CN108234189A - A kind of alarm data treating method and apparatus - Google Patents

A kind of alarm data treating method and apparatus Download PDF

Info

Publication number
CN108234189A
CN108234189A CN201611199564.8A CN201611199564A CN108234189A CN 108234189 A CN108234189 A CN 108234189A CN 201611199564 A CN201611199564 A CN 201611199564A CN 108234189 A CN108234189 A CN 108234189A
Authority
CN
China
Prior art keywords
alarm
alarm data
analysis
logic
subport
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201611199564.8A
Other languages
Chinese (zh)
Other versions
CN108234189B (en
Inventor
杨林辉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Shenzhou Taiyue Software Co Ltd
Original Assignee
Beijing Shenzhou Taiyue Software Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Shenzhou Taiyue Software Co Ltd filed Critical Beijing Shenzhou Taiyue Software Co Ltd
Priority to CN201611199564.8A priority Critical patent/CN108234189B/en
Publication of CN108234189A publication Critical patent/CN108234189A/en
Application granted granted Critical
Publication of CN108234189B publication Critical patent/CN108234189B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0604Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0604Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
    • H04L41/0622Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time based on time
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/069Management of faults, events, alarms or notifications using logs of notifications; Post-processing of notifications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/16Threshold monitoring

Abstract

The invention discloses a kind of alarm data treating method and apparatus, method includes:Monitor the alarm data in Network Management System;Whether every alarm data for judging to listen to meets presupposition analysis rule, and one analysis thread of distribution is corresponded to the alarm data for meeting presupposition analysis rule, carries out fault rootstock analyzing and processing to alarm data, obtains the analysis result of alarm data;The analysis result is saved in alert analysis database.The treating method and apparatus of this alarm data of the present embodiment starts an analysis thread, to judge the fault rootstock of alarm data, so as to improve the analysis efficiency of alarm data since the alarm data for meeting presupposition analysis rule to listen to corresponds to.And by carrying out fault rootstock positioning analysis to the alarm data for meeting presupposition analysis rule, more reference informations for alarming processing can be provided, meet the application demand of enterprise.

