CN112994910A - Method and device for processing network port alarm information - Google Patents
Method and device for processing network port alarm information Download PDFInfo
- Publication number
- CN112994910A CN112994910A CN201911282300.2A CN201911282300A CN112994910A CN 112994910 A CN112994910 A CN 112994910A CN 201911282300 A CN201911282300 A CN 201911282300A CN 112994910 A CN112994910 A CN 112994910A
- Authority
- CN
- China
- Prior art keywords
- alarm
- port
- unavailable
- pieces
- protocol
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000012545 processing Methods 0.000 title claims abstract description 71
- 238000000034 method Methods 0.000 title claims abstract description 28
- 238000001914 filtration Methods 0.000 claims abstract description 27
- 238000004590 computer program Methods 0.000 claims description 16
- 230000010365 information processing Effects 0.000 claims description 8
- 238000003860 storage Methods 0.000 claims description 8
- 230000004083 survival effect Effects 0.000 claims description 7
- 238000012423 maintenance Methods 0.000 abstract description 5
- 238000010586 diagram Methods 0.000 description 13
- 238000003672 processing method Methods 0.000 description 6
- 230000006870 function Effects 0.000 description 5
- 238000004458 analytical method Methods 0.000 description 3
- ABEXEQSGABRUHS-UHFFFAOYSA-N 16-methylheptadecyl 16-methylheptadecanoate Chemical compound CC(C)CCCCCCCCCCCCCCCOC(=O)CCCCCCCCCCCCCCC(C)C ABEXEQSGABRUHS-UHFFFAOYSA-N 0.000 description 2
- 241000764238 Isis Species 0.000 description 2
- 238000005417 image-selected in vivo spectroscopy Methods 0.000 description 2
- 238000012739 integrated shape imaging system Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000007306 turnover Effects 0.000 description 2
- 230000005856 abnormality Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 230000006872 improvement Effects 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 238000012544 monitoring process Methods 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 230000008569 process Effects 0.000 description 1
- 238000010926 purge Methods 0.000 description 1
- 230000001360 synchronised effect Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0604—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0604—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
- H04L41/0613—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time based on the type or category of the network elements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0604—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
- H04L41/0618—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time based on the physical or logical position
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0631—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
- H04L41/065—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis involving logical or physical relationship, e.g. grouping and hierarchies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/12—Discovery or management of network topologies
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
The invention discloses a method and a device for processing network port alarm information, wherein the method comprises the following steps: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm; determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered; according to the method and the device, the convergence processing or the filtering processing is carried out on the plurality of pieces of alarm information according to the alarm types, the fault sources of the alarm information can be identified based on the plurality of pieces of alarm information of the ports and the plurality of dimensionalities of the network topology, the convergence or the filtering processing is carried out on the alarm information, the reporting frequency of the alarm information is reduced, the reporting reliability of the alarm information is improved, and the fault processing can be carried out by network maintenance personnel more easily.
Description
Technical Field
The present invention relates to the field of data processing technologies, and in particular, to a method and an apparatus for processing network port alarm information.
Background
The network port alarm is the most common alarm in the alarm monitoring of the IP domain of the operator and has the largest number, and the types of the port class alarm generally include "port Down" and "port protocol Down", where the "port protocol Down" further includes various alarm types such as specific protocol alarm "ISIS protocol Down", "PIM protocol Down" and "PFD session Down".
A port of a network device may generate a port alarm due to link interruption, port failure, protocol configuration error, port looseness, and the like, and a large amount of port alarms may cause congestion of circuit flow and even interruption of services, resulting in serious failures. Furthermore, the occurrence of a port alarm may be accompanied by a series of alarms, such as: a certain port is frequently flashed off, a large amount of repeated alarms can be generated in a short time, so that a large amount of repeated alarm information appears on an alarm panel, maintenance personnel is influenced to carry out fault positioning and fault processing, and some major faults are even missed to be processed because of being buried by a large amount of repeated alarm information.
In view of the above problems, no effective solution has been proposed.
Disclosure of Invention
The embodiment of the invention provides a method for processing network port alarm information, which is used for reducing the alarm reporting frequency and improving the alarm reporting reliability and comprises the following steps:
acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and performing convergence processing or filtering processing on the plurality of pieces of alarm information according to the alarm types.
