CN102195791A - Alarm analysis method, device and system - Google Patents

Alarm analysis method, device and system Download PDF

Info

Publication number
CN102195791A
CN102195791A CN2010101203077A CN201010120307A CN102195791A CN 102195791 A CN102195791 A CN 102195791A CN 2010101203077 A CN2010101203077 A CN 2010101203077A CN 201010120307 A CN201010120307 A CN 201010120307A CN 102195791 A CN102195791 A CN 102195791A
Authority
CN
China
Prior art keywords
alarm
information
management system
root
alarming processing
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2010101203077A
Other languages
Chinese (zh)
Inventor
苏强
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN2010101203077A priority Critical patent/CN102195791A/en
Publication of CN102195791A publication Critical patent/CN102195791A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses an alarm analysis method, an alarm analysis device and an alarm analysis system. The method of the technical scheme comprises the following steps of: acquiring alarm processing information obtained by the network element alarm processing of a network management system from a database; and analyzing the alarm processing information according to a preset alarm analysis sheet, and determining a source alarm. The device comprises a first information acquisition module and a first information processing module, wherein the first information acquisition module is used for acquiring the alarm processing information obtained by the network element alarm processing of the network management system from the database; and the first information processing module is used for analyzing the alarm processing information according to the preset alarm analysis sheet, and determining the source alarm. In the technical scheme, the alarm processing information of the network management system can be analyzed again according to the preset alarm analysis sheet, and the source alarm of a failure in the system can be timely determined, thereby ensuring the normal running of a communication network.