Description

A kind of alarm data treating method and apparatus
Technical field
The present invention relates to technical field of network management, and in particular to a kind of alarm data treating method and apparatus.
Background technology
It is growing day by day to the dependence of computer network with the development of computer and the communication technology so that network management Effect and status are also more prominent, and alarm management is the basis of network management.In Network Management System, there is a large amount of Alarm data, network management system need to analyze alarm data, calculate and be saved in a series of processing of database.Mesh Before, common alarm type has:Hardware problem alarm, port alarm, transmission problem alarm, allocation problem alarm and clock problem Alarm etc..The prior art when handling alarm, is limited to the processor of network management system, the performance of input-output equipment And the limitation of hardware environment etc., processing speed and event that is less efficient, also, not generated in the prior art to alarm data Barrier root is analyzed, it is impossible to meet application demand.
Invention content
The present invention provides a kind of alarm data treating method and apparatus, to solve alarm data processing effect in the prior art Rate is low and the fault rootstock of alarm data generation is not analyzed, it is impossible to the problem of meeting application demand.
A kind of alarm data processing method according to an embodiment of the invention, method include:
Monitor the alarm data in Network Management System;
Whether the alarm data for judging to listen to meets presupposition analysis rule, and the alarm number to meet presupposition analysis rule According to corresponding one analysis thread of distribution, fault rootstock analyzing and processing is carried out to alarm data, obtains the analysis result of alarm data;
The analysis result is saved in alert analysis database.
According to another aspect of the present invention, a kind of alarm data processing unit, alarm data processing unit packet are provided It includes:
Monitoring unit is alerted, for monitoring the alarm data in Network Management System;
Alarming processing unit, for judging whether the alarm data listened to meets presupposition analysis rule, and it is pre- to meet If the alarm data of analysis rule corresponds to one analysis thread of distribution, fault rootstock analyzing and processing is carried out to alarm data, is obtained The analysis result of alarm data;
Storage unit, for preserving in the analysis result to alert analysis database.
The advantageous effect of the embodiment of the present invention is:The alarm data treating method and apparatus of the present invention, by monitoring network Alarm data in management system, the alarm data for meeting presupposition analysis rule to listen to, which corresponds to, starts an analytical line Journey to carry out fault rootstock analyzing and processing to alarm data, obtains the analysis result of alarm data, analysis result is saved in announcement In alert analytical database, so as to distribute independent thread to the alarm data for meeting presupposition analysis rule, realize multi-thread Journey handles the advantageous effect of alarm data, compared with prior art, improves the speed and efficiency of alarm data processing.In addition, To meeting the alarm data of presupposition analysis rule, the present embodiment can further analyze the fault rootstock of this kind of alarm data, so as to Processing for alarm data provides more reference informations, avoids reprocessing the alarm data generated by same fault rootstock, The workload of alarm management is reduced, improves the validity and value of network management alarm management.
Description of the drawings
Fig. 1 is a kind of flow chart of alarm data processing method of one embodiment of the invention;
Fig. 2 is a kind of overall flow figure of alarm data processing method of another embodiment of the present invention;
Fig. 3 is a kind of flow diagram of alarm data processing method of another embodiment of the invention;
Fig. 4 is a kind of block diagram of alarm data processing unit of one embodiment of the invention.
Specific embodiment
The exemplary embodiment of the disclosure is more fully described below with reference to accompanying drawings.Although the disclosure is shown in attached drawing Exemplary embodiment, it being understood, however, that may be realized in various forms the disclosure without should be by embodiments set forth here It is limited.On the contrary, these embodiments are provided to facilitate a more thoroughly understanding of the present invention, and can be by the scope of the present disclosure Completely it is communicated to those skilled in the art.
The design concept of the present invention is:Using the multithreading characteristic of Java language each to meet presupposition analysis rule Alarm starts independent analysis thread, and, when physical port delays alarm generation, its derivative is filtered so as to fulfill in network monitoring Logic subport out is delayed alarm, carries out handling caused weight to avoid to alarm data a plurality of caused by same fault rootstock Multiple labour mitigates the advantageous effect of the pressure of daily alarm work.
Java language supports multithreading, and the purpose of multithreading is to utilize cpu resource to greatest extent, is improved at data The efficiency of reason.Thread:Same class thread shares code and data space, and per thread has independent running stack and programmed counting Device, Thread-switch overhead are small.Multithreading refers to have multiple sequential flows performing in same program.Java applet operates in Java In virtual machine (Java Virtual Machine, abbreviation JVM), in the inside of JVM, the multitask of program is come real by thread Existing.For multiple threads in a process, multiple threads share the memory block of process, when having what new thread generated When, operating system does not distribute new memory, but new thread is allowed to share the memory of original process block.Therefore, cross-thread Communication is easy to, and speed is also quickly.
In Network Management System, alarm is there are many type, for example, according to the fault rootstock that alarm generates, alarm can divide For:It is alerted caused by the logic subport failure of alarm caused by physical port failure and physical port binding.
Physical port:Physical port is also known as interface, is visible port, for example, the RJ45 network interfaces of computer back panel, exchange The RJ45 ports of the network equipments such as machine, router, hub.
Logic subport:Logic interfacing refers to realize and data exchanging function but physically be not present, and needs to pass through and is configured The interface of foundation connects product, LoopBack interfaces, NULL interfaces, backup center logical channel including Dialer (dialing) interface, son And virtual-template interface etc..
In practical network monitoring, since logic subport is subordinated to physical port, so when a physical port is delayed When falling, generating alarm, under all logic subports can also generate interface and delay alarm.In this case, if not by logic Port alarm filter falls, then when subsequently handling again alarm data, certainly will cause for same failure (i.e. physics end Mouthful failure) caused by a plurality of alarm reprocessing, increase the pressure and workload of alarming processing.
