information pushing efficiency can be effectively improved. The interfaces of the application servers and the platform application interfaces are managed, and the interface mapping table is established, so that the mapping relation among the servers can be effectively established, and further, the event processing information can be effectively monitored and pushed.
It should be understood that although the various steps in the flow charts of fig. 2-3 are shown in order as indicated by the arrows, the steps are not necessarily performed in order as indicated by the arrows. The steps are not performed in the exact order shown and described, and may be performed in other orders, unless explicitly stated otherwise. Moreover, at least some of the steps in fig. 2-3 may include multiple sub-steps or multiple stages that are not necessarily performed at the same time, but may be performed at different times, and the order of performance of the sub-steps or stages is not necessarily sequential, but may be performed in turn or alternating with other steps or at least some of the sub-steps or stages of other steps.
In one embodiment, as shown in fig. 4, there is provided an event monitoring system comprising: user terminal 402, application server 404, monitored server cluster 406, and monitoring server 408, wherein:
a user terminal 402, configured to send an event request to an application server, where the event request includes request information and a request type; the request information comprises a user identification;
an application server 404, configured to receive an event request sent by a user terminal; calling a corresponding service system according to the event type to process the event request; acquiring event processing information of an event request processing process, and sending the event processing information to an event library of a monitored server cluster for storage according to the request information;
the monitored server cluster 406 is used for acquiring event processing information in the application server through a preset monitoring interface and storing the event processing information to an event library according to the request information;
the monitoring server 408 is configured to obtain event processing information stored in an event library in the monitored server cluster, where the event processing information includes a user identifier and an event type; acquiring a preset event analysis model according to the event type, and analyzing the event processing information through the event analysis model to obtain a corresponding analysis result, wherein the analysis result comprises a plurality of data index values; when the data index value exceeding the preset threshold exists in the analysis result, determining the data index value exceeding the preset threshold as an abnormal index value, and generating corresponding abnormal information and event record information according to the abnormal index value and the analysis result; acquiring a preset interface mapping table, and acquiring a bound platform application identifier according to a user identifier; and calling a corresponding platform application interface according to the platform application identifier, and pushing the abnormal information and the event record information to a user terminal corresponding to the user identifier through the platform application interface.
In one embodiment, the event analysis model includes a plurality of decision nodes, and the monitoring server 408 is further configured to traverse processing node information of the event processing information through the event analysis model; respectively calculating multi-dimensional index values of processing node information according to a plurality of decision nodes of the event analysis model; calculating an abnormal index value of the event processing information according to the multi-dimensional index value; and generating an analysis result corresponding to the event processing information according to the multi-dimensional index value and the abnormal index value.
In an embodiment, the monitoring server 408 is further configured to obtain a target sharing community corresponding to the user identifier, and obtain a bound target platform application identifier according to the target sharing community; acquiring a preset interface mapping table, and acquiring a corresponding interface identifier according to a target platform application identifier; and calling the corresponding target platform application interface according to the interface identifier, and pushing the abnormal information to the user terminal corresponding to the user identifier through the target platform application interface.
In one embodiment, the monitoring server 408 is further configured to obtain a preset visualization model, and convert the anomaly information and the event record information into corresponding visualization anomaly data values through the visualization model; acquiring a preset integration function according to the event type, and integrating the visual abnormal data value into corresponding view data through the integration function; and pushing the visual abnormal data to the corresponding user terminal through the target platform application interface.
