CN109309577A - Alert processing method, apparatus and system for SDN network - Google Patents

Alert processing method, apparatus and system for SDN network Download PDF

Info

Publication number
CN109309577A
CN109309577A CN201710622980.2A CN201710622980A CN109309577A CN 109309577 A CN109309577 A CN 109309577A CN 201710622980 A CN201710622980 A CN 201710622980A CN 109309577 A CN109309577 A CN 109309577A
Authority
CN
China
Prior art keywords
alarm
analysis
association analysis
service routine
warning
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201710622980.2A
Other languages
Chinese (zh)
Inventor
邢瑞江
武炳正
张永福
王茜
庞俊英
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shanghai Layer Peak Network Technology Co ltd
Original Assignee
Hangzhou Da Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou Da Technology Co Ltd filed Critical Hangzhou Da Technology Co Ltd
Priority to CN201710622980.2A priority Critical patent/CN109309577A/en
Publication of CN109309577A publication Critical patent/CN109309577A/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/069Management of faults, events, alarms or notifications using logs of notifications; Post-processing of notifications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0893Assignment of logical groups to network elements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/22Traffic shaping
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/29Flow control; Congestion control using a combination of thresholds

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

This application discloses a kind of methods of alarming processing for SDN network, which comprises warning association analysis handles service routine and receives the alarm that alarm source is sent;The warning association analysis processing service routine is the service routine independently of SDN controller and monitoring system constructed in advance;The warning association analysis processing service routine is associated analysis to the alarm received;According to the association analysis as a result, judge it is described alarm whether really for influence business or be failure non-derived alarm;If it is not, filtering the alarm;If so, sending the alarm.Using the above method, solving the problems, such as to be currently used for exist in the alert processing method of SDN network influences that the function of SDN controller, alarm source are single and alarm is bombed.