In order to solve this problem, the present embodiment proposes a kind of technical solution that fault rootstock analysis is carried out to alarm, sentences Whether each logic subport of breaking alarm of delaying generates since physical port is broken down, if it is, logic subport is delayed alarm It filters out, to reduce the quantity of daily alarming processing, improves the validity of alarm monitoring.
Embodiment one
Fig. 1 is a kind of flow chart of alarm data processing method of one embodiment of the invention, referring to Fig. 1, the present embodiment This alarm data processing method include the following steps:
Step S101 monitors the alarm data in Network Management System;
Step S102, judges whether the alarm data listened to meets presupposition analysis rule, and to meet presupposition analysis rule Alarm data then corresponds to one analysis thread of distribution, carries out fault rootstock analyzing and processing to alarm data, obtains alarm data Analysis result;
The analysis result is saved in alert analysis database by step S103.
Method as shown in Figure 1 works as receipts it is found that by being monitored to the alarm data in network management system in the present embodiment Whether meet presupposition analysis rule, and to meet presupposition analysis rule to the alarm data listened to during alarm data for judgement Alarm data, which corresponds to, distributes independent thread, carries out fault rootstock analysis, so as to provide alarm failure root information for fortune Dimension personnel refer to, and the alarm that subsequent filter is generated by same fault rootstock is facilitated (not carried out to the alarm filtered out Reason), the quantity of alarming processing is reduced, improves the validity of alarm monitoring.Further, since the alarm to meet presupposition analysis rule Data correspond to one analysis thread of distribution, also ensure the efficiency of alarming processing.
Embodiment two
It should be noted that the application environment of the processing method of the alarm data of the present embodiment is Network Management System, tool Body, be to apply be configured between physical port and logic subport in the Network Management System of binding relationship.In network pipe Establish analysis strategy in reason system, Allocation Analysis rule and alarm pressing time threshold value in strategy, then, in Network Management System Middle startup Analysis Service (that is, processing method of the alarm data of the present embodiment) meets default point when Analysis Service receives one Analysis rule interface delay alarm when, start one analysis thread, to interface fault carry out root-cause analysis;Finally, by analysis result Alert analysis database is uploaded to, is used for interface, notice and worksheet processing.
Fig. 2 is a kind of overall flow figure of alarm data processing method of another embodiment of the present invention, referring to Fig. 2, sheet The overall flow of the alarm data processing method of embodiment is as follows:
Step S201 starts Analysis Service;
Specifically, when Network Management System starts, the alarm data of the present embodiment can be handled Analysis Service and started.Point Analysis service is an independent threading service, and the life cycle of the threading service can be with the life cycle phase of Network Management System Together, the life cycle of network management system, the i.e. network management system, when network management system stops, being divided from the whole cycle for starting to stopping Analysis service is also stopped.
In addition, in Analysis Service start-up course, user is used for alarm failure root by network management system by interface configurations The analysis strategy of source analysis is loaded into memory (including presupposition analysis rule and pressing time), and by alert analysis database It is loaded into memory through existing root failure analysis result, after the completion of presupposition analysis rule and the loading of existing analysis result, Start alarm to monitor.
Step S202, the fault rootstock analysis of alarm data;
After Analysis Service starts, start monitoring alarm, when alerting generation, one analysis thread of startup carries out root event when having Barrier analysis.
Step S203 uploads analysis result.
Here, the analysis result of upload is to upload to carry out the analysis result obtained after fault rootstock analysis, example to alarm Such as, after alarm of delaying to physical port carries out fault rootstock analysis, it is determined that being delayed caused by this failure as physical port, then exist Step S203 can upload physical port and delay alarm particular content and failure cause (that is, physical port is delayed).And for logic Port is delayed alarm, after carrying out fault rootstock analysis, it is determined that being delayed (rather than physical port is delayed) this failure by logic subport It is caused, then step S203 can upload logic subport delay alarm particular content and failure cause (that is, logic subport Delay) upload to database.
After the corresponding analysis thread of alarm data performs, the analysis result of alarm data is uploaded in database It preserves, is used for interface, notice, worksheet processing.
Embodiment three
Fig. 3 is a kind of flow diagram of alarm data processing method of another embodiment of the invention, referring to Fig. 3, sheet The alarm data processing method of embodiment includes the following steps:
Flow starts.
Step S301 is performed, monitors alarm data;
The alarm data processing method of the present embodiment reads the analysis plan in memory cache when listening to an alarm Slightly, presupposition analysis rule is configured in analysis strategy.
Step S302 judges whether to meet presupposition analysis rule;It is then, to perform step S303, otherwise terminate flow;
Due to Network Management System, there is more than monitoring interfaces to delay alarm, also many other types of alarm, this implementation It only delays in example to physical port and alarm and is subordinated to the logic subport alarm of delaying of physical port and handles, therefore, it is necessary to Alarm in network management system is filtered, judges whether current alarm data are that physical port is delayed or logic subport is delayed, such as Fruit is not the alarm of this two class, is directly terminated.
In the present embodiment, judge whether alarm data meets presupposition analysis rule and include:Obtain the middle instruction of alarm data The alarm type identification information of alarm type, judges whether the alarm type of alarm type identification information instruction advises with presupposition analysis Alarm type matching in then is then, to determine that alarm data meets presupposition analysis rule, otherwise, it determines alarm data is unsatisfactory for Presupposition analysis rule.Alarm type in presupposition analysis rule includes:Physical port is delayed alarm, alternatively, being bound with physical port Logic subport delay alarm.