In an embodiment, the application server 404 is further configured to receive a binding request sent by a user terminal, where the binding request carries user group information and a target sharing community; acquiring a platform application identifier of a target sharing community; and binding according to the user group information and the platform application identifier to generate a corresponding target sharing configuration table.
In one embodiment, the application server 404 is further configured to obtain a target sharing configuration table, and obtain a corresponding platform application interface parameter according to the platform application identifier; packaging the platform application interface according to the platform application interface parameters to obtain a packaged platform application interface; and binding association is carried out according to the community sharing configuration table and the packaged platform application interface, and an interface mapping table is generated.
For the specific definition of the event monitoring system, reference may be made to the above definition of the event monitoring method, which is not described herein again. The modules in the event monitoring system can be implemented in whole or in part by software, hardware and a combination thereof. The modules can be embedded in a hardware form or independent from a processor in the computer device, and can also be stored in a memory in the computer device in a software form, so that the processor can call and execute operations corresponding to the modules.
In one embodiment, a computer device is provided, which may be a server, the internal structure of which may be as shown in fig. 5. The computer device includes a processor, a memory, a network interface, and a database connected by a system bus. Wherein the processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device comprises a nonvolatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of an operating system and computer programs in the non-volatile storage medium. The database of the computer device is used for storing data such as event processing information, an interface mapping table and the like. The network interface of the computer device is used for communicating with an external terminal through a network connection. The computer program is executed by a processor to implement the steps of the event monitoring method provided in any of the embodiments of the present application.
Those skilled in the art will appreciate that the architecture shown in fig. 5 is merely a block diagram of some of the structures associated with the disclosed aspects and is not intended to limit the computing devices to which the disclosed aspects apply, as particular computing devices may include more or less components than those shown, or may combine certain components, or have a different arrangement of components.
In one embodiment, a computer readable storage medium is provided, having stored thereon a computer program, which when executed by a processor, performs the steps of the event monitoring method provided in any one of the embodiments of the present application.
It will be understood by those skilled in the art that all or part of the processes of the methods of the embodiments described above can be implemented by hardware instructions of a computer program, which can be stored in a non-volatile computer-readable storage medium, and when executed, can include the processes of the embodiments of the methods described above. Any reference to memory, storage, database, or other medium used in the embodiments provided herein may include non-volatile and/or volatile memory, among others. Non-volatile memory can include read-only memory (ROM), Programmable ROM (PROM), Electrically Programmable ROM (EPROM), Electrically Erasable Programmable ROM (EEPROM), or flash memory. Volatile memory can include Random Access Memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDRSDRAM), Enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus Direct RAM (RDRAM), direct bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
The technical features of the above embodiments can be arbitrarily combined, and for the sake of brevity, all possible combinations of the technical features in the above embodiments are not described, but should be considered as the scope of the present specification as long as there is no contradiction between the combinations of the technical features.
The above-mentioned embodiments only express several embodiments of the present application, and the description thereof is more specific and detailed, but not construed as limiting the scope of the invention. It should be noted that, for a person skilled in the art, several variations and modifications can be made without departing from the concept of the present application, which falls within the scope of protection of the present application. Therefore, the protection scope of the present patent shall be subject to the appended claims.

