CN101577648B - Method for determining root cause of network fault and analytic equipment thereof - Google Patents

Method for determining root cause of network fault and analytic equipment thereof Download PDF

Info

Publication number
CN101577648B
CN101577648B CN200910148650XA CN200910148650A CN101577648B CN 101577648 B CN101577648 B CN 101577648B CN 200910148650X A CN200910148650X A CN 200910148650XA CN 200910148650 A CN200910148650 A CN 200910148650A CN 101577648 B CN101577648 B CN 101577648B
Authority
CN
China
Prior art keywords
alarm
analyzed
root
equipment
record
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN200910148650XA
Other languages
Chinese (zh)
Other versions
CN101577648A (en
Inventor
张学明
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Priority to CN200910148650XA priority Critical patent/CN101577648B/en
Publication of CN101577648A publication Critical patent/CN101577648A/en
Application granted granted Critical
Publication of CN101577648B publication Critical patent/CN101577648B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses a method for determining root cause of a network fault and analytic equipment thereof. The method comprises the following steps: analysis is carried out on received alarming tobe analyzed according to stored root cause of alarming record; if the analytic result of the alarming to be analyzed is the root cause of alarming, the alarming to be analyzed is added into the root cause of alarming record, and presentative alarming of the alarming to be analyzed is deleted from the root cause of alarming record; if the analytic result of the alarming to be analyzed is presentative alarming, the alarming to be analyzed is not added into the root cause of alarming record; root cause of network fault is determined according to the root cause of alarming record. By adopting theinvention, network management equipment can accurately analyze the received alarming, and inhibit a plenty of presentative alarming which is irrelevant to network fault. The root cause of alarming is presented to users so that users can determine the position of network fault easily, which can improve the practicability of alarming system.

