CN102571424A - Processing method, device and system for engineering event - Google Patents

Processing method, device and system for engineering event Download PDF

Info

Publication number
CN102571424A
CN102571424A CN2011104536211A CN201110453621A CN102571424A CN 102571424 A CN102571424 A CN 102571424A CN 2011104536211 A CN2011104536211 A CN 2011104536211A CN 201110453621 A CN201110453621 A CN 201110453621A CN 102571424 A CN102571424 A CN 102571424A
Authority
CN
China
Prior art keywords
engineering
event
incident
network equipment
rules
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2011104536211A
Other languages
Chinese (zh)
Inventor
欧阳辉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Service Co Ltd
Original Assignee
Huawei Technologies Service Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Service Co Ltd filed Critical Huawei Technologies Service Co Ltd
Priority to CN2011104536211A priority Critical patent/CN102571424A/en
Publication of CN102571424A publication Critical patent/CN102571424A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The embodiment of the invention discloses a processing method, a processing device and a processing system for an engineering event. The method comprises the following steps of: extracting event attribute information from an obtained event; acquiring event source information for the production of the event from the event attribute information, wherein the event source information comprises the sub-object information of network equipment; and searching for rule item records matched with the event source information from configured engineering event rules by taking the event source information as an index condition, and if the matched rule item records are found, identifying the event as the engineering event. Therefore, the event status of the network equipment is subdivided to a sub-object of the network equipment, and the event produced by the sub-object of the network equipment is identified to realize the accurate identification of the engineering event.