Description

A kind of analytical method of alarm, Apparatus and system
Technical field
The present invention relates to communication technical field, in particular, relate to a kind of analytical method, Apparatus and system of alarm.
Background technology
Fault management can guarantee the normal operation of network as an important component part in the modern communication networks management.Because the fast development of communication network becomes network configuration and becomes increasingly complex, a large amount of warning information of network manager in the face of producing in the communication network often are difficult to therefrom find out the true cause of fault, thereby can't implement fault restoration and removal of obstacle fast.In order better to solve failure diagnosis and orientation problem, need carry out alarm correlation analysis to the warning information that is received, find the basic reason that triggers alarm, also be called Root alarm, so that can finish the task of fault management better.
Root alarm is the alarm that basic fault produces in a series of alarms; Such as, the port hardware fault of veneer has caused the port hardware alarm, and port flow is crossed low alarm, a series of alarms such as newsletter terminal alarm.But its basic reason is the port hardware fault, so the port hardware alarm is Root alarm, as long as solved this Root alarm, other alarm nature will disappear, and alarm correlation analysis is exactly a method of seeking this Root alarm.
Can realize alarm correlation analysis based on model reasoning in the prior art, in the network management system of optical-fiber network bottom standard network, generally pass through.Because optical-fiber network is structured in unified ITU-T (ITUTelecommunication Standardization Sector, International Telecommunications Union's telecommunication standards group) standard, model is standard very, from the hardware device to the physical link and logical links, strict hierarchical relationship or linking relationship are arranged all.Such as: in SDH (Synchronous Digital Hierarchy, SDH (Synchronous Digital Hierarchy)) network, link is divided into physical link, RS link and MS link from the bottom to the high level; As TM-A (Termination Multiplexer, terminating multiplexer) light mouth infringement, the alarm that can cause comprises: REG (relaying) equipment is alarmed at physical layer R-LOS (receiving end signal is lost), REG equipment is in RS layer R-LOS alarm, and TM-B equipment damages hardware alarm in MS layer R-LOS alarm and TM-A equipment light mouth.According to strict model specification of SDH and clear and definite Topo relation, can determine conveniently that the Root alarm in these alarms is " TM-A equipment light mouth damages hardware alarm ", network management system just can in time be carried out troubleshooting or reparation to Root alarm like this.
Can also adopt the mode of custom rule to realize alarm correlation analysis in the prior art, for example: based on physical correlation, type correlation and temporal correlation carry out self-defined to alarm regulation, it is relevant with alarm type B to define the alarm type A that takes place in 10 seconds on the same port, and B is the Root alarm of A.This mode can be carried out the expansion of rule, satisfies simple alarm correlation requirement.
In realizing process of the present invention, the inventor finds that there are the following problems at least in the prior art:
Existing alarm correlation means can't be found system's catastrophe failure by the method for statistical analysis from a large amount of low level alarm events in application process.For example: in certain office point of IPTV (IPTV), there is a large amount of host software module (PC Server), business relations complexity between these modules, when a nucleus module fault, relative module all can report and alarm, the keeper can be submerged produce at short notice repeat in a large number to alarm in the alarm windstorm that causes.Because the complex relationship between these modules can not at will stop the alarm notification of these modules, thus can't find basic reason to carry out troubleshooting timely, thus seriously influence the operation of network regular traffic.
Summary of the invention
Embodiments of the invention provide a kind of analytical method, Apparatus and system of alarm, by the alarming processing information of network management system being analyzed once more according to the alert analysis table that sets in advance, can in time determine the Root alarm of fault in the system, thereby guarantee the normal operation of communication network.
The technical scheme of the embodiment of the invention is as described below:
The embodiment of the invention provides a kind of analytical method of alarm, and technical scheme comprises:
From database, obtain the alarming processing information after network management system is handled at network element alarm;
According to predetermined alert analysis table described alarming processing information is analyzed, determined Root alarm.
The embodiment of the invention provides a kind of alert analysis device, and technical scheme comprises:
First information acquisition module is used for obtaining alarming processing information after network management system is handled at network element alarm from database;
First information processing module is used for according to predetermined alert analysis table described alarming processing information being analyzed, and determines Root alarm.
The embodiment of the invention provides a kind of warning information analytical system, and technical scheme comprises:
Network management system be used for handling at network element alarm, and the alarming processing information after will handling is kept in the database; Also be used for the Root alarm that the receiving alarm analytical equipment is determined;
The alert analysis device, be used for the alarming processing information after alarm is handled at network element of obtaining from database that described network management system preserves, after according to predetermined alert analysis table described alarming processing information being analyzed, determine Root alarm, and report to network management system.
The technical scheme that is provided by the embodiment of the invention described above as can be seen, adopt the alarm quadratic dependence analytical plan of the embodiment of the invention based on statistical analysis, the alarming processing information that the alarm that the network management system of obtaining is reported network element is handled is carried out statistical analysis, can in time determine the basic failure cause of the common alarm of whole network mass-sending property, so that network management system can in time be handled this failure cause, guarantee the normal operation of network.
Description of drawings
In order to be illustrated more clearly in the technical scheme of the embodiment of the invention, the accompanying drawing of required use is done to introduce simply in will describing embodiment below, apparently, accompanying drawing in describing below only is some embodiments of the present invention, for those of ordinary skills, under the prerequisite of not paying creative work, can also obtain other accompanying drawing according to these accompanying drawings.
Fig. 1 is the analytical method flow chart of embodiment of the invention alarm;
Fig. 2 is the structural representation of embodiment of the invention alert analysis device;
Fig. 3 is the concrete structure schematic diagram of one embodiment of the invention alert analysis device;
Fig. 4 is the structural representation of embodiment of the invention alert analysis system;
Fig. 5 is the application scenarios figure of embodiment of the invention alert analysis method.
Embodiment