Description

Alert processing method, apparatus and system for SDN network
Technical field
The present invention relates to SDN network technologies, and in particular to a kind of alert processing method and device for SDN network.This It invents while being related to a kind of alarming processing system for SDN network.
Background technique
In SDN network, alarm monitoring faces following challenge: because the sensibility and importance of the network equipment, network are set When encountering failure or network fluctuation, a large amount of alarm may be generated, wherein existing largely on business without influence Also should not the alarm that participates in of network O&M personnel, need to identify the alarm of real traffic affecting and mistake by warning association analysis Filter useless warning information.
Under the prior art, in SDN network, the method for the alarming processing for SDN network, processing mode mainly with Lower scheme (be specifically detailed in patent application " a kind of controller and the method for alarm association processing " (application No. is 201410802293.5)):
Increase the association analysis and association process function of alarm in SDN controller.When event occurs in the network equipment of lower layer When barrier, SDN controller is reported to, when controller receives the alarm that southbound interface reports, to the net of the alarm and this controller Existing alarm within the scope of network carries out alarm association analysis.When the result of alarm association analysis is to find Root alarm (i.e. Non-derived alarm), then the controller inhibits reporting for the alarm.
When the result of alarm association analysis is not find Root alarm, then the controller gives the alarm report Upper controller or application, or do not find Root alarm, then the controller is according to preconfigured alert analysis strategy Determine whether the alarm report to upper controller or application.
The method of prior art alarming processing haves the defects that some apparent:
1, the function of SDN controller is influenced: firstly, warning association analysis and the function of processing are added in SDN controller, SDN controller complexity is increased, controller is made to become too fat to move;Under the huge scene of alarm amount, when resource consumption is excessive, shadow Ring the function of SDN controller.
2, alarm source is single: the warning information that can only be associated with inside SDN controller.
3, cause unnecessarily to alert bombing: due to the only derivative alarm of association filtering, and for the exception of the network equipment Root alarm caused by fluctuation etc., can not filter, therefore still result in and unnecessarily alert not influencing on business It bombs.
In conclusion the method for the existing alarming processing for SDN network, which exists, to be influenced the function of SDN controller, accuses The problem of alert source is single and alarm is caused to be bombed.
Summary of the invention
The application provides a kind of alarm association processing method, to solve to be currently used for the side of the alarming processing of SDN network Method has that the function of influence SDN controller, alarm source are single and alarm is caused to be bombed.
The alarm association processing method, comprising:
Warning association analysis handles service routine and receives the alarm that alarm source is sent;The warning association analysis processing service Program is the service routine independently of SDN controller and monitoring system constructed in advance;
The warning association analysis processing service routine is associated analysis to the alarm received;
According to the association analysis as a result, judge it is described alarm whether really for influence business or be failure non-derived announcement It is alert;If it is not, filtering the alarm;
If so, sending the alarm.
Optionally, before the step of sending the alarm, comprising:
Whether judgement configures automatic recovery policy for the alarm;If so, carrying out recovery processing;
Judge whether to be successfully recovered, if so, filtering the alarm, enters the step of sending the alarm if not.
Optionally, after warning association analysis processing service routine receives the alarm step that alarm source is sent, comprising:
The frequency occurred according to the alarm polymerize this alarm.
Optionally, the frequency occurred according to the alarm polymerize this alarm, comprising:
When the frequency that the alarm occurs is greater than or equal to predeterminated frequency threshold value, this alarm is polymerize.
Optionally, the described pair of alarm received is associated analysis, comprising:
It is associated with the analysis of SDN controller and/or association monitoring analysis.
Optionally, the association analysis, comprising:
The alarm type of the alarm is analyzed;And/or
Analysis to alarm to service impact.
Optionally, the alarm source includes: network element, SDN controller, monitoring system, log processing system, monitoring script.
Optionally, the warning association analysis handles service routine, comprising:
The warning association analysis processing service routine provides unified alarm report interface, sends for receiving alarm source Alarm.
The application also provides a kind of device of alarming processing for SDN network, and described device includes:
Receiving unit is alerted, receives the alarm that alarm source is sent for warning association analysis processing service routine;The announcement Alert association analysis processing service routine is the service routine independently of SDN controller and monitoring system constructed in advance;
Alert analysis unit closes the alarm received for warning association analysis processing service routine Connection analysis;
Breakdown judge unit, for according to the association analysis as a result, judge it is described alarm whether be influence business or really The actually alarm of failure;
Alarm filter unit, for filtering the alarm when the output of breakdown judge unit is no;
Transmission unit is alerted, for sending the alarm when the output of type judging unit, which is, is.
In addition the application provides a kind of alarming processing system of SDN network, the system comprises: association analysis handles mould Block, tactful configuration module, data memory module, alarm and report query module;
The association analysis processing module, for receiving the alarm of alarm source transmission and the alarm being associated analysis And processing;
The strategy configuration module, for carrying out the configuration of warning strategies;
The data memory module, for storing the warning information of association analysis processing module transmission.
The alarm and report query module, for carrying out the inquiry of alarm and report.
Compared with prior art, the invention has the following advantages that
The application provides a kind of method of alarming processing for SDN network, which comprises at warning association analysis It manages service routine and receives the alarm that alarm source is sent;Warning association analysis processing service routine be construct in advance independently of The service routine of SDN controller and monitoring system;The alarm of the warning association analysis processing service routine to receiving It is associated analysis;According to the association analysis as a result, judging whether the alarm is certain influence business or is the non-of failure Derivative alarm;If it is not, filtering the alarm;If so, sending the alarm.