The embodiment of the invention provides a processing device of network port alarm information, which is used for reducing the alarm reporting frequency and improving the alarm reporting reliability, and comprises the following components:
the alarm information acquisition module is used for acquiring a plurality of pieces of alarm information and network topology of the first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
the alarm type determining module is used for determining an alarm type according to the plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and the alarm information processing module is used for carrying out convergence processing or filtering processing on a plurality of pieces of alarm information according to the alarm types.
The embodiment of the invention also provides computer equipment which comprises a memory, a processor and a computer program which is stored on the memory and can run on the processor, wherein the processor realizes the processing method of the network port alarm information when executing the computer program.
The embodiment of the invention also provides a computer readable storage medium, which stores a computer program for executing the processing method of the network port alarm information.
The embodiment of the invention comprises the following steps: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm; determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered; according to the method and the device, the convergence processing or the filtering processing is carried out on the plurality of pieces of alarm information according to the alarm types, the fault sources of the alarm information can be identified based on the plurality of pieces of alarm information of the ports and the plurality of dimensionalities of the network topology, the convergence or the filtering processing is carried out on the alarm information, the reporting frequency of the alarm information is reduced, the reporting reliability of the alarm information is improved, and the fault processing can be carried out by network maintenance personnel more easily.
Drawings
In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly described below, it is obvious that the drawings in the following description are only some embodiments of the present invention, and for those skilled in the art, other drawings can be obtained according to the drawings without creative efforts. In the drawings:
FIG. 1 is a schematic diagram of a processing method flow of network port alarm information in an embodiment of the present invention;
fig. 2 is a schematic diagram of a network port alarm information processing method flow according to an embodiment of the present invention;
fig. 3 is a schematic diagram of a structure of a device for processing network port alarm information according to an embodiment of the present invention.
Detailed Description
The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present invention.
In order to solve the technical problem that a large number of port alarms cause IP circuit traffic congestion and even service interruption, which causes serious failures, an embodiment of the present invention provides a method for processing network port alarm information, so as to reduce the frequency of alarm reporting and improve the reliability of alarm reporting, fig. 1 is a schematic diagram of a flow of a method for processing network port alarm information in an embodiment of the present invention, as shown in fig. 1, the method includes:
step 101: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
step 102: determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
step 103: and performing convergence processing or filtering processing on the plurality of pieces of alarm information according to the alarm types.
As shown in fig. 1, an embodiment of the present invention is implemented by: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm; determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered; according to the method and the device, the convergence processing or the filtering processing is carried out on the plurality of pieces of alarm information according to the alarm types, the fault sources of the alarm information can be identified based on the plurality of pieces of alarm information of the ports and the plurality of dimensionalities of the network topology, the convergence or the filtering processing is carried out on the alarm information, the reporting frequency of the alarm information is reduced, the reporting reliability of the alarm information is improved, and the fault processing can be carried out by network maintenance personnel more easily.
In specific implementation, in step 101, multiple pieces of alarm information of the first port may be obtained according to the following method, including: when a network device fails, the failure is reported to a network management system in a Syslog (system log or system record) or snmp trap (simple network management protocol trap) manner, an alarm receiving and analyzing unit in the network management system can actively acquire a failure message reported by the network device, and the failure message is analyzed into alarm information conforming to the definition of the network management system through a preset Syslog analysis rule or snmp analysis rule. The alarm information of the port may include "port Down", "port protocol Down", and the like, where the "port protocol Down" may include specific protocol alarms such as "ISIS protocol Down", "PIM protocol Down", and "PFD session Down", the first port unavailable alarm is the "port Down" alarm, and the network topology may be a connection relationship between ports.
In one embodiment, step 102 may comprise:
and when a plurality of first port available alarms and a plurality of first port unavailable alarms which exceed a preset threshold exist in a preset time length, determining the alarm type as a port stroboscopic alarm.
In one embodiment, step 103 may comprise:
and converging the plurality of first port available alarms and the plurality of first port unavailable alarms into one first port stroboscopic alarm according to the port stroboscopic alarm.