Description

The definite method and the analytical equipment of network fault root
Technical field
The present invention relates to networking technology area, relate in particular to a kind of definite method and analytical equipment of network fault root.
Background technology
Along with the fast rise of network size and IT (Information Technology, information technology) traffic carrying capacity, the network equipment reports the also anxious huge rising of alarm quantity of webmaster, can present to a large amount of alarm of webmaster.Therefore be necessary alarm is simplified and compressed, only present alarm crucial, core, so the warning association analysis technology is arisen at the historic moment.By warning association analysis, the user is fault location equipment fast, shortens the cycle of troubleshooting, thereby fundamentally improve the returns of investment ratio of enterprise to network, makes things convenient for the user to carry out every business on network.
Network topology structure has determined to exist between the equipment upstream and downstream annexation; a device fails regular meeting causes a slice equipment alarm; during as upstream equipment generation equipment inaccessible alarm, must cause having only all upstream devices of unique link that the equipment inaccessible alarm also takes place.This moment, the inaccessible alarm of upstream equipment was a Root alarm, and the inaccessible alarm of upstream device is the presentation alarm of above-mentioned alarm.The Root alarm here is meant the alarm that causes other alarms, is the root of other alarms.And the presentation alarm is meant because the alarm that other alarms cause is the presentation of Root alarm.When the location has solved Root alarm, the alarm of the presentation of Root alarm correspondence also will be solved simultaneously.
With networking scene shown in Figure 1 is example, and Network Management Equipment is by the equipment 1 as access device, and visit visits again equipment 4, equipment 5, equipment 6, equipment 7, equipment 9 and equipment 10 in the subnet as equipment 2, equipment 3, the equipment 8 of nucleus equipment.The access device here refer to connect Network Management Equipment and managed networks, from Network Management Equipment nearest router or switch, Network Management Equipment can't not visited managed networks when having access device.Access device is also managed by Network Management Equipment.And nucleus equipment is meant the gateway device of each subnet in the network, and other equipment in the network are by each equipment in this nucleus equipment access subnetwork.
In the existing regional warning association analysis method, the equipment of equipment inaccessible alarm is taken place in all, pool a zone according to the topological link relation, identify the equipment that is positioned at edges of regions, promptly have the equipment be connected with the equipment that the equipment inaccessible alarm does not take place, the equipment inaccessible alarm of equipment that will be positioned at edges of regions is as Root alarm.
In the network of Fig. 1, if the equipment inaccessible alarm takes place in equipment 8, equipment 9, equipment 10, can identify equipment 8 for being positioned at the equipment of edges of regions according to regional warning association analysis algorithm, judgment device 8 corresponding equipment inaccessible alarms are Root alarm thus, and equipment 9, equipment 10 corresponding equipment inaccessible alarms are the presentation alarm of equipment 8 corresponding equipment inaccessible alarms.
In the existing regional warning association analysis method,, two situations that are positioned at the equipment at edge can not identify Root alarm to being arranged in the zone.Be example still with network scenarios shown in Figure 1, equipment 6 is connected to two upstream equipments: equipment 2 and equipment 3, when the equipment inaccessible alarm takes place for equipment 2, equipment 3 and equipment 6, can't judgment device 2 corresponding equipment inaccessible alarms be that Root alarm or equipment 3 corresponding equipment inaccessible alarms are Root alarm.Therefore in network, when an equipment that is arranged in backup link was connected to two upstream equipments, existing regional warning association analysis method can't be carried out the accurate location of Root alarm.
Summary of the invention
The invention provides a kind of definite method and analytical equipment of network fault root, be used for the alarm that network takes place is accurately located.
The invention provides a kind of definite method of network fault root, comprising:
According to the Root alarm record of having stored, the alarm to be analyzed that receives is analyzed;
When the analysis result of described alarm to be analyzed is Root alarm, described alarm to be analyzed is added described Root alarm record, and the presentation alarm of alarm to be analyzed described in the described Root alarm record is deleted; When the analysis result of described alarm to be analyzed is the presentation alarm, described alarm to be analyzed is not added described Root alarm record;
Determine network fault root according to described Root alarm record.
Wherein, the described alarm to be analyzed that receives is analyzed comprises:
Whenever receive an alarm to be analyzed, promptly the described alarm to be analyzed that receives is analyzed; Or
Buffer memory is carried out in the alarm to be analyzed that receives, and regularly trigger analysis the alarm to be analyzed of buffer memory; Described the alarm to be analyzed that receives is analyzed after, the alarm to be analyzed after analyzing is deleted from described buffer memory.
Wherein, the alarm to be analyzed that receives is analyzed, being comprised:
According to the object identity OID of described alarm to be analyzed, judge the type of described alarm to be analyzed;
When the type of described alarm to be analyzed is Root alarm, in the described Root alarm record of having stored, search the presentation alarm of described alarm to be analyzed;
When the type of described alarm to be analyzed is the presentation alarm, in the described Root alarm record of having stored, search the Root alarm of described alarm to be analyzed.
Wherein, when the type of described alarm to be analyzed is Root alarm, in the described Root alarm record of having stored, search the presentation alarm of described alarm to be analyzed, comprising:
A1, described alarm to be analyzed is added the Root alarm record;
A2, obtain the YITIAOGEN source alarm of not analyzing in the described Root alarm record, judge whether described Root alarm is the presentation alarm of described alarm to be analyzed; Then search end when not having the Root alarm of not analyzing; If not then repeating this steps A 2, otherwise carry out steps A 3;
A3, judge whether described Root alarm corresponding equipment is the upstream device of described alarm corresponding equipment to be analyzed; If not then carrying out steps A 2; If then carry out steps A 4;
Whether A4, judgement exist without the physical link of described alarm corresponding equipment to be analyzed between Network Management Equipment and described Root alarm corresponding equipment; If there is no then carry out steps A 5, otherwise carry out steps A 6;
A5, the described Root alarm of judgement are the presentation alarm of described alarm to be analyzed, and the described Root alarm of deletion in described Root alarm record carries out steps A 2;
A6, judge whether each upstream equipment of alarm corresponding equipment to be analyzed described in the described physical link all receives described alarm to be analyzed, if not then returning steps A 2; Otherwise carry out steps A 5.
Wherein, when the type of described alarm to be analyzed is the presentation alarm, in the described Root alarm record of having stored, search the Root alarm of described alarm to be analyzed, comprising:
B1, obtain the YITIAOGEN source alarm of not analyzing in the described Root alarm record, judge whether described Root alarm is the Root alarm of described alarm to be analyzed; Then described alarm to be analyzed is not added described Root alarm record as Root alarm when not having the Root alarm of not analyzing; If not then repeating this step B1, otherwise carry out step B2;
B2, judge whether described Root alarm corresponding equipment is the upstream equipment of described alarm corresponding equipment to be analyzed; If not then carrying out step B1; If then carry out step B3;
Whether B3, judgement exist without the physical link of described Root alarm corresponding equipment between Network Management Equipment and described alarm corresponding equipment to be analyzed; If there is no then carry out step B5, otherwise carry out step B4;
B4, judge whether each upstream equipment of alarm corresponding equipment to be analyzed described in the described physical link all receives described alarm to be analyzed, if not then returning step B1; Otherwise carry out step B5.
The presentation alarm that B5, the described alarm to be analyzed of judgement are described Root alarm.
Wherein, also comprise: set up the set of physical link annexation, per unit upstream equipment and upstream device in the record network, and the physical link information of equipment room, judge according to described physical link annexation set:
Whether described Root alarm corresponding equipment is the upstream equipment of described alarm corresponding equipment to be analyzed;
Whether described Root alarm corresponding equipment is the upstream device of described alarm corresponding equipment to be analyzed;
Between Network Management Equipment and described alarm corresponding equipment to be analyzed, whether exist without the physical link of described Root alarm corresponding equipment;
Between Network Management Equipment and described Root alarm corresponding equipment, whether exist without the physical link of described alarm corresponding equipment to be analyzed.
Wherein, also comprise: the association analysis standard is set, comprises the relation between the OID of the OID of Root alarm and presentation alarm in the described association analysis standard; Judge according to described association analysis standard:
Whether described Root alarm is the Root alarm or the presentation alarm of described alarm to be analyzed.
The present invention also provides a kind of analytical equipment of network fault root, comprising:
The alarm receiving element is used to receive alarm to be analyzed;