Compared with prior art, technical solution provided by the present application has significant advantage.
1, service routine is handled using the warning association analysis independently of SDN controller and monitoring system, does not will increase SDN Controller complexity, even if will not consume the resource of too many SDN controller when under the huge scene of alarm amount, will not influence The function of SDN controller;
2, except due to warning association analysis processing service routine independently of SDN controller and monitoring system, can pass through Unified alarm report interface is interacted with alarm source, therefore can receive the alarm that various alarm sources are sent, and realizes alarm source Diversification;
3, this programme is other than being filtered derivative alarm, for non-derived alarm, only certain influence business or is The non-derived alarm of failure is just sent to network O&M personnel, remaining non-derived alarm is filtered, and avoids alarm and bombs Occur.
Detailed description of the invention
Fig. 1 is a kind of flow chart of the method for alarming processing for SDN network that the application first embodiment provides.
Fig. 2 is a kind of schematic diagram of the device for alarming processing for SDN network that the application second embodiment provides.
Fig. 3 is a kind of schematic diagram for alarming processing system for SDN network that the application 3rd embodiment provides.
Specific embodiment
In the following description, numerous specific details are set forth in order to facilitate a full understanding of the present invention.But the present invention can be with Much it is different from other way described herein to implement, those skilled in the art can be without prejudice to intension of the present invention the case where Under do similar popularization, therefore the present invention is not limited to the specific embodiments disclosed below.
In the embodiment of the present application, method, the one kind for each providing a kind of alarming processing for SDN network are used for The device of the alarming processing of SDN network and alarming processing architecture system for SDN network.In the following embodiments by One is described in detail.
The method is mainly by the association analysis processing module 101 in the alarming processing architecture system for SDN network real It is existing.The application is discussed in detail below in conjunction with the alarming processing architecture system for SDN network to be used at the alarm of SDN network The method of reason.
The application first embodiment provides a kind of method of alarming processing for SDN network.Referring to FIG. 1, it shows A kind of flow chart of the method for the alarming processing for SDN network provided according to an embodiment of the present application has been provided.Below in conjunction with Fig. 1 is described in detail.
Step S101, warning association analysis handle service routine and receive the alarm that alarm source is sent.
The alarm source refers to the source for generating alarm, comprising: network element, SDN controller, monitoring system, log processing system System, monitoring script etc..
The SDN (Software Defined Networking), i.e. software defined network, relative to traditional network A kind of new network framework of innovation, it is intended to realize the data plane for making the network equipment and control being completely separated for plane;It is described SDN controller is the application program in software defined network (SDN), is responsible for flow control to ensure intelligent network.
The network element (NE:Network Element) is responsible for the network functional entity of data forwarding, network element and network element Between link network consisting Forwarding plane.For example, Openflow interchanger.
The SDN controller: referring to the control unit interacted with network element, and single or multiple controller composition controls are flat Face.
The alarm refers to that the network equipment encounters the warning information generated when failure or network fluctuation.The alarm Include: to derive alarm and non-derived alarm (i.e. Root alarm), is wherein alerted and not shadow in Root alarm comprising traffic affecting The alarm of the business of sound.The derivative alarm, is often referred to that there are the alarms that upstream alerts;The non-derived alarm, refers to that there is no upper Swim the alarm of alarm.For example, if some alarm has found its upstream by association analysis for link down (link failure) Existing node down (node failure) or port down (port failure), then link down is derivative alarm;If logical Association analysis is crossed, node down (node failure) or port down (port failure) existing for its upstream cannot be found, then Link down is non-derived alarm or Root alarm.
The warning association analysis handles service routine (Alert Sevice Handler, referred to as AHS), refers to building Independently of the service routine of SDN controller and monitoring system.AHS provides unified alarm report interface, customizes specific alarm Message format.The warning association analysis processing service routine can receive the alarm in any source and carry out to received alarm Association analysis.
The warning association analysis includes two aspect meanings: being on the one hand wherein to judge that the alarm is by association analysis Derivative alarm or non-derived alarm;On the other hand by association analysis judge it is described alert whether influence business or whether be Failure.By warning association analysis, so as to warning association analysis processing service routine different types of alarm is made it is different Processing.
Service routine is handled using the warning association analysis independently of SDN controller and monitoring system, avoiding will alert The code of module adds the too fat to move problem for increasing controller complexity in SDN controller, becoming controller;And alarm mould The code update of block may influence the network function of SDN controller script, increase the problem of code risk.
The warning association analysis processing service module receives the alarm that alarm source is sent, and can refer to the alarm association point The alarm that analysis processing service routine is sent by unified alarm report interface alarm source.Due to using in unified alarm Interface is reported, therefore various alarm scenes and mode can be compatible with.
When sending alarm to warning association analysis processing service routine, the warning information sent can use alarm source The specific alarm information format customized to warning association analysis processing service routine, for example, warning information can be customized including Following parameter: alarm grade (level), timestamp (timestamp), edge_cluster_id (edge bank ID), alarm type (type), device name (nodename), warning content (Content),
Below it is the example of node down warning information:
level:critical
timestamp:2017-05-13T13:23:52.251
edge_cluster_id:3
type:node
nodename:GD-GZ-SSW-1
Content:node[GD-GZ-SSW-1]down,nodeId[openflow:128984041998]
