CN108234189A - A kind of alarm data treating method and apparatus - Google Patents
A kind of alarm data treating method and apparatus Download PDFInfo
- Publication number
- CN108234189A CN108234189A CN201611199564.8A CN201611199564A CN108234189A CN 108234189 A CN108234189 A CN 108234189A CN 201611199564 A CN201611199564 A CN 201611199564A CN 108234189 A CN108234189 A CN 108234189A
- Authority
- CN
- China
- Prior art keywords
- alarm
- alarm data
- analysis
- logic
- subport
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0631—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0604—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0604—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
- H04L41/0622—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time based on time
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/069—Management of faults, events, alarms or notifications using logs of notifications; Post-processing of notifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/16—Threshold monitoring
Abstract
The invention discloses a kind of alarm data treating method and apparatus, method includes:Monitor the alarm data in Network Management System;Whether every alarm data for judging to listen to meets presupposition analysis rule, and one analysis thread of distribution is corresponded to the alarm data for meeting presupposition analysis rule, carries out fault rootstock analyzing and processing to alarm data, obtains the analysis result of alarm data;The analysis result is saved in alert analysis database.The treating method and apparatus of this alarm data of the present embodiment starts an analysis thread, to judge the fault rootstock of alarm data, so as to improve the analysis efficiency of alarm data since the alarm data for meeting presupposition analysis rule to listen to corresponds to.And by carrying out fault rootstock positioning analysis to the alarm data for meeting presupposition analysis rule, more reference informations for alarming processing can be provided, meet the application demand of enterprise.
Description
Technical field
The present invention relates to technical field of network management, and in particular to a kind of alarm data treating method and apparatus.
Background technology
It is growing day by day to the dependence of computer network with the development of computer and the communication technology so that network management
Effect and status are also more prominent, and alarm management is the basis of network management.In Network Management System, there is a large amount of
Alarm data, network management system need to analyze alarm data, calculate and be saved in a series of processing of database.Mesh
Before, common alarm type has:Hardware problem alarm, port alarm, transmission problem alarm, allocation problem alarm and clock problem
Alarm etc..The prior art when handling alarm, is limited to the processor of network management system, the performance of input-output equipment
And the limitation of hardware environment etc., processing speed and event that is less efficient, also, not generated in the prior art to alarm data
Barrier root is analyzed, it is impossible to meet application demand.
Invention content
The present invention provides a kind of alarm data treating method and apparatus, to solve alarm data processing effect in the prior art
Rate is low and the fault rootstock of alarm data generation is not analyzed, it is impossible to the problem of meeting application demand.
A kind of alarm data processing method according to an embodiment of the invention, method include:
Monitor the alarm data in Network Management System;
Whether the alarm data for judging to listen to meets presupposition analysis rule, and the alarm number to meet presupposition analysis rule
According to corresponding one analysis thread of distribution, fault rootstock analyzing and processing is carried out to alarm data, obtains the analysis result of alarm data;
The analysis result is saved in alert analysis database.
According to another aspect of the present invention, a kind of alarm data processing unit, alarm data processing unit packet are provided
It includes:
Monitoring unit is alerted, for monitoring the alarm data in Network Management System;
Alarming processing unit, for judging whether the alarm data listened to meets presupposition analysis rule, and it is pre- to meet
If the alarm data of analysis rule corresponds to one analysis thread of distribution, fault rootstock analyzing and processing is carried out to alarm data, is obtained
The analysis result of alarm data;
Storage unit, for preserving in the analysis result to alert analysis database.
The advantageous effect of the embodiment of the present invention is:The alarm data treating method and apparatus of the present invention, by monitoring network
Alarm data in management system, the alarm data for meeting presupposition analysis rule to listen to, which corresponds to, starts an analytical line
Journey to carry out fault rootstock analyzing and processing to alarm data, obtains the analysis result of alarm data, analysis result is saved in announcement
In alert analytical database, so as to distribute independent thread to the alarm data for meeting presupposition analysis rule, realize multi-thread
Journey handles the advantageous effect of alarm data, compared with prior art, improves the speed and efficiency of alarm data processing.In addition,
To meeting the alarm data of presupposition analysis rule, the present embodiment can further analyze the fault rootstock of this kind of alarm data, so as to
Processing for alarm data provides more reference informations, avoids reprocessing the alarm data generated by same fault rootstock,
The workload of alarm management is reduced, improves the validity and value of network management alarm management.
Description of the drawings
Fig. 1 is a kind of flow chart of alarm data processing method of one embodiment of the invention;
Fig. 2 is a kind of overall flow figure of alarm data processing method of another embodiment of the present invention;
Fig. 3 is a kind of flow diagram of alarm data processing method of another embodiment of the invention;
Fig. 4 is a kind of block diagram of alarm data processing unit of one embodiment of the invention.