Description

A kind of engineering event-handling method, device and system
Technical field
The present invention relates to communication technical field, particularly a kind of engineering event-handling method, device and system.
Background technology
During network equipment engineering maintenance, as: upgrading, patch, dilatation, network adjustment, configuration operation etc., the network equipment can report a large amount of engineering incidents.Specific as follows through the flow process of network element ID engineering state at present:
(1) NMS issues the network element engineering state and rule is set to Element management system;
(2) Element management system is handed down to corresponding net element with the engineering state setting;
(3) network element returns engineering state results messages is set;
(4) network element detects fault, produces alarm;
(5) network element, is the engineering alarm with alarm identifier then, otherwise is normal alarm if network element is in engineering state according to the engineering state processing policy;
(6) alarm of reported by network elements band engineering state sign is to Element management system;
(7) Element management system will forward NMS to the alarm of engineering state sign;
(8) monitoring client is showed alarm, and shows the engineering state sign;
From the existing network data analysis, adopt above flow process to carry out reporting of engineering incident, the engineering incident accounts for about 30% of total volume of event.In fact belong to normal incident owing to the engineering incident, the monitor staff can monitor these incidents, but daily monitoring of the normal incident of these events affectings and maintenance reduce maintenance efficiency greatly.
Summary of the invention
The embodiment of the invention provides a kind of engineering event-handling method, device and system, realizes accurate recognitive engineering incident.
The embodiment of the invention provides a kind of engineering event-handling method, and this method comprises:
From the incident that obtains, extract event attribute information;
From said event attribute information, obtain the event source information of generation incident, said event source information comprises: the subobject information of the network equipment;
, searching and said event source information matching rules item record from the engineering event rules of configuration as the index condition with said event source information, if matching rules item record is found, is the engineering incident with said event identifier then.
The embodiment of the invention also provides a kind of engineering event handling system, and this system comprises the network equipment and monitoring server, wherein:
The said network equipment is used for: when detecting the fault of self, produce the incident of the said fault of representative, and send said incident to said monitoring server;
Said monitoring server is used for: receive the incident from the network equipment; From said incident, extract event attribute information; From said event attribute information, obtain the event source information of generation incident, said event source information comprises: the subobject information of the network equipment; , searching and said event source information matching rules item record from the engineering event rules of configuration as the index condition with said event source information, if matching rules item record is found, is the engineering incident with said event identifier then.
The embodiment of the invention also provides another kind of engineering event handling system, and this system comprises the monitoring server and the network equipment, wherein:
The said network equipment is used for: when detecting the fault of self, produce the incident of the said fault of representative, and from the incident of said generation, extract event attribute information; From said event attribute information, obtain the event source information of generation incident, said event source information comprises: the subobject information of the network equipment; With said event source information as the index condition; From the engineering event rules of configuration, search and said event source information matching rules item record; If matching rules item record is found, and is the engineering incident with said event identifier then, send all incidents to said monitoring server;
Said monitoring server is used for: receive the incident that the said network equipment sends, report the engineering incident according to the engineering reporting events strategy that disposes, said engineering reporting events strategy indicates whether to report the engineering incident; If said engineering reporting events strategy indication reports the engineering incident, then report the incident that is designated the engineering incident; If said engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
The embodiment of the invention also provides a kind of engineering event processing apparatus, and this device comprises:
The incident acquiring unit is used for extracting event attribute information from incident;
The object acquisition unit is used for obtaining from said event attribute information the event source information of generation incident, and said event source information comprises: the subobject information of the network equipment;
Identify unit is used for said event source information as the index condition, from the engineering event rules of configuration, searches and said event source information matching rules item record, if matching rules item record is found, be the engineering incident then with said event identifier.
Can find out that from above technical scheme the embodiment of the invention provides a kind of methods, devices and systems of engineering event handling, through from the incident that obtains, extracting event attribute information; From said event attribute information, obtain the event source information of generation incident, said event source information comprises: the subobject information of the network equipment; With said event source information as the index condition; From the engineering event rules of configuration, search and said event source information matching rules item record; If the matching rules record is found, be the engineering incident then, thereby the state-event of the network equipment is sub-divided into the subobject of the network equipment said event identifier; And the incident that the subobject of the network equipment is produced identifies, and realized accurate recognitive engineering incident.
Description of drawings
In order to be illustrated more clearly in the technical scheme in the embodiment of the invention; The accompanying drawing of required use is briefly introduced in will describing embodiment below; Obviously, the accompanying drawing in describing below only is some embodiments of the present invention, for those of ordinary skill in the art; Under the prerequisite of not paying creative work property, can also obtain other accompanying drawing according to these accompanying drawings.
Fig. 1 is an embodiment of the invention method flow sketch map;
Fig. 2 is an embodiment of the invention method flow sketch map;
Fig. 3 is an embodiment of the invention method flow sketch map;
Fig. 4 is the structural representation of embodiment of the invention engineering event handling equipment;
Fig. 5 a is an embodiment of the invention system configuration sketch map;
Fig. 5 b is an embodiment of the invention system configuration sketch map;
Fig. 6 is an embodiment of the invention system configuration sketch map;
Fig. 7 is an embodiment of the invention system configuration sketch map;
Fig. 8 is an embodiment of the invention apparatus structure sketch map;
Fig. 9 is an embodiment of the invention apparatus structure sketch map;
Figure 10 is an embodiment of the invention apparatus structure sketch map.
Embodiment