Generally, every alarm data includes following information substantially:Title, alarm level, alarm status are alerted, alerts sequence Row number and alarm notification mode etc..The alarm title of wherein every alarm data is indicated generally at the type of this alarm data, because This, in the present embodiment, when receiving an alarm data, extraction alarm title, can by alert title instruction alarm type and Alarm type (two classes) in presupposition analysis rule:Physical port is delayed alarm, alternatively, logic subport is delayed, alarm is matched. When matching one of them, subsequent processing steps are carried out, are mismatched when with two kinds of alarm types in presupposition analysis rule When, directly terminate.
Step S303 starts analysis thread, judges whether to meet that there are analysis results;Otherwise, step S304 is performed, is then Terminate flow;
In this step, the logic for all logic subports of alarm and physical port binding of delaying for each physical port Subport is delayed the same analysis thread of alarm handler.
Specifically, when receiving an alarm data for meeting analysis rule, that is, receive a physical port delay alarm or Person's logic subport delay alarm when, first judge whether relevant existing analysis thread, if there is existing analysis thread, then This alarm data is included into existing analysis thread and is analyzed, if there is no relevant existing analysis thread, then for This alarm data distributes a new analysis thread, carries out fault rootstock analysis.
For example, logic subport there are two physical port A bindings, respectively:Logic subport a and logic subport B, when the method for the present embodiment formerly listen to physical port A physical port delay alarm when, judge there is no have analytical line Journey is then delayed the new analysis thread Process01 of alarm handler one for this physical port of physical port A.Then, at 3 seconds The logic subport for having listened to the logic subport a of physical port A later is delayed alarm, is carried out thread judgement, then can be found to deposit In relevant existing analysis thread Process01, then no longer delaying for the logic subport of logic subport a, alarm handler is new to be divided Analyse thread, but by the logic subport of logic subport a delay alarm be included into existing analysis thread Process01 carry out therefore Hinder root-cause analysis.
In addition, delay in the present embodiment to the physical port of physical port A alarm and the logic subport and logic of logic a The delay sequence of alarm of the logic subport of subport b is not restricted, that is, in the example above explanation, it is also possible to first listen to logic The logic subport of subport a is delayed alarm, and process flow is identical at this time, that is, is equally first carried out with the presence or absence of relevant existing point The judgement of thread is analysed, exists, is then included into existing analysis thread, is not present, then distribute new analysis thread.
It can be seen that by distributing same point for each physical port and its logic subport of binding in the present embodiment Thread is analysed, realizes the parallel processing that alarm data fault rootstock is analyzed in Network Management System, the processing mode with single thread It compares, improves the speed and efficiency of alert analysis.
In addition, in real network management system, alarm monitoring has continuity, is taken turns for being spaced to schedule The alarm followed, as long as failure is not eliminated, this kind of alarm can occur primary at regular intervals.
So after an alarm for meeting presupposition analysis condition is received, first judge whether alarm had been analyzed, if It has been analyzed that, no longer analyzed, and terminated thread.If do not analyzed, then carry out consequent malfunction root-cause analysis.
It is searched whether in alert analysis database there are the analysis result of the alarm that is, being first passed through in the present embodiment to accusing It is alert to carry out duplicate removal judgement, specifically, obtaining the alarm sequence number (Alarm_id) of every alarm data of unique mark, utilize alarm Searched in the analysis result that sequence number preserves in alert analysis database, when in analysis result there are during this alarm data, Terminate analysis;When this alarm data is not present in analysis result, grasped accordingly according to the alarm type of alarm data Make.
In this way, for the alarm that those had been analyzed, it can directly terminate flow, no longer carry out subsequent analysis, so as to Improve the efficiency of alarm data processing.
Step S304 determines whether that physical port is delayed alarm;It is then, to perform step S305, uploads analysis result;It is no Then, step S306 is performed;
When being made whether to meet the judgement of presupposition analysis rule to alarm in above mentioned steps S3 02, it may be determined that go out current announcement Alert type (be physical port delay alarm or logic subport is delayed alarm), in this step, i.e. step S304, specific judgement Whether current alarm is that physical port is delayed alarm, when alarm data alarm type for physical port delay alarm when, number will be alerted It is preserved according to being uploaded in alert analysis database.
Note:Since the usual influence power of the failure of physical port is larger, so for the physics as caused by physical port failure Port delay alarm need carry out key monitoring, when receiving this kind of alarm, such alarm data can be uploaded directly into alert analysis It is convenient that subsequent processing is carried out to this kind of alarm data in database.
And for the logic subport for being subordinated to physical port, there are two types of situations for the generation of alarm:The first is accused Police is caused by physical port failure, that is, the fault rootstock that logic subport is delayed be physical port, second alarm be by Caused by the failure of logic subport in itself, i.e., the fault rootstock that logic subport is delayed is logic subport.
In the present embodiment, the first alarm for logic subport, i.e. fault rootstock are this kind of alarm of physical port It needs to be filtered, carries out replicate analysis processing to avoid to alarm a plurality of caused by same failure, increase the work of alarming processing It measures.
Step S306, alarm data is suppressed;
When the alarm type of alarm data is delayed for logic subport to be alerted, alarm data is sent to logic subport and is tied up The corresponding alarm compacting queue of fixed physical port is suppressed.
Note:Alarm of why delaying in the present embodiment to logic subport is suppressed, and is alerted not because physical port is delayed One be scheduled on logic subport delay alarm before occur, it is also possible to logic subport delay alarm after occur.Such as:Physics end Mouth delays to alert to be occurred behind 5 seconds after logic subport delays alarm.
As a result, when logic subport delay alarm occur when, need in system temporary cache for a period of time, if without If compacting, the alarm of delaying of logic subport will be uploaded to database, this alarm is not just filtered, and can cause to alert It repeats.
Step S307 judges whether to receive corresponding physical port and delays alarm;It is then, to perform step S308, otherwise, performs Step S305;
It delays during alarm data is pressed in logic subport, the present embodiment judges whether that listening to the logic subport ties up The physical port of fixed physical port is delayed alarm data, otherwise, logic subport delay alarm data pressing time beyond pre- If during pressing time threshold value, logic subport alarm data of delaying is suppressed in queue from alarm and takes out and be uploaded to alert analysis number According to being preserved in library.