Below in conjunction with the accompanying drawing in the embodiment of the invention, the technical scheme in the embodiment of the invention is clearly and completely described, obviously, described embodiment only is the present invention's part embodiment, rather than whole embodiment.Based on the embodiment among the present invention, those of ordinary skills belong to the scope of protection of the invention not making the every other embodiment that is obtained under the creative work prerequisite.
The analytical method of a kind of alarm of the embodiment of the invention, Apparatus and system, alarming processing information regular or that in real time the network management system in the record alert database is alarmed after handling at network element is carried out statistical analysis by the alert analysis table in network management system, thereby in low level alarm event in batches, in time find the Root alarm of system level, and the Root alarm of determining reported alarm treatment device, so that network management system can in time be handled the alarm event relevant with Root alarm, guarantee the normal operation of network.
Existing alarming processing logic is not changed in the embodiment of the invention, and be based on the analysis mode of a kind of alarm that proposes on the basis of alarming processing data in the existing alarm database, can solve in the prior art and can not from batch low level incident, in time find the problem of system level catastrophe failure.
Understanding for the ease of to the technical scheme of embodiment of the invention record describes below in conjunction with embodiment.
As shown in Figure 1, the analytical method of a kind of alarm of the embodiment of the invention can be achieved through the following technical solutions:
Step 101: from database, obtain the alarming processing information after network management system is handled at network element alarm;
Step 102: according to predetermined alert analysis table described alarming processing information is analyzed, determined Root alarm.
In one embodiment of the invention, from database, obtain the process of the alarming processing information after network management system is handled at network element alarm, specifically can be achieved through the following technical solutions:
From database, extract described alarming processing information according to alarm type;
Described alarming processing packets of information purse rope guard system after to the network element alarming processing data and/or the data behind the alarm correlation analysis.
Specifically, be to come the alarm that network element reports is handled in network management system by warning processing module, network management system is analyzed, shows, is transmitted the alarm that receives by warning processing module or carries out existing alarm correlation analysis operation, will the related data after the network element alarming processing be stored in the record alert database then.
For the ease of determining identical alarm type Root alarm down, the embodiment of the invention can be by the mode of obtaining in real time when extracting alarming processing information, or the mode that timing is obtained is extracted according to alarm type.
In one embodiment of the invention, step 102 specifically can be achieved through the following technical solutions:
Step 1021: according to the described network management system of described alert analysis table analysis after to the network element alarming processing data and/or the data behind the alarm correlation analysis, write down the Root alarm Rule of judgment of formulating at different alarm types in the described alert analysis table;
Step 1022: according to determining Root alarm the alarming processing information of described Root alarm Rule of judgment under identical alarm type;
Step 1023: notify described Root alarm to network management system, so that network management system can in time be known this Root alarm.。
Specifically, mainly be based on the Root alarm of determining system level from record alert database in the warning information that the alert analysis table extracts in the embodiment of the invention.Wherein, the alert analysis table pre-establishes according to alarm type, and Root alarm is according to the Root alarm Rule of judgment alarming processing data under the same type that extracts to be judged what the back was determined respectively.This Root alarm Rule of judgment can be formulated according to factors such as the alarm number of times of same type alarming processing data, frequencies.
In one embodiment of the invention, the analytical method of alarm can also comprise:
Alarm and described Root alarm by the network element that alarm identifier is distinguished under the described same alarm type.
Specifically, can significantly distinguish the Root alarm of new generation and the common alarm event that the legacy network element produces for the ease of the network manager, in embodiments of the present invention, can realize by alarm identifier, for example: can be Root alarm by this alarm of critical alarm sign prompting, the network manager can clearly distinguish network element alarm time and Root alarm, preferentially the alarm event relevant with Root alarm handled, thereby solved other the relevant common alarm that causes by this Root alarm.
As shown in Figure 2, based on above-mentioned embodiment shown in Figure 1, the embodiment of the invention also provides a kind of alert analysis device, can comprise following functional module:
First information acquisition module 21 is used for obtaining alarming processing information after network management system is handled at network element alarm from database;
First information processing module 22 is used for according to predetermined alert analysis table described alarming processing information being analyzed, and determines Root alarm.
As shown in Figure 3, in one embodiment of the invention, the described device of the embodiment of the invention specifically can comprise following functional module:
First information acquisition module 21 specifically can comprise:
First information extraction unit 211 is used for extracting described alarming processing information from database according to alarm type; Described alarming processing packets of information purse rope guard system after to the network element alarming processing data and/or the data behind the alarm correlation analysis;
First information delivery unit 212 is used for sending the described alarming processing information that described first information extraction unit obtains to described first information processing module.
First information processing module 22 specifically can comprise:
First information judging unit 221, be used for according to the described network management system of described alert analysis table analysis after to the network element alarming processing data and/or the data behind the alarm correlation analysis, write down the Root alarm Rule of judgment of formulating at different alarm types in the described alert analysis table;
Root alarm determining unit 222 is used for generating described Root alarm according to described Root alarm Rule of judgment.
In one embodiment of the invention, the alert analysis device can also comprise:
Root alarm notification module 24 is used for described Root alarm notice network management system, so that network management system is known described Root alarm;
Root alarm reminding module 23 is used for distinguishing network element alarm event and described Root alarm under the described same alarm type by alarm identifier.
Need to prove that the embodiment of the invention is based on that above-mentioned method embodiment shown in Figure 1 obtains, wherein the technical scheme that each step is put down in writing among each functional module and Fig. 1 embodiment is corresponding, specifically can be referring to the associated description among above-mentioned Fig. 1 embodiment.