Specific embodiment
The exemplary embodiment of the disclosure is more fully described below with reference to accompanying drawings.Although the disclosure is shown in attached drawing
Exemplary embodiment, it being understood, however, that may be realized in various forms the disclosure without should be by embodiments set forth here
It is limited.On the contrary, these embodiments are provided to facilitate a more thoroughly understanding of the present invention, and can be by the scope of the present disclosure
Completely it is communicated to those skilled in the art.
The design concept of the present invention is:Using the multithreading characteristic of Java language each to meet presupposition analysis rule
Alarm starts independent analysis thread, and, when physical port delays alarm generation, its derivative is filtered so as to fulfill in network monitoring
Logic subport out is delayed alarm, carries out handling caused weight to avoid to alarm data a plurality of caused by same fault rootstock
Multiple labour mitigates the advantageous effect of the pressure of daily alarm work.
Java language supports multithreading, and the purpose of multithreading is to utilize cpu resource to greatest extent, is improved at data
The efficiency of reason.Thread:Same class thread shares code and data space, and per thread has independent running stack and programmed counting
Device, Thread-switch overhead are small.Multithreading refers to have multiple sequential flows performing in same program.Java applet operates in Java
In virtual machine (Java Virtual Machine, abbreviation JVM), in the inside of JVM, the multitask of program is come real by thread
Existing.For multiple threads in a process, multiple threads share the memory block of process, when having what new thread generated
When, operating system does not distribute new memory, but new thread is allowed to share the memory of original process block.Therefore, cross-thread
Communication is easy to, and speed is also quickly.
In Network Management System, alarm is there are many type, for example, according to the fault rootstock that alarm generates, alarm can divide
For:It is alerted caused by the logic subport failure of alarm caused by physical port failure and physical port binding.
Physical port:Physical port is also known as interface, is visible port, for example, the RJ45 network interfaces of computer back panel, exchange
The RJ45 ports of the network equipments such as machine, router, hub.
Logic subport:Logic interfacing refers to realize and data exchanging function but physically be not present, and needs to pass through and is configured
The interface of foundation connects product, LoopBack interfaces, NULL interfaces, backup center logical channel including Dialer (dialing) interface, son
And virtual-template interface etc..
In practical network monitoring, since logic subport is subordinated to physical port, so when a physical port is delayed
When falling, generating alarm, under all logic subports can also generate interface and delay alarm.In this case, if not by logic
Port alarm filter falls, then when subsequently handling again alarm data, certainly will cause for same failure (i.e. physics end
Mouthful failure) caused by a plurality of alarm reprocessing, increase the pressure and workload of alarming processing.
In order to solve this problem, the present embodiment proposes a kind of technical solution that fault rootstock analysis is carried out to alarm, sentences
Whether each logic subport of breaking alarm of delaying generates since physical port is broken down, if it is, logic subport is delayed alarm
It filters out, to reduce the quantity of daily alarming processing, improves the validity of alarm monitoring.
Embodiment one
Fig. 1 is a kind of flow chart of alarm data processing method of one embodiment of the invention, referring to Fig. 1, the present embodiment
This alarm data processing method include the following steps:
Step S101 monitors the alarm data in Network Management System;
Step S102, judges whether the alarm data listened to meets presupposition analysis rule, and to meet presupposition analysis rule
Alarm data then corresponds to one analysis thread of distribution, carries out fault rootstock analyzing and processing to alarm data, obtains alarm data
Analysis result;
The analysis result is saved in alert analysis database by step S103.
Method as shown in Figure 1 works as receipts it is found that by being monitored to the alarm data in network management system in the present embodiment
Whether meet presupposition analysis rule, and to meet presupposition analysis rule to the alarm data listened to during alarm data for judgement
Alarm data, which corresponds to, distributes independent thread, carries out fault rootstock analysis, so as to provide alarm failure root information for fortune
Dimension personnel refer to, and the alarm that subsequent filter is generated by same fault rootstock is facilitated (not carried out to the alarm filtered out
Reason), the quantity of alarming processing is reduced, improves the validity of alarm monitoring.Further, since the alarm to meet presupposition analysis rule
Data correspond to one analysis thread of distribution, also ensure the efficiency of alarming processing.
Embodiment two
It should be noted that the application environment of the processing method of the alarm data of the present embodiment is Network Management System, tool
Body, be to apply be configured between physical port and logic subport in the Network Management System of binding relationship.In network pipe
Establish analysis strategy in reason system, Allocation Analysis rule and alarm pressing time threshold value in strategy, then, in Network Management System
Middle startup Analysis Service (that is, processing method of the alarm data of the present embodiment) meets default point when Analysis Service receives one
Analysis rule interface delay alarm when, start one analysis thread, to interface fault carry out root-cause analysis;Finally, by analysis result
Alert analysis database is uploaded to, is used for interface, notice and worksheet processing.