Note:The physics of logic subport binding is not received during alarm data is pressed if delayed in logic subport The physical port of port is delayed, and to represent the fault rootstock of this alarm data be not physical port to alarm data, so being accused Police is reported for subsequent processing.
In addition, the logic subport also periodically suppressed in queue alarm in the present embodiment is delayed, alarm data is examined Look into decision logic subport delay alarm data pressing time whether beyond default pressing time threshold value.
For example, once alert compacting queue every 1 second poll, check logic subport delay alarm pressing time whether More than preset pressing time threshold value (threshold value can be set as 5 seconds).If it exceeds the pressing time and do not receive the logic son The physical port of the physical port of port binding delay alarm logic subport can then be delayed alarm upload to database and terminate point Analyse thread.
Step S308, filters out alarm data;
If delayed during alarm data is pressed in logic subport, the physical port of logic subport binding is listened to Physical port delay alarm data, then logic subport alarm data of delaying is suppressed in queue from alarm and is taken out, and filter out this Logic subport is delayed alarm data.
Note:The physics end of logic subport binding is had received during alarm data is pressed if delayed in logic subport Mouthful physical port delay that represent the fault rootstock of this alarm data be physical port to alarm data, so not needing to be alerted It reports.
So far, flow terminates.
It is real as shown in Figure 3 it is found that the processing method of the alarm data of the present embodiment utilizes the multithreading characteristic of Java language Show the fault rootstock that physical port common in network management delays alarm and logic subport is delayed between alarm to position, reduce day The quantity of normal alarming processing.It is the sub- end of logic of each physical port and its binding and in specific fault rootstock analytic process Mouth is established and starts an analysis thread, improves the efficiency of alarm data analysis and the validity of alarm monitoring.
Example IV
Fig. 4 is a kind of block diagram of alarm data processing unit of one embodiment of the invention, referring to Fig. 4, at alarm data Reason device 40 includes:
Monitoring unit 401 is alerted, for monitoring the alarm data in Network Management System;
Alarming processing unit 402, for judging whether the alarm data listened to meets presupposition analysis rule, and to meet The alarm data of presupposition analysis rule corresponds to one analysis thread of distribution, carries out fault rootstock analyzing and processing to alarm data, obtains To the analysis result of alarm data;
Storage unit 403, for preserving in analysis result to alert analysis database.
In one embodiment of the invention, alarming processing unit 402 includes:Type judgment sub-unit,
Type judgment sub-unit for obtaining the alarm type identification information of the middle instruction alarm type of alarm data, is sentenced Whether the alarm type of disconnected alarm type identification information instruction matches with the alarm type in presupposition analysis rule, is then, to determine Alarm data meets presupposition analysis rule, otherwise, it determines alarm data is unsatisfactory for presupposition analysis rule,
Alarm type in presupposition analysis rule includes:Physical port is delayed alarm, alternatively, the logic with physical port binding Subport is delayed alarm.
In one embodiment of the invention, alarming processing unit 402 further includes:Thread assignment unit, for being every A physical port delay alarm and physical port binding all logic subports logic subport alarm handler of delaying it is same A analysis thread;
Duplicate removal subelement for obtaining the alarm sequence number of every alarm data of unique mark, is existed using alarm sequence number It is searched in the analysis result preserved in alert analysis database, when there are during this alarm data, terminate to analyze in analysis result; When this alarm data is not present in analysis result, operated accordingly according to the alarm type of alarm data.
In one embodiment of the invention, alarming processing unit 402 is specifically for the alarm type for working as alarm data Physical port delay alarm when, alarm data is uploaded in alert analysis database and is preserved, when the alarm type of alarm data is Logic subport delay alarm when, by alarm data be sent to logic subport binding physical port it is corresponding alarm compacting queue It is suppressed.
In one embodiment of the invention, alarming processing unit 402 is additionally operable to, and is delayed alarm data quilt in logic subport During compacting, the physical port for judging whether to listen to the physical port of logic subport binding is delayed alarm data, be then, will Logic subport alarm data of delaying is suppressed in queue from alarm and is taken out, and filter out the logic subport and delay alarm data;Otherwise, Logic subport delay pressing time of alarm data exceed default pressing time threshold value when, logic subport is delayed alarm data It suppresses to take out and be uploaded in alert analysis database in queue from alarm and preserve.
In one embodiment of the invention, alarming processing unit 402 is additionally operable to, and periodically alarm is suppressed in queue Logic subport delay alarm data check decision logic subport delay alarm data pressing time whether beyond pre- If pressing time threshold value.
It should be noted that this alarm data processing unit of the present embodiment be in aforementioned alarm data processing method Corresponding steps it is corresponding, thus, the more detailed course of work of alarm data processing unit of the present embodiment may refer to aforementioned Explanation in alarm data processing method embodiment, which is not described herein again.
In summary, the treating method and apparatus of the alarm data of the embodiment of the present invention utilizes the more of Java development languages Thread characteristics solve alarm reprocessing caused by not carrying out fault rootstock analysis to alarm in the prior art, alert work Amount and pressure it is big the problem of, by listen to Network Management System occur physical port delay alarm when, filter the physical port The logic subport that failure is derived is delayed alarm, avoids and a plurality of alarm data caused by same root failure is repeated Analyzing and processing, so as to alleviate the quantity of daily alarming processing and pressure, improves the efficiency of alarming processing, meets enterprise Application demand.
The above description is merely a specific embodiment, under the above-mentioned introduction of the present invention, those skilled in the art Other improvement or deformation can be carried out on the basis of above-described embodiment.It will be understood by those skilled in the art that above-mentioned tool The purpose of the present invention is only preferably explained in body description, and protection scope of the present invention is subject to the protection scope in claims.