The Root alarm record cell is used to preserve the Root alarm record;
Analytic unit, be used for Root alarm record according to described Root alarm record cell, the alarm to be analyzed that described alarm receiving element receives is analyzed, and upgrade Root alarm record in the described Root alarm record cell: when the analysis result of described alarm to be analyzed is Root alarm according to analysis result, described alarm to be analyzed is added described Root alarm record, and the presentation alarm of alarm to be analyzed described in the described Root alarm record is deleted; When the analysis result of described alarm to be analyzed is the presentation alarm, described alarm to be analyzed is not added described Root alarm record;
Failure location unit is used for determining network fault root according to the Root alarm record after upgrading after described analytic unit upgrades the Root alarm of described Root alarm record cell record.
Wherein, described alarm receiving element specifically is used for:
Whenever receive an alarm to be analyzed, promptly trigger described analytic unit the described alarm to be analyzed that receives is analyzed; Or
Buffer memory is carried out in the alarm to be analyzed that receives, and regularly trigger of the analysis of described analytic unit the alarm to be analyzed of buffer memory; After described analytic unit is analyzed alarm to be analyzed, the alarm to be analyzed after analyzing is deleted from described buffer memory.
Wherein, described analytic unit comprises:
The type judgment sub-unit is used for the object identity OID according to described alarm to be analyzed, judges the type of described alarm to be analyzed;
Root alarm is analyzed subelement, be used for when the type of described alarm to be analyzed is Root alarm, described alarm to be analyzed is added described Root alarm record, in the Root alarm record in described Root alarm record cell, search the presentation alarm of described alarm to be analyzed;
Presentation alert analysis subelement is used in the Root alarm record in described Root alarm record cell, searching the Root alarm of described alarm to be analyzed when the type of described alarm to be analyzed is the presentation alarm;
Upgrade subelement, be used for that described Root alarm is analyzed subelement and alarm, deletion from the Root alarm record of described Root alarm record cell in the presentation that Root alarm writes down the described alarm to be analyzed that finds.
Wherein, described Root alarm analysis subelement specifically is used for carrying out:
A1, described alarm to be analyzed is added the Root alarm record;
A2, obtain the YITIAOGEN source alarm of not analyzing in the described Root alarm record, judge whether described Root alarm is the presentation alarm of described alarm to be analyzed; Then search end when not having the Root alarm of not analyzing; If not then repeating this steps A 2, otherwise carry out steps A 3;
A3, judge whether described Root alarm corresponding equipment is the upstream device of described alarm corresponding equipment to be analyzed; If not then carrying out steps A 2; If then carry out steps A 4;
Whether A4, judgement exist without the physical link of described alarm corresponding equipment to be analyzed between Network Management Equipment and described Root alarm corresponding equipment; If there is no then carry out steps A 5, otherwise carry out steps A 6;
A5, the described Root alarm of judgement are the presentation alarm of described alarm to be analyzed, and the described Root alarm of deletion in described Root alarm record carries out steps A 2;
A6, judge whether each upstream equipment of alarm corresponding equipment to be analyzed described in the described physical link all receives described alarm to be analyzed, if not then returning steps A 2; Otherwise carry out steps A 5.
Wherein, described presentation alert analysis subelement specifically is used for carrying out:
B1, obtain the YITIAOGEN source alarm of not analyzing in the described Root alarm record, judge whether described Root alarm is the Root alarm of described alarm to be analyzed; Then described alarm to be analyzed is not added described Root alarm record as Root alarm when not having the Root alarm of not analyzing; If not then repeating this step B1, otherwise carry out step B2;
B2, judge whether described Root alarm corresponding equipment is the upstream equipment of described alarm corresponding equipment to be analyzed; If not then carrying out step B1; If then carry out step B3;
Whether B3, judgement exist without the physical link of described Root alarm corresponding equipment between Network Management Equipment and described alarm corresponding equipment to be analyzed; If there is no then carry out step B5, otherwise carry out step B4;
B4, judge whether each upstream equipment of alarm corresponding equipment to be analyzed described in the described physical link all receives described alarm to be analyzed, if not then returning step B1; Otherwise carry out step B5.
The presentation alarm that B5, the described alarm to be analyzed of judgement are described Root alarm.
Wherein, also comprise: physical link annexation memory cell, be used to set up the set of physical link annexation, per unit upstream equipment and upstream device in the record network, and the physical link information of equipment room, described physical link annexation set is offered described analytic unit is used for judging:
Whether described Root alarm corresponding equipment is the upstream equipment of described alarm corresponding equipment to be analyzed;
Whether described Root alarm corresponding equipment is the upstream device of described alarm corresponding equipment to be analyzed;
Between Network Management Equipment and described alarm corresponding equipment to be analyzed, whether exist without the physical link of described Root alarm corresponding equipment;
Between Network Management Equipment and described Root alarm corresponding equipment, whether exist without the physical link of described alarm corresponding equipment to be analyzed.
Wherein, also comprise: the association analysis standard memory location, be used to be provided with the association analysis standard, comprise the relation between the OID of the OID of Root alarm and presentation alarm in the described association analysis standard; Described association analysis standard is offered described analytic unit to be used for judging:
Whether described Root alarm is the Root alarm or the presentation alarm of described alarm to be analyzed.
Compared with prior art, the present invention has the following advantages:
The application of the invention, Network Management Equipment can be analyzed the alarm that receives accurately, has suppressed the numerous presentation alarms irrelevant with network failure, and Root alarm is presented to the user, make things convenient for the quick locating network fault of user, improved the practicality of warning system.
Description of drawings
Fig. 1 is the networking scene schematic diagram that regional warning association analysis method is used in the prior art;
Fig. 2 is the flow chart that the network fault root that provides among the present invention is determined method;
Fig. 3 is the flow chart that network fault root is determined method in the application scenarios of the present invention;
Fig. 4 A be in the application scenarios of the present invention when alarm 1 when being Root alarm, the flow chart of all presentation alarms of alarm 1 correspondence is searched in tabulation according to Root alarm;
Fig. 4 B is that the flow chart of the Root alarm of alarm 1 correspondence was searched in tabulation according to Root alarm when alarm 1 was the presentation alarm in the application scenarios of the present invention;
Fig. 5 is the structural representation of the analytical equipment that provides among the present invention;
Fig. 6 is the structural representation of analytic unit in the analytical equipment that provides among the present invention.
Embodiment
Below in conjunction with the accompanying drawing in the embodiment of the invention, the technical scheme in the embodiment of the invention is clearly and completely described.
As shown in Figure 2, the invention provides a kind of definite method of network fault root, comprising:
The Root alarm record that step s201, basis have been stored is analyzed the alarm to be analyzed that receives;
When the analysis result of step s202, alarm to be analyzed is Root alarm, should alarm to be analyzed add the Root alarm record, and the presentation alarm of this alarm to be analyzed in the Root alarm record was deleted; When the analysis result of alarm to be analyzed is the presentation alarm, should alarm to be analyzed not add the Root alarm record;
Step s203, determine network fault root according to Root alarm record.And, can position network failure according to the Root alarm that writes down in the Root alarm record.
Below in conjunction with concrete application scenarios, network fault root among the present invention is determined the execution mode of method is elaborated.
In the application scenarios of the present invention,, must determine earlier that the topology between the equipment connects the upstream and downstream relation in order to analyze the alarm of Root alarm and presentation.Its reason is, is example with the equipment inaccessible alarm, and when poll, the obstructed equipment of Network Management Equipment ping is then judged the equipment inaccessible alarm has been taken place; When poll, the success of webmaster pinged device thinks that then equipment state is normal.For the equipment inaccessible alarm, have only the upstream and downstream topological connection relation of middle equipment Network Based correct analysis to go out Root alarm and presentation alarm.For example other the alarm relevant again with topology, the too high alarm of interface packets packet loss, upstream device visit outer net as upstream equipment postpone alarm, need identify upstream equipment and upstream device, and then the too high alarm of interface packets packet loss that could determine upstream equipment is Root alarm, and upstream device visit outer net postpones alarm to be alarmed for presentation.