In one embodiment, step 102 may further comprise:
the first step is as follows: after the first port unavailability alarm is obtained, maintaining the unavailability state of the first port within a preset time period, and recording the alarm times;
the second step is that: and comparing the alarm times in the preset time with a preset threshold value, and determining whether a plurality of first port available alarms and a plurality of first port unavailable alarms exceeding the preset threshold value exist in the preset time.
In one embodiment, the step 102 of maintaining the unavailable state of the first port for the preset time period in the first step may include:
setting a survival time length for the unavailable state of the first port;
performing the following operations for each first port available alarm and each first port unavailable alarm: and starting timing, when a first port available alarm and a first port unavailable alarm appear in the survival time, keeping the first port unavailable state, and restarting timing.
In specific implementation, when a fault of port looseness occurs, the port can always perform Down/up state turnover in a short time, and then a large amount of repeated port Down/port up alarm information can be generated, frequent turnover of the port state can cause frequent route convergence for an IP network, and the time efficiency of alarm analysis can be slowed Down for a network management system by the large amount of repeated alarm information. Aiming at the large amount of repeated alarms, a layer of cache can be added, the inversion times of the alarms are counted in the cache, and the alarm state is kept, so that the large amount of repeated alarms are subjected to convergence processing.
The network management system may generate a port Down alarm of the first port when receiving the "port Down" of the first port for the first time, and store the Down state of the first port in a database (the msyql cluster may be used as the database) and a cache (the Redis cluster may be used as the cache of the system), if receiving the "port up" again, the Down state of the first port in the cache may be set to be recovered, but the cache is not recovered immediately, and the result is not synchronized to the database, but a survival time duration, i.e. ttl (time to live), may be set to 1 minute, if the "port Down" does not appear in the first port within 1 minute, the Down state of the first port is recovered to the up state, if the "port Down" appears in the first port within 1 minute again, the number of inversion times of the alarm is recorded in the cache, and updating the ttl in the cache and recalculating the purge time of the Down state of the first port. If the number of inversion times of the alarms in the cache within the preset time duration reaches a preset threshold, it may be determined that the alarm type is a port strobe alarm, and the "port Down" and the "port up" of the plurality of first ports may be converged into one "port flipping" alarm of the first port, that is, the first port strobe alarm, and all repeated alarms occurring in the first port within the preset time duration are converged into one alarm.
In one embodiment, step 102 may comprise:
when the first port unavailable alarm is not accompanied by the first port protocol alarm, determining the alarm type as the alarm to be filtered;
in one embodiment, step 103 may comprise:
and filtering the unavailable alarm of the first port according to the alarm to be filtered.
In specific implementation, when the network management system receives an alarm of a port Down of a certain network element and does not receive any protocol type alarm corresponding to the port, i.e., "port protocol Down", which indicates that the port is an unoccupied port and does not configure any IP service, it may determine that the alarm type is an alarm to be filtered, and may perform filtering processing on the alarm of this type without performing subsequent alarm processing.
In one embodiment, step 102 may comprise:
if the first port unavailable alarm is accompanied with the first port protocol alarm, and a second port connected with the first port through an IP circuit has a second port unavailable alarm and a second port protocol alarm, determining the alarm type as an IP circuit interruption alarm;
in one embodiment, step 103 may comprise:
and converging the first port unavailable alarm, the first port protocol alarm, the second port unavailable alarm and the second port protocol alarm into an IP circuit interruption alarm according to the IP circuit interruption alarm.
In particular, in the operator network, the two end ports of the "IP circuit" may be respectively identified by the middle two addresses of the 30 mask, for example: the 4 addresses 172.10.10.4, 172.10.10.5, 172.10.10.6, 172.10.10.7 represented by "172.10.10.4/30" can identify an IP circuit with the middle two addresses 172.10.10.5, 172.10.10.6, where 172.10.10.5 identifies a first port and 172.10.10.6 identifies a second port. For a double-ended port of an IP circuit, if a first port appears ' port Down ', a protocol enabled by the port is accompanied by a corresponding ' port protocol Down ', and a second port connected with the first port through the IP circuit also appears ' port Down ' and a corresponding ' port protocol Down ', the alarm type can be determined to be an IP circuit interruption alarm, the first port ' port Down ', the port protocol Down ' and the ' port Down ' of the second port can be converged into an alarm of ' IP circuit interruption ', and the alarm is more fit for a fault source, so that a fault processing person can more easily locate a fault and know the influence caused by the fault.