Claims (10)

1. a kind of alarm data processing method, which is characterized in that the method includes:
Monitor the alarm data in Network Management System;
Whether the alarm data for judging to listen to meets presupposition analysis rule, and the alarm data pair to meet presupposition analysis rule An analysis thread should be distributed, fault rootstock analyzing and processing is carried out to alarm data, obtains the analysis result of alarm data;
The analysis result is saved in alert analysis database.
2. according to the method described in claim 1, it is characterized in that, described to judge whether the alarm data that listens to meets default Analysis rule includes:
The alarm type identification information that alarm type is indicated in alarm data is obtained, judges the alarm type identification information instruction Alarm type whether matched with the alarm type in presupposition analysis rule,
It is then, to determine that the alarm data meets presupposition analysis rule,
Otherwise, it determines the alarm data is unsatisfactory for presupposition analysis rule;
Alarm type in the presupposition analysis rule includes:Physical port is delayed alarm, alternatively, the logic with physical port binding Subport is delayed alarm.
3. according to the method described in claim 2, it is characterized in that, described is the alarm data correspondence for meeting presupposition analysis rule One analysis thread of distribution includes:
It delays alarm for the delay logic subport of all logic subports of alarm and physical port binding of each physical port Distribute same analysis thread.
4. according to the method in claim 2 or 3, which is characterized in that described that fault rootstock analysis bag is carried out to alarm data It includes:
The alarm sequence number of every alarm data of unique mark is obtained,
It is searched in the analysis result preserved in the alert analysis database using alarm sequence number, when in the analysis result There are during this alarm data, terminate analysis;
When this alarm data is not present in the analysis result, grasped accordingly according to the alarm type of alarm data Make.
5. according to the method described in claim 4, it is characterized in that, described carry out accordingly according to the alarm type of alarm data Operation includes:
When the alarm type of alarm data is delayed for physical port to be alerted, alarm data is uploaded to the alert analysis database Middle preservation;
When the alarm type of alarm data is delayed for logic subport to be alerted, alarm data is sent to the binding of logic subport The corresponding alarm compacting queue of physical port is suppressed.
6. according to the method described in claim 5, it is characterized in that, this method further includes:It delays alarm data in logic subport During being pressed, judge whether that the physical port for listening to the physical port of logic subport binding is delayed alarm data,
Be then, by logic subport delay alarm data from it is described alarm compacting queue in take out, and filter out the logic subport It delays alarm data;
Otherwise, logic subport delay pressing time of alarm data exceed default pressing time threshold value when, by logic subport Alarm data of delaying, which takes out and is uploaded in the alert analysis database from the alarm compacting queue, to be preserved.
7. according to the method described in claim 6, it is characterized in that, this method further includes:
Alarm data of periodically delaying to the logic subport in the alarm compacting queue carries out checking decision logic subport Delay alarm data pressing time whether beyond default pressing time threshold value.
8. a kind of alarm data processing unit, which is characterized in that the alarm data processing unit includes:
Monitoring unit is alerted, for monitoring the alarm data in Network Management System;
Alarming processing unit, for judging whether the alarm data listened to meets presupposition analysis rule, and to meet default point The alarm data of analysis rule corresponds to one analysis thread of distribution, carries out fault rootstock analyzing and processing to alarm data, is alerted The analysis result of data;
Storage unit, for preserving in the analysis result to alert analysis database.
9. alarm data processing unit according to claim 8, which is characterized in that the alarming processing unit includes:Class Type judgment sub-unit,
The type judgment sub-unit for obtaining the alarm type identification information that alarm type is indicated in alarm data, judges Whether the alarm type of the alarm type identification information instruction matches with the alarm type in presupposition analysis rule,
It is then, to determine that the alarm data meets presupposition analysis rule, otherwise, it determines the alarm data is unsatisfactory for presupposition analysis Rule,
Alarm type in the presupposition analysis rule includes:Physical port is delayed alarm, alternatively, the logic with physical port binding Subport is delayed alarm.
10. alarm data processing unit according to claim 9, which is characterized in that
The alarming processing unit includes:Thread assignment unit, for for each physical port delay alarm and the physics end The logic subport of all logic subports of mouthful binding is delayed the same analysis thread of alarm handler;
Alarming processing unit further includes:Duplicate removal subelement, for obtaining the alarm sequence number of every alarm data of unique mark, profit It is searched in the analysis result preserved in the alert analysis database with alarm sequence number, it should when existing in the analysis result During alarm data, terminate analysis;When this alarm data is not present in the analysis result, according to the alarm of alarm data Type is operated accordingly.
CN201611199564.8A 2016-12-22 2016-12-22 Alarm data processing method and device Active CN108234189B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201611199564.8A CN108234189B (en) 2016-12-22 2016-12-22 Alarm data processing method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201611199564.8A CN108234189B (en) 2016-12-22 2016-12-22 Alarm data processing method and device

