Summary of the invention
Embodiment of the present invention technical problem to be solved is, a kind of warning analysis method based on Simple Network Management Protocol is provided, and the method comprises the following steps:
Receive the warning information of OAMAgent;
According to described warning information, in the rule configuration file prestoring, search corresponding business rule, and generate according to described business rule the warning information that meets service logic;
Wherein, in the step of warning information that receives OAMAgent, receive the simple network management protocol trap packet of OAMAgent;
Describedly according to described warning information, in the rule configuration file prestoring, search corresponding business rule, and according to described business rule, generate the warning information that meets service logic and comprise:
Simple network management protocol trap packet is resolved, obtain object identifier, and produce an event object model, described event object model is the data structure of the warning information that described object identifier is corresponding;
According to described object identifier, in the rule configuration file prestoring, search corresponding business rule;
Resolve the binding field information in described event object model, obtain all conditions of the business rule that described object identifier is corresponding, bring the binding field information in described event object model into each condition, generate the warning information that meets service logic.
In the rule configuration file prestoring according to described warning information, search corresponding business rule, and according to described business rule, generate in the step of the warning information that meets service logic further comprising the steps of:
According to simple network management protocol trap packet, obtain object identifier;
Judge whether described object identifier is included in the Simple Network Management Protocol configuration file prestoring, and described Simple Network Management Protocol configuration file comprises the corresponding field information of management information bank nodename;
When described object identifier is included in the Simple Network Management Protocol configuration file prestoring, binding parameter to simple network management protocol trap packet is resolved, and produce an event object model, described event object model is the data structure of the warning information that described object identifier is corresponding.
In the binding parameter to simple network management protocol trap packet, resolve, and produce after the step of an event object model further comprising the steps of:
Judge whether described object identifier is included in the rule configuration file prestoring, described in the rule configuration file that prestores comprise the business rule of at least one corresponding described object identifier;
When described object identifier is included in the rule configuration file prestoring, the binding parameter that described simple network management protocol trap packet is contained is carried out corresponding business rule;
Generate the execution result of carrying out described business rule;
Described execution result is converted into the warning information that is applicable to different language user;
Described warning information is stored in database;
Show described warning information.
In the binding parameter that described simple network management protocol trap packet is contained, carrying out the step of corresponding business rule and described generation carries out between the execution result step of described business rule further comprising the steps of:
When in the corresponding described rule configuration file of described object identifier during multiple business rule, only carry out first qualified business rule.
Accordingly, embodiment of the present invention also provides a kind of warning analysis network management workstation based on Simple Network Management Protocol, and it comprises:
Receiver module, for receiving the warning information of OAMAgent;
Described alarm generation module, for searching corresponding business rule according to described warning information at the rule configuration file prestoring, and generates the warning information that meets service logic according to described business rule;
Described receiver module is for receiving the simple network management protocol trap packet of described OAMAgent;
Described alarm generation module, for simple network management protocol trap packet is resolved, obtains object identifier, and produces an event object model, and described event object model is the data structure of the warning information that described object identifier is corresponding;
According to described object identifier, in the rule configuration file prestoring, search corresponding business rule;
Resolve the binding field information in described event object model, obtain all conditions of the business rule that described object identifier is corresponding, bring the binding field information in described event object model into each condition, generate the warning information that meets service logic.
Wherein, described alarm generation module comprises:
Identifier obtains submodule, for obtaining object identifier according to simple network management protocol trap packet;
Identifier match submodule, for judging whether described object identifier is included in the Simple Network Management Protocol configuration file prestoring, and described Simple Network Management Protocol configuration file comprises the corresponding field information of management information bank nodename;
Analyzing sub-module, resolves for the binding parameter to simple network management protocol trap packet, and produces an event object model, and described event object model is the data structure of the warning information that object identifier is corresponding.
Described alarm generation module also comprises:
Rule match submodule, for judging whether described object identifier is included in the rule configuration file prestoring;
Implementation sub-module, carries out corresponding business rule for the binding parameter that described simple network management protocol trap packet is contained;
The module that bears fruit, for generating the execution result of carrying out described business rule;
Internationalization submodule, for being converted into described execution result the warning information that is applicable to different language user;
Sub module stored, for storing described warning information into database;
Display sub-module, shows described warning information.
Described alarm generation module also comprises:
Chooser module is used for, when the multiple business rule of the corresponding described rule configuration file of described object identifier, only carrying out first qualified business rule.