Among the present invention, topology connects the upstream and downstream relation concrete determine method can for: according to parameters such as the IP address of each equipment in the network that gets access to, MAC Address, Network Management Equipment can the topology that method finds the equipment in the network automatically and calculate equipment in the network such as be looked into and connects the upstream and downstream relation by routing table is counter, when the access device that calculates automatically (equipment 1 in the network environment for example shown in Figure 1) was not in the residing management system of Network Management Equipment, the keeper need add access device the system by the Network Management Equipment management.For nucleus equipment is the gateway device (equipment 2 in the network environment for example shown in Figure 1, equipment 3 and equipment 8) of each subnet in the map network, possibly can't obtain because the complexity of network is different, need directly specify at Network Management Equipment by the user by calculating directly.Above topology connects the concrete of upstream and downstream relation and determines that method is a kind of optional mode, for example also can adopt the keeper directly to specify topology to connect the mode of upstream and downstream relation, and the present invention does not limit this.
After above-mentioned flow process finished, Network Management Equipment was for each equipment in the network, need this equipment of record based on two etale topologies, with respect to all physical link annexations set of nucleus equipment and access device, be designated as DevLinkMap.Record per unit upstream equipment, upstream device information among this DevLinkMap.Equipment in network increases or deletion, when physical link increase or deletion, all needs to safeguard simultaneously above-mentioned physical link annexation set DevLinkMap.
One example of the structure of this physical link annexation set DevLinkMap is as shown in table 1,
The structure of table 1. physical link annexation set DevLinkMap
Sequence number Device id MAC Upstream equipment ID Upstream device ID
1 Equipment 1 MAC1 Equipment S Equipment 2; Equipment 3; Equipment 8
2 Equipment 2 MAC2 Equipment 1 Equipment 4; Equipment 5; Equipment 6
3 Equipment 3 MAC3 Equipment 1 Equipment 6; Equipment 7
4 Equipment 4 MAC4 Equipment 2 --
5 Equipment 5 MAC5 Equipment 2 --
6 Equipment 6 MAC6 Equipment 2; Equipment 3 --
7 Equipment 7 MAC7 Equipment 3 --
8 Equipment 8 MAC8 Equipment 1 --
9 Equipment 9 MAC9 Equipment 8 --
10 Equipment 10 MAC10 Equipment 8 --
By this DevLinkMap, can know the link information of per unit upstream equipment, upstream device and equipment room.For example, for equipment 2, can know that its upstream equipment is an equipment 1, its upstream device is equipment 4, equipment 5 and equipment 6.Be to have physical link between equipment 2 and the equipment 1, also have physical link between equipment 2 and equipment 4, equipment 5 and the equipment 6 respectively.Simultaneously, by this DevLinkMap, can be informed in two physical links of existence between equipment 1 and the equipment 6, i.e. equipment 1-equipment 2-equipment 6, and equipment 1-equipment 3-equipment 6.
When Network Management Equipment detects the alarm generation, need OID (Object ID according to the alarm that receives, object identifier), obtain warning content (inaccessible alarm, CPU average load surpass threshold alarm etc.), alarm type (Root alarm and presentation alarm) and this alarm and the relation (Root alarm that has write down is that the Root alarm that the presentation of this alarm is alarmed or write down is the Root alarm of this alarm) of the Root alarm that write down.
With topological class alarm is example, and warning content and corresponding OID thereof that topological class alarm comprises comprise following several:
(1.3.6.1.4.1.2011.10.4.1.1.2.6.1 expression OID, below similar), equipment inaccessible alarm (expression warning content, below similar);
1.3.6.1.4.1.2011.10.2.35.1.6.15 the CPU average load surpasses threshold alarm;
1.3.6.1.4.1.2011.10.9.1.2.6.8 cpu busy percentage surpasses the threshold value alarm;
1.3.6.1.4.1.2011.10.9.1.2.6.9 memory usage surpasses the threshold value alarm
For above-mentioned four kinds of alarms, its alarm type be Root alarm also be presentation alarm.
In addition,, need to store some association analysis rules on the Network Management Equipment for the alarm that newly receives and the relation of the Root alarm that has write down are analyzed, this regular form can for:
(OID1,OID2)、(OID3,OID4),....(OIDM,OIDN)。
For (OIDM, OIDN), expression OID is that the alarm of OIDM is the presentation alarm of the alarm of OIDN for OID, OID is that the alarm of OIDN is the Root alarm of the alarm of OIDM for OID.
When newly receiving alarm, after the OID combination of the OID of the alarm that Network Management Equipment will newly receive and the Root alarm that has write down, mate with the alarm association rule of having stored, can think then when the match is successful that the Root alarm of record is that the presentation alarm of this alarm or the Root alarm that has write down are the Root alarm of this alarm.For example, the OID that newly receives alarm is OID1, the OID of the YITIAOGEN source alarm of having write down is OID2, owing to have (OID1 in the association analysis rule, OID2), therefore can think that OID is that the alarm of OID1 is the presentation alarm of the alarm of OID2 for OID, OID is that the alarm of OID2 is the Root alarm of the alarm of OID1 for OID.
Above-mentioned association analysis rule is a kind of optional form, in concrete application complicated more association analysis rule can be set as required on the basis of above-mentioned association analysis rule.
In addition, Network Management Equipment is provided with the Root alarm tabulation that is used to store Root alarm among the present invention, is designated as RootTrapList, is used to store the Root alarm in some and the certain hour window.When the quantity of the Root alarm of storing among the RootTrapList surpasses default amount threshold, abandon time Root alarm the earliest according to time sequencing; In addition, when the time of the Root alarm of storing among the RootTrapList surpasses the time window that sets in advance, abandon this Root alarm; At last, when Network Management Equipment confirms that the fault of certain Root alarm correspondence has been got rid of, abandon this Root alarm.When the Network Management Equipment initialization, content among the Root alarm tabulation RootTrapList is empty, this moment is if judge alarming for presentation of receiving according to OID, then, also the presentation alarm that receives is stored among the Root alarm tabulation RootTrapList as Root alarm owing to do not have Root alarm to exist as yet among the Root alarm tabulation RootTrapList.
Record among the Root alarm tabulation RootTrapList Root alarm ID, OID and with the device id of this Root alarm corresponding equipment, an example of the structure of this Root alarm tabulation RootTrapList is as shown in table 2,
The structure of table 2. Root alarm tabulation RootTrapList
Sequence number Root alarm ID OID Device id
1 Alarm 1 OID1 Equipment 1
2 Alarm 2 OID2 Equipment 3
...... ...... ...... ......
n Alarm n OIDn Equipment M
Among the present invention, being applied to Network Management Equipment with definite method of network fault root is example, and each bar alarm that Network Management Equipment will receive is buffered in the formation, and this formation is the alarm buffer queue of pending analysis.Network Management Equipment can detect the alarm buffer queue in real time, when whenever receiving an alarm in the alarm buffer queue, just the alarm that receives is analyzed, and the alarm that will analyze is deleted from the alarm buffer queue.In order to improve treatment effeciency, Network Management Equipment also can regularly detect the alarm buffer queue, disposable alarm all alarms in the buffer queue are analyzed, order during analysis can be according to the time of reception of each alarm, alarm type etc., and alarm is by analysis deleted from the alarm buffer queue.Suppose that alarm article one in the buffer queue alarms alarm to be analyzed for alarm 1, from equipment 1, then Network Management Equipment flow process that the alarm in the alarm buffer queue is analyzed may further comprise the steps as shown in Figure 3:
Step s301, obtain alarm to be analyzed, suppose that this alarm is alarm 1.
Step s302, judge that according to alarm 1 OID alarm 1 is presentation alarm or Root alarm, carry out step s303 when being Root alarm, carry out step s304 when being the presentation alarm.
Step s303, alarm 1 are when being Root alarm, to alarm 1 and add Root alarm tabulation RootTrapList, simultaneously according to Root alarm tabulation RootTrapList, search all presentation alarms of alarm 1 correspondence, and the Root alarm that will find in the Root alarm tabulation is deleted commentaries on classics step s305 from Root alarm tabulation RootTrapList.
When step s304, alarm 1 are the presentation alarm, obtain Root alarm tabulation RootTrapList, search the Root alarm of alarm 1 correspondence, search the end back and change step s305.
Need to prove, if the OID according to alarm 1 judges that alarm 1 both had been the presentation alarm, be again Root alarm (i.e. this alarm both can also can be the Root alarm of its upstream device for the presentation alarm of its upstream equipment), then can carry out the presentation alarm that step s303 handles alarm 1 correspondence earlier; Carry out step s304 then and handle the Root alarm of alarming 1 correspondence.Certainly, also can carry out the Root alarm that step s304 handles alarm 1 correspondence earlier; Carry out the presentation alarm that step s303 handles alarm 1 correspondence then.The present invention does not limit the analysis sequence of Root alarm and presentation alarm.
Step s305 judges whether that all alarms to be analyzed all finish by analysis, is then to carry out flow process to finish, otherwise carries out step s301.
Below the handling process of " alarm 1 is when being Root alarm; according to Root alarm tabulation RootTrapList; search all presentation alarms of alarm 1 correspondence, and the Root alarm that will find in the Root alarm tabulation is deleted from Root alarm tabulation RootTrapList " that relate among the step s303 is described in detail.Shown in Fig. 4 A, may further comprise the steps:
Step s3031, obtain Root alarm tabulation RootTrapList.
Step s3032, judge whether there is the Root alarm record of not analyzing among the Root alarm tabulation RootTrapList, be then to carry out step s3033, otherwise flow process finishes.