Publications (2)

Publication Number Publication Date
CN108234189A true CN108234189A (en) 2018-06-29
CN108234189B CN108234189B (en) 2021-10-08

Family

ID=62657219

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201611199564.8A Active CN108234189B (en) 2016-12-22 2016-12-22 Alarm data processing method and device

Country Status (1)

Country Link
CN (1) CN108234189B (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2021109521A1 (en) * 2019-12-06 2021-06-10 江苏智臻能源科技有限公司 Buffer mechanism-based multi-type alarm determination algorithm
CN113590427A (en) * 2021-08-09 2021-11-02 中国建设银行股份有限公司 Alarm method, device, storage medium and equipment for monitoring index abnormity
CN114071263A (en) * 2021-07-14 2022-02-18 北京天元创新科技有限公司 Method and device for removing duplicate of optical fiber network alarm repeated data
CN115333916A (en) * 2022-07-19 2022-11-11 广州爱浦路网络技术有限公司 Network element alarm information processing method, device and storage medium in communication network
CN113590427B (en) * 2021-08-09 2024-05-03 中国建设银行股份有限公司 Alarm method, device, storage medium and equipment for monitoring index abnormality

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1492624A (en) * 2002-10-22 2004-04-28 华为技术有限公司 Processing method of communication network warning and relatively analysis management device
CN101090296A (en) * 2007-07-31 2007-12-19 亿阳信通股份有限公司 Diagnostic method and device for breakout of cable
CN102136949A (en) * 2011-03-24 2011-07-27 国网电力科学研究院 Method and system for analyzing alarm correlation based on network and time
CN103929326A (en) * 2014-03-18 2014-07-16 烽火通信科技股份有限公司 Communication network transmission type alarm uniform analysis device and method
CN104243192A (en) * 2013-06-17 2014-12-24 北京神州泰岳软件股份有限公司 Fault treatment method and system
CN105471661A (en) * 2015-12-28 2016-04-06 福建星网锐捷网络有限公司 Alarming processing method and system
US20160269255A1 (en) * 2003-12-29 2016-09-15 Ebay Inc. Method and system to process issue data pertaining to a system
CN106254137A (en) * 2016-08-30 2016-12-21 广州汇通国信信息科技有限公司 The alarm root-cause analysis system and method for supervisory systems