Fig. 2 is a kind of overall flow figure of alarm data processing method of another embodiment of the present invention, referring to Fig. 2, sheet
The overall flow of the alarm data processing method of embodiment is as follows:
Step S201 starts Analysis Service;
Specifically, when Network Management System starts, the alarm data of the present embodiment can be handled Analysis Service and started.Point
Analysis service is an independent threading service, and the life cycle of the threading service can be with the life cycle phase of Network Management System
Together, the life cycle of network management system, the i.e. network management system, when network management system stops, being divided from the whole cycle for starting to stopping
Analysis service is also stopped.
In addition, in Analysis Service start-up course, user is used for alarm failure root by network management system by interface configurations
The analysis strategy of source analysis is loaded into memory (including presupposition analysis rule and pressing time), and by alert analysis database
It is loaded into memory through existing root failure analysis result, after the completion of presupposition analysis rule and the loading of existing analysis result,
Start alarm to monitor.
Step S202, the fault rootstock analysis of alarm data;
After Analysis Service starts, start monitoring alarm, when alerting generation, one analysis thread of startup carries out root event when having
Barrier analysis.
Step S203 uploads analysis result.
Here, the analysis result of upload is to upload to carry out the analysis result obtained after fault rootstock analysis, example to alarm
Such as, after alarm of delaying to physical port carries out fault rootstock analysis, it is determined that being delayed caused by this failure as physical port, then exist
Step S203 can upload physical port and delay alarm particular content and failure cause (that is, physical port is delayed).And for logic
Port is delayed alarm, after carrying out fault rootstock analysis, it is determined that being delayed (rather than physical port is delayed) this failure by logic subport
It is caused, then step S203 can upload logic subport delay alarm particular content and failure cause (that is, logic subport
Delay) upload to database.
After the corresponding analysis thread of alarm data performs, the analysis result of alarm data is uploaded in database
It preserves, is used for interface, notice, worksheet processing.
Embodiment three
Fig. 3 is a kind of flow diagram of alarm data processing method of another embodiment of the invention, referring to Fig. 3, sheet
The alarm data processing method of embodiment includes the following steps:
Flow starts.
Step S301 is performed, monitors alarm data;
The alarm data processing method of the present embodiment reads the analysis plan in memory cache when listening to an alarm
Slightly, presupposition analysis rule is configured in analysis strategy.
Step S302 judges whether to meet presupposition analysis rule;It is then, to perform step S303, otherwise terminate flow;
Due to Network Management System, there is more than monitoring interfaces to delay alarm, also many other types of alarm, this implementation
It only delays in example to physical port and alarm and is subordinated to the logic subport alarm of delaying of physical port and handles, therefore, it is necessary to
Alarm in network management system is filtered, judges whether current alarm data are that physical port is delayed or logic subport is delayed, such as
Fruit is not the alarm of this two class, is directly terminated.
In the present embodiment, judge whether alarm data meets presupposition analysis rule and include:Obtain the middle instruction of alarm data
The alarm type identification information of alarm type, judges whether the alarm type of alarm type identification information instruction advises with presupposition analysis
Alarm type matching in then is then, to determine that alarm data meets presupposition analysis rule, otherwise, it determines alarm data is unsatisfactory for
Presupposition analysis rule.Alarm type in presupposition analysis rule includes:Physical port is delayed alarm, alternatively, being bound with physical port
Logic subport delay alarm.
Generally, every alarm data includes following information substantially:Title, alarm level, alarm status are alerted, alerts sequence
Row number and alarm notification mode etc..The alarm title of wherein every alarm data is indicated generally at the type of this alarm data, because
This, in the present embodiment, when receiving an alarm data, extraction alarm title, can by alert title instruction alarm type and
Alarm type (two classes) in presupposition analysis rule:Physical port is delayed alarm, alternatively, logic subport is delayed, alarm is matched.
When matching one of them, subsequent processing steps are carried out, are mismatched when with two kinds of alarm types in presupposition analysis rule
When, directly terminate.
Step S303 starts analysis thread, judges whether to meet that there are analysis results;Otherwise, step S304 is performed, is then
Terminate flow;
In this step, the logic for all logic subports of alarm and physical port binding of delaying for each physical port
Subport is delayed the same analysis thread of alarm handler.
Specifically, when receiving an alarm data for meeting analysis rule, that is, receive a physical port delay alarm or
Person's logic subport delay alarm when, first judge whether relevant existing analysis thread, if there is existing analysis thread, then
This alarm data is included into existing analysis thread and is analyzed, if there is no relevant existing analysis thread, then for
This alarm data distributes a new analysis thread, carries out fault rootstock analysis.