Claims (9)

1. A method of event monitoring, the method comprising:
acquiring event processing information stored in an event library in a monitored server cluster, wherein the event processing information is generated by processing an event request sent by a user terminal based on an application server, and comprises a user identifier and an event type;
acquiring a preset event analysis model according to the event type, performing traversal analysis on processing node information of the event processing information through a plurality of decision nodes of the event analysis model, respectively calculating multi-dimensional index values corresponding to the event processing information through the plurality of decision nodes, further calculating abnormal index values in the event processing information according to the multi-dimensional index values, and acquiring corresponding analysis results according to the multi-dimensional index values and the abnormal index values, wherein the analysis results comprise a plurality of data index values;
when the data index value exceeding a preset threshold exists in the analysis result, determining the data index value exceeding the preset threshold as an abnormal index value, and generating corresponding abnormal information and event record information according to the abnormal index value and the analysis result;
acquiring a preset interface mapping table, and acquiring a bound platform application identifier according to the user identifier;
and calling a corresponding platform application interface according to the platform application identifier, and pushing the abnormal information and the event record information to a user terminal corresponding to the user identifier through the platform application interface.
2. The method of claim 1, further comprising:
acquiring a target sharing community corresponding to the user identifier, and acquiring a bound target platform application identifier according to the target sharing community;
acquiring a preset interface mapping table, and acquiring a corresponding interface identifier according to the target platform application identifier;
and calling a corresponding target platform application interface according to the interface identifier, and pushing the abnormal information to a user terminal corresponding to the user identifier through the target platform application interface.
3. The method of claim 2, further comprising:
acquiring a preset visual model, and converting the abnormal information and the event record information into corresponding visual abnormal data values through the visual model;
acquiring a preset integration function according to an event type, and integrating the visual abnormal data value into corresponding view data through the integration function;
and pushing the visual abnormal data to a corresponding user terminal through the target platform application interface.
4. A method of event monitoring, the method comprising:
receiving an event request sent by a user terminal, wherein the event request carries request information and an event type;
calling a corresponding service system according to the event type to process the event request;
acquiring event processing information of the event request processing process, and sending the event processing information to an event library of a monitored server cluster for storage according to the request information; the event processing information is generated by processing an event request sent by a user terminal based on an application server, and comprises a user identifier and an event type; enabling a monitoring server to acquire event processing information from the event library, acquiring a preset event analysis model according to the event type of the event processing information, performing traversal analysis on the processing node information of the event processing information through a plurality of decision nodes of the event analysis model, respectively calculating a multi-dimensional index value corresponding to the event processing information through the plurality of decision nodes, further calculating an abnormal index value in the event processing information according to the multi-dimensional index value, and acquiring a corresponding analysis result according to the multi-dimensional index value and the abnormal index value, wherein the analysis result comprises a plurality of data index values; when the data index value exceeding a preset threshold exists in the analysis result, determining the data index value exceeding the preset threshold as an abnormal index value, and generating corresponding abnormal information and event record information according to the abnormal index value and the analysis result; acquiring a preset interface mapping table, and acquiring a bound platform application identifier according to the user identifier; and calling a corresponding platform application interface according to the platform application identifier, and pushing the abnormal information and the event record information to a user terminal corresponding to the user identifier through the platform application interface, so as to analyze and monitor the event processing information.
5. The method of claim 4, further comprising:
receiving a binding request sent by the user terminal, wherein the binding request carries user group information and a target sharing community;
acquiring a platform application identifier of the target sharing community;
and binding the user group information and the platform application identifier to generate a corresponding target sharing configuration table.
6. The method of claim 5, further comprising:
acquiring the target sharing configuration table, and acquiring corresponding platform application interface parameters according to the platform application identification;
packaging the platform application interface according to the platform application interface parameters to obtain a packaged platform application interface;
and binding association is carried out according to the community sharing configuration table and the packaged platform application interface, and an interface mapping table is generated.
7. An event monitoring system, the system comprising:
the system comprises a user terminal, a server and a server, wherein the user terminal is used for sending an event request to the application server, and the event request comprises request information and a request type; the request information comprises a user identification;
the application server is used for receiving an event request sent by the user terminal; calling a corresponding service system to process the event request according to the request type; acquiring event processing information of the event request processing process, and sending the event processing information to an event library of a monitored server cluster for storage according to the request information;
the monitored server cluster is used for acquiring event processing information in the application server through a preset monitoring interface and storing the event processing information to an event library according to the request information;
the monitoring server is used for acquiring event processing information stored in an event library in a monitored server cluster, wherein the event processing information comprises a user identifier and an event type; acquiring a preset event analysis model according to the event type, performing traversal analysis on processing node information of the event processing information through a plurality of decision nodes of the event analysis model, respectively calculating multi-dimensional index values corresponding to the event processing information through the plurality of decision nodes, further calculating abnormal index values in the event processing information according to the multi-dimensional index values, and acquiring corresponding analysis results according to the multi-dimensional index values and the abnormal index values, wherein the analysis results comprise a plurality of data index values; when the data index value exceeding a preset threshold exists in the analysis result, determining the data index value exceeding the preset threshold as an abnormal index value, and generating corresponding abnormal information and event record information according to the abnormal index value and the analysis result; acquiring a preset interface mapping table, and acquiring a bound platform application identifier according to the user identifier; and calling a corresponding platform application interface according to the platform application identifier, and pushing the abnormal information and the event record information to a user terminal corresponding to the user identifier through the platform application interface.
8. A computer device comprising a memory and a processor, the memory storing a computer program, wherein the processor when executing the computer program implements the steps of the method of any of claims 1 to 3 or 4 to 6.
9. A computer-readable storage medium, on which a computer program is stored, which, when being executed by a processor, carries out the steps of the method of any one of claims 1 to 3 or 4 to 6.
CN201910604037.8A 2019-07-05 2019-07-05 Event monitoring method, system, computer device and storage medium Active CN110445637B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910604037.8A CN110445637B (en) 2019-07-05 2019-07-05 Event monitoring method, system, computer device and storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910604037.8A CN110445637B (en) 2019-07-05 2019-07-05 Event monitoring method, system, computer device and storage medium