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1492624A (en) * 2002-10-22 2004-04-28 华为技术有限公司 Processing method of communication network warning and relatively analysis management device
US20160269255A1 (en) * 2003-12-29 2016-09-15 Ebay Inc. Method and system to process issue data pertaining to a system
CN101090296A (en) * 2007-07-31 2007-12-19 亿阳信通股份有限公司 Diagnostic method and device for breakout of cable
CN102136949A (en) * 2011-03-24 2011-07-27 国网电力科学研究院 Method and system for analyzing alarm correlation based on network and time
CN104243192A (en) * 2013-06-17 2014-12-24 北京神州泰岳软件股份有限公司 Fault treatment method and system
CN103929326A (en) * 2014-03-18 2014-07-16 烽火通信科技股份有限公司 Communication network transmission type alarm uniform analysis device and method
CN105471661A (en) * 2015-12-28 2016-04-06 福建星网锐捷网络有限公司 Alarming processing method and system
CN106254137A (en) * 2016-08-30 2016-12-21 广州汇通国信信息科技有限公司 The alarm root-cause analysis system and method for supervisory systems

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2021109521A1 (en) * 2019-12-06 2021-06-10 江苏智臻能源科技有限公司 Buffer mechanism-based multi-type alarm determination algorithm
CN114071263A (en) * 2021-07-14 2022-02-18 北京天元创新科技有限公司 Method and device for removing duplicate of optical fiber network alarm repeated data
CN113590427A (en) * 2021-08-09 2021-11-02 中国建设银行股份有限公司 Alarm method, device, storage medium and equipment for monitoring index abnormity
CN113590427B (en) * 2021-08-09 2024-05-03 中国建设银行股份有限公司 Alarm method, device, storage medium and equipment for monitoring index abnormality
CN115333916A (en) * 2022-07-19 2022-11-11 广州爱浦路网络技术有限公司 Network element alarm information processing method, device and storage medium in communication network
CN115333916B (en) * 2022-07-19 2023-07-25 广州爱浦路网络技术有限公司 Network element alarm information processing method, device and storage medium in communication network

Also Published As

Publication number Publication date
CN108234189B (en) 2021-10-08

Similar Documents

Publication Publication Date Title
CN107688496B (en) Task distributed processing method and device, storage medium and server
CN107908530B (en) A kind of alert processing method and device
US10545807B2 (en) Method and system for acquiring parameter sets at a preset time interval and matching parameters to obtain a fault scenario type
CN108234189A (en) A kind of alarm data treating method and apparatus
CN112350854B (en) Flow fault positioning method, device, equipment and storage medium
CN111708627A (en) Task scheduling method and device based on distributed scheduling framework
JP5050357B2 (en) Logging information management method, logging information management system, and logging information management means
CN110855481B (en) Data acquisition system and method
CN113806191A (en) Data processing method, device, equipment and storage medium
CN112134754A (en) Pressure testing method and device, network equipment and storage medium
CN105471626A (en) Method and system for distributing storage data of internal memory
CN111010290B (en) Service log processing method and device, electronic equipment and storage medium
CN110609761B (en) Method and device for determining fault source, storage medium and electronic equipment
CN113760634A (en) Data processing method and device
CN105187490B (en) A kind of transfer processing method of internet of things data
CN116431344A (en) Configuration method and device of financial service resource degradation strategy and electronic equipment
CN110134578A (en) A kind of data processing method and device
CN109728957A (en) A kind of method and device of interactive mode O&M
CN111538604B (en) Distributed task processing system
CN108304293A (en) A kind of software systems monitoring method based on big data technology
CN107819750A (en) Processing method, device, storage medium, processor and the system of request message
CN107231352A (en) A kind of system journal monitoring method and device towards Xen virtualized environments
CN112416719A (en) Monitoring processing method, system, equipment and storage medium for database container
CN112953792A (en) Network traffic monitoring method and device
CN114090382B (en) Health inspection method and device for super-converged cluster

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
CB02 Change of applicant information

Address after: Room 818, 8 / F, 34 Haidian Street, Haidian District, Beijing 100080

Applicant after: BEIJING ULTRAPOWER SOFTWARE Co.,Ltd.

Address before: 100089 Beijing city Haidian District wanquanzhuang Road No. 28 Wanliu new building 6 storey block A Room 601

Applicant before: BEIJING ULTRAPOWER SOFTWARE Co.,Ltd.

CB02 Change of applicant information
GR01 Patent grant
GR01 Patent grant