Embodiment of the present invention also provides a kind of system of the warning analysis based on Simple Network Management Protocol, this system comprises that above-mentioned network management workstation and operates in the OAMAgent on managed device, and described OAMAgent sends alarm to described network management workstation.
Warning analysis method based on Simple Network Management Protocol provided by the invention is owing to having adopted the rule configuration file that comprises business rule, thereby can resolve for the alarm report that has service logic.
In addition, the operation of configuration file is the parallel work-flow of multiple judgment rules.Therefore, performance is more stable, and fault-tolerance is better, and in development process, operating efficiency is higher.And while revising, only need the different parameters of alteration ruler configuration file just can adapt to different situations, development cost is low, reduces maintenance workload.
Meanwhile, described rule judgment process can be used as an independent operational module, is increased in existing system, also can need to from system, delete by difference.Do not affect the running of existing system.
Embodiment
Below in conjunction with the accompanying drawing in embodiment of the present invention, the technical scheme in embodiment of the present invention is clearly and completely described, obviously, described execution mode is only the present invention's part execution mode, rather than whole execution modes.Based on the execution mode in the present invention, those of ordinary skills, not making the every other execution mode obtaining under creative work prerequisite, belong to the scope of protection of the invention.
In embodiment of the present invention, by having adopted the rule configuration file that comprises business rule, thereby can resolve for the alarm report that has service logic.
Refer to Fig. 1, the analytic method based on Simple Network Management Protocol providing for the first execution mode provided by the invention.The method comprises step:
Step 101, the warning information of reception OAMAgent.In present embodiment, OAMAgent 20 from managed devices obtains simple network management protocol trap packet (hereinafter to be referred as SNMP Trap packet), SNMP Trap packet is decoded, extract the OID in decoded SNMP Trap packet, and judge whether to be included in Simple Network Management Protocol configuration file, if the entrained OID value of SNMP Trap packet is identical with the OID value of the data structure of a warning information of preserving in Simple Network Management Protocol configuration file, the binding parameter of SNMP Trap packet is resolved, and produce an event object model.Described Simple Network Management Protocol configuration file is existing configuration file, the xml file that described Simple Network Management Protocol configuration file is defined by third party, comprising MIB (Management Information Base, management information bank) the corresponding field information of nodename.Described event object model is the data structure of the warning information that OID is corresponding.In present embodiment, described data structure is a kind of key-value pair form.
Step 103 is searched corresponding business rule according to described warning information in the rule configuration file prestoring, and generates according to described business rule the warning information that meets service logic.
In present embodiment, described in the rule configuration file that prestores comprise the business rule of at least one corresponding OID.Particularly, described each business rule comprises at least one conditional operation, and described conditional operation can be " being greater than ", " being less than ", compare operations such as " equaling "; Or the conditional operation such as "AND" and "or"; Or redirected alarm name, alarm level, Alarm Classification, alarm details information is at assign operations such as alarm details; Or by the java API that internationalizes, the numeral that SNMP Trap is reported or English name replace with compilation operations of the alarm description that service logic is relevant etc.
In this step, according to described event object model, remove to search corresponding business rule, if there is no corresponding business rule, abandons described event object model so.If there is corresponding business rule, so according to the information of binding parameter in described SNMP Trap packet, carry out corresponding service rule, and generate the warning information that meets service logic.
Refer to Fig. 2, the structured flowchart of the resolution system based on Simple Network Management Protocol 100 providing for first embodiment of the invention.
The resolution system 100 of described Simple Network Management Protocol comprises that network management workstation 10 and operates in the OAMAgent 20 on managed device.
Described OAMAgent 20 is for sending a warning message to described network management workstation 10.In present embodiment, described OAMAgent 20 sends to described network management workstation 10 the SNMP Trap packet that comprises warning information.
Described network management workstation 10 comprises receiver module 11 and alarm generation module 12.
Described receiver module 11 is for receiving the alarm of OAMAgent 20.In present embodiment, described receiver module 11 is produced event object model according to the step 101 of the first execution mode.
Described alarm generation module 12 is for searching corresponding business rule according to described warning information at the rule configuration file prestoring, and generates according to described business rule the warning information that meets service logic.In present embodiment, described alarm generation module 12 obtains a rule configuration file prestoring, described rule configuration file comprises at least one business rule, according to described warning information, in described rule configuration file, search corresponding described business rule, carry out described business rule, generate the warning information that meets service logic.In present embodiment, described receiver module 11 generates the warning information that meets service logic according to the step 103 of the first execution mode.
Refer to Fig. 3, the analytic method based on Simple Network Management Protocol providing for the second execution mode provided by the invention.The method comprises step:
Step 201, the SNMP Trap packet of reception OAMAgent.
Step 203, obtains OID according to SNMP Trap packet.In present embodiment, the SNMP Trap packet obtaining is decoded, then extract the OID in decoded SNMP Trap packet.
Step 205, judges whether described OID is included in the Simple Network Management Protocol configuration file prestoring.In present embodiment, described Simple Network Management Protocol configuration file is existing configuration file, and the xml file that described Simple Network Management Protocol configuration file is defined by third party, comprising the corresponding field information of MIB nodename.
Step 207, when described OID is included in the Simple Network Management Protocol configuration file prestoring, binding parameter to SNMP Trap packet is resolved, and produces an event object model, and described event object model is the data structure of the warning information that OID is corresponding.In present embodiment, described data structure is a kind of key-value pair form.
Step 209, judges whether described OID is included in the rule configuration file prestoring.The described rule configuration file prestoring comprises the business rule of at least one corresponding OID.Particularly, described each business rule comprises at least one conditional operation, and described conditional operation can be " being greater than ", " being less than ", compare operations such as " equaling "; Or the conditional operation such as "AND" and "or"; Or redirected alarm name, alarm level, Alarm Classification, alarm details information is at assign operations such as alarm details; Or by the java API that internationalizes, the numeral that SNMP Trap is reported or English name replace with compilation operations being applicable to different language user etc.Particularly, in present embodiment, in described step 209, first load events rule configuration file then removes to search corresponding business rule in rule configuration file according to OID.
Step 211, when described OID is included in the rule configuration file prestoring, the binding parameter that SNMP Trap packet is contained is carried out corresponding business rule.Particularly, when described OID is included in the rule configuration file prestoring, resolve the binding field information in described event object model.Then obtain all conditions of the business rule that described OID is corresponding, bring the binding field information in described event object model into each condition, and return to the result that each condition is calculated.In present embodiment, return to the results list of Boolean type.Because the binding parameter of described OID may meet multiple conditions, and to cause user to perplex in order preventing, to make user obtain a clear and definite information.In present embodiment, in described business rule, also comprise the operation of "AND" and "or".When the binding parameter of described OID meets multiple condition, each condition is carried out to AND-operation, and obtain the result of AND-operation.In described rule configuration file, also comprise the object information corresponding with AND-operation.When the binding parameter of described OID meets multiple condition, will from described rule configuration file, return to corresponding result.When the binding parameter of described OID meets multiple condition, each condition can also be carried out to OR operation, and obtain the result of OR operation.In present embodiment, when the binding parameter of described OID meets multiple condition, return to the result that first satisfies condition.
Certainly, in present embodiment, for the convenient represented implication of binding field information of revising in described event object model, and need to revise the represented implication of binding field information in described event object model according to difference.Can also be redirected alarm name, alarm level, Alarm Classification and alarm details information.The binding field information being about in described event object model need to define different alarm name, alarm level, Alarm Classification and alarm details information according to difference.For example, corresponding same alarm name can be defined as environment and report to the police, and also can be defined as temperature alarming.Alarm level can, according to the adaptability of system, be defined as high severity alarm or fatal warning to same alarm level.
Certainly, in execution mode, can also directly the binding field information in described event object model or above-mentioned redirected alarm name, alarm level, Alarm Classification and alarm details information exchange be crossed to java internationalization API, be revised as the information that is applicable to different language crowd.This step is carried out and is conducive to improve treatment effeciency after step 205.Without the binding parameter that all SNMP Trap packets are contained, resolve.
Step 213, when in the corresponding described rule configuration file of described OID during multiple business rule, only carries out first qualified business rule.In present embodiment, when the binding parameter of described OID meets multiple condition, also each condition can be carried out to AND-operation, and obtain the result of AND-operation.In described rule configuration file, also comprise the object information corresponding with AND-operation.When the binding parameter of described OID meets multiple condition, will from described rule configuration file, return to corresponding result.
Step 215, generates the execution result of carrying out described business rule.In present embodiment, obtain the execution result of carrying out described business rule, and the execution result of described business rule is converted to event.