Publications (2)

Publication Number Publication Date
CN110445637A CN110445637A (en) 2019-11-12
CN110445637B true CN110445637B (en) 2022-08-09

Family

ID=68429034

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910604037.8A Active CN110445637B (en) 2019-07-05 2019-07-05 Event monitoring method, system, computer device and storage medium

Country Status (1)

Country Link
CN (1) CN110445637B (en)

Families Citing this family (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111130919B (en) * 2019-11-13 2022-04-26 贵州医渡云技术有限公司 Interface monitoring method, device and system and storage medium
CN111352975B (en) * 2020-03-04 2024-01-30 建信金融科技有限责任公司 Data quality management method, client, server and system
CN111612188B (en) * 2020-04-24 2023-05-23 深圳奇迹智慧网络有限公司 Event analysis method, device, computer equipment and storage medium
CN113656259B (en) * 2020-05-12 2023-09-05 北京市天元网络技术股份有限公司 Event processing center monitoring method and device
CN111737023B (en) * 2020-05-14 2024-04-30 重庆长安汽车股份有限公司 Vehicle-mounted event processing method, cloud server and computer readable storage medium
CN113742664B (en) * 2020-05-29 2024-03-29 钉钉控股(开曼)有限公司 Monitoring and auditing method, equipment and system
CN112291302B (en) * 2020-09-28 2023-04-07 北京京东尚科信息技术有限公司 Internet of things equipment behavior data analysis method and processing system
CN112422502A (en) * 2020-09-29 2021-02-26 苏宁云计算有限公司 Method, device, computer equipment and storage medium for retransmitting data
CN112199256A (en) * 2020-10-16 2021-01-08 济南浪潮数据技术有限公司 Deployment event monitoring method, device and equipment
CN113535518B (en) * 2021-07-23 2023-12-05 北京八分量信息科技有限公司 Distributed real-time dynamic monitoring method and system for user behaviors
CN113780580B (en) * 2021-09-09 2024-04-19 平安银行股份有限公司 Data analysis method, device, equipment and storage medium based on machine learning
CN113821794B (en) * 2021-09-14 2023-08-18 北京八分量信息科技有限公司 Distributed trusted computing system and method
CN113835921A (en) * 2021-09-29 2021-12-24 平安普惠企业管理有限公司 Method, device, equipment and storage medium for processing interface service exception
CN114090644B (en) * 2022-01-20 2022-04-26 飞狐信息技术(天津)有限公司 Data processing method and device
CN115292081B (en) * 2022-08-10 2023-10-20 朴道征信有限公司 Information sending method, device, electronic equipment and medium
CN115712628A (en) * 2023-01-09 2023-02-24 江苏中天科技股份有限公司 Data storage and data sending method, device and equipment based on integrated controller
CN115794444B (en) * 2023-02-02 2023-05-16 广州钛动科技股份有限公司 Event communication method, event communication device, computer equipment and computer readable storage medium
CN117528431A (en) * 2023-10-25 2024-02-06 广州市玄武无线科技股份有限公司 Data monitoring method and device of communication platform and terminal equipment
CN117234859B (en) * 2023-11-14 2024-03-12 苏州元脑智能科技有限公司 Performance event monitoring method, device, equipment and storage medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101068171A (en) * 2007-06-25 2007-11-07 中兴通讯股份有限公司 Speed-measuring resource dynamic distributing method and system for network speed-measuring system
CN104537015A (en) * 2014-12-19 2015-04-22 电信科学技术第十研究所 Log analysis computer implementation method, computer and system
CN108304308A (en) * 2018-02-07 2018-07-20 平安普惠企业管理有限公司 User behavior monitoring method, device, computer equipment and storage medium
CN109688188A (en) * 2018-09-07 2019-04-26 平安科技(深圳)有限公司 Monitoring alarm method, apparatus, equipment and computer readable storage medium