Shown in Figure 4, based on method embodiment shown in Figure 1, the embodiment of the invention has also proposed a kind of warning information analytical system, and technical scheme can comprise:
Network management system 41 be used for handling at network element alarm, and the alarming processing information after will handling is kept in the database; Also be used for the Root alarm that the receiving alarm analytical equipment is determined;
Alert analysis device 42, be used for the alarming processing information after alarm is handled at network element of obtaining from database that described network management system preserves, after according to predetermined alert analysis table described alarming processing information being analyzed, determine Root alarm, and report to network management system.
Need to prove that the embodiment of the invention is based on that above-mentioned method embodiment shown in Figure 1 obtains, wherein the technical scheme that each step is put down in writing among each functional module and Fig. 1 embodiment is corresponding, specifically can be referring to the associated description among above-mentioned Fig. 1 embodiment.
In order further to understand the technical scheme of the embodiment of the invention, describe below in conjunction with specific embodiment.
Embodiment one:
The embodiment of the invention, (Collection Module, CM are responsible for gathering up to a hundred streaming media servers (Media Server, MS) consumption to each data acquisition module in the IPTV system, when MS detects with the CM communication abnormality, all can report one and the alarm of CM communication abnormality; Usually, it is that network is unusual that indivedual MS report the reason of this alarm, but when a large amount of MS report with the CM communication abnormality at short notice, illustrates that then center C M equipment breaks down, if untimely breaking down at center C M equipment handled, will influence the normal operation of the whole network business.Adopt the described method of the embodiment of the invention that above-mentioned alarming processing process is elaborated below.
As shown in Figure 5:
100, network element MS produces " MS and CM communication abnormality " alarm according to alarm regulation, and with this alarm notification SNMP (Simple Network Management Protocol, Simple Network Management Protocol) Agent; Wherein, above-mentioned alarm regulation is that the alarm according to the definition of the service needed of network element equipment produces exceptional condition, surpasses 60 degree, network connected terminal, internal memory utility ratio as: temperature and surpasses 70% etc.;
200, after SNMP Agent receives the alarm that MS reports, this alarm can be reported webmaster in the mode of SNMP Trap; Also can select MML (Man-MachineLanguage at different systems, man-machine language), SOAP (Simple Object Access Protocol, Simple Object Access Protocol), TCP (Transmission Control Protocol, transmission control protocol) etc. agreement reports, but all adopts snmp protocol to report this alarm in most systems usually;
300, adopt warning processing module that the alarm that SNMP Agent reports is handled in the network management system;
In the embodiment of the invention, according to the alert analysis table to the information analysis of network management system after to the network element alarming processing before, the warning processing module in the network management system adopts existing alarming processing flow process that the alarm that network element reports is handled; Warning processing module is carried out the analysis of information extraction, association, displaying, forwarding, alarm correlation to this alarm event after the alarm of receiving network element, deposit the related data of this alarm in record alert database; Wherein, above-mentioned " displaying " is that warning processing module is carried out in the processing procedure alarm event, can point out the keeper to check by the mode of sound/light/electricity, also can point out the keeper to check corresponding warning information by the mode that browse at the interface;
400, the embodiment of the invention adopts the alert analysis engine regularly (can be set to 1 minute, specifically formulate according to application scenarios) alarming processing information after from record alert database, extracting network management system the alarm of network element being handled, in this example the warning information of alarm type for " MS and CM communication abnormality " extracted, analyze according to the alert analysis table, determine the Root alarm of this alarm type;
Concrete, because present embodiment is in advance according to different alarm types, formulated the alert analysis table according to alarm correlation, according to the Root alarm Rule of judgment, can find some faults of IPTV system mass-sending property, for example: certain type alarm is concentrated outburst in some periods, and its root is owing to the central apparatus fault causes.Root alarm Rule of judgment in the present embodiment is set at " when MS and CM communication abnormality alarm frequency surpasses 10 times in 1 minute, generating the alarm of CM system exception ";
500, by above-mentioned Root alarm Rule of judgment, the Root alarm of judging " MS and the CM communication abnormality " alarm that produces in the current system is " alarm of CM system exception ", to represent with " critical alarm " sign simultaneously " CM system exception alarm, and be transmitted to warning processing module in the network management system by SNMP Agent;
In the embodiment of the invention one, the alert analysis engine provides the general framework mechanism of alarm report, and for example: analysis logic regularly triggers, alarm report etc.; Concrete alarm triggered mechanism can specifically customize according to product needed.
In the embodiment of the invention one, the Root alarm that is generated by the alert analysis engine directly is notified to network management system, but for the minimizing of trying one's best impact to existing network management system, keep framework, handling process and the service logic of existing network management system, still be transmitted to network management system in the embodiment of the invention by SNMP Agent;
In the alarm data that above-mentioned alert analysis engine is extracting, find the process of Root alarm, can realize by storing process, and this storing process can load or shield as required dynamically.
In the embodiment of the invention, the loading of alarm regulation can define by configuration file, an alarm of each line display of each configuration file detection mission, and form is:
Storing process name alarm name Alarm ID alarm severity level proof cycle (if the front adds #, then this rule is not temporarily carried out in expression)
In the embodiment of the invention, the Root alarm of determining by the alert analysis engine and the alarm regulation of loading.Can represent by above-mentioned form.
Simultaneously, because storing process can add in system dynamically, the alarm detection mission also can be added or deletion by configuration file is dynamic; That is to say, from record alert database, obtain the alarming processing information of network management system after, and analyze the process that obtains Root alarm and also can dynamically add deletion as required the network element alarming processing.
600, SNMP Agent is with newly-generated alarm " CM system exception " report and alarm processing module, network management system is in a large amount of alarm events, preferentially check the alarm event of " critical alarm ", alarm " MS and CM communication abnormality " thereby solved with a large amount of low levels of this high-level alarm " CM system exception " guiding.