For example, logic subport there are two physical port A bindings, respectively:Logic subport a and logic subport
B, when the method for the present embodiment formerly listen to physical port A physical port delay alarm when, judge there is no have analytical line
Journey is then delayed the new analysis thread Process01 of alarm handler one for this physical port of physical port A.Then, at 3 seconds
The logic subport for having listened to the logic subport a of physical port A later is delayed alarm, is carried out thread judgement, then can be found to deposit
In relevant existing analysis thread Process01, then no longer delaying for the logic subport of logic subport a, alarm handler is new to be divided
Analyse thread, but by the logic subport of logic subport a delay alarm be included into existing analysis thread Process01 carry out therefore
Hinder root-cause analysis.
In addition, delay in the present embodiment to the physical port of physical port A alarm and the logic subport and logic of logic a
The delay sequence of alarm of the logic subport of subport b is not restricted, that is, in the example above explanation, it is also possible to first listen to logic
The logic subport of subport a is delayed alarm, and process flow is identical at this time, that is, is equally first carried out with the presence or absence of relevant existing point
The judgement of thread is analysed, exists, is then included into existing analysis thread, is not present, then distribute new analysis thread.
It can be seen that by distributing same point for each physical port and its logic subport of binding in the present embodiment
Thread is analysed, realizes the parallel processing that alarm data fault rootstock is analyzed in Network Management System, the processing mode with single thread
It compares, improves the speed and efficiency of alert analysis.
In addition, in real network management system, alarm monitoring has continuity, is taken turns for being spaced to schedule
The alarm followed, as long as failure is not eliminated, this kind of alarm can occur primary at regular intervals.
So after an alarm for meeting presupposition analysis condition is received, first judge whether alarm had been analyzed, if
It has been analyzed that, no longer analyzed, and terminated thread.If do not analyzed, then carry out consequent malfunction root-cause analysis.
It is searched whether in alert analysis database there are the analysis result of the alarm that is, being first passed through in the present embodiment to accusing
It is alert to carry out duplicate removal judgement, specifically, obtaining the alarm sequence number (Alarm_id) of every alarm data of unique mark, utilize alarm
Searched in the analysis result that sequence number preserves in alert analysis database, when in analysis result there are during this alarm data,
Terminate analysis;When this alarm data is not present in analysis result, grasped accordingly according to the alarm type of alarm data
Make.
In this way, for the alarm that those had been analyzed, it can directly terminate flow, no longer carry out subsequent analysis, so as to
Improve the efficiency of alarm data processing.
Step S304 determines whether that physical port is delayed alarm;It is then, to perform step S305, uploads analysis result;It is no
Then, step S306 is performed;
When being made whether to meet the judgement of presupposition analysis rule to alarm in above mentioned steps S3 02, it may be determined that go out current announcement
Alert type (be physical port delay alarm or logic subport is delayed alarm), in this step, i.e. step S304, specific judgement
Whether current alarm is that physical port is delayed alarm, when alarm data alarm type for physical port delay alarm when, number will be alerted
It is preserved according to being uploaded in alert analysis database.
Note:Since the usual influence power of the failure of physical port is larger, so for the physics as caused by physical port failure
Port delay alarm need carry out key monitoring, when receiving this kind of alarm, such alarm data can be uploaded directly into alert analysis
It is convenient that subsequent processing is carried out to this kind of alarm data in database.
And for the logic subport for being subordinated to physical port, there are two types of situations for the generation of alarm:The first is accused
Police is caused by physical port failure, that is, the fault rootstock that logic subport is delayed be physical port, second alarm be by
Caused by the failure of logic subport in itself, i.e., the fault rootstock that logic subport is delayed is logic subport.
In the present embodiment, the first alarm for logic subport, i.e. fault rootstock are this kind of alarm of physical port
It needs to be filtered, carries out replicate analysis processing to avoid to alarm a plurality of caused by same failure, increase the work of alarming processing
It measures.
Step S306, alarm data is suppressed;
When the alarm type of alarm data is delayed for logic subport to be alerted, alarm data is sent to logic subport and is tied up
The corresponding alarm compacting queue of fixed physical port is suppressed.
Note:Alarm of why delaying in the present embodiment to logic subport is suppressed, and is alerted not because physical port is delayed
One be scheduled on logic subport delay alarm before occur, it is also possible to logic subport delay alarm after occur.Such as:Physics end
Mouth delays to alert to be occurred behind 5 seconds after logic subport delays alarm.
As a result, when logic subport delay alarm occur when, need in system temporary cache for a period of time, if without
If compacting, the alarm of delaying of logic subport will be uploaded to database, this alarm is not just filtered, and can cause to alert
It repeats.