Step s3033, obtain among the RootTrapList Root alarm record do not analyzed as the OID of alarm 2,, judge whether alarm 2 is the presentation alarm of alarm 1 according to the association analysis rule; If not then returning step s3032, if then carry out step s3034.
Whether step s3034, judgement alarm 2 corresponding equipment 2 are the upstream device of equipment 1; If not upstream device, then explanation alarm 2 is not the presentation alarm of alarm 1, returns step s3032.If upstream device then changes step s3035.In this step, can be according to the record among the physical link annexation set DevLinkMap, whether be that the upstream device of equipment 1 is judged to equipment 2.
Step s3035, according to physical link annexation set DevLinkMap, judge at Network Management Equipment and alarm between 2 corresponding equipment 2 whether exist without the physical link of equipment 1; If there is no, then explanation alarm 2 is carried out step s3036 for the presentation alarm of alarm 1; If exist, carry out step s3037.
Step s3036, alarm 2 are the presentation alarm of alarm 1, deletion alarm 2 in RootTrapList, and the while Network Management Equipment writes down alarm 2 in the alarm database of record of this locality Root alarm is alarm 1.Return step s3032.
Whether step s3037, each upstream equipment of judging equipment 1 in this physical link all receive alarm 1, if exist a certain upstream equipment of equipment 1 not receive alarm 1, then explanation alarm 2 is not the presentation alarm of alarm 1, returns step s3032.If all upstream equipments of equipment 1 have all received alarm 1, then explanation alarm 2 is carried out step s3036 for the presentation alarm of alarm 1.
After carrying out above-mentioned steps s3031~s3037, after all Root alarm records among the Root alarm tabulation RootTrapList have all been carried out analyzing, still do not find the presentation alarm of alarm 1, the presentation alarm that does not have alarm 1 in RootTrapList then is described.
Below the handling process of " alarm 1 is presentation when alarm, according to Root alarm tabulation RootTrapList, searches the Root alarm of alarm 1 correspondence " that relate among the step s304 is described in detail.Shown in Fig. 4 B, may further comprise the steps:
Step s3041, obtain Root alarm tabulation RootTrapList.
Step s3042, judge whether there is the Root alarm record of not analyzing among the Root alarm tabulation RootTrapList, be then to carry out step s3043, otherwise carry out step s3048.
Step s3043, according to the Root alarm record of not analyzing among the RootTrapList as the OID of alarm 2,, according to the association analysis rule, judge whether alarm 2 is the Root alarm of alarm 1; If not then returning step s3042.If then carry out step s3044.
Whether step s3044, judgement alarm 2 corresponding equipment 2 are the upstream equipment of equipment 1, if not upstream equipment, then return step s3042.If upstream equipment then carries out step s3045.In this step, can be according to the record among the physical link annexation set DevLinkMap, whether be that the upstream equipment of equipment 1 is judged to equipment 2.
Step s3045, according to physical link annexation set DevLinkMap, judge the physical link that between Network Management Equipment and equipment 1, whether exists without alarm 2 corresponding equipment 2.If there is no, then explanation alarm 2 Root alarm for alarm 1 carry out step s3047; If there is backup link, carry out step s3046.
Whether step s3046, each upstream equipment of judging equipment 1 in this physical link all receive alarm 1, if exist a certain upstream equipment of equipment 1 not receive alarm 1, then explanation alarm 2 is returned step s3042 for the Root alarm of alarm 1.If then explanation alarm 2 Root alarm for alarm 1 carry out step s3047.
Step s3047, record alarm 2 Root alarm for alarm 1 in the alarm database of record of Network Management Equipment this locality record finish alarming 1 analysis process.
Step s3048, all Root alarm records among the Root alarm tabulation RootTrapList have all been carried out analyzing after, still do not find the Root alarm of alarm 1, therefore will alarm 1 as Root alarm adding RootTrapList.
Below in conjunction with network configuration shown in Figure 1, the embodiment that network fault root provided by the invention under the different application scenarioss is determined method is described.
(scene 1) Network Management Equipment is analyzed the inaccessible alarm 1 about equipment of equipment 4 at moment T1.
For the equipment inaccessible alarm, its Root alarm is identical with the OID of presentation alarm.Therefore can judge that according to OID alarm 1 both for the presentation alarm, is again a Root alarm.According to flow process shown in Figure 3 and description thereof, can carry out step s303 earlier, handle the presentation alarm of alarm 1 correspondence, carry out step s304 then, handle the Root alarm of alarm 1 correspondence.Owing to exist without any the alarm record among the Root alarm tabulation this moment RootTrapList, therefore do not have the presentation alarm of alarm 1.Then to alarm 1 analyze after, will alarm 1 and add among the Root alarm tabulation RootTrapList as Root alarm.
(scene 2) Network Management Equipment is analyzed the inaccessible alarm 2 about equipment of equipment 2 at moment T2.
For the equipment inaccessible alarm, its Root alarm is identical with the OID of presentation alarm.Therefore can judge that according to OID alarm 2 both for the presentation alarm, is again a Root alarm.Only have alarm 1 among the Root alarm tabulation this moment RootTrapList, alarming 1 corresponding equipment is equipment 4.
According to network configuration shown in Figure 1, equipment 4 is the upstream device of equipment 2.According to flow process and the description thereof shown in Fig. 3 and Fig. 4 A, at first judge the presentation alarm (step s3033) of alarm 1 for alarm 2, and then judge that alarm 1 corresponding equipment 4 is for alarming the upstream device (step s3034) of 2 corresponding equipment 2, and then judge the physical link (step s3035) that does not exist between gateway device and the equipment 4 without equipment 2, therefore judge the presentation alarm of alarm 1, from Root alarm tabulation RootTrapList deletion alarm 1 (step s3036) for alarm 2.Only there is alarm 2 among the Root alarm tabulation this moment RootTrapList.
(scene 3) Network Management Equipment is analyzed the inaccessible alarm 3 about equipment of equipment 6 at moment T3.
For the equipment inaccessible alarm, its Root alarm is identical with the OID of presentation alarm.Therefore can judge that according to OID alarm 2 both for the presentation alarm, is again a Root alarm.Only have alarm 2 among the Root alarm tabulation this moment RootTrapList, alarming 2 corresponding equipment is equipment 2.
According to network configuration shown in Figure 1, equipment 6 is the upstream device of equipment 2, has two physical links between equipment 6 and the Network Management Equipment, is respectively link 1: equipment 6-equipment 2-equipment 1-Network Management Equipment, and link 2: equipment 6-equipment 3-equipment 1-Network Management Equipment, link 2 is without equipment 2.
According to flow process and the description thereof shown in Fig. 3 and Fig. 4 B, at first judge the Root alarm (step s3043) of alarm 2 for alarm 3, and then judge that alarm 2 corresponding equipment 2 are for alarming the upstream equipment (step s3044) of 3 corresponding equipment 6, and then judge that existence is without the physical link (step s3045) of equipment 2 between Network Management Equipment and equipment 6, and then the equipment in the judgement link 3 do not receive alarm 3 (step s3047), and then judges that alarm 3 is not the presentation alarm (step s3046) of alarm 2.Therefore, will alarm 3 joins among the Root alarm tabulation RootTrapList as Root alarm.Root alarm tabulation this moment RootTrapList exists alarm 2 and alarm 3, and alarming 2 corresponding equipment is equipment 2, and alarming 3 corresponding equipment is equipment 6.
(scene 4) Network Management Equipment is analyzed the inaccessible alarm 4 about equipment of equipment 3 at moment T4.
For the equipment inaccessible alarm, its Root alarm is identical with the OID of presentation alarm.Therefore can judge that according to OID alarm 2 both for the presentation alarm, is again a Root alarm.Root alarm tabulation this moment RootTrapList exists alarm 2 and alarm 3, and alarming 2 corresponding equipment is equipment 2, and alarming 3 corresponding equipment is equipment 6.
According to network configuration shown in Figure 1, equipment 6 is the upstream device of equipment 3 and equipment 2.According to flow process and the description thereof shown in Fig. 3 and Fig. 4 A, at first judge the presentation alarm (step s3033) of alarm 3 for alarm 4, and then judge that alarm 3 corresponding equipment 6 are for alarming the upstream device (step s3034) of 4 corresponding equipment 3, and then judge that existence is without the physical link (step s3035) of equipment 3 between gateway device and the equipment 6, and then all upstream equipments of judging this equipment 3 all receive alarm 4 (step s3037), therefore judge the presentation alarm of alarm 3, from Root alarm tabulation RootTrapList deletion alarm 3 (step s3036) for alarm 4.Root alarm tabulation this moment RootTrapList exists alarm 2 and alarm 4, and alarming 2 corresponding equipment is equipment 2, and alarming 4 corresponding equipment is equipment 3.
(scene 5) Network Management Equipment is analyzed the inaccessible alarm 5 about equipment of equipment 1 at moment T5.
For the equipment inaccessible alarm, its Root alarm is identical with the OID of presentation alarm.Therefore can judge that according to OID alarm 5 both for the presentation alarm, is again a Root alarm.Root alarm tabulation this moment RootTrapList exists alarm 2 and alarm 4, and alarming 2 corresponding equipment is equipment 2, and alarming 4 corresponding equipment is equipment 3.
According to network configuration shown in Figure 1, equipment 1 is the upstream equipment of equipment 2 and equipment 3.According to flow process and the description thereof shown in Fig. 3 and Fig. 4 A, for alarm 2, at first judge the presentation alarm (step s30333) of alarm 2 for alarm 5, and then judge that alarm 2 corresponding equipment 2 are for alarming the upstream device (step s3034) of 5 corresponding equipment 1, and then judge the physical link (step s3035) that does not exist between gateway device and the equipment 2 without equipment 1, therefore judge the presentation alarm of alarm 2, from Root alarm tabulation RootTrapList deletion alarm 2 (step s3036) for alarm 5.There are alarm 4 and alarm 5 among the Root alarm tabulation this moment RootTrapList.