In order to make the object of the invention, technical scheme and advantage clearer, will combine accompanying drawing that the present invention is done to describe in detail further below, obviously, described embodiment only is a part of embodiment of the present invention, rather than whole embodiment.Based on the embodiment among the present invention, those of ordinary skills are not making all other embodiment that obtained under the creative work prerequisite, all belong to the scope of the present invention's protection.
The inventor analyzes the flow process of background technology in the process that realizes the embodiment of the invention:
Because the continuous lifting of single network equipment control ability, the network range that single network equipment is managed constantly enlarges, and the engineering maintenance activity is some veneer of the network equipment or port often, is not that the whole network equipment is all done the engineering maintenance; Because the flow process in the background technology is supported whole network equipment engineering state, the local engineering state of network enabled equipment not; Along with the continuous expansion of network size, engineering maintenance activity meeting is frequent more, and the engineering state rule need frequently be set, and workload is big, and maintenance efficiency reduces.In addition, handle,, then require whole network equipment all need realize the engineering state recognition function, realize that cost is high, is difficult for applying if the whole network all need be supported engineering state because background technology flow process network enabled equipment side carries out engineering state identification.
Technical term is in embodiments of the present invention explained as follows: engineering state is meant a kind of state during the network equipment is in engineering maintenance.The engineering incident is meant the network equipment because the incident that fault produced that the engineering maintenance activity causes.The engineering maintenance planning table is meant the specific timetable of network equipment engineering maintenance (like upgrading, patch, dilatation, network adjustment, configuration operation etc.), comprising information such as engineering maintenance object, engineering time sections.The engineering event rules is meant whether be used for decision event belongs to the tactful or regular of engineering incident.Fine granularity engineering event rules refers to comprise the engineering event rules of subobject fine granularity objects such as (as: veneer, ports etc.).
The embodiment of the invention provides a kind of engineering event-handling method, and is as shown in Figure 1, comprising:
101: from the incident that obtains, extract event attribute information;
In this step; The mode of obtaining event attribute information can have a lot; For example: receive incident, from above-mentioned incident, extract event attribute information, perhaps from the fault of the network equipment; The network equipment carries out fault detect to himself, and obtains the event attribute information of detected event of failure.That is: this event attribute information source can be that network equipment monitoring obtains self, also can be to come from the event attribute information that the network equipment reports.Present embodiment will not limit this.
102: from above-mentioned event attribute information, obtain the event source information of generation incident, above-mentioned event source information comprises: the subobject information of the network equipment;
The embodiment of the invention is for the engineering state of accurate recognition network equipment; Satisfy the accurate identification of engineering incident during the local engineering maintenance of large equipment; This instance is through being provided with the engineering event rules; The engineering event rules can comprise: the information such as time period that the subobject of the network equipment, the network equipment (that is: each part of the network equipment, like veneer, port etc.), engineering incident take place.Because the engineering event rules is segmented, and also can be called fine granularity engineering event rules.Need to prove,, can only comprise the purple object of the network equipment so in the engineering event rules, also can comprise the subobject of the network equipment and the network equipment simultaneously if event source information includes only the subobject of the network equipment.
103:, searching and above-mentioned event source information matching rules item record from the engineering event rules of configuration as the index condition with above-mentioned event source information, if the matching rules record is found, is the engineering incident with above-mentioned event identifier then.It is understandable that, if can not find the matching rules record, can be normal event with above-mentioned event identifier then, and the embodiment of the invention will not limit whether identifying normal event.
The state-event of the network equipment is sub-divided into the subobject of the network equipment, and the incident that the subobject of the network equipment produces is identified, realized accurate recognitive engineering incident, and condition is provided for the filtration of engineering incident.
Further; In 102, also comprise: network equipment information as if above-mentioned event source information; Said method also comprises: with above-mentioned network equipment information as the index condition; From the engineering event rules of above-mentioned configuration, searching and above-mentioned network equipment matching rules item record, if the matching rules record is found, is the engineering incident with above-mentioned event attribute message identification then.
In 103, the engineering event rules can preset, and also can be that the user is provided with, because the engineering event rules can be the rule that the user imports, also can be the form of input, and said method also comprises so: receive the engineering event rules; Perhaps, receive the engineering maintenance planning table, and resolve above-mentioned engineering maintenance planning table and obtain the engineering event rules.
Particularly, above-mentioned engineering event rules comprises: the subobject of the network equipment, and the corresponding engineering time section of the subobject of the network equipment;
Event source information and engineering event rules coupling comprises in so above-mentioned 103:
Above-mentioned event source information belongs to the subobject of the network equipment in the above-mentioned engineering event rules, and the generation of the incident of above-mentioned event source information belongs to the corresponding engineering time section of subobject of the above-mentioned network equipment constantly.
Further; After the engineering incident was labeled, the strategy that the strategy that can be used to show also can be used to report was if be used to report; Said method also comprises so: receive engineering reporting events strategy, above-mentioned engineering reporting events strategy indicates whether to report the engineering incident; If above-mentioned engineering reporting events strategy indication reports the engineering incident, then report the incident that is designated the engineering incident; If above-mentioned engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
Above embodiment can be carried out by the network equipment; Also can carry out by monitoring server or other equipment; Said method can also be divided the work to carry out by a plurality of entity devices; Adopt different allocative decisions to have the different techniques effect, below provide two for example: the network equipment carries out fault detect to himself, and the event attribute information of fault is sent to monitoring server; Monitoring server receives the event attribute information from the fault of the network equipment; Above-mentioned monitoring server obtains the event source information of generation incident from the incident attribute information; Above-mentioned event source information comprises: the subobject of the network equipment; If above-mentioned event source information and engineering event rules coupling, then above-mentioned monitoring server is the engineering incident with above-mentioned event attribute message identification; If do not match, then be designated normal event; Perhaps, the network equipment carries out fault detect to himself, and obtains the event attribute information of detected fault; From the incident attribute information, obtain the event source information of generation incident; Above-mentioned event source information comprises: the subobject of the network equipment; If above-mentioned event source information and engineering event rules coupling are the engineering incident with above-mentioned event attribute message identification then; If do not match, then be designated normal event.The embodiment of the invention will be illustrated in subsequent instance at this point.