Step S307 judges whether to receive corresponding physical port and delays alarm;It is then, to perform step S308, otherwise, performs
Step S305;
It delays during alarm data is pressed in logic subport, the present embodiment judges whether that listening to the logic subport ties up
The physical port of fixed physical port is delayed alarm data, otherwise, logic subport delay alarm data pressing time beyond pre-
If during pressing time threshold value, logic subport alarm data of delaying is suppressed in queue from alarm and takes out and be uploaded to alert analysis number
According to being preserved in library.
Note:The physics of logic subport binding is not received during alarm data is pressed if delayed in logic subport
The physical port of port is delayed, and to represent the fault rootstock of this alarm data be not physical port to alarm data, so being accused
Police is reported for subsequent processing.
In addition, the logic subport also periodically suppressed in queue alarm in the present embodiment is delayed, alarm data is examined
Look into decision logic subport delay alarm data pressing time whether beyond default pressing time threshold value.
For example, once alert compacting queue every 1 second poll, check logic subport delay alarm pressing time whether
More than preset pressing time threshold value (threshold value can be set as 5 seconds).If it exceeds the pressing time and do not receive the logic son
The physical port of the physical port of port binding delay alarm logic subport can then be delayed alarm upload to database and terminate point
Analyse thread.
Step S308, filters out alarm data;
If delayed during alarm data is pressed in logic subport, the physical port of logic subport binding is listened to
Physical port delay alarm data, then logic subport alarm data of delaying is suppressed in queue from alarm and is taken out, and filter out this
Logic subport is delayed alarm data.
Note:The physics end of logic subport binding is had received during alarm data is pressed if delayed in logic subport
Mouthful physical port delay that represent the fault rootstock of this alarm data be physical port to alarm data, so not needing to be alerted
It reports.
So far, flow terminates.
It is real as shown in Figure 3 it is found that the processing method of the alarm data of the present embodiment utilizes the multithreading characteristic of Java language
Show the fault rootstock that physical port common in network management delays alarm and logic subport is delayed between alarm to position, reduce day
The quantity of normal alarming processing.It is the sub- end of logic of each physical port and its binding and in specific fault rootstock analytic process
Mouth is established and starts an analysis thread, improves the efficiency of alarm data analysis and the validity of alarm monitoring.
Example IV
Fig. 4 is a kind of block diagram of alarm data processing unit of one embodiment of the invention, referring to Fig. 4, at alarm data
Reason device 40 includes:
Monitoring unit 401 is alerted, for monitoring the alarm data in Network Management System;
Alarming processing unit 402, for judging whether the alarm data listened to meets presupposition analysis rule, and to meet
The alarm data of presupposition analysis rule corresponds to one analysis thread of distribution, carries out fault rootstock analyzing and processing to alarm data, obtains
To the analysis result of alarm data;
Storage unit 403, for preserving in analysis result to alert analysis database.
In one embodiment of the invention, alarming processing unit 402 includes:Type judgment sub-unit,
Type judgment sub-unit for obtaining the alarm type identification information of the middle instruction alarm type of alarm data, is sentenced
Whether the alarm type of disconnected alarm type identification information instruction matches with the alarm type in presupposition analysis rule, is then, to determine
Alarm data meets presupposition analysis rule, otherwise, it determines alarm data is unsatisfactory for presupposition analysis rule,
Alarm type in presupposition analysis rule includes:Physical port is delayed alarm, alternatively, the logic with physical port binding
Subport is delayed alarm.
In one embodiment of the invention, alarming processing unit 402 further includes:Thread assignment unit, for being every
A physical port delay alarm and physical port binding all logic subports logic subport alarm handler of delaying it is same
A analysis thread;
Duplicate removal subelement for obtaining the alarm sequence number of every alarm data of unique mark, is existed using alarm sequence number
It is searched in the analysis result preserved in alert analysis database, when there are during this alarm data, terminate to analyze in analysis result;
When this alarm data is not present in analysis result, operated accordingly according to the alarm type of alarm data.
In one embodiment of the invention, alarming processing unit 402 is specifically for the alarm type for working as alarm data
Physical port delay alarm when, alarm data is uploaded in alert analysis database and is preserved, when the alarm type of alarm data is
Logic subport delay alarm when, by alarm data be sent to logic subport binding physical port it is corresponding alarm compacting queue
It is suppressed.
In one embodiment of the invention, alarming processing unit 402 is additionally operable to, and is delayed alarm data quilt in logic subport
During compacting, the physical port for judging whether to listen to the physical port of logic subport binding is delayed alarm data, be then, will
Logic subport alarm data of delaying is suppressed in queue from alarm and is taken out, and filter out the logic subport and delay alarm data;Otherwise,
Logic subport delay pressing time of alarm data exceed default pressing time threshold value when, logic subport is delayed alarm data
It suppresses to take out and be uploaded in alert analysis database in queue from alarm and preserve.