By the invention described above embodiment as can be known, technical solution of the present invention is in original alarming processing flow process, introduces the statistical analysis process: by other alarm event of fine granularity level is carried out statistical analysis, thereby find systematic, the traffic issues of broad perspectives; If when not adopting the described method of the foregoing description, when in the IPTV system because the CM system exception causes that a large amount of MS all report to webmaster " MS and CM communication abnormality " during alarm, the system manager has no way of doing it at a large amount of alarm events; When adopting the technical scheme of the invention described above embodiment, the system manager can in time make webmaster pay close attention to Root alarm by alarm identifier in a large amount of alarm events, the alarm event relevant with " Root alarm " handled, avoided the generation of network catastrophe failure.
The embodiment of the invention is introduced two pairs of alert analysis tables of embodiment and is described once more.
Embodiment two:
The embodiment of the invention, the MS equipment of IPTV system are to be responsible for Streaming Media to provide, and be very high to the requirement of bandwidth, and " bandwidth usage is too high " alarm that MS equipment occurs when heavy traffic is normal alarm.But if the alert frequency of same MS equipment is obviously greater than other MS equipment in the system, its reason is likely that there are unusual network traffics in this MS equipment, perhaps unusual storage flow.There are unusual network or storage flow.
Adopt the technical scheme of the embodiment of the invention that the alert analysis flow is elaborated at the IPTV system below:
Wherein, need to prove, network element MS equipment is to the SNMPAgent report and alarm in the embodiment of the invention two, and SNMP Agent in the handling process of webmaster report and alarm and the foregoing description one in the step 100,200 and 300 handling process of record identical, its difference only is the type and the content difference of alarm event, specifically can not give unnecessary details at this referring to the correlation step in the foregoing description one;
400, adopt the alert analysis engine alarming processing information after the extraction webmaster network element alarming processing from record alert database regularly in the embodiment of the invention, in this example the warning information of alarm type for " bandwidth usage is too high " extracted, carry out statistical analysis according to the alert analysis table, determine the Root alarm of this alarm type;
Concrete, because present embodiment has been formulated the alert analysis table according to different alarm types in advance, so, can find some faults of IPTV system mass-sending property according to the Root alarm Rule of judgment in this alert analysis table.
This Root alarm Rule of judgment is set in the present embodiment:
1) alarm type be the alarm event of " the broadband occupancy is too high " in the statistics 1 day, determines the average time of the alarm event of each MS equipment generation " the broadband occupancy is too high ";
2) " the broadband occupancy is too high " alarm event number of times that each MS equipment is produced is compared with average time, if this difference is greater than 5 times relatively, then its Root alarm may be " the MS device bandwidth is used different band ";
500, by above-mentioned Root alarm Rule of judgment, the Root alarm of judging " the broadband occupancy the is too high " alarm that produces in the current system may be " MS equipment broadband is used unusual ", represent this Root alarm by " critical alarm " sign simultaneously, and be transmitted to network management system by SNMP Agent;
In the embodiment of the invention two, can directly notify network management system by the Root alarm that the alert analysis engine generates, also can be transmitted to network management system by SNMP Agent.
600, SNMP Agent is with newly-generated alarm " MS equipment broadband is used unusual " report and alarm processing module, network management system is in a large amount of alarm events, when preferentially other alarm event of " critical alarm " level being handled, will know this Root alarm, adopt the mode pair alarm event relevant of checking service dispatching rate or inspection storage flow in time to handle, avoided the generation of network catastrophe failure with this Root alarm.
By the invention described above embodiment as can be known, when the IPTV system because the scheduling strategy unreasonable allocation, during the equipment component overload, large number quipments all can report " bandwidth usage is too high " if prompt alarm does not adopt the technical scheme of the embodiment of the invention when using the peak, the keeper determines therefrom whether these alarms belong to the prompt alarm of equipment, because its alarm level is not high, so reduced the processing probability of Root alarm to a great extent; After the technical scheme that adopts the embodiment of the invention, the alert analysis engine is by carrying out statistical analysis to a large amount of " bandwidth usage is too high " warning information, by " the MS device bandwidth is used unusual " is designated " critical alarm ", the keeper can be very easy to find fault MS equipment, Adjustment System load in time solves the alarm event relevant with this Root alarm.
At unusual in the IPTV system owing to device storage, it is big to cause storing the iostream quantitative change, during storage port " bandwidth usage is too high ", if do not adopt the technical scheme of the embodiment of the invention, the keeper determines therefrom whether these alarms belong to the normal alarm of the network element equipment of equipment; After the technical scheme that adopts the embodiment of the invention, large number quipments all reports " bandwidth usage is too high " alarm when the equipment peak; The alert analysis engine is by carrying out statistical analysis to a large amount of " bandwidth usage is too high " warning information, report Root alarm by " the MS device bandwidth is used unusual " of " critical alarm " sign expression, the keeper is very easy to find fault MS equipment, it is unusual that thereby guidance system keeper finds storage as early as possible, avoids being used for service impact.
Based on the invention described above embodiment, the present invention is based on statistical analysis to the low level alarm, the high-level fault warning of discovery system, and realization of the present invention does not change the existing alarm processing logic, just on the basis of existing alarm data, alarm data is carried out statistical analysis, expose the system failure reason of essence, and in time notify network management system that this root fault is handled, to guarantee the safety of network.
One of ordinary skill in the art will appreciate that all or part of flow process that realizes in the foregoing description method, be to instruct relevant hardware to finish by computer program, described program can be stored in the computer read/write memory medium, this program can comprise the flow process as the embodiment of above-mentioned each side method when carrying out.Wherein, described storage medium can be magnetic disc, CD, read-only storage memory body (Read-Only Memory, ROM) or at random store memory body (Random Access Memory, RAM) etc.
The above; only for the preferable embodiment of the present invention, but protection scope of the present invention is not limited thereto, and anyly is familiar with those skilled in the art in the technical scope that the present invention discloses; the variation that can expect easily or replacement all should be encompassed within protection scope of the present invention.Therefore, protection scope of the present invention should be as the criterion with the protection range of claim.