Instance one, as shown in Figure 2, idiographic flow is following:
201: the user imports to monitor terminal with " engineering maintenance planning table " information; This instance adopts the engineering maintenance planning table to carry the relevant information of engineering event rules.For the engineering event rules efficiently is set; The support of this instance monitor terminal imports " engineering maintenance planning table " automatically; Generate the engineering event rules; Monitor terminal support extend markup language (Extensible Markup Language, XML), comma separated value file (Comma Separated value, CSV), text (TXT; A kind of ASCII American Standard Code for Information Interchange, ASCII text file) etc. the engineering maintenance planning table file of form imports automatically.As shown in table 1, be the example of " engineering maintenance rule list ".
Table 1
Figure BDA0000126756140000071
202: monitor terminal reads " engineering maintenance planning table " file;
203: monitor terminal is resolved " engineering maintenance planning table " file, and obtains engineering maintenance information;
204: the engineering maintenance information translation that monitor terminal will derive from the engineering maintenance planning table is the engineering event rules of supervisory control system; The concrete realization of above-mentioned conversion can be: read the network equipment/subobject in the engineering maintenance planning table file, implement the engineering maintenance time started, implement engineering maintenance concluding time information, then according to these information setting engineering event rules in supervisory control system.The network equipment/subobject in the engineering maintenance planning table information, enforcement engineering maintenance time started, enforcement engineering maintenance concluding time are with the network equipment/subobject in the engineering event rules, engineering time section correspondence.Engineering event rules example is as shown in table 2.
Table 2
Figure BDA0000126756140000072
205: monitor terminal issues the engineering event rules to monitoring server;
206: monitoring server storage engineering event rules, the engineering event rules is the fine granularity rule, rule comprises information such as the network equipment, subobject, engineering time section; Storage engineering incident can also be returned response message to monitor terminal later, to acknowledge receipt of the engineering event rules;
207: the network equipment detects fault, the generation incident;
208: network equipment reported event message; Carried the incident that need report in this event message, this incident might be that the engineering incident also possibly be a normal event;
209: engineering event analysis device carries out the engineering event analysis according to the engineering event rules;
Shown in Figure 2, engineering event analysis device is positioned at monitoring server.In fact engineering event analysis device is positioned at monitor terminal and also is fine.
210: the network equipment and the subobject information of from incident, obtaining the generation incident;
211: use the network equipment and subobject information to mate, mate successfully, then think the engineering incident, otherwise be normal event in the network equipment, subobject and the time period information of engineering event rules;
212: subobject carries out cascade coupling, if that is: parent object is in engineering state, then its all subobjects are all thought and are in engineering state.The network equipment is the parent object of the subobject of the network equipment.Need to prove: subobject is represented with the network equipment as shown in table 2 and subobject in event attribute information, can directly get access to the network equipment at above-mentioned subobject place so; Do not comprise the network equipment if only comprise subobject in the event attribute information, can also get access to the network equipment at above-mentioned subobject place so through the source of engineering incident, as for the parent object that how to get access to subobject, the embodiment of the invention does not limit.
213: after analyzing completion, on event attribute information, increase the engineering state attribute, if the engineering incident then is designated the engineering incident with engineering state, i.e. " engineering attitude ", otherwise be designated normal event, i.e. " normal state ";
214: the incident of transmitting band engineering state attribute is to monitor terminal; Filtration can be accomplished also and can accomplish in follow-up 215 steps in this step; Sign in 213 steps provides condition for filtration.
If realize filtering 214, the engineering incident can not need be forwarded to monitor terminal, reduces network traffics.
215: the monitor terminal presented event, can conveniently check the engineering state attribute in this step, and can filter by the engineering state attribute.
Instance two, as shown in Figure 3, idiographic flow is following:
Different with instance one is: this instance is in order to support a small amount of engineering maintenance scene, and engineering event rules support maintenance personnel are provided with one by one or revise through supervisory control system is manual.The engineering incident common attendant need not pay close attention to, and in this example, the attendant can be set to the engineering incident through supervisory control system and not be forwarded to monitor terminal.
301: the user is through the manual fine granularity engineering event rules that is provided with of monitor terminal;
302: monitor terminal issues fine granularity engineering event rules to monitoring server;
303: monitoring server issues fine granularity engineering event rules to the network equipment;
304: network equipment storage fine granularity engineering event rules; Simultaneously can also return response message, receive to confirm fine granularity engineering event rules to monitoring server and monitor terminal.
305: the user is provided with not forwarding strategy of engineering incident through monitor terminal; This step and following engineering incident not be provided with flow process and the top fine granularity engineering event rules of forwarding strategy are provided with flow performing and do not have precedence relation in proper order.
306: monitor terminal issue the engineering incident not forwarding strategy to monitoring server;
307: monitoring server storage engineering incident is forwarding strategy not; Simultaneously can also return response message to monitor terminal, with confirm the engineering incident not forwarding strategy receive.
308: the network equipment detects fault, produces event attribute information;
309: the network equipment is analyzed according to fine granularity engineering event rules, identifies the engineering incident; Be specially: from above-mentioned event attribute information, obtain the event source information of generation incident, if above-mentioned event source information and engineering event rules coupling confirm that then above-mentioned event attribute information is the engineering incident.
310: the network equipment increases an engineering state attribute on event attribute information, if the engineering incident, then engineering state is designated the engineering incident, i.e. and " engineering attitude ", otherwise be designated normal event, i.e. " normal state ";