It should be noted that the specific alarm information format of warning association analysis processing service routine customization is not limited to This example.
For example, the warning association analysis processing service routine has received above-mentioned node down alarm in step S101 Information.
Step S102, the warning association analysis processing service routine are associated analysis to the alarm received.
The warning association analysis processing service routine needs to be associated analysis after receiving alarm, is obtained by analysis Take alarm type, alarm to business whether there is or not impacting and whether being the information such as failure, to carry out phase based on the analysis results It should handle.
The association analysis, including association SDN controller are analyzed and are associated with monitoring analysis.Since SDN controller is The core of SDN network, which control the network equipments such as network element in entire SDN network, therefore there is SDN in SDN controller The operation information of each network equipment in network, the warning association analysis processing service routine can pass through inquiry SDN control The association analysis that device is alerted.It, can also be by looking into except through the association analysis that inquiry inquiry SDN controller is alerted Ask the association analysis that monitoring system is alerted.
The association SDN controller analysis, refers to some information being associated with inside SDN controller when carrying out alert analysis, Including Network status, link (link) situation, port situation etc..
The association monitoring analysis refers to the information that the equipment of monitoring system monitoring is associated with when carrying out alert analysis, It include: Openflow interchanger situation, port situation etc..
When being associated analysis, it can be first associated the analysis of SDN controller, then be associated monitoring analysis, It can also be first associated monitoring analysis, then be associated the analysis of SDN controller, sequence is unrestricted.
In order to avoid the bombing of alarm causes meaningless resource consumption and alarm is caused to accumulate or handle delay, alerting After association analysis handles the alarm step that service routine receives alarm source transmission, the frequency that can be first occurred according to alarm is to this Item alarm is polymerize, and then executes step S202 again.
The frequency occurred according to the alarm polymerize this alarm, comprising: when the frequency that the alarm occurs When rate is greater than or equal to predeterminated frequency threshold value, this alarm is polymerize.When the frequency that alarm occurs reaches certain value, need It is polymerize, reduces the quantity of alarm.The predeterminated frequency threshold value, for the preset minimum frequency for needing to carry out Alert aggregation Rate.For example, predeterminated frequency threshold value is set as 5 beats/min, then when the frequency that alarm occurs is greater than or equal to 5 beats/min, need The alarm is polymerize.
Above-mentioned example is still continued to use, AHS obtains the entitled GD-GZ-RMZ-SSW-1 of the network equipment, then calculates the announcement Alert frequency, if the frequency of the alarm is greater than or equal to predeterminated frequency threshold value, AHS polymerize this alarm, such as will be every A plurality of Alert aggregation of minute is 1 alarming processing.
Still continue to use above-mentioned example, the warning association analysis processing service is associated point the alarm received Analysis, AHS by analysis, judges that the node down alerts as non-derived alarm, then described by being somebody's turn to do before alarm clearing The link down alarm of node is automatically recognized as derivative alarm.
Step S103, according to the association analysis as a result, judging the alarm whether really for influence business or be failure Non-derived alarm;If it is not, executing step S104;If so, executing step S105.
Due to generally including various types of alarms, example in the alarm that warning association analysis processing service routine receives As derived alarm, the not non-derived alarm of traffic affecting, non-derived alarm etc. due to caused by network fluctuation.Wherein, very big by one Part is alerted there is no business either failure is really influenced, and is filtered to these alarms, can be effectively prevented from network and bang Fried influence.
Judge it is described alarm whether really for influence business or be failure non-derived alarm, need to carry out sentencing for various dimensions It is disconnected, can first determine whether the alarm is derivative alarm, be alerted if it is derivative, then filter the alarm;If described Whether alarm is non-derived alarm, then need further to judge the non-derived alarm really for influence business or be the non-of failure Derivative alarm, if so, thening follow the steps S105, sends the alarm;If it is not, thening follow the steps S104, the alarm is filtered.
Judge the alarm whether really for influence business or be failure the process of non-derived alarm in, the also row of need Alerted caused by fluctuation except the network equipment, after alarm influences business or is confirmed as failure, need to wait one it is of short duration when Between be confirmed whether to restore, if can restore, alerted caused by the fluctuation for the network equipment, then follow the steps S104, filter The alarm;If cannot restore, S105 is thened follow the steps, sends the alarm.
Above-mentioned example is still continued to use, since node down alarm is non-derived alarm, further described in judgement Whether node down alarm is the non-derived alarm of traffic affecting really, and AHS can be judged by access SDN controller, if Business is impacted, in order to exclude the influence of network fluctuation, an of short duration time can be waited, determine that GD-GZ-SSW-1 is No automatic recovery illustrates it is alarm caused by the fluctuation of the network equipment, to business after recovery if GD-GZ-SSW-1 restores It will not impact, be not belonging to the non-derived alarm of real traffic affecting, need to filter the alarm, if cannot restore, sentence The alarm of breaking is the non-derived alarm of traffic affecting, sends alarm;AHS can also by access monitoring system to determine whether The flow of all VLL of GD-GZ-SSW-1 is obtained by access monitoring system for failure, if flow has exception, is judged An of short duration time can be waited in order to exclude the influence of network fluctuation for failure, determines that whether automatic GD-GZ-SSW-1 is extensive It is multiple, if GD-GZ-SSW-1 restores, illustrates it is alarm caused by the fluctuation of the network equipment, and real failure is not present, need It filters the alarm and sends alarm;If cannot restore, judge that the alarm for non-derived alarm caused by failure, sends and accuses It is alert.
It should be noted that in specific implementation, judging the alarm whether really for influence business or be failure When non-derived alarm, warning association analysis processing service routine needs to access SDN controller and monitoring system to determine the announcement Whether police influences business or the non-derived alarm for failure.Specifically, being needed if first access SDN controller is no abnormal Further access monitoring system determines whether alarm causes exception;If first access monitoring system is no abnormal, need to be into one Step access SDN controller determines whether alarm causes exception;If found when first access monitoring system or SDN controller different Often, alarm is sent, it is not necessary to be further continued for accessing.