Claims (10)

1. the analytical method of an alarm is characterized in that, comprising:
From database, obtain the alarming processing information after network management system is handled at network element alarm;
According to predetermined alert analysis table described alarming processing information is analyzed, determined Root alarm.
2. method according to claim 1 is characterized in that, obtains the alarming processing information after network management system is handled at network element alarm from database, comprising:
From database, extract described alarming processing information according to alarm type; Described alarming processing packets of information purse rope guard system after to the network element alarming processing data and/or the data behind the alarm correlation analysis.
3. method according to claim 2 is characterized in that, according to predetermined alert analysis table described alarming processing information is analyzed, and determines Root alarm, comprising:
According to the described network management system of described alert analysis table analysis after to the network element alarming processing data and/or the data behind the alarm correlation analysis, write down the Root alarm Rule of judgment of formulating at different alarm types in the described alert analysis table;
Generate described Root alarm according to described Root alarm Rule of judgment.
4. method according to claim 3 is characterized in that, described method also comprises: with described Root alarm notice network management system, so that network management system is known described Root alarm.
5. according to arbitrary described method in the claim 1 to 4, it is characterized in that described method also comprises: alarm and described Root alarm with the network element that alarm identifier is distinguished under the described same alarm type.
6. an alert analysis device is characterized in that, comprising:
First information acquisition module is used for obtaining alarming processing information after network management system is handled at network element alarm from database;
First information processing module is used for according to predetermined alert analysis table described alarming processing information being analyzed, and determines Root alarm.
7. device according to claim 6 is characterized in that, described first information acquisition module comprises:
First information extraction unit is used for extracting described alarming processing information from database according to alarm type; Described alarming processing packets of information purse rope guard system after to the network element alarming processing data and/or the data behind the alarm correlation analysis;
First information delivery unit is used for sending the described alarming processing information that described first information extraction unit obtains to described first information processing module.
8. device according to claim 7 is characterized in that, described first information processing module comprises:
First information judging unit, be used for according to the described network management system of described alert analysis table analysis after to the network element alarming processing data and/or the data behind the alarm correlation analysis, write down the Root alarm Rule of judgment of formulating at different alarm types in the described alert analysis table;
The Root alarm determining unit is used for generating described Root alarm according to described Root alarm Rule of judgment.
9. according to arbitrary described device among the claim 6-8, it is characterized in that described device also comprises:
The Root alarm notification module is used for described Root alarm notice network management system, so that network management system is known described Root alarm;
The Root alarm reminding module is used for distinguishing network element alarm event and described Root alarm under the described same alarm type by alarm identifier.
10. an alert analysis system is characterized in that, comprising:
Network management system be used for handling at network element alarm, and the alarming processing information after will handling is kept in the database; Also be used for the Root alarm that the receiving alarm analytical equipment is determined;
The alert analysis device, be used for the alarming processing information after alarm is handled at network element of obtaining from database that described network management system preserves, after according to predetermined alert analysis table described alarming processing information being analyzed, determine Root alarm, and report to network management system.
CN2010101203077A 2010-03-05 2010-03-05 Alarm analysis method, device and system Pending CN102195791A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2010101203077A CN102195791A (en) 2010-03-05 2010-03-05 Alarm analysis method, device and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2010101203077A CN102195791A (en) 2010-03-05 2010-03-05 Alarm analysis method, device and system