In one embodiment, step 102 may comprise:
if the first port unavailable alarm is accompanied with the first port protocol alarm, and the second port connected with the first port through the IP circuit does not have the second port unavailable alarm and the second port protocol alarm, determining the alarm type as the port protocol alarm;
in one embodiment, step 103 may comprise:
and converging the first port unavailable alarm and the first port protocol alarm into a first port protocol alarm according to the port protocol alarm.
In specific implementation, when the network management system receives an alarm of a port Down of a first port and simultaneously receives a port protocol Down of the first port, which indicates that the first port starts a routing protocol and configures an IP service, and the second port connected to the first port through the IP circuit does not have the port Down and the port protocol Down, which indicates that the port Down occurs in the first port and causes a port protocol abnormality and possibly causes an IP service interruption, it may be determined that the alarm type is a port protocol alarm, and the port Down and the port protocol Down of the first port may be converged into a port protocol Down of the first port, which requires a worker to perform subsequent processing. In addition, if the first port does not belong to an IP circuit already incorporated in the network management system, the first port "port Down" and the "port protocol Down" may also be converged into a first port "port protocol Down", and a series of alarms generated on the first port may be used as sub-alarms of the "port protocol Down".
In specific implementation, when the network management system receives the port protocol Down and does not receive the corresponding port Down, it indicates that the devices and ports at the two ends of the IP circuit have no fault, but the protocol is interrupted due to the fault of a device in the middle, which affects the IP service.
In specific implementation, the alarm generated after the convergence processing by the network management system may be defined as a derived alarm, the alarm reported by the network device is a sub-alarm of the derived alarm, and when all sub-alarms corresponding to the derived alarm are recovered, the derived alarm is recovered.
A specific example is given below to facilitate an understanding of how the invention may be carried out, as shown in fig. 2:
step 201: obtaining a "port Down" of the first port;
step 202: judging whether a plurality of first ports 'port Down' and 'port up' exceeding a preset threshold exist in a preset time length, if so, performing step 203, and if not, performing step 204;
step 203: determining the alarm type as a port stroboscopic alarm, converging the 'port Down' and 'port up' of a plurality of first ports into an alarm of 'port flipping' of the first port,
step 204: judging whether the port Down of the first port has a port protocol Down, if not, performing the step 205, and if so, performing the step 206;
step 205: determining the alarm type as the alarm to be filtered, and filtering the alarm to be filtered;
step 206: according to the network topology, judging whether a second port connected with the first port through an IP circuit has a second port 'Port Down' and a 'Port protocol Down', if yes, performing step 207, and if not, performing step 208;
step 207: determining that the alarm type is an IP circuit interruption alarm, and converging a first port 'port Down', a port protocol Down 'and a second port' port Down 'and a port protocol Down' into an alarm of 'IP circuit interruption';
step 208: and determining that the alarm type is a port protocol alarm, and converging the first port ' port Down ' and the port protocol Down ' into a first port ' port protocol Down '.
Based on the same inventive concept, the embodiment of the present invention further provides a device for processing network port alarm information, as in the following embodiments. Because the principle of the device for processing the network port alarm information to solve the problem is similar to the method for processing the network port alarm information, the implementation of the device can refer to the implementation of the method, and repeated parts are not described again. As used hereinafter, the term "unit" or "module" may be a combination of software and/or hardware that implements a predetermined function. Although the means described in the embodiments below are preferably implemented in software, an implementation in hardware, or a combination of software and hardware is also possible and contemplated.
Fig. 3 is a schematic diagram of a structure of a device for processing network port alarm information according to an embodiment of the present invention, and as shown in fig. 3, the device may include:
the alarm information acquisition module 01 is used for acquiring a plurality of pieces of alarm information and network topology of the first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
the alarm type determining module 02 is used for determining an alarm type according to the plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and the alarm information processing module 03 is configured to perform convergence processing or filtering processing on multiple pieces of alarm information according to the alarm types.