For alarm 4, at first judge the presentation alarm (step s3033) of alarm 4 for alarm 5, and then judge that alarm 4 corresponding equipment 3 are for alarming the upstream device (step s3034) of 5 corresponding equipment 1, and then judge the physical link (step s3035) that does not exist between gateway device and the equipment 3 without equipment 1, therefore judge the presentation alarm of alarm 4, from Root alarm tabulation RootTrapList deletion alarm 4 (step s3036) for alarm 5.Only there is alarm 5 among the Root alarm tabulation this moment RootTrapList.
Can find by above-mentioned application scenarios, use method provided by the invention, Network Management Equipment can be analyzed the alarm that receives accurately, judge that it is Root alarm or the alarm of the presentation of other Root alarm that existed, the numerous presentation alarms irrelevant have been suppressed with network failure, Root alarm is presented to the user, make things convenient for the quick locating network fault of user, improved the practicality of warning system.
The present invention also provides a kind of analytical equipment of network fault root, and this analytical equipment can be the Network Management Equipment in the network, and the structure of this equipment comprises as shown in Figure 5:
Alarm receiving element 10 is used to receive alarm to be analyzed, and alarm to be analyzed is sent to analytic unit 30.Concrete, can whenever receive an alarm to be analyzed, promptly trigger the alarm to be analyzed that 30 pairs of described analytic units receive and analyze; Perhaps buffer memory is carried out in the alarm to be analyzed that receives, and regularly trigger the analysis of the alarm to be analyzed of 30 pairs of buffer memorys of analytic unit; After 30 pairs of alarms to be analyzed of analytic unit are analyzed, the alarm to be analyzed after analyzing is deleted from buffer memory.
Root alarm record cell 20 is used to preserve the Root alarm record.
Analytic unit 30, be used for Root alarm record according to Root alarm record cell 20, the alarm to be analyzed that receives is analyzed, and upgrade Root alarm record in the Root alarm record cell 20: when the analysis result of alarm to be analyzed is Root alarm according to analysis result, alarm to be analyzed is added the Root alarm record, and the presentation alarm of alarm to be analyzed in the Root alarm record of Root alarm record cell 20 preservations is deleted; When the analysis result of alarm to be analyzed is the presentation alarm, alarm to be analyzed is not added described Root alarm record.
Failure location unit 40 is used for determining network fault root according to the Root alarm record after the Root alarm record of 30 pairs of Root alarm record cells 20 of analytic unit upgrades.
This analytical equipment also comprises:
Physical link annexation memory cell 50, be used to set up the set of physical link annexation, per unit upstream equipment and upstream device in the record network, and the physical link information of equipment room offer analytic unit 30 with the set of physical link annexation and are used for judging:
Whether the Root alarm corresponding equipment is the upstream equipment of alarm corresponding equipment to be analyzed;
Whether the Root alarm corresponding equipment is the upstream device of alarm corresponding equipment to be analyzed;
Between Network Management Equipment and alarm corresponding equipment to be analyzed, whether exist without the physical link of Root alarm corresponding equipment;
Between Network Management Equipment and Root alarm corresponding equipment, whether exist without the physical link of alarm corresponding equipment to be analyzed.
Association analysis standard memory location 60 is used to be provided with the association analysis standard, comprises the relation between the OID of the OID of Root alarm and presentation alarm in the association analysis standard; The association analysis standard is offered analytic unit 30 to be used for judging:
Whether Root alarm is the Root alarm or the presentation alarm of alarm to be analyzed.
In the analytical equipment provided by the invention, as shown in Figure 6, this analytic unit 30 specifically comprises: type judgment sub-unit 31, Root alarm are analyzed subelement 32, presentation alert analysis subelement 33 and are upgraded subelement 34.Wherein:
Type judgment sub-unit 31 is used for the object identity OID according to the alarm to be analyzed of alarm receiving element 10 receptions, judges the type of alarm to be analyzed;
Root alarm is analyzed subelement 32, is used for when the type of alarm to be analyzed is Root alarm, and this alarm to be analyzed is added Root alarm record in Root alarm record cell 20, and the presentation of searching alarm to be analyzed in the Root alarm record is alarmed; Specifically be used for carrying out:
A1, alarm to be analyzed is added the Root alarm record;
A2, obtain the YITIAOGEN source alarm of not analyzing in the Root alarm record, judge whether Root alarm is the presentation alarm of alarm to be analyzed, and this judgement can be carried out according to the association analysis standard of setting in the association analysis standard memory location 60; Then search end when not having the Root alarm of not analyzing; If not then repeating this steps A 2, otherwise carry out steps A 3;
A3, judge whether the Root alarm corresponding equipment is the upstream device of alarm corresponding equipment to be analyzed, this judgement can be carried out according to the physical link annexation set of storage in the physical link annexation memory cell 50; If not then carrying out steps A 2; If then carry out steps A 4;
Whether A4, judgement exist without the physical link of alarm corresponding equipment to be analyzed between Network Management Equipment and Root alarm corresponding equipment, and this judgement can be carried out according to the physical link annexation set of storage in the physical link annexation memory cell 50; If there is no then carry out steps A 5, otherwise carry out steps A 6;
A5, judgement Root alarm are the presentation alarm of alarm to be analyzed, delete Root alarm in the Root alarm record, carry out steps A 2;
A6, judge whether each upstream equipment of alarm corresponding equipment to be analyzed in the physical link all receives alarm to be analyzed, if not then returning steps A 2; Otherwise carry out steps A 5.
Presentation alert analysis subelement 33 is used in the Root alarm record in Root alarm record cell 20, searching the Root alarm of alarm to be analyzed when the type of alarm to be analyzed is the presentation alarm.Specifically be used for carrying out:
B1, obtain the YITIAOGEN source alarm of not analyzing in the Root alarm record, judge whether Root alarm is the Root alarm of alarm to be analyzed, this judgement can be carried out according to the association analysis standard of setting in the association analysis standard memory location 60; Then alarm to be analyzed is not added the Root alarm record as Root alarm when not having the Root alarm of not analyzing; If not then repeating this step B1, otherwise carry out step B2;
B2, judge whether the Root alarm corresponding equipment is the upstream equipment of alarm corresponding equipment to be analyzed, this judgement can be carried out according to the physical link annexation set of storage in the physical link annexation memory cell 50; If not then carrying out step B1; If then carry out step B3;
Whether B3, judgement exist without the physical link of Root alarm corresponding equipment between Network Management Equipment and alarm corresponding equipment to be analyzed, and this judgement can be carried out according to the physical link annexation set of storage in the physical link annexation memory cell 50; If there is no then carry out step B5, otherwise carry out step B4;
B4, judge whether each upstream equipment of alarm corresponding equipment to be analyzed in the physical link all receives alarm to be analyzed, if not then returning step B1; Otherwise carry out step B5.
B5, judgement alarm to be analyzed are the presentation alarm of Root alarm.
Upgrade subelement 34, be used for that Root alarm is analyzed subelement 32 and alarm, deletion from the Root alarm record that Root alarm record cell 20 is preserved in the presentation that Root alarm writes down the alarm to be analyzed that finds.
Can find by above-mentioned application scenarios, use equipment provided by the invention, can analyze the alarm that receives accurately, judge that it is Root alarm or the alarm of the presentation of other Root alarm that existed, the numerous presentation alarms irrelevant have been suppressed with network failure, Root alarm is presented to the user, make things convenient for the quick locating network fault of user, improved the practicality of warning system.
Through the above description of the embodiments, those skilled in the art can be well understood to the present invention and can realize by hardware, also can realize by the mode that software adds necessary general hardware platform.Based on such understanding, technical scheme of the present invention can embody with the form of software product, it (can be CD-ROM that this software product can be stored in a non-volatile memory medium, USB flash disk, portable hard drive etc.) in, comprise as dried fruit instruction with (can be personal computer, server, the perhaps network equipment etc.) described method of execution each embodiment of the present invention so that computer equipment.
It will be appreciated by those skilled in the art that accompanying drawing is the schematic diagram of a preferred embodiment, unit in the accompanying drawing or flow process might not be that enforcement the present invention is necessary.
It will be appreciated by those skilled in the art that the unit in the device among the embodiment can be distributed in the device of embodiment according to the embodiment description, also can carry out respective change and be arranged in the one or more devices that are different from present embodiment.A unit can be merged in the unit of the foregoing description, also can further split into a plurality of subelements.
The invention described above embodiment sequence number is not represented the quality of embodiment just to description.