311: the network equipment reports the incident of band " engineering state " attribute to monitoring server;
312: monitoring server according to the engineering incident not forwarding strategy filter out the engineering incident;
313: monitoring server is only transmitted normal event;
In 313 steps, the engineering incident need not be forwarded to monitor terminal, reduces network traffics.314: monitor terminal shows normal event.
The relevant treatment of engineering incident can be carried out at the network equipment, monitoring server or monitor terminal in the embodiment of the invention; As shown in Figure 4; This structure can be positioned at any end of above three, preferably can be according to the functional unit of aforementioned this structure of 3 instances distribution.Comprise: engineering event analysis device 4100 represents 4200 liang of big modules with the engineering incident.Wherein engineering event analysis 4100 comprises: engineering maintenance planning document processing module 4101, regular modular converter 4102, engineering event rules memory module 4103, rule match analysis module 4014, engineering event identifier module 4105, engineering event processing module 4106; The engineering incident represents 4200 and comprises: engineering state attribute display module 4201, engineering state filtering module 4202;
Engineering maintenance planning document processing module 4101: be responsible for reading and resolving of engineering maintenance planning file, and obtain engineering maintenance information.
Rule modular converter 4102: be responsible for the engineering maintenance information translation is become the fine-grained engineering event analysis rule in the supervisory control system.The network equipment/subobject in the engineering maintenance planning table information, enforcement engineering maintenance time started, enforcement engineering maintenance concluding time are with the network equipment/subobject in the engineering event rules, engineering time section correspondence.
Engineering event rules memory module 4103: rule and the manual engineering event rules that is provided with of user being responsible for monitor terminal is imported store on the monitoring server.
Rule match analysis module 4104: be responsible for the network equipment and subobject information in the extraction incident, mate with fine granularity engineering event rules then, mate and successfully then think the engineering incident, otherwise be normal event.
Engineering event identifier module 4105: be responsible on event attribute information, increasing " engineering state " attribute, the engineering event identifier is " an engineering attitude ", and other event identifiers are " normal state ".
Engineering event processing module 4106: the responsible engineering incident that is provided with according to the user not forwarding strategy filters out the engineering incident, is not forwarded to monitor terminal.
The engineering incident represents module 4201: be responsible for representing engineering incident and normal event, represent " engineering state " attribute, let the user see easily which is the engineering incident, and which is a normal event.
Engineering state filtering module 4202: be responsible for filtering according to engineering state, the user can select to check or not check the engineering incident through the engineering state filtercondition is set." engineering state filtering module " and " engineering event processing module " if two have, can be realized flexible setting.If have only one, also can work independently; Need to prove: if " engineering event processing module " carried out event filtering, " engineering state filtering module " is inoperative, because can not receive the incident of engineering state.
Shown in Fig. 5 a, the embodiment of the invention also provides a kind of engineering event handling system, comprising: the network equipment 501 and monitoring server 502;
The above-mentioned network equipment 501 is used for: when detecting the fault of self, produce the incident of the above-mentioned fault of representative, and send above-mentioned incident to above-mentioned monitoring server 502;
Above-mentioned monitoring server 502 is used for: receive the incident from the network equipment; From above-mentioned incident, extract event attribute information; From above-mentioned event attribute information, obtain the event source information of generation incident, above-mentioned event source information comprises: the subobject information of the network equipment; , searching and above-mentioned event source information matching rules item record from the engineering event rules of configuration as the index condition with above-mentioned event source information, if the matching rules record is found, is the engineering incident with above-mentioned event identifier then.
Further; If above-mentioned event source information also comprises: network equipment information; Above-mentioned monitoring server 502 also is used for: with above-mentioned network equipment information as the index condition; From the engineering event rules of above-mentioned configuration, searching and above-mentioned network equipment matching rules item record, if the matching rules record is found, is the engineering incident with above-mentioned event attribute message identification then.
Further, shown in Fig. 5 b, said above-mentioned supervisory control system also comprises monitor terminal 503, and above-mentioned monitor terminal 503 is used for: receive the engineering event rules that the user is provided with, and said above-mentioned engineering event rules is sent to said above-mentioned monitoring server; Perhaps, receive the engineering maintenance planning table that the user is provided with, resolve said above-mentioned engineering maintenance planning table and obtain the engineering event rules, and said above-mentioned engineering event rules is sent to said above-mentioned monitoring server; Perhaps, receive the engineering maintenance planning table, and the said above-mentioned engineering maintenance planning table that will comprise the engineering event rules sends to said above-mentioned monitoring server; If what above-mentioned monitor terminal 503 sent to monitoring server 502 is the engineering maintenance planning table, then above-mentioned monitoring server also is used for: receive the engineering maintenance planning table that above-mentioned monitor terminal sends, resolve above-mentioned engineering maintenance planning table and obtain the engineering event rules.
Further, above-mentioned monitor terminal 503 also is used to receive engineering reporting events strategy, and above-mentioned engineering reporting events strategy indicates whether to report the engineering incident; And above-mentioned engineering reporting events strategy sent to monitoring server 502; Affiliated monitoring server 502 also is used for: receive the above-mentioned engineering reporting events strategy that monitor terminal sends, if the indication of above-mentioned engineering reporting events strategy reports the engineering incident, then report the incident that is designated the engineering incident; If above-mentioned engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
As shown in Figure 6, the embodiment of the invention also provides another kind of engineering event handling system, comprising:
Monitoring server 601 is used to receive the incident that the above-mentioned network equipment sends, and reports the engineering incident according to the engineering reporting events strategy that disposes, and above-mentioned engineering reporting events strategy indicates whether to report the engineering incident; If above-mentioned engineering reporting events strategy indication reports the engineering incident, then report the incident that is designated the engineering incident; If above-mentioned engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
The network equipment 602 is used for: when detecting the fault of self, produce the incident of the above-mentioned fault of representative, and from the incident of above-mentioned generation, extract event attribute information; From above-mentioned event attribute information, obtain the event source information of generation incident, above-mentioned event source information comprises: the subobject information of the network equipment; With above-mentioned event source information as the index condition; From the engineering event rules of configuration, search and above-mentioned event source information matching rules item record; If the matching rules record is found, and is the engineering incident with above-mentioned event identifier then, send all incidents to above-mentioned monitoring server;
Further; If above-mentioned event source information also comprises: network equipment information; The above-mentioned network equipment 602 also is used for: with above-mentioned network equipment information as the index condition; From the engineering event rules of above-mentioned configuration, searching and above-mentioned network equipment matching rules item record, if the matching rules record is found, is the engineering incident with above-mentioned event attribute message identification then.
Further, as shown in Figure 7, above-mentioned supervisory control system also comprises monitor terminal 603;
Monitor terminal 603 is used for: receive the engineering event rules that the user is provided with, and above-mentioned engineering event rules is sent to monitoring server 601; Perhaps, receive the engineering maintenance planning table that the user is provided with, resolve above-mentioned engineering maintenance planning table and obtain the engineering event rules, and above-mentioned engineering event rules is sent to monitoring server 601; Perhaps, receive the engineering maintenance planning table, and the above-mentioned engineering maintenance planning table that will comprise the engineering event rules sends to monitoring server 601;
Monitoring server 601 also is used for: receive the engineering event rules that monitor terminal 603 sends, and above-mentioned engineering event rules is sent to the network equipment 602; Perhaps,
Receive the engineering maintenance planning table that monitor terminal sends, resolve above-mentioned engineering maintenance planning table and obtain the engineering event rules, and above-mentioned engineering event rules is sent to the network equipment 602.
In addition, as shown in Figure 7, above-mentioned monitor terminal 603 can also be used for: receive the engineering reporting events strategy that the user is provided with, and above-mentioned engineering reporting events strategy is sent to monitoring server 601; Accordingly, monitoring server 601 also is used for: receive and store the engineering reporting events strategy that above-mentioned monitor terminal sends.
Need to prove that the supervisory control system that the embodiment of the invention provides can adopt client/server, and (Client/Server, C/S) structure also can adopt browser/server (Browser/Server, B/S) structure; Monitor terminal and monitoring server can be deployed on the physical machine simultaneously, and for example the form with virtual machine is deployed on the physical machine, also can be deployed in respectively on the physical machine with communication connection of two platform independent; Supervisory control system can have one or more monitor terminal, also one or more monitoring server can be arranged.In addition; The physical machine that the embodiment of the invention is used can be a physical computer; Specifically can be personal computer PC, notebook computer laptop, work station Workstation, server S erver, large-scale computer Mainframe or supercomputer Supercomputer, perhaps specifically can be mobile phone, intelligent terminal or the like.
As shown in Figure 8, the embodiment of the invention also provides a kind of engineering event processing apparatus, comprising:
Incident acquiring unit 801 is used for extracting event attribute information from incident;
Object acquisition unit 802 is used for obtaining from above-mentioned event attribute information the event source information of generation incident, and above-mentioned event source information comprises: the subobject information of the network equipment;
Identify unit 803 is used for above-mentioned event source information as the index condition, from the engineering event rules of configuration, searches and above-mentioned event source information matching rules item record, if the matching rules record is found, be the engineering incident then with above-mentioned event identifier.
Alternatively; If above-mentioned event source information also comprises: network equipment information; Above-mentioned identify unit also is used for: with above-mentioned network equipment information as the index condition; From the engineering event rules of above-mentioned configuration, searching and above-mentioned network equipment matching rules item record, if the matching rules record is found, is the engineering incident with above-mentioned event attribute message identification then.
Further, as shown in Figure 9, said apparatus also comprises:
Rule receiving element 901 is used to receive the engineering event rules, perhaps, receives the engineering maintenance planning table;
If what receive is the engineering maintenance planning table, then said apparatus also comprises: resolution unit 902 is used to resolve the engineering maintenance planning table and obtains the engineering event rules.
Alternatively, above-mentioned engineering event rules comprises: the subobject of the network equipment, and the corresponding engineering time section of the subobject of the network equipment;
Above-mentioned identify unit 803 specifically is used for; If above-mentioned event source information belongs to the subobject of the network equipment in the above-mentioned engineering event rules; And the generation of the incident of above-mentioned event source information belongs to the corresponding engineering time section of subobject of the above-mentioned network equipment constantly, is the engineering incident with above-mentioned event attribute message identification then.
Further, shown in figure 10, said apparatus also comprises: tactful receiving element 1001 with report unit 1002;
Strategy receiving element 1001 is used to receive engineering reporting events strategy, and above-mentioned engineering reporting events strategy indicates whether to report the engineering incident;
Report unit 1002, be used for then reporting the incident that is designated the engineering incident if the indication of above-mentioned engineering reporting events strategy reports the engineering incident; If above-mentioned engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
It should be noted that among the said equipment embodiment that each included unit is just divided according to function logic, but is not limited to above-mentioned division, as long as can realize function corresponding; In addition, the concrete title of each functional unit also just for the ease of mutual differentiation, is not limited to protection scope of the present invention.
In addition; One of ordinary skill in the art will appreciate that all or part of step that realizes among above-mentioned each method embodiment is to instruct relevant hardware to accomplish through program; Corresponding program can be stored in a kind of computer-readable recording medium, and the above-mentioned storage medium of mentioning can be read-only memory, random asccess memory, disk or CD etc.
More than be merely the preferable embodiment of the present invention; But protection scope of the present invention is not limited thereto; Any technical staff who is familiar with the present technique field is in the technical scope that the embodiment of the invention discloses, and the variation that can expect easily or replacement all should be encompassed within protection scope of the present invention.Therefore, protection scope of the present invention should be as the criterion with the protection range of claim.

Claims (16)

1. an engineering event-handling method is characterized in that, said method comprises:
From the incident that obtains, extract event attribute information;
From said event attribute information, obtain the event source information of generation incident, said event source information comprises: the subobject information of the network equipment;
, searching and said event source information matching rules item record from the engineering event rules of configuration as the index condition with said event source information, if matching rules item record is found, is the engineering incident with said event identifier then.
2. according to the said method of claim 1, it is characterized in that said event source information also comprises: network equipment information, said method also comprises:
, from the engineering event rules of said configuration, searching and said network equipment matching rules item record as the index condition with said network equipment information, if the matching rules record is found, is the engineering incident with said event attribute message identification then.
3. according to the said method of claim 1, it is characterized in that said method also comprises:
Receive the engineering event rules; Perhaps,
Receive the engineering maintenance planning table, and resolve said engineering maintenance planning table and obtain the engineering event rules.
4. according to any said method of claim 1 to 3, it is characterized in that said method also comprises:
Receive engineering reporting events strategy, said engineering reporting events strategy indicates whether to report the engineering incident;
If said engineering reporting events strategy indication reports the engineering incident, then report the incident that is designated the engineering incident; If said engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
5. an engineering event handling system is characterized in that, said system comprises the network equipment and monitoring server, wherein:
The said network equipment is used for: when detecting the fault of self, produce the incident of the said fault of representative, and send said incident to said monitoring server;
Said monitoring server is used for: receive the incident from the network equipment; From said incident, extract event attribute information; From said event attribute information, obtain the event source information of generation incident, said event source information comprises: the subobject information of the network equipment; , searching and said event source information matching rules item record from the engineering event rules of configuration as the index condition with said event source information, if matching rules item record is found, is the engineering incident with said event identifier then.
6. according to the said system of claim 5; It is characterized in that; Said event source information also comprises: network equipment information, and said monitoring server also is used for:, from the engineering event rules of said configuration, search and said network equipment matching rules item record as the index condition with said network equipment information; If the matching rules record is found, and is the engineering incident with said event attribute message identification then.
7. according to the said system of claim 5, it is characterized in that said supervisory control system also comprises monitor terminal;
Said monitor terminal is used for: receive the engineering event rules that the user is provided with, and said engineering event rules is sent to said monitoring server; Perhaps,
Receive the engineering maintenance planning table that the user is provided with, resolve said engineering maintenance planning table and obtain the engineering event rules, and said engineering event rules is sent to said monitoring server; Perhaps,
Receive the engineering maintenance planning table, and the said engineering maintenance planning table that will comprise the engineering event rules sends to said monitoring server;
If what said monitor terminal sent to monitoring server is the engineering maintenance planning table, then said monitoring server also is used for: receive the engineering maintenance planning table that said monitor terminal sends, resolve said engineering maintenance planning table and obtain the engineering event rules.
8. according to the said system of claim 7, it is characterized in that,
Said monitor terminal also is used for: receive engineering reporting events strategy, said engineering reporting events strategy indicates whether to report the engineering incident; And said engineering reporting events strategy sent to monitoring server;
Said monitoring server also is used for: receive the said engineering reporting events strategy that monitor terminal sends, if the indication of said engineering reporting events strategy reports the engineering incident, then report the incident that is designated the engineering incident; If said engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
9. an engineering event handling system is characterized in that, said system comprises the monitoring server and the network equipment, wherein:
The said network equipment is used for: when detecting the fault of self, produce the incident of the said fault of representative, and from the incident of said generation, extract event attribute information; From said event attribute information, obtain the event source information of generation incident, said event source information comprises: the subobject information of the network equipment; With said event source information as the index condition; From the engineering event rules of configuration, search and said event source information matching rules item record; If matching rules item record is found, and is the engineering incident with said event identifier then, send all incidents to said monitoring server;
Said monitoring server is used for: receive the incident that the said network equipment sends, report the engineering incident according to the engineering reporting events strategy that disposes, said engineering reporting events strategy indicates whether to report the engineering incident; If said engineering reporting events strategy indication reports the engineering incident, then report the incident that is designated the engineering incident; If said engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
10. system according to claim 9; It is characterized in that; Said event source information also comprises: network equipment information, and the said network equipment also is used for:, from the engineering event rules of said configuration, search and said network equipment matching rules item record as the index condition with said network equipment information; If the matching rules record is found, and is the engineering incident with said event attribute message identification then.
11., it is characterized in that said system also comprises: monitor terminal according to claim 9 or 10 described systems;
Said monitor terminal is used for: receive the engineering event rules that the user is provided with, and said engineering event rules is sent to said monitoring server; Perhaps,
Receive the engineering maintenance planning table that the user is provided with, resolve said engineering maintenance planning table and obtain the engineering event rules, and said engineering event rules is sent to said monitoring server; Perhaps,
Receive the engineering maintenance planning table, and the said engineering maintenance planning table that will comprise the engineering event rules sends to said monitoring server;
Said monitoring server also is used for: receive the engineering event rules that said monitor terminal sends, and said engineering event rules is sent to the said network equipment; Perhaps,
Receive the engineering maintenance planning table that monitor terminal sends, resolve said engineering maintenance planning table and obtain the engineering event rules, and said engineering event rules is sent to the said network equipment.
12. system according to claim 11 is characterized in that, said system also comprises: monitor terminal;
Said monitor terminal is used for: receive the engineering reporting events strategy that the user is provided with, and said engineering reporting events strategy is sent to said monitoring server;
Said monitoring server also is used for: receive and store the engineering reporting events strategy that said monitor terminal sends.
13. an engineering event processing apparatus is characterized in that, said device comprises:
The incident acquiring unit is used for extracting event attribute information from incident;
The object acquisition unit is used for obtaining from said event attribute information the event source information of generation incident, and said event source information comprises: the subobject information of the network equipment;
Identify unit is used for said event source information as the index condition, from the engineering event rules of configuration, searches and said event source information matching rules item record, if matching rules item record is found, be the engineering incident then with said event identifier.
14. according to the said device of claim 13; It is characterized in that; Said event source information also comprises: network equipment information, and said identify unit also is used for:, from the engineering event rules of said configuration, search and said network equipment matching rules item record as the index condition with said network equipment information; If the matching rules record is found, and is the engineering incident with said event attribute message identification then.
15., it is characterized in that said device also comprises according to the said device of claim 13:
The rule receiving element is used to receive the engineering event rules, perhaps, receives the engineering maintenance planning table;
If what receive is the engineering maintenance planning table, then said device also comprises: resolution unit is used to resolve said engineering maintenance planning table and obtains the engineering event rules.
16., it is characterized in that said device also comprises according to any said device of claim 13 to 15:
The strategy receiving element is used to receive engineering reporting events strategy, and said engineering reporting events strategy indicates whether to report the engineering incident;
Report the unit, be used for then reporting the incident that is designated the engineering incident if the indication of said engineering reporting events strategy reports the engineering incident; If said engineering reporting events strategy indication does not report the engineering incident, then report the incident that is not designated the engineering incident.
CN2011104536211A 2011-12-29 2011-12-29 Processing method, device and system for engineering event Pending CN102571424A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2011104536211A CN102571424A (en) 2011-12-29 2011-12-29 Processing method, device and system for engineering event

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2011104536211A CN102571424A (en) 2011-12-29 2011-12-29 Processing method, device and system for engineering event

Publications (1)

Publication Number Publication Date
CN102571424A true CN102571424A (en) 2012-07-11

Family

ID=46415950

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2011104536211A Pending CN102571424A (en) 2011-12-29 2011-12-29 Processing method, device and system for engineering event

Country Status (1)

Country Link
CN (1) CN102571424A (en)

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102780585A (en) * 2012-08-01 2012-11-14 华为技术有限公司 Warning management method and network management system
CN103812688A (en) * 2012-11-15 2014-05-21 中国移动通信集团设计院有限公司 Alarm determining method and device
CN105763371A (en) * 2016-02-29 2016-07-13 杭州华三通信技术有限公司 Alarm processing method and apparatus
CN107146012A (en) * 2017-04-28 2017-09-08 顺丰速运有限公司 Risk case processing method and system
CN110362406A (en) * 2017-01-20 2019-10-22 腾讯科技(深圳)有限公司 Event-handling method and device
CN113379185A (en) * 2021-04-28 2021-09-10 广东广宇科技发展有限公司 Engineering event authenticity judgment method and system and storage medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101425940A (en) * 2008-12-09 2009-05-06 华为技术有限公司 Method, apparatus and system for alarm processing
CN101883015A (en) * 2009-05-06 2010-11-10 北京亿阳信通软件研究院有限公司 Method and system for filtering construction alarms
CN102136935A (en) * 2010-11-16 2011-07-27 华为技术有限公司 Maintenance port and safety protection method thereof
CN102156799A (en) * 2011-01-17 2011-08-17 西安交通大学 Cascadable complex event processing engine and train overhauling automatic recording method

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101425940A (en) * 2008-12-09 2009-05-06 华为技术有限公司 Method, apparatus and system for alarm processing
CN101883015A (en) * 2009-05-06 2010-11-10 北京亿阳信通软件研究院有限公司 Method and system for filtering construction alarms
CN102136935A (en) * 2010-11-16 2011-07-27 华为技术有限公司 Maintenance port and safety protection method thereof
CN102156799A (en) * 2011-01-17 2011-08-17 西安交通大学 Cascadable complex event processing engine and train overhauling automatic recording method

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102780585A (en) * 2012-08-01 2012-11-14 华为技术有限公司 Warning management method and network management system
CN103812688A (en) * 2012-11-15 2014-05-21 中国移动通信集团设计院有限公司 Alarm determining method and device
CN105763371A (en) * 2016-02-29 2016-07-13 杭州华三通信技术有限公司 Alarm processing method and apparatus
CN105763371B (en) * 2016-02-29 2019-07-09 新华三技术有限公司 A kind of alert processing method and device
CN110362406A (en) * 2017-01-20 2019-10-22 腾讯科技(深圳)有限公司 Event-handling method and device
CN107146012A (en) * 2017-04-28 2017-09-08 顺丰速运有限公司 Risk case processing method and system
CN107146012B (en) * 2017-04-28 2021-01-22 顺丰速运有限公司 Risk event processing method and system
CN113379185A (en) * 2021-04-28 2021-09-10 广东广宇科技发展有限公司 Engineering event authenticity judgment method and system and storage medium

Similar Documents

Publication Publication Date Title
CN104407964B (en) A kind of centralized monitoring system and method based on data center
CN107886238B (en) Business process management system and method based on mass data analysis
CN102571424A (en) Processing method, device and system for engineering event
CN103942210B (en) Processing method, device and the system of massive logs information
CN107943668A (en) Computer server cluster daily record monitoring method and monitor supervision platform
CN101616428B (en) Mobile data service monitoring analysis system and implementation method thereof
CN102567531B (en) General method for monitoring status of light database
CN102523137B (en) Fault monitoring method, device and system
CN105512790A (en) Integrated operation and maintenance management system
CN105427193A (en) Device and method for big data analysis based on distributed time sequence data service
CN106055608A (en) Method and apparatus for automatically collecting and analyzing switch logs
CN105824837B (en) A kind of log processing method and device
CN103488793A (en) User behavior monitoring method based on information retrieval
CN111127250B (en) Power data monitoring event analysis system and method
CN102497230A (en) General-purpose processing method adopted by ONT for multi-vendor non-standard management entity
CN111046000B (en) Government data exchange sharing oriented security supervision metadata organization method
CN105303316A (en) National power grid distribution network fault processing system
CN108228664B (en) Unstructured data processing method and device
CN113505048A (en) Unified monitoring platform based on application system portrait and implementation method
CN109800133A (en) A kind of method, one-stop monitoring alarm platform and the system of unified monitoring alarm
CN203149604U (en) Hand transcriber system for intelligent inspection of industrial equipment
CN105335770A (en) Abnormal production event real-time management system
CN106817262A (en) A kind of log analysis device
CN102340791A (en) System used for realizing data consistency and method thereof
CN115689277B (en) Chemical industry garden risk early warning system under cloud edge cooperation technology

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C12 Rejection of a patent application after its publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20120711