Step 217, is converted into described execution result the warning information that is applicable to different language user.In present embodiment, by the java API that internationalizes, the numeral in described execution result, character code, date etc. are converted into the information that is applicable to different language user.Particularly, load internationalized resources file, resolve and in described execution result, need the resource that internationalize and process, by the binding field information in described execution result and resource information binding, generate and the customization event of traffic aided.The process of the conversion of language is carried out in this step, rather than carried out in step 209, can only to satisfactory information, transform, and without all information is all transformed, can raise the efficiency.
Step 219, stores described warning information in database into.In present embodiment, described customization event is converted to the alarm object of the system of being applicable to, then the warning information in described alarm object is stored in database.
Step 221, shows described warning information.In present embodiment, described warning information is shown on interface.
In described step 209, when described OID is not included in the rule configuration file prestoring, carries out other operations, and no longer carry out follow-up step 211-221.
In described step 205, when described OID is not included in the Simple Network Management Protocol configuration file prestoring, carries out other operations, and no longer carry out follow-up step 207-221.
In other embodiments, described step 219 and step 221 can be optional one.
Refer to Fig. 4, the resolution system based on Simple Network Management Protocol 300 that second embodiment of the invention provides and the resolution system based on Simple Network Management Protocol 100 of the first execution mode are basic identical.
The described resolution system 300 based on Simple Network Management Protocol comprises receiver module 310 and alarm generation module 320.
Described receiver module 310 is for receiving the SNMP Trap packet of OAMAgent.
Described alarm generation module 320 comprises that identifier obtains submodule 321, identifier match submodule 322, alarm generation module 323, analyzing sub-module 324, rule match submodule 325, implementation sub-module 326, chooser module 327, the module that bears fruit 328, internationalization submodule 329, sub module stored 330 and display sub-module 331.
Described identifier obtains submodule 321 for obtaining OID according to SNMP Trap packet.In present embodiment, described identifier obtains submodule 322 and adopts the method for described step 203 to extract the OID in SNMP Trap packet.
Described identifier match submodule 323 is for judging whether described OID is included in the Simple Network Management Protocol configuration file prestoring.In present embodiment, described identifier match submodule 323 adopts the method judgement of described step 205.
Described analyzing sub-module 324 is for the binding parameter of SNMP Trap packet is resolved, and produces an event object model, and described event object model is the data structure of the warning information that OID is corresponding.In present embodiment, described data structure is a kind of key-value pair form.
Described rule match submodule 325 is for judging whether described OID is included in the rule configuration file prestoring.In present embodiment, described rule match submodule 325 adopts the method for step 209 to judge whether described OID is included in the rule configuration file prestoring.
Described implementation sub-module 326 is carried out corresponding business rule for the binding parameter that described SNMP Trap packet is contained.In present embodiment, the binding parameter that described implementation sub-module 326 adopts the method for step 211 to contain described SNMP Trap packet is carried out corresponding business rule.
Described chooser module 327, for when the multiple business rule of the corresponding described rule configuration file of described OID, is only carried out first qualified business rule.
The described module 328 that bears fruit is for generating the execution result of carrying out described business rule.In present embodiment, obtain the execution result of carrying out described business rule, and the execution result of described business rule is converted to event.
Described internationalization submodule 329 is for being converted into described execution result the warning information that is applicable to different language user.In present embodiment, described internationalization submodule 329 adopts the method for step 217 to carry out language conversion.
Described sub module stored 330 is for storing described warning information into database.In present embodiment, described sub module stored 330 is converted to described customization event the alarm object of the system of being applicable to, and then the warning information in described alarm object is stored in database.
Described display sub-module 332 shows described warning information.In present embodiment, described warning information is shown on interface.
Because increase many hard codeds that judge statement outside Simple Network Management Protocol configuration file, respectively judge between statement and have upper and lower hierarchical relationship, revise one of them and judge statement, will do corresponding modify to other statements afterwards, easily make mistakes, not easy care.Debug process time while is long, and the construction cycle is long.And analytic method based on Simple Network Management Protocol provided by the invention and system are owing to having adopted rule configuration file, the operation of configuration file is the parallel work-flow of multiple judgment rules, and therefore, performance is more stable, fault-tolerance is better, and in development process, operating efficiency is higher.And while revising, only need the different parameters of alteration ruler configuration file just can adapt to different situations, development cost is low, reduces maintenance workload.In addition, described rule judgment process can be used as an independent operational module, is increased in existing system, also can need to from system, delete by difference.Do not affect the running of existing system.
Above disclosed is only a kind of preferred embodiments of the present invention, certainly can not limit with this interest field of the present invention, and the equivalent variations of therefore doing according to the claims in the present invention, still belongs to the scope that the present invention is contained.