In one embodiment of the invention, alarming processing unit 402 is additionally operable to, and periodically alarm is suppressed in queue
Logic subport delay alarm data check decision logic subport delay alarm data pressing time whether beyond pre-
If pressing time threshold value.
It should be noted that this alarm data processing unit of the present embodiment be in aforementioned alarm data processing method
Corresponding steps it is corresponding, thus, the more detailed course of work of alarm data processing unit of the present embodiment may refer to aforementioned
Explanation in alarm data processing method embodiment, which is not described herein again.
In summary, the treating method and apparatus of the alarm data of the embodiment of the present invention utilizes the more of Java development languages
Thread characteristics solve alarm reprocessing caused by not carrying out fault rootstock analysis to alarm in the prior art, alert work
Amount and pressure it is big the problem of, by listen to Network Management System occur physical port delay alarm when, filter the physical port
The logic subport that failure is derived is delayed alarm, avoids and a plurality of alarm data caused by same root failure is repeated
Analyzing and processing, so as to alleviate the quantity of daily alarming processing and pressure, improves the efficiency of alarming processing, meets enterprise
Application demand.
The above description is merely a specific embodiment, under the above-mentioned introduction of the present invention, those skilled in the art
Other improvement or deformation can be carried out on the basis of above-described embodiment.It will be understood by those skilled in the art that above-mentioned tool
The purpose of the present invention is only preferably explained in body description, and protection scope of the present invention is subject to the protection scope in claims.
Claims (10)
1. a kind of alarm data processing method, which is characterized in that the method includes:
Monitor the alarm data in Network Management System;
Whether the alarm data for judging to listen to meets presupposition analysis rule, and the alarm data pair to meet presupposition analysis rule
An analysis thread should be distributed, fault rootstock analyzing and processing is carried out to alarm data, obtains the analysis result of alarm data;
The analysis result is saved in alert analysis database.
2. according to the method described in claim 1, it is characterized in that, described to judge whether the alarm data that listens to meets default
Analysis rule includes:
The alarm type identification information that alarm type is indicated in alarm data is obtained, judges the alarm type identification information instruction
Alarm type whether matched with the alarm type in presupposition analysis rule,
It is then, to determine that the alarm data meets presupposition analysis rule,
Otherwise, it determines the alarm data is unsatisfactory for presupposition analysis rule;
Alarm type in the presupposition analysis rule includes:Physical port is delayed alarm, alternatively, the logic with physical port binding
Subport is delayed alarm.
3. according to the method described in claim 2, it is characterized in that, described is the alarm data correspondence for meeting presupposition analysis rule
One analysis thread of distribution includes:
It delays alarm for the delay logic subport of all logic subports of alarm and physical port binding of each physical port
Distribute same analysis thread.
4. according to the method in claim 2 or 3, which is characterized in that described that fault rootstock analysis bag is carried out to alarm data
It includes:
The alarm sequence number of every alarm data of unique mark is obtained,
It is searched in the analysis result preserved in the alert analysis database using alarm sequence number, when in the analysis result
There are during this alarm data, terminate analysis;
When this alarm data is not present in the analysis result, grasped accordingly according to the alarm type of alarm data
Make.
5. according to the method described in claim 4, it is characterized in that, described carry out accordingly according to the alarm type of alarm data
Operation includes:
When the alarm type of alarm data is delayed for physical port to be alerted, alarm data is uploaded to the alert analysis database
Middle preservation;
When the alarm type of alarm data is delayed for logic subport to be alerted, alarm data is sent to the binding of logic subport
The corresponding alarm compacting queue of physical port is suppressed.
6. according to the method described in claim 5, it is characterized in that, this method further includes:It delays alarm data in logic subport
During being pressed, judge whether that the physical port for listening to the physical port of logic subport binding is delayed alarm data,
Be then, by logic subport delay alarm data from it is described alarm compacting queue in take out, and filter out the logic subport
It delays alarm data;
Otherwise, logic subport delay pressing time of alarm data exceed default pressing time threshold value when, by logic subport
Alarm data of delaying, which takes out and is uploaded in the alert analysis database from the alarm compacting queue, to be preserved.
7. according to the method described in claim 6, it is characterized in that, this method further includes:
Alarm data of periodically delaying to the logic subport in the alarm compacting queue carries out checking decision logic subport
Delay alarm data pressing time whether beyond default pressing time threshold value.