Claims (14)

1. definite method of a network fault root is characterized in that, comprising:
According to the Root alarm record of having stored, the alarm to be analyzed that receives is analyzed;
When the analysis result of described alarm to be analyzed is Root alarm, described alarm to be analyzed is added described Root alarm record, and the presentation alarm of alarm to be analyzed described in the described Root alarm record is deleted; When the analysis result of described alarm to be analyzed is the presentation alarm, described alarm to be analyzed is not added described Root alarm record;
Determine network fault root according to described Root alarm record.
2. the method for claim 1 is characterized in that, the described alarm to be analyzed that receives is analyzed comprises:
Whenever receive an alarm to be analyzed, promptly the described alarm to be analyzed that receives is analyzed; Or
Buffer memory is carried out in the alarm to be analyzed that receives, and regularly trigger analysis the alarm to be analyzed of buffer memory; Described the alarm to be analyzed that receives is analyzed after, the alarm to be analyzed after analyzing is deleted from described buffer memory.
3. method as claimed in claim 1 or 2 is characterized in that, the alarm to be analyzed that receives is analyzed, and comprising:
According to the object identity OID of described alarm to be analyzed, judge the type of described alarm to be analyzed;
When the type of described alarm to be analyzed is Root alarm, in the described Root alarm record of having stored, search the presentation alarm of described alarm to be analyzed;
When the type of described alarm to be analyzed is the presentation alarm, in the described Root alarm record of having stored, search the Root alarm of described alarm to be analyzed.
4. method as claimed in claim 3 is characterized in that, when the type of described alarm to be analyzed is Root alarm, in the described Root alarm record of having stored, searches the presentation alarm of described alarm to be analyzed, comprising:
A1, described alarm to be analyzed is added the Root alarm record;
A2, obtain the YITIAOGEN source alarm of not analyzing in the described Root alarm record, judge whether described Root alarm is the presentation alarm of described alarm to be analyzed; Then search end when not having the Root alarm of not analyzing; If not then repeating this steps A 2, otherwise carry out steps A 3;
A3, judge whether described Root alarm corresponding equipment is the upstream device of described alarm corresponding equipment to be analyzed; If not then carrying out steps A 2; If then carry out steps A 4;
Whether A4, judgement exist without the physical link of described alarm corresponding equipment to be analyzed between Network Management Equipment and described Root alarm corresponding equipment; If there is no then carry out steps A 5, otherwise carry out steps A 6;
A5, the described Root alarm of judgement are the presentation alarm of described alarm to be analyzed, and the described Root alarm of deletion in described Root alarm record carries out steps A 2;
A6, judge whether each upstream equipment of alarm corresponding equipment to be analyzed described in the described physical link all receives described alarm to be analyzed, if not then returning steps A 2; Otherwise carry out steps A 5.
5. method as claimed in claim 3 is characterized in that, when the type of described alarm to be analyzed is the presentation alarm, in the described Root alarm record of having stored, searches the Root alarm of described alarm to be analyzed, comprising:
B1, obtain the YITIAOGEN source alarm of not analyzing in the described Root alarm record, judge whether described Root alarm is the Root alarm of described alarm to be analyzed; Then described alarm to be analyzed is not added described Root alarm record as Root alarm when not having the Root alarm of not analyzing; If not then repeating this step B1, otherwise carry out step B2;
B2, judge whether described Root alarm corresponding equipment is the upstream equipment of described alarm corresponding equipment to be analyzed; If not then carrying out step B1; If then carry out step B3;
Whether B3, judgement exist without the physical link of described Root alarm corresponding equipment between Network Management Equipment and described alarm corresponding equipment to be analyzed; If there is no then carry out step B5, otherwise carry out step B4;
B4, judge whether each upstream equipment of alarm corresponding equipment to be analyzed described in the described physical link all receives described alarm to be analyzed, if not then returning step B1; Otherwise carry out step B5.
The presentation alarm that B5, the described alarm to be analyzed of judgement are described Root alarm.
6. as claim 4 or 5 described methods, it is characterized in that, also comprise: set up the set of physical link annexation, per unit upstream equipment and upstream device in the record network, and the physical link information of equipment room, judge according to described physical link annexation set:
Whether described Root alarm corresponding equipment is the upstream equipment of described alarm corresponding equipment to be analyzed;
Whether described Root alarm corresponding equipment is the upstream device of described alarm corresponding equipment to be analyzed;
Between Network Management Equipment and described alarm corresponding equipment to be analyzed, whether exist without the physical link of described Root alarm corresponding equipment;
Between Network Management Equipment and described Root alarm corresponding equipment, whether exist without the physical link of described alarm corresponding equipment to be analyzed.
7. as claim 4 or 5 described methods, it is characterized in that, also comprise: the association analysis standard is set, comprises the relation between the OID of the OID of Root alarm and presentation alarm in the described association analysis standard; Judge according to described association analysis standard:
Whether described Root alarm is the Root alarm or the presentation alarm of described alarm to be analyzed.
8. the analytical equipment of a network fault root is characterized in that, comprising:
The alarm receiving element is used to receive alarm to be analyzed;
The Root alarm record cell is used to preserve the Root alarm record;
Analytic unit, be used for Root alarm record according to described Root alarm record cell, the alarm to be analyzed that described alarm receiving element receives is analyzed, and upgrade Root alarm record in the described Root alarm record cell: when the analysis result of described alarm to be analyzed is Root alarm according to analysis result, described alarm to be analyzed is added described Root alarm record, and the presentation alarm of alarm to be analyzed described in the described Root alarm record is deleted; When the analysis result of described alarm to be analyzed is the presentation alarm, described alarm to be analyzed is not added described Root alarm record;
Failure location unit is used for determining network fault root according to the Root alarm record after upgrading after described analytic unit upgrades the Root alarm of described Root alarm record cell record.
9. equipment as claimed in claim 8 is characterized in that, described alarm receiving element specifically is used for:
Whenever receive an alarm to be analyzed, promptly trigger described analytic unit the described alarm to be analyzed that receives is analyzed; Or
Buffer memory is carried out in the alarm to be analyzed that receives, and regularly trigger of the analysis of described analytic unit the alarm to be analyzed of buffer memory; After described analytic unit is analyzed alarm to be analyzed, the alarm to be analyzed after analyzing is deleted from described buffer memory.
10. equipment as claimed in claim 8 or 9 is characterized in that described analytic unit comprises:
The type judgment sub-unit is used for the object identity OID according to described alarm to be analyzed, judges the type of described alarm to be analyzed;
Root alarm is analyzed subelement, be used for when the type of described alarm to be analyzed is Root alarm, described alarm to be analyzed is added described Root alarm record, in the Root alarm record in described Root alarm record cell, search the presentation alarm of described alarm to be analyzed;
Presentation alert analysis subelement is used in the Root alarm record in described Root alarm record cell, searching the Root alarm of described alarm to be analyzed when the type of described alarm to be analyzed is the presentation alarm;
Upgrade subelement, be used for that described Root alarm is analyzed subelement and alarm, deletion from the Root alarm record of described Root alarm record cell in the presentation that Root alarm writes down the described alarm to be analyzed that finds.
11. equipment as claimed in claim 10 is characterized in that, described Root alarm is analyzed subelement and specifically is used for carrying out:
A1, described alarm to be analyzed is added the Root alarm record;
A2, obtain the YITIAOGEN source alarm of not analyzing in the described Root alarm record, judge whether described Root alarm is the presentation alarm of described alarm to be analyzed; Then search end when not having the Root alarm of not analyzing; If not then repeating this steps A 2, otherwise carry out steps A 3;
A3, judge whether described Root alarm corresponding equipment is the upstream device of described alarm corresponding equipment to be analyzed; If not then carrying out steps A 2; If then carry out steps A 4;
Whether A4, judgement exist without the physical link of described alarm corresponding equipment to be analyzed between Network Management Equipment and described Root alarm corresponding equipment; If there is no then carry out steps A 5, otherwise carry out steps A 6;
A5, the described Root alarm of judgement are the presentation alarm of described alarm to be analyzed, and the described Root alarm of deletion in described Root alarm record carries out steps A 2;
A6, judge whether each upstream equipment of alarm corresponding equipment to be analyzed described in the described physical link all receives described alarm to be analyzed, if not then returning steps A 2; Otherwise carry out steps A 5.
12. equipment as claimed in claim 10 is characterized in that, described presentation alert analysis subelement specifically is used for carrying out:
B1, obtain the YITIAOGEN source alarm of not analyzing in the described Root alarm record, judge whether described Root alarm is the Root alarm of described alarm to be analyzed; Then described alarm to be analyzed is not added described Root alarm record as Root alarm when not having the Root alarm of not analyzing; If not then repeating this step B1, otherwise carry out step B2;
B2, judge whether described Root alarm corresponding equipment is the upstream equipment of described alarm corresponding equipment to be analyzed; If not then carrying out step B1; If then carry out step B3;
Whether B3, judgement exist without the physical link of described Root alarm corresponding equipment between Network Management Equipment and described alarm corresponding equipment to be analyzed; If there is no then carry out step B5, otherwise carry out step B4;
B4, judge whether each upstream equipment of alarm corresponding equipment to be analyzed described in the described physical link all receives described alarm to be analyzed, if not then returning step B1; Otherwise carry out step B5.
The presentation alarm that B5, the described alarm to be analyzed of judgement are described Root alarm.
13. as claim 11 or 12 described equipment, it is characterized in that, also comprise: physical link annexation memory cell, be used to set up the set of physical link annexation, per unit upstream equipment and upstream device in the record network, and the physical link information of equipment room, described physical link annexation set is offered described analytic unit is used for judging:
Whether described Root alarm corresponding equipment is the upstream equipment of described alarm corresponding equipment to be analyzed;
Whether described Root alarm corresponding equipment is the upstream device of described alarm corresponding equipment to be analyzed;
Between Network Management Equipment and described alarm corresponding equipment to be analyzed, whether exist without the physical link of described Root alarm corresponding equipment;
Between Network Management Equipment and described Root alarm corresponding equipment, whether exist without the physical link of described alarm corresponding equipment to be analyzed.
14. as claim 11 or 12 described equipment, it is characterized in that, also comprise: the association analysis standard memory location, be used to be provided with the association analysis standard, comprise the relation between the OID of the OID of Root alarm and presentation alarm in the described association analysis standard; Described association analysis standard is offered described analytic unit to be used for judging:
Whether described Root alarm is the Root alarm or the presentation alarm of described alarm to be analyzed.
CN200910148650XA 2009-06-26 2009-06-26 Method for determining root cause of network fault and analytic equipment thereof Expired - Fee Related CN101577648B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN200910148650XA CN101577648B (en) 2009-06-26 2009-06-26 Method for determining root cause of network fault and analytic equipment thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN200910148650XA CN101577648B (en) 2009-06-26 2009-06-26 Method for determining root cause of network fault and analytic equipment thereof