Publications (1)

Publication Number Publication Date
CN102195791A true CN102195791A (en) 2011-09-21

Family

ID=44603216

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2010101203077A Pending CN102195791A (en) 2010-03-05 2010-03-05 Alarm analysis method, device and system

Country Status (1)

Country Link
CN (1) CN102195791A (en)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102387043A (en) * 2011-12-07 2012-03-21 深圳市同洲视讯传媒有限公司 Alarm analysis method, workstation and system based on simple network management protocol
CN103428009A (en) * 2012-05-14 2013-12-04 中兴通讯股份有限公司 Method and device for achieving OAM of grouped synchronous networks
CN107026761A (en) * 2017-05-12 2017-08-08 网宿科技股份有限公司 A kind of method and device for determining alarm source
CN107180267A (en) * 2017-06-01 2017-09-19 国家电网公司 A kind of familial defect diagnostic method of secondary operation management system
CN108108280A (en) * 2016-11-25 2018-06-01 东讯股份有限公司 Interactive warning method and warning system of electronic equipment
CN111564027A (en) * 2020-05-08 2020-08-21 北京深演智能科技股份有限公司 Alarm information processing method and device
WO2021115450A1 (en) * 2019-12-12 2021-06-17 中兴通讯股份有限公司 Optical transport network alarm processing method and apparatus, terminal device, and storage medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1768283A1 (en) * 2004-06-22 2007-03-28 ZTE Corporation Method for analyzing the alarm relativity in an optical synchronous transmission network
CN101047556A (en) * 2006-06-01 2007-10-03 华为技术有限公司 Integral maintaining method and system for multi-equipment
CN101355451A (en) * 2008-09-09 2009-01-28 中兴通讯股份有限公司 Method and system for analyzing alarm correlativity
CN101582807A (en) * 2009-07-02 2009-11-18 北京讯风光通信技术开发有限责任公司 Method and system based on northbound interface to realize network management