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101068171A (en) * 2007-06-25 2007-11-07 中兴通讯股份有限公司 Speed-measuring resource dynamic distributing method and system for network speed-measuring system
CN104537015A (en) * 2014-12-19 2015-04-22 电信科学技术第十研究所 Log analysis computer implementation method, computer and system
CN108304308A (en) * 2018-02-07 2018-07-20 平安普惠企业管理有限公司 User behavior monitoring method, device, computer equipment and storage medium
CN109688188A (en) * 2018-09-07 2019-04-26 平安科技(深圳)有限公司 Monitoring alarm method, apparatus, equipment and computer readable storage medium

Also Published As

Publication number Publication date
CN110445637A (en) 2019-11-12

Similar Documents

Publication Publication Date Title
CN110445637B (en) Event monitoring method, system, computer device and storage medium
CN109408746B (en) Image information query method, image information query device, computer equipment and storage medium
CN111506498B (en) Automatic generation method and device of test case, computer equipment and storage medium
CN108965381B (en) Nginx-based load balancing implementation method and device, computer equipment and medium
CN110209652B (en) Data table migration method, device, computer equipment and storage medium
CN109474578B (en) Message checking method, device, computer equipment and storage medium
CN111061628B (en) Data analysis method, system, device, computer equipment and storage medium
CN111563368A (en) Report generation method and device, computer equipment and storage medium
CN110008251B (en) Data processing method and device based on time sequence data and computer equipment
CN109543891B (en) Method and apparatus for establishing capacity prediction model, and computer-readable storage medium
CN109885624A (en) Data processing method, device, computer equipment and storage medium
CN108256322B (en) Security testing method and device, computer equipment and storage medium
CN115412371B (en) Big data security protection method and system based on Internet of things and cloud platform
CN109492856B (en) Service request processing method, device, computer equipment and storage medium
CN109218131B (en) Network monitoring method and device, computer equipment and storage medium
CN113672475A (en) Alarm processing method and device, computer equipment and storage medium
CN115952398B (en) Traditional calculation method, system and storage medium based on data of Internet of things
CN110838940B (en) Underground cable inspection task configuration method and device
CN109656707B (en) Metering data acquisition method and device, computer equipment and storage medium
CN114422213B (en) INT-based abnormal flow detection method and device
CN111176930B (en) Component operation data processing method and device, computer equipment and storage medium
CN114428704A (en) Method and device for full-link distributed monitoring, computer equipment and storage medium
CN114629690A (en) Equipment safety baseline compliance detection method and device and computer equipment
CN109508356B (en) Data abnormality early warning method, device, computer equipment and storage medium
CN114928582B (en) Resource combination method, device, equipment and storage medium

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant