CN105095523A - Alarm event handling method and system - Google Patents

Alarm event handling method and system Download PDF

Info

Publication number
CN105095523A
CN105095523A CN201510626721.8A CN201510626721A CN105095523A CN 105095523 A CN105095523 A CN 105095523A CN 201510626721 A CN201510626721 A CN 201510626721A CN 105095523 A CN105095523 A CN 105095523A
Authority
CN
China
Prior art keywords
alarm
index information
information
association rule
rule base
Prior art date
Application number
CN201510626721.8A
Other languages
Chinese (zh)
Inventor
贾东伟
袁鹏飞
Original Assignee
浪潮(北京)电子信息产业有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 浪潮(北京)电子信息产业有限公司 filed Critical 浪潮(北京)电子信息产业有限公司
Priority to CN201510626721.8A priority Critical patent/CN105095523A/en
Publication of CN105095523A publication Critical patent/CN105095523A/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/90Details of database functions independent of the retrieved data types
    • G06F16/901Indexing; Data structures therefor; Storage structures
    • GPHYSICS
    • G06COMPUTING; CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/90Details of database functions independent of the retrieved data types
    • G06F16/95Retrieval from the web
    • G06F16/958Organisation or management of web site content, e.g. publishing, maintaining pages or automatic linking

Abstract

The invention discloses an alarm event handling method. The alarm event handling method is applied to a cluster management system, data in an alarm database are analyzed with an association rule, and an alarm association rule base is formed; the method further comprises steps as follows: acquiring fault alarm information; processing the fault alarm information to acquire index information; comparing the index information with data in the alarm association rule base to determine a handling scheme corresponding to the index information. With the adoption of the method, the alarm information can be effectively processed, meanwhile, waste of manpower and material resources caused by trials of different handling schemes is reduced, and the efficiency for solving the cluster alarm problem is improved. The invention discloses an alarm event handling system.

Description

A kind of method and system processing alarm event
Technical field
The present invention relates to computer program management domain, particularly a kind of method and system processing alarm event.
Background technology
The alarm module of general cluster management system comprises alarm level, problem description, time prompting and solution.Collected by alarm module, the various problem that feedback and supplying system run into when running and operation, the various problems run into when allowing system manager understand system cloud gray model in time, due to complicacy and the relevance in logic of system, single equipment failure may cause a large amount of alarms, form alarm windstorm, but alarm module directly can not judge reason of makeing mistakes, but provide solution one by one according to the problem of makeing mistakes, key to the issue place can not be found, maintenance experience mainly by system operator individual carries out manual sort's judgement and analysis to it, and finally draw the root place that alarm event occurs.
Therefore, alarm problem of the prior art is all more single, just provides some solutions for current problem fault.Safeguard to get up to waste time and energy, accurately can not find the key of process problem.
Summary of the invention
The object of this invention is to provide a kind of method processing alarm event, the method while effectively processing warning information, can saving the waste because trying out the manpower and materials that different processing schemes produces, improving the efficiency solving cluster alarm problem; In addition, another object of the present invention is to provide a kind of system processing alarm event.
For solving the problems of the technologies described above, the invention provides a kind of method processing alarm event, being applied to cluster management system, utilize correlation rule to the data analysis in record alert database, form alarm association rule base, also comprise:
Obtain fault warning information;
Described fault warning information is processed, obtains index information;
Data in described index information and described alarm association rule base are contrasted, determines the processing scheme corresponding with described index information.
Wherein, described fault warning information is processed, obtains index information and comprise:
Described fault warning information is carried out semantic analysis, using the keyword of extraction as index information.
Wherein, the data in described index information and described alarm association rule base are contrasted, determine that the processing scheme corresponding with described index information comprises:
Correlation rule table data in described index information and described alarm association rule base is contrasted, determines correlation rule;
According to described correlation rule, determine the processing scheme corresponding with described correlation rule.
Wherein, also comprise:
By described fault warning information reporting to described record alert database.
Wherein, also comprise:
Regularly described alarm association rule base is upgraded.
The present invention also provides a kind of system processing alarm event, is applied to cluster management system, comprises alarm association rule base, for utilizing correlation rule to the data analysis in record alert database, forming alarm association rule base, also comprising:
Acquisition module, for obtaining fault warning information;
Processing module, for described fault warning information being processed, obtains index information;
Contrast module, for the data in described index information and described alarm association rule base being contrasted, determines the processing scheme corresponding with described index information.
Wherein, described processing module comprises:
Described fault warning information is carried out semantic analysis, using the keyword of extraction as index information.
Wherein, described contrast module comprises:
Contrast unit, for the correlation rule table data in described index information and described alarm association rule base being contrasted, determines correlation rule;
Determining unit, for according to described correlation rule, determines the processing scheme corresponding with described correlation rule.
Wherein, also comprise:
Reporting module, for by described fault warning information reporting to described record alert database.
Wherein, also comprise:
Update module, for regularly upgrading described alarm association rule base.
The method of process alarm event provided by the present invention, is applied to cluster management system, utilizes correlation rule to the data analysis in record alert database, forms alarm association rule base, also comprises: obtain fault warning information; Described fault warning information is processed, obtains index information; Data in described index information and described alarm association rule base are contrasted, determines the processing scheme corresponding with described index information;
It is single that the method changes alarm level in prior art, problem description, time prompting and solution, just provides some fixing solutions for current problem fault; The method, by by the data analysis in record alert database, finds the incidence relation between each data, forms alarm association rule base; Alarm association rule base can get rid of some unnecessary solutions, increases flexibility ratio, People Analysis's failure message of assisting management, and improves accuracy and the actual effect of process warning information.Namely the method utilizes alarm association rule base while effectively processing warning information, can to save the waste because trying out the manpower and materials that different processing schemes produces, improving the efficiency solving cluster alarm problem.
Accompanying drawing explanation
In order to be illustrated more clearly in the embodiment of the present invention or technical scheme of the prior art, be briefly described to the accompanying drawing used required in embodiment or description of the prior art below, apparently, accompanying drawing in the following describes is only embodiments of the invention, for those of ordinary skill in the art, under the prerequisite not paying creative work, other accompanying drawing can also be obtained according to the accompanying drawing provided.
The process flow diagram of the method for the process alarm event that Fig. 1 provides for the embodiment of the present invention;
The structured flowchart of the system of the process alarm event that Fig. 2 provides for the embodiment of the present invention;
The structured flowchart of the system of another process alarm event that Fig. 3 provides for the embodiment of the present invention;
The structured flowchart of the system of the another process alarm event that Fig. 4 provides for the embodiment of the present invention.
Embodiment
Core of the present invention is to provide a kind of method processing alarm event, and the method while effectively processing warning information, can saving the waste because trying out the manpower and materials that different processing schemes produces, improving the efficiency solving cluster alarm problem.
For making the object of the embodiment of the present invention, technical scheme and advantage clearly, below in conjunction with the accompanying drawing in the embodiment of the present invention, technical scheme in the embodiment of the present invention is clearly and completely described, obviously, described embodiment is the present invention's part embodiment, instead of whole embodiments.Based on the embodiment in the present invention, those of ordinary skill in the art, not making the every other embodiment obtained under creative work prerequisite, belong to the scope of protection of the invention.
Please refer to Fig. 1, the process flow diagram of the method for the process alarm event that Fig. 1 provides for the embodiment of the present invention; The method is applied to cluster management system, first utilizes correlation rule to the data analysis in record alert database, forms alarm association rule base; Form alarm association rule base; Wherein, by carrying out analyzing and processing to a large-scale record alert database, finally form an alarm association rule base.
Based on this alarm association rule base, the method can comprise:
S100, acquisition fault warning information;
Wherein, after occurring when breaking down, cluster alarm module meeting report and alarm information, cluster collects fault warning information.Warning information can comprise: the description of alarm level, problem, time prompting etc. describe the information of this fault.
S110, described fault warning information to be processed, obtain index information;
Wherein, this fault warning information is processed, crucial index information can be obtained; The title of such as faulty equipment, failure mode, fault rank etc.Using these information as index information.
S120, the data in described index information and described alarm association rule base to be contrasted, determine the processing scheme corresponding with described index information.
Wherein, the data in index information and alarm association rule base are contrasted; The equipment be such as mapped in alarm association rule base by the device name in index information is compared, determine the storage space with this device-dependent, contrast according to other index informations again, and finally determine the processing scheme corresponding with described index information.
Because the solution in alarm association rule base is not carry out for Single-issue, but according to a large amount of data analyses, the efficient solution determined.Such as there is certain fault in A equipment, according to the operation of physical device, can know that this fault may have influence on another problem, therefore, solve this problem time, be not only overcome this fault, but from root solve come thus with problem.Reach and enable system manager quick and precisely find problem, and the most effective solution is provided.
Namely the environment of cluster management system of the present invention builds in cluster environment, therefore, after cluster environment has been built, a large amount of warning information can be stored in the record alert database of cluster management system, wherein contain the useful information of many regularity, therefore by data analysis, the correlation rule of alarm is found.Inferred by these correlation rules and the root that outgoing event occurs produce a new solution.
Based on technique scheme, the method of the process alarm event that the embodiment of the present invention provides, it is single that the method changes alarm level in prior art, problem description, time prompting and solution, just provides some fixing solutions for current problem fault; The method, by by the data analysis in record alert database, finds the incidence relation between each data, forms alarm association rule base; Alarm association rule base can get rid of some unnecessary solutions, increases flexibility ratio, People Analysis's failure message of assisting management, and improves accuracy and the actual effect of process warning information.Namely the method utilizes alarm association rule base while effectively processing warning information, can to save the waste because trying out the manpower and materials that different processing schemes produces, improving the efficiency solving cluster alarm problem.
Based on technique scheme, optionally, described fault warning information processed in said method, obtaining index information can comprise:
Described fault warning information is carried out semantic analysis, using the keyword of extraction as index information.
Wherein, can semantic analysis technology be utilized here, extract the keyword in fault warning information; Can certainly extract by other modes, or have certain form when obtaining failure message, extract according to form type.
Can facilitate by the index information obtained, position in alarm association rule base accurately, obtain solution accurately.
Based on technique scheme, in the method, the data in described index information and described alarm association rule base are contrasted, determine that the processing scheme corresponding with described index information can comprise:
Correlation rule table data in described index information and described alarm association rule base is contrasted, determines correlation rule;
According to described correlation rule, determine the processing scheme corresponding with described correlation rule.
Wherein, be that its process can be realized by projected forms, or is realized by data list by using the mode of refinement layer by layer to carry out searching of processing scheme here.
Based on above-mentioned any technical scheme, the method can also comprise:
By described fault warning information reporting to described record alert database.
Wherein, record alert database can be enriched by the way, along with the progress of technology, more failure mode may be there is, therefore, the method can be made by the way can to remain advanced, can provide optimum all the time, solution accurately.
Based on above-mentioned any technical scheme, the method can also comprise:
Regularly described alarm association rule base is upgraded.
Wherein, because record alert database etc. all can upgrade along with the improvement of technology, in order to solve any technical matters accurately, therefore, alarm association rule base also needs regularly to upgrade.Thus can ensure that the solution of storage inside is accurately, reliably.Improve the treatment effeciency of alarm event.
Based on technique scheme, the method for the process alarm event that the embodiment of the present invention provides, the method breaks the pattern of the solution that original fixing warning information provides.But consider the singularity of cluster environment, by alarm solution by original direct propelling movement solution, become and first feed back the most accurate solution again by rule treatments.While effectively processing warning information, the waste because trying out the manpower and materials that different processing schemes produces can being saved, improving the efficiency solving cluster alarm problem.Detailed process: namely first by carrying out data mining to existing large-scale record alert database, find alarm item relevance wherein, analyzing and associating rule, and for building alarm association rule base, real-time relevance of alarm information is analyzed of rule in last application rule storehouse, and new accurate solution is proposed.
Embodiments provide the method for process alarm event, while effectively processing warning information, can being saved the waste because trying out the manpower and materials that different processing schemes produces, improving the efficiency solving cluster alarm problem by said method.
Be introduced the system of the process alarm event that the embodiment of the present invention provides below, the system of process alarm event described below can mutual corresponding reference with the method for above-described process alarm event.
Please refer to Fig. 2, the structured flowchart of the system of the process alarm event that Fig. 2 provides for the embodiment of the present invention; Be applied to cluster management system, comprise alarm association rule base 400, for utilizing correlation rule to the data analysis in record alert database, form alarm association rule base, this system can also comprise:
Acquisition module 100, for obtaining fault warning information;
Processing module 200, for described fault warning information being processed, obtains index information;
Contrast module 300, for the data in described index information and described alarm association rule base being contrasted, determines the processing scheme corresponding with described index information.
Optionally, described processing module 200 can comprise:
Described fault warning information is carried out semantic analysis, using the keyword of extraction as index information.
Optionally, described contrast module 300 can comprise:
Contrast unit, for the correlation rule table data in described index information and described alarm association rule base being contrasted, determines correlation rule;
Determining unit, for according to described correlation rule, determines the processing scheme corresponding with described correlation rule.
Based on technique scheme, please refer to Fig. 3, this system can also comprise:
Reporting module 500, for by described fault warning information reporting to described record alert database.
Based on technique scheme, please refer to Fig. 4, this system can also comprise:
Update module 600, for regularly upgrading described alarm association rule base.
Based on technique scheme, the system of the process alarm event that the embodiment of the present invention provides, this system can make full use of the relevance of alarm data, can make alarm issue handling rapid, simplify, alarm solution is flexible, the exact regimen that can provide for alarm problem, saves the resource consumption that warning information process is used.
In instructions, each embodiment adopts the mode of going forward one by one to describe, and what each embodiment stressed is the difference with other embodiments, between each embodiment identical similar portion mutually see.For device disclosed in embodiment, because it corresponds to the method disclosed in Example, so description is fairly simple, relevant part illustrates see method part.
Professional can also recognize further, in conjunction with unit and the algorithm steps of each example of embodiment disclosed herein description, can realize with electronic hardware, computer software or the combination of the two, in order to the interchangeability of hardware and software is clearly described, generally describe composition and the step of each example in the above description according to function.These functions perform with hardware or software mode actually, depend on application-specific and the design constraint of technical scheme.Professional and technical personnel can use distinct methods to realize described function to each specifically should being used for, but this realization should not thought and exceeds scope of the present invention.
The software module that the method described in conjunction with embodiment disclosed herein or the step of algorithm can directly use hardware, processor to perform, or the combination of the two is implemented.Software module can be placed in the storage medium of other form any known in random access memory (RAM), internal memory, ROM (read-only memory) (ROM), electrically programmable ROM, electrically erasable ROM, register, hard disk, moveable magnetic disc, CD-ROM or technical field.
Above the method and system of process alarm event provided by the present invention are described in detail.Apply specific case herein to set forth principle of the present invention and embodiment, the explanation of above embodiment just understands method of the present invention and core concept thereof for helping.It should be pointed out that for those skilled in the art, under the premise without departing from the principles of the invention, can also carry out some improvement and modification to the present invention, these improve and modify and also fall in the protection domain of the claims in the present invention.

Claims (10)

1. process a method for alarm event, be applied to cluster management system, it is characterized in that, utilize correlation rule to the data analysis in record alert database, form alarm association rule base, also comprise:
Obtain fault warning information;
Described fault warning information is processed, obtains index information;
Data in described index information and described alarm association rule base are contrasted, determines the processing scheme corresponding with described index information.
2. the method for claim 1, is characterized in that, described fault warning information is processed, obtains index information and comprise:
Described fault warning information is carried out semantic analysis, using the keyword of extraction as index information.
3. method as claimed in claim 2, is characterized in that, the data in described index information and described alarm association rule base contrasted, determine that the processing scheme corresponding with described index information comprises:
Correlation rule table data in described index information and described alarm association rule base is contrasted, determines correlation rule;
According to described correlation rule, determine the processing scheme corresponding with described correlation rule.
4. the method as described in any one of claims 1 to 3, is characterized in that, also comprises:
By described fault warning information reporting to described record alert database.
5. method as claimed in claim 4, is characterized in that, also comprise:
Regularly described alarm association rule base is upgraded.
6. process a system for alarm event, be applied to cluster management system, it is characterized in that, comprise alarm association rule base, for utilizing correlation rule to the data analysis in record alert database, forming alarm association rule base, also comprising:
Acquisition module, for obtaining fault warning information;
Processing module, for described fault warning information being processed, obtains index information;
Contrast module, for the data in described index information and described alarm association rule base being contrasted, determines the processing scheme corresponding with described index information.
7. system as claimed in claim 6, it is characterized in that, described processing module comprises:
Described fault warning information is carried out semantic analysis, using the keyword of extraction as index information.
8. system as claimed in claim 7, it is characterized in that, described contrast module comprises:
Contrast unit, for the correlation rule table data in described index information and described alarm association rule base being contrasted, determines correlation rule;
Determining unit, for according to described correlation rule, determines the processing scheme corresponding with described correlation rule.
9. the system as described in any one of claim 6 to 8, is characterized in that, also comprises:
Reporting module, for by described fault warning information reporting to described record alert database.
10. system as claimed in claim 9, is characterized in that, also comprise:
Update module, for regularly upgrading described alarm association rule base.
CN201510626721.8A 2015-09-28 2015-09-28 Alarm event handling method and system CN105095523A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510626721.8A CN105095523A (en) 2015-09-28 2015-09-28 Alarm event handling method and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510626721.8A CN105095523A (en) 2015-09-28 2015-09-28 Alarm event handling method and system

Publications (1)

Publication Number Publication Date
CN105095523A true CN105095523A (en) 2015-11-25

Family

ID=54575958

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510626721.8A CN105095523A (en) 2015-09-28 2015-09-28 Alarm event handling method and system

Country Status (1)

Country Link
CN (1) CN105095523A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106713017A (en) * 2016-12-08 2017-05-24 国网北京市电力公司 Alarm information processing method and apparatus
CN107069960A (en) * 2017-04-11 2017-08-18 北京四方继保自动化股份有限公司 A kind of online defect diagnostic method of secondary operation management system
CN107861856A (en) * 2017-11-08 2018-03-30 郑州云海信息技术有限公司 The processing method and computer-readable storage medium of warning information in cloud data system

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101651576A (en) * 2009-08-28 2010-02-17 曙光信息产业(北京)有限公司 Alarm information processing method and system
CN103209096A (en) * 2013-04-01 2013-07-17 大唐移动通信设备有限公司 Method and device for alarm processing
CN103744897A (en) * 2013-12-24 2014-04-23 华为技术有限公司 Associated search method and associated search system for fault information, and network management system
CN103812688A (en) * 2012-11-15 2014-05-21 中国移动通信集团设计院有限公司 Alarm determining method and device
CN104133986A (en) * 2014-07-10 2014-11-05 国家电网公司 Multi-business-object-oriented distribution network warning information integrated rational analysis method
CN104218676A (en) * 2014-09-02 2014-12-17 广东电网公司茂名供电局 Intelligent warning system and method for power dispatching automation master station

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101651576A (en) * 2009-08-28 2010-02-17 曙光信息产业(北京)有限公司 Alarm information processing method and system
CN103812688A (en) * 2012-11-15 2014-05-21 中国移动通信集团设计院有限公司 Alarm determining method and device
CN103209096A (en) * 2013-04-01 2013-07-17 大唐移动通信设备有限公司 Method and device for alarm processing
CN103744897A (en) * 2013-12-24 2014-04-23 华为技术有限公司 Associated search method and associated search system for fault information, and network management system
CN104133986A (en) * 2014-07-10 2014-11-05 国家电网公司 Multi-business-object-oriented distribution network warning information integrated rational analysis method
CN104218676A (en) * 2014-09-02 2014-12-17 广东电网公司茂名供电局 Intelligent warning system and method for power dispatching automation master station

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106713017A (en) * 2016-12-08 2017-05-24 国网北京市电力公司 Alarm information processing method and apparatus
CN106713017B (en) * 2016-12-08 2020-06-19 国网北京市电力公司 Alarm information processing method and device
CN107069960A (en) * 2017-04-11 2017-08-18 北京四方继保自动化股份有限公司 A kind of online defect diagnostic method of secondary operation management system
CN107069960B (en) * 2017-04-11 2020-07-28 云南电网有限责任公司保山供电局 Online defect diagnosis method for secondary operation and maintenance management system
CN107861856A (en) * 2017-11-08 2018-03-30 郑州云海信息技术有限公司 The processing method and computer-readable storage medium of warning information in cloud data system

Similar Documents

Publication Publication Date Title
Bailis et al. Macrobase: Prioritizing attention in fast data
US10191977B2 (en) System and method for providing technology assisted data review with optimizing features
US9424157B2 (en) Early detection of failing computers
Oliner et al. Carat: Collaborative energy diagnosis for mobile devices
Lee et al. Micro interaction metrics for defect prediction
US9372713B2 (en) Optimizing virtual storage size in a virtual computer system based on information related to virtual machines, user inputs and/or configuration parameters
EP3152869B1 (en) Real-time model of states of monitored devices
US20190163675A1 (en) Identification of Relevant Data Events by Use of Clustering
Qin et al. Estimating wind speed probability distribution using kernel density method
US20200192741A1 (en) Automatic model-based computing environment performance monitoring
US9477835B2 (en) Event model for correlating system component states
US20170178038A1 (en) Discovering linkages between changes and incidents in information technology systems
CN106462484B (en) Distributed stream processing in cloud
US20170124464A1 (en) Rapid predictive analysis of very large data sets using the distributed computational graph
US20170017698A1 (en) Method for analyzing time series activity streams and devices thereof
US8676818B2 (en) Dynamic storage and retrieval of process graphs representative of business processes and extraction of formal process models therefrom
US20150067835A1 (en) Detecting Anomalous User Behavior Using Generative Models of User Actions
US8423638B2 (en) Performance monitoring of a computer resource
Begoli et al. Design principles for effective knowledge discovery from big data
Kolar et al. Sparsistent learning of varying-coefficient models with structural changes
US10102097B2 (en) Transaction server performance monitoring using component performance data
TWI564732B (en) A method and apparatus for monitoring user requests to run in a decentralized system
US10284577B2 (en) Method and apparatus for file identification
US9678822B2 (en) Real-time categorization of log events
US10692007B2 (en) Behavioral rules discovery for intelligent computing environment administration

Legal Events

Date Code Title Description
PB01 Publication
C06 Publication
SE01 Entry into force of request for substantive examination
C10 Entry into substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20151125

RJ01 Rejection of invention patent application after publication