8. a kind of alarm data processing unit, which is characterized in that the alarm data processing unit includes:
Monitoring unit is alerted, for monitoring the alarm data in Network Management System;
Alarming processing unit, for judging whether the alarm data listened to meets presupposition analysis rule, and to meet default point
The alarm data of analysis rule corresponds to one analysis thread of distribution, carries out fault rootstock analyzing and processing to alarm data, is alerted
The analysis result of data;
Storage unit, for preserving in the analysis result to alert analysis database.
9. alarm data processing unit according to claim 8, which is characterized in that the alarming processing unit includes:Class
Type judgment sub-unit,
The type judgment sub-unit for obtaining the alarm type identification information that alarm type is indicated in alarm data, judges
Whether the alarm type of the alarm type identification information instruction matches with the alarm type in presupposition analysis rule,
It is then, to determine that the alarm data meets presupposition analysis rule, otherwise, it determines the alarm data is unsatisfactory for presupposition analysis
Rule,
Alarm type in the presupposition analysis rule includes:Physical port is delayed alarm, alternatively, the logic with physical port binding
Subport is delayed alarm.
10. alarm data processing unit according to claim 9, which is characterized in that
The alarming processing unit includes:Thread assignment unit, for for each physical port delay alarm and the physics end
The logic subport of all logic subports of mouthful binding is delayed the same analysis thread of alarm handler;
Alarming processing unit further includes:Duplicate removal subelement, for obtaining the alarm sequence number of every alarm data of unique mark, profit
It is searched in the analysis result preserved in the alert analysis database with alarm sequence number, it should when existing in the analysis result
During alarm data, terminate analysis;When this alarm data is not present in the analysis result, according to the alarm of alarm data
Type is operated accordingly.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201611199564.8A CN108234189B (en) | 2016-12-22 | 2016-12-22 | Alarm data processing method and device |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201611199564.8A CN108234189B (en) | 2016-12-22 | 2016-12-22 | Alarm data processing method and device |
Publications (2)
Publication Number | Publication Date |
---|---|
CN108234189A true CN108234189A (en) | 2018-06-29 |
CN108234189B CN108234189B (en) | 2021-10-08 |
Family
ID=62657219
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201611199564.8A Active CN108234189B (en) | 2016-12-22 | 2016-12-22 | Alarm data processing method and device |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN108234189B (en) |
Cited By (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2021109521A1 (en) * | 2019-12-06 | 2021-06-10 | 江苏智臻能源科技有限公司 | Buffer mechanism-based multi-type alarm determination algorithm |
CN113590427A (en) * | 2021-08-09 | 2021-11-02 | 中国建设银行股份有限公司 | Alarm method, device, storage medium and equipment for monitoring index abnormity |
CN114071263A (en) * | 2021-07-14 | 2022-02-18 | 北京天元创新科技有限公司 | Method and device for removing duplicate of optical fiber network alarm repeated data |
CN115333916A (en) * | 2022-07-19 | 2022-11-11 | 广州爱浦路网络技术有限公司 | Network element alarm information processing method, device and storage medium in communication network |
CN113590427B (en) * | 2021-08-09 | 2024-05-03 | 中国建设银行股份有限公司 | Alarm method, device, storage medium and equipment for monitoring index abnormality |
Citations (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1492624A (en) * | 2002-10-22 | 2004-04-28 | 华为技术有限公司 | Processing method of communication network warning and relatively analysis management device |
CN101090296A (en) * | 2007-07-31 | 2007-12-19 | 亿阳信通股份有限公司 | Diagnostic method and device for breakout of cable |
CN102136949A (en) * | 2011-03-24 | 2011-07-27 | 国网电力科学研究院 | Method and system for analyzing alarm correlation based on network and time |
CN103929326A (en) * | 2014-03-18 | 2014-07-16 | 烽火通信科技股份有限公司 | Communication network transmission type alarm uniform analysis device and method |
CN104243192A (en) * | 2013-06-17 | 2014-12-24 | 北京神州泰岳软件股份有限公司 | Fault treatment method and system |
CN105471661A (en) * | 2015-12-28 | 2016-04-06 | 福建星网锐捷网络有限公司 | Alarming processing method and system |
US20160269255A1 (en) * | 2003-12-29 | 2016-09-15 | Ebay Inc. | Method and system to process issue data pertaining to a system |
CN106254137A (en) * | 2016-08-30 | 2016-12-21 | 广州汇通国信信息科技有限公司 | The alarm root-cause analysis system and method for supervisory systems |
-
2016
- 2016-12-22 CN CN201611199564.8A patent/CN108234189B/en active Active