In one embodiment, the alarm type determining module 02 is specifically configured to:
and when a plurality of first port available alarms and a plurality of first port unavailable alarms which exceed a preset threshold exist in a preset time length, determining the alarm type as a port stroboscopic alarm.
In one embodiment, the alarm information processing module 03 is specifically configured to:
and converging the plurality of first port available alarms and the plurality of first port unavailable alarms into one first port stroboscopic alarm according to the port stroboscopic alarm.
In one embodiment, the alarm type determination module 02 is further configured to:
after the first port unavailability alarm is obtained, maintaining the unavailability state of the first port within a preset time period, and recording the alarm times;
and comparing the alarm times in the preset time with a preset threshold value, and determining whether a plurality of first port available alarms and a plurality of first port unavailable alarms exceeding the preset threshold value exist in the preset time.
In one embodiment, the maintaining of the unavailable state of the first port by the alarm type determining module 02 for the preset time period may include:
setting a survival time length for the unavailable state of the first port;
performing the following operations for each first port available alarm and each first port unavailable alarm: and starting timing, when a first port available alarm and a first port unavailable alarm appear in the survival time, keeping the first port unavailable state, and restarting timing.
In one embodiment, the alarm type determining module 02 is specifically configured to:
and when the unavailable alarm of the first port is not accompanied by the protocol alarm of the first port, determining the alarm type as the alarm to be filtered.
In one embodiment, the alarm information processing module 03 is specifically configured to:
and filtering the unavailable alarm of the first port according to the alarm to be filtered.
In one embodiment, the alarm type determining module 02 is specifically configured to:
and if the unavailable alarm of the first port is accompanied by the protocol alarm of the first port, and the unavailable alarm of the second port and the protocol alarm of the second port exist in the second port connected with the first port through the IP circuit, determining the alarm type as the IP circuit interruption alarm.
In one embodiment, the alarm information processing module 03 is specifically configured to:
and converging the first port unavailable alarm, the first port protocol alarm, the second port unavailable alarm and the second port protocol alarm into an IP circuit interruption alarm according to the IP circuit interruption alarm.
In one embodiment, the alarm type determining module 02 is specifically configured to:
and if the first port unavailable alarm is accompanied with the first port protocol alarm and the second port connected with the first port through the IP circuit does not have the second port unavailable alarm and the second port protocol alarm, determining the alarm type as the port protocol alarm.
In one embodiment, the alarm information processing module 03 is specifically configured to:
and converging the first port unavailable alarm and the first port protocol alarm into a first port protocol alarm according to the port protocol alarm.
The embodiment of the invention also provides computer equipment which comprises a memory, a processor and a computer program which is stored on the memory and can run on the processor, wherein the processor realizes the processing method of the network port alarm information when executing the computer program.
The embodiment of the invention also provides a computer readable storage medium, and the computer readable storage medium stores a computer program for executing the processing method of the network port alarm information.
In summary, the embodiment of the present invention provides: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm; determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered; according to the method and the device, the convergence processing or the filtering processing is carried out on the plurality of pieces of alarm information according to the alarm types, the fault sources of the alarm information can be identified based on the plurality of pieces of alarm information of the ports and the plurality of dimensionalities of the network topology, the convergence or the filtering processing is carried out on the alarm information, the reporting frequency of the alarm information is reduced, the reporting reliability of the alarm information is improved, and the fault processing can be carried out by network maintenance personnel more easily.
As will be appreciated by one skilled in the art, embodiments of the present invention may be provided as a method, system, or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, and the like) having computer-usable program code embodied therein.
The present invention is described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each flow and/or block of the flow diagrams and/or block diagrams, and combinations of flows and/or blocks in the flow diagrams and/or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means which implement the function specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
The above is only a preferred embodiment of the present invention, and is not intended to limit the present invention, and various modifications and variations of the embodiment of the present invention may occur to those skilled in the art. Any modification, equivalent replacement, or improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims (10)
1. A method for processing network port alarm information is characterized by comprising the following