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1768283A1 (en) * 2004-06-22 2007-03-28 ZTE Corporation Method for analyzing the alarm relativity in an optical synchronous transmission network
CN101047556A (en) * 2006-06-01 2007-10-03 华为技术有限公司 Integral maintaining method and system for multi-equipment
CN101355451A (en) * 2008-09-09 2009-01-28 中兴通讯股份有限公司 Method and system for analyzing alarm correlativity
CN101582807A (en) * 2009-07-02 2009-11-18 北京讯风光通信技术开发有限责任公司 Method and system based on northbound interface to realize network management

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102387043A (en) * 2011-12-07 2012-03-21 深圳市同洲视讯传媒有限公司 Alarm analysis method, workstation and system based on simple network management protocol
CN102387043B (en) * 2011-12-07 2014-04-16 深圳市龙视传媒有限公司 Alarm analysis method, workstation and system based on simple network management protocol
CN103428009A (en) * 2012-05-14 2013-12-04 中兴通讯股份有限公司 Method and device for achieving OAM of grouped synchronous networks
CN103428009B (en) * 2012-05-14 2018-09-11 中兴通讯股份有限公司 Realize Operation, Administration and Maintenance (OAM) method and device of packet synchronization net
CN108108280A (en) * 2016-11-25 2018-06-01 东讯股份有限公司 Interactive warning method and warning system of electronic equipment
CN107026761A (en) * 2017-05-12 2017-08-08 网宿科技股份有限公司 A kind of method and device for determining alarm source
CN107180267A (en) * 2017-06-01 2017-09-19 国家电网公司 A kind of familial defect diagnostic method of secondary operation management system
CN107180267B (en) * 2017-06-01 2020-05-05 国家电网公司 Familial defect diagnosis method of secondary operation and maintenance management system
WO2021115450A1 (en) * 2019-12-12 2021-06-17 中兴通讯股份有限公司 Optical transport network alarm processing method and apparatus, terminal device, and storage medium
CN111564027A (en) * 2020-05-08 2020-08-21 北京深演智能科技股份有限公司 Alarm information processing method and device
CN111564027B (en) * 2020-05-08 2022-05-13 北京深演智能科技股份有限公司 Alarm information processing method and device

Similar Documents

Publication Publication Date Title
CN110224858B (en) Log-based alarm method and related device
CN106385331A (en) Method and system for monitoring alarm based on log
CN102195791A (en) Alarm analysis method, device and system
US7225250B1 (en) Method and system for predictive enterprise resource management
CN103296755B (en) Network online monitoring system for transformer substation
CN103220173B (en) A kind of alarm monitoring method and supervisory control system
CN105282772A (en) Wireless network data communication equipment monitoring system and equipment monitoring method
CN106649055A (en) Domestic CPU (central processing unit) and operating system based software and hardware fault alarming system and method
CN103544093A (en) Monitoring and alarm control method and system
CN110806921B (en) OVS (optical virtual system) abnormity alarm monitoring system and method
CN102882701B (en) Intelligent monitoring and warning system and method for power grid core service data
US8205116B2 (en) Common chronics resolution management
CN111049673A (en) Method and system for counting and monitoring API call in service gateway
CN104574219A (en) System and method for monitoring and early warning of operation conditions of power grid service information system
CN111130821B (en) Power failure alarm method, processing method and device
CN104935456A (en) Alarm message transmission and processing method of communication network alarm system
CN105323002B (en) Optical fiber running state analysis method
CN101345656B (en) global fault rate measuring method
CN116795643A (en) Alarm management method
CN113783710B (en) Process layer network fault positioning method and device based on self-learning criteria
WO2014040470A1 (en) Alarm message processing method and device
Jukić et al. Integrated view on telecommunication network status
CN112395160A (en) Method, device and system for generating relay protection fault report
CN114257414A (en) Intelligent network security duty method and system
CN113434366A (en) Event processing method and system

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C12 Rejection of a patent application after its publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20110921