Step S104 filters the alarm.
When the output of step S103 is no, the alarm is filtered.
The filtering alarm refers to and does not send alarm.
After passing through association analysis, determine the alarm for derivative alarm, not the non-derived alarm of traffic affecting, can be automatic When the non-derived alarm restored, require to filter the alarm.
By filtering out non-derived alarm caused by derivative alarm, the network equipment and network fluctuation and can restore automatically Non-derived alarm avoids alarm and bombs.
Step S105 sends the alarm.
When the output of step S103, which is, is, the alarm is sent.
It is described to send the alarm, refer to that the warning association analysis processing service routine sends the alarm to network O&M The computer of operated by personnel excludes network failure so that operation maintenance personnel can handle alarm as early as possible.
In order to be further reduced the alarm quantity of transmission, plan can be restored automatically accordingly for different alarm configurations Slightly.Before sending the alarm, it can be determined that whether configure automatic recovery policy for the alarm;If so, being restored Processing, if restoring to handle successfully, abnormal caused by the alarm or influence caused by business disappears, and filters the alarm, If failed restore, the alarm is sent.
So far, the embodiment of the method for the alarming processing provided in this embodiment for SDN network has been carried out in detail Explanation.Firstly, the application, which is used, handles service routine independently of SDN controller and the warning association analysis of monitoring system, with SDN By interactive interfacing, the function of SDN controller will not influence;Secondly, warning association analysis processing service routine passes through unification The alarm that alarm report interface alarm source is sent can be compatible with various due to using unified alarm report interface Alert scene and mode;In addition, the not traffic affecting to flood tide caused by the reasons such as the fluctuation of the network equipment and network alerts Or by the alarm that can restore automatically of strategy, effectively accurately filtering is carried out, alarm is avoided and bombs, allows network O&M personnel's energy It is enough quick, real traffic affecting fault warning is accurately received, favorably there is the normal operation of SDN network.
Corresponding with the method for the above-mentioned alarming processing for SDN network, present invention also provides one kind to be used for SDN net The device of the alarming processing of network.Since the embodiment of described device is substantially similar to the embodiment of method, so describing to compare Simply, the relevent part can refer to the partial explaination of embodiments of method.Installation practice described below is only schematical. The Installation practice of the alarming processing for SDN network is as follows:
Referring to FIG. 2, it illustrates at a kind of alarm for SDN network provided according to the second embodiment of the application The schematic diagram of the device of reason.
Described device includes: alarm receiving unit 201, alert analysis unit 202, breakdown judge unit 203, alarm filter Unit 204, alarm transmission unit 205.
Receiving unit 201 is alerted, receives the alarm that alarm source is sent for warning association analysis processing service routine;It is described It is the service routine independently of SDN controller and monitoring system constructed in advance that warning association analysis, which handles service routine,;
Alert analysis unit 202, for the warning association analysis processing service routine to receive it is described alert into Row association analysis;
Whether breakdown judge unit 203 is used for according to the association analysis as a result, judging the alarm really for influence industry Business or for failure alarm;
Alarm filter unit 204, for filtering the alarm when the output of breakdown judge unit is no;
Transmission unit 205 is alerted, for sending the alarm when the output of type judging unit, which is, is.
Optionally, described device includes:
Tactful recovery unit, for before alarm transmission unit work, it is automatic whether judgement configures for the alarm Recovery policy;If so, carrying out recovery processing;Judge whether to be successfully recovered, if so, the alarm is filtered, if it is not, sending the announcement It is alert.
Optionally, described device includes:
Alert aggregation unit, for being accused according to the frequency that the alarm occurs to this after alarm receiving unit work Police is polymerize.
Optionally, the Alert aggregation unit, is specifically used for:
When the frequency that the alarm occurs is greater than or equal to predeterminated frequency threshold value, this alarm is polymerize.
Optionally, the alert analysis unit, comprising:
Controller analyzes subelement, for being associated with the analysis of SDN controller;
Monitoring analysis subelement, for being associated with monitoring analysis.
Optionally, the association analysis, comprising:
The alarm type of the alarm is analyzed;And/or
Analysis to alarm to service impact.
Optionally, the alarm source includes: network element, SDN controller, monitoring system, log processing system, monitoring script.
Optionally, the warning association analysis handles service routine, comprising:
The warning association analysis processing service routine provides unified alarm report interface, sends for receiving alarm source Alarm.
The application 3rd embodiment provides a kind of alarming processing system for SDN network, the alarming processing system It can be used to realize a kind of alert processing method for SDN network that the application first embodiment provides.Referring to FIG. 3, its A kind of schematic diagram of the alarming processing system for SDN network provided according to an embodiment of the present application is provided.Below in conjunction with Fig. 3 is described in detail.Wherein, the alarming processing system for SDN network includes: association analysis processing module 301, plan Slightly configuration module 302, data memory module 303, alarm and report query module 304.
The association analysis processing module, for receiving the alarm of alarm source transmission and the alarm being associated analysis And processing;
The strategy configuration module, for carrying out the configuration of warning strategies;
The data memory module, for storing the warning information of association analysis processing module transmission.
The alarm and report query module, for providing the inquiry of alarm and report.
Although the present invention is disclosed as above with preferred embodiment, it is not for limiting the present invention, any this field skill Art personnel without departing from the spirit and scope of the present invention, can make possible variation and modification, therefore guarantor of the invention Shield range should be subject to the range that the claims in the present invention are defined.