Patent Citations (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1492624A (en) * | 2002-10-22 | 2004-04-28 | 华为技术有限公司 | Processing method of communication network warning and relatively analysis management device |
US20160269255A1 (en) * | 2003-12-29 | 2016-09-15 | Ebay Inc. | Method and system to process issue data pertaining to a system |
CN101090296A (en) * | 2007-07-31 | 2007-12-19 | 亿阳信通股份有限公司 | Diagnostic method and device for breakout of cable |
CN102136949A (en) * | 2011-03-24 | 2011-07-27 | 国网电力科学研究院 | Method and system for analyzing alarm correlation based on network and time |
CN104243192A (en) * | 2013-06-17 | 2014-12-24 | 北京神州泰岳软件股份有限公司 | Fault treatment method and system |
CN103929326A (en) * | 2014-03-18 | 2014-07-16 | 烽火通信科技股份有限公司 | Communication network transmission type alarm uniform analysis device and method |
CN105471661A (en) * | 2015-12-28 | 2016-04-06 | 福建星网锐捷网络有限公司 | Alarming processing method and system |
CN106254137A (en) * | 2016-08-30 | 2016-12-21 | 广州汇通国信信息科技有限公司 | The alarm root-cause analysis system and method for supervisory systems |
Cited By (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2021109521A1 (en) * | 2019-12-06 | 2021-06-10 | 江苏智臻能源科技有限公司 | Buffer mechanism-based multi-type alarm determination algorithm |
CN114071263A (en) * | 2021-07-14 | 2022-02-18 | 北京天元创新科技有限公司 | Method and device for removing duplicate of optical fiber network alarm repeated data |
CN113590427A (en) * | 2021-08-09 | 2021-11-02 | 中国建设银行股份有限公司 | Alarm method, device, storage medium and equipment for monitoring index abnormity |
CN113590427B (en) * | 2021-08-09 | 2024-05-03 | 中国建设银行股份有限公司 | Alarm method, device, storage medium and equipment for monitoring index abnormality |
CN115333916A (en) * | 2022-07-19 | 2022-11-11 | 广州爱浦路网络技术有限公司 | Network element alarm information processing method, device and storage medium in communication network |
CN115333916B (en) * | 2022-07-19 | 2023-07-25 | 广州爱浦路网络技术有限公司 | Network element alarm information processing method, device and storage medium in communication network |
Also Published As
Publication number | Publication date |
---|---|
CN108234189B (en) | 2021-10-08 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN107688496B (en) | Task distributed processing method and device, storage medium and server | |
CN107908530B (en) | A kind of alert processing method and device | |
US10545807B2 (en) | Method and system for acquiring parameter sets at a preset time interval and matching parameters to obtain a fault scenario type | |
CN108234189A (en) | A kind of alarm data treating method and apparatus | |
CN112350854B (en) | Flow fault positioning method, device, equipment and storage medium | |
CN111708627A (en) | Task scheduling method and device based on distributed scheduling framework | |
JP5050357B2 (en) | Logging information management method, logging information management system, and logging information management means | |
CN110855481B (en) | Data acquisition system and method | |
CN113806191A (en) | Data processing method, device, equipment and storage medium | |
CN112134754A (en) | Pressure testing method and device, network equipment and storage medium | |
CN105471626A (en) | Method and system for distributing storage data of internal memory | |
CN111010290B (en) | Service log processing method and device, electronic equipment and storage medium | |
CN110609761B (en) | Method and device for determining fault source, storage medium and electronic equipment | |
CN113760634A (en) | Data processing method and device | |
CN105187490B (en) | A kind of transfer processing method of internet of things data | |
CN116431344A (en) | Configuration method and device of financial service resource degradation strategy and electronic equipment | |
CN110134578A (en) | A kind of data processing method and device | |
CN109728957A (en) | A kind of method and device of interactive mode O&M | |
CN111538604B (en) | Distributed task processing system | |
CN108304293A (en) | A kind of software systems monitoring method based on big data technology | |
CN107819750A (en) | Processing method, device, storage medium, processor and the system of request message | |
CN107231352A (en) | A kind of system journal monitoring method and device towards Xen virtualized environments | |
CN112416719A (en) | Monitoring processing method, system, equipment and storage medium for database container | |
CN112953792A (en) | Network traffic monitoring method and device | |
CN114090382B (en) | Health inspection method and device for super-converged cluster |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information |
Address after: Room 818, 8 / F, 34 Haidian Street, Haidian District, Beijing 100080 Applicant after: BEIJING ULTRAPOWER SOFTWARE Co.,Ltd. Address before: 100089 Beijing city Haidian District wanquanzhuang Road No. 28 Wanliu new building 6 storey block A Room 601 Applicant before: BEIJING ULTRAPOWER SOFTWARE Co.,Ltd. |
|
CB02 | Change of applicant information | ||
GR01 | Patent grant | ||
GR01 | Patent grant |