Publications (2)

Publication Number Publication Date
CN101577648A CN101577648A (en) 2009-11-11
CN101577648B true CN101577648B (en) 2011-08-03

Family

ID=41272442

Family Applications (1)

Application Number Title Priority Date Filing Date
CN200910148650XA Expired - Fee Related CN101577648B (en) 2009-06-26 2009-06-26 Method for determining root cause of network fault and analytic equipment thereof

Country Status (1)

Country Link
CN (1) CN101577648B (en)

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102195826B (en) * 2010-03-10 2014-06-04 杭州华三通信技术有限公司 Method and device for detecting root alarm
CN102394765A (en) * 2011-09-01 2012-03-28 上海大学 Method for positioning faults of cable television network management system
CN102387035B (en) * 2011-09-13 2014-02-05 瑞斯康达科技发展股份有限公司 Alarm processing method and alarm processing device
CN103856339B (en) * 2012-12-04 2017-11-21 中国移动通信集团广西有限公司 A kind of method and apparatus being compressed to warning information
CN103607295A (en) * 2013-10-31 2014-02-26 南京中兴新软件有限责任公司 Alarm processing method and alarm system
CN106330297B (en) * 2015-06-18 2020-06-05 中兴通讯股份有限公司 Method and device for detecting optical fiber fault point
CN105071970B (en) * 2015-08-27 2018-09-11 中国电信股份有限公司 Failure analysis methods and system and Network Management Equipment
CN105516710B (en) * 2015-11-27 2017-12-15 凌云天博光电科技股份有限公司 Wired TV network equipment fault detection method and device
CN106776690A (en) * 2016-11-10 2017-05-31 上海斐讯数据通信技术有限公司 A kind of network element loses even alert processing method and system
CN106850463A (en) * 2017-02-28 2017-06-13 深圳市风云实业有限公司 A kind of access switch
CN110166264B (en) * 2018-02-11 2022-03-08 北京三快在线科技有限公司 Fault positioning method and device and electronic equipment
CN111193627B (en) * 2019-12-31 2022-08-12 中国移动通信集团江苏有限公司 Information processing method, device, equipment and storage medium
CN113285840B (en) * 2021-06-11 2021-09-17 云宏信息科技股份有限公司 Storage network fault root cause analysis method and computer readable storage medium

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101039209A (en) * 2006-03-13 2007-09-19 中国电信股份有限公司 Method for analyzing root warning for multi-manufacturer DWDM network management system
CN101183989A (en) * 2007-12-03 2008-05-21 中兴通讯股份有限公司 Incremental analysis method of optical synchronization transmission network alarm correlation

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101039209A (en) * 2006-03-13 2007-09-19 中国电信股份有限公司 Method for analyzing root warning for multi-manufacturer DWDM network management system
CN101183989A (en) * 2007-12-03 2008-05-21 中兴通讯股份有限公司 Incremental analysis method of optical synchronization transmission network alarm correlation

Also Published As

Publication number Publication date
CN101577648A (en) 2009-11-11

Similar Documents

Publication Publication Date Title
CN101577648B (en) Method for determining root cause of network fault and analytic equipment thereof
RU2375746C2 (en) Method and device for detecting network devices
JP5950979B2 (en) Node deduplication in network monitoring system
US9225586B2 (en) Automatic expansion method, management device, management system
EP3167571A1 (en) Network topology estimation based on event correlation
CN108566296B (en) Network device layering method, network management device and computer readable storage medium
CN110071978A (en) A kind of method and device of cluster management
CN105426375A (en) Relationship network calculation method and apparatus
CN106330501A (en) Fault correlation method and device
CN102075368A (en) Method, device and system for diagnosing service failure
CN109639488A (en) A kind of more outer nets shunt accelerated method and system
CN107995032B (en) Method and device for building network experiment platform based on cloud data center
CN108769118A (en) The choosing method and device of host node in a kind of distributed system
WO2016095716A1 (en) Fault information processing method and related device
CN102866964B (en) Method and device for protecting data on storage equipment
CN111245662B (en) Method and device for displaying network topology
US9319271B2 (en) Management device and management method
CN110932913B (en) Self-adaptive service migration method and device based on case base matching
CN107659435B (en) Interface information processing method and device
CN103067203B (en) policy consistency auditing method, device and equipment
CN111897869A (en) Data display method and device and readable storage medium
KR101801825B1 (en) Apparatus and method for detecting link information among network switches
CN109309576B (en) Fault community detection method and management node
US8719633B2 (en) Search device, search method, and search program
CN110912760A (en) Link state detection method and device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP03 Change of name, title or address
CP03 Change of name, title or address

Address after: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Patentee after: Xinhua three Technology Co., Ltd.

Address before: 310053 Hangzhou hi tech Industrial Development Zone, Zhejiang province science and Technology Industrial Park, No. 310 and No. six road, HUAWEI, Hangzhou production base

Patentee before: Huasan Communication Technology Co., Ltd.

CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20110803

Termination date: 20200626