Claims (10)

1. a kind of method of the alarming processing for SDN network characterized by comprising
Warning association analysis handles service routine and receives the alarm that alarm source is sent;The warning association analysis handles service routine For the service routine independently of SDN controller and monitoring system constructed in advance;
The warning association analysis processing service routine is associated analysis to the alarm received;
According to the association analysis as a result, judge it is described alarm whether really for influence business or be failure non-derived alarm; If it is not, filtering the alarm;
If so, sending the alarm.
2. the method for the alarming processing according to claim 1 for SDN network, which is characterized in that sending the announcement Before alert step, comprising:
Whether judgement configures automatic recovery policy for the alarm;If so, carrying out recovery processing;
Judge whether to be successfully recovered, if so, filtering the alarm, enters the step of sending the alarm if not.
3. the method for the alarming processing according to claim 1 for SDN network, which is characterized in that in alarm association point Analysis processing service routine receives after the alarm step that alarm source is sent, comprising:
The frequency occurred according to the alarm polymerize this alarm.
4. the method for the alarming processing according to claim 3 for SDN network, which is characterized in that described according to The frequency occurred is alerted to polymerize this alarm, comprising:
When the frequency that the alarm occurs is greater than or equal to predeterminated frequency threshold value, this alarm is polymerize.
5. the method for the alarming processing according to claim 1 for SDN network, which is characterized in that described pair receives The alarm be associated analysis, comprising:
It is associated with the analysis of SDN controller and/or association monitoring analysis.
6. the method for the alarming processing according to claim 5 for SDN network, the association analysis, comprising:
The alarm type of the alarm is analyzed;And/or
Analysis to alarm to service impact.
7. the method for the alarming processing according to claim 1 for SDN network, which is characterized in that the alarm source packet It includes: network element, SDN controller, monitoring system, log processing system, monitoring script.
8. the method for the alarming processing according to claim 1 for SDN network, the warning association analysis processing service Program, comprising:
The warning association analysis processing service routine provides unified alarm report interface, for receiving the announcement of alarm source transmission It is alert.
9. a kind of device of the alarming processing for SDN network characterized by comprising
Receiving unit is alerted, receives the alarm that alarm source is sent for warning association analysis processing service routine;The alarm is closed Connection analysis processing service routine is the service routine independently of SDN controller and monitoring system constructed in advance;
Alert analysis unit is associated point the alarm received for warning association analysis processing service routine Analysis;
Breakdown judge unit, for according to the association analysis as a result, judging whether the alarm is influence business or is really The alarm of failure;
Alarm filter unit, for filtering the alarm when the output of breakdown judge unit is no;
Transmission unit is alerted, for sending the alarm when the output of type judging unit, which is, is.
10. a kind of alarming processing system of SDN network characterized by comprising association analysis processing module, strategy configuration mould Block, data memory module, alarm and report query module;
The association analysis processing module, for receiving the alarm of alarm source transmission and the alarm being associated analysis and place Reason;
The strategy configuration module, for carrying out the configuration of warning strategies;
The data memory module, for storing the warning information of association analysis processing module transmission.
The alarm and report query module, for carrying out the inquiry of alarm and report.
CN201710622980.2A 2017-07-27 2017-07-27 Alert processing method, apparatus and system for SDN network Pending CN109309577A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710622980.2A CN109309577A (en) 2017-07-27 2017-07-27 Alert processing method, apparatus and system for SDN network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710622980.2A CN109309577A (en) 2017-07-27 2017-07-27 Alert processing method, apparatus and system for SDN network

Publications (1)

Publication Number Publication Date
CN109309577A true CN109309577A (en) 2019-02-05

Family

ID=65202430

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710622980.2A Pending CN109309577A (en) 2017-07-27 2017-07-27 Alert processing method, apparatus and system for SDN network

Country Status (1)

Country Link
CN (1) CN109309577A (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110247862A (en) * 2019-06-14 2019-09-17 西安电子科技大学 Business quickly continuous switching system and method when SDN clustering fault
CN113992495A (en) * 2021-10-15 2022-01-28 中国工商银行股份有限公司 Alarm information processing method and device, computer equipment and storage medium
CN114721912A (en) * 2021-01-04 2022-07-08 腾讯科技(深圳)有限公司 Data analysis method, device, equipment and medium
CN115941442A (en) * 2022-12-01 2023-04-07 中国联合网络通信集团有限公司 Business fault analysis method and device, electronic equipment and medium

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100014431A1 (en) * 2008-07-17 2010-01-21 Paritosh Bajpay Method and apparatus for providing automated processing of a network service alarm
CN103688510A (en) * 2013-09-13 2014-03-26 华为技术有限公司 Method and device for inter-network communication
CN103746911A (en) * 2014-01-20 2014-04-23 中国联合网络通信集团有限公司 SDN (software defined networking) structure and communication method thereof
CN105790972A (en) * 2014-12-18 2016-07-20 中兴通讯股份有限公司 Controller and alarm correlation processing method
CN105991332A (en) * 2015-01-27 2016-10-05 中兴通讯股份有限公司 Alarm processing method and device

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100014431A1 (en) * 2008-07-17 2010-01-21 Paritosh Bajpay Method and apparatus for providing automated processing of a network service alarm
CN103688510A (en) * 2013-09-13 2014-03-26 华为技术有限公司 Method and device for inter-network communication
CN103746911A (en) * 2014-01-20 2014-04-23 中国联合网络通信集团有限公司 SDN (software defined networking) structure and communication method thereof
CN105790972A (en) * 2014-12-18 2016-07-20 中兴通讯股份有限公司 Controller and alarm correlation processing method
CN105991332A (en) * 2015-01-27 2016-10-05 中兴通讯股份有限公司 Alarm processing method and device

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110247862A (en) * 2019-06-14 2019-09-17 西安电子科技大学 Business quickly continuous switching system and method when SDN clustering fault
CN110247862B (en) * 2019-06-14 2021-03-23 西安电子科技大学 SDN cluster fault-time service rapid and continuous switching system and method
CN114721912A (en) * 2021-01-04 2022-07-08 腾讯科技(深圳)有限公司 Data analysis method, device, equipment and medium
CN114721912B (en) * 2021-01-04 2024-07-09 腾讯科技(深圳)有限公司 Data analysis method, device, equipment and medium
CN113992495A (en) * 2021-10-15 2022-01-28 中国工商银行股份有限公司 Alarm information processing method and device, computer equipment and storage medium
CN113992495B (en) * 2021-10-15 2024-02-02 中国工商银行股份有限公司 Alarm information processing method and device, computer equipment and storage medium
CN115941442A (en) * 2022-12-01 2023-04-07 中国联合网络通信集团有限公司 Business fault analysis method and device, electronic equipment and medium

Similar Documents

Publication Publication Date Title
CN111885012B (en) Network situation perception method and system based on information acquisition of various network devices
CN103544093B (en) Monitoring alarm control method and system thereof
CN109309577A (en) Alert processing method, apparatus and system for SDN network
CN106992877B (en) Network Fault Detection and restorative procedure based on SDN framework
CN104038371B (en) A kind of electric power communication transmission network adaptive performance acquisition method
CN108063753A (en) A kind of information safety monitoring method and system
CN107547228B (en) Implementation architecture of safe operation and maintenance management platform based on big data
US7430688B2 (en) Network monitoring method and apparatus
WO2007143943A1 (en) Method, system and network device of centralized maintenance of multiple devices
CN110891283A (en) Small base station monitoring device and method based on edge calculation model
CN107483268A (en) A kind of alert processing method and system
CN105847083A (en) Business centralized monitoring method and system
CN109413642B (en) Terminal safety detection and monitoring systematization method
CN107872339B (en) Operation and maintenance implementation method and device in virtual network and virtual network system
CN106330533A (en) Real-time topology establishment method of large-scale network alarms
US20180269963A1 (en) Method and apparatus for hot standby of controllers in distributed protection
CN112468592B (en) Terminal online state detection method and system based on electric power information acquisition
CN108021485A (en) The monitoring method and device of application program running state
CN113671909A (en) Safety monitoring system and method for steel industrial control equipment
CN104104542B (en) RS 485-based real-time intelligent obstacle removing method
CN106452941A (en) Network anomaly detection method and device
US20170207954A1 (en) Policy-based m2m terminal device monitoring and control method and device
CN106936621A (en) A kind of work order storm control method, apparatus and system
CN102195791A (en) Alarm analysis method, device and system
CN106453504A (en) Monitoring system and method based on NGINX server cluster

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
TA01 Transfer of patent application right

Effective date of registration: 20200324

Address after: 200040 room 1013, No. 250, JIANGCHANG Third Road, Jing'an District, Shanghai

Applicant after: Shanghai layer peak Network Technology Co.,Ltd.

Address before: 310012 506, room 4, 998 West Wen Yi Road, Wuchang Street, Yuhang District, Hangzhou, Zhejiang.

Applicant before: HANGZHOU DAHU TECHNOLOGY Co.,Ltd.

TA01 Transfer of patent application right
RJ01 Rejection of invention patent application after publication

Application publication date: 20190205

RJ01 Rejection of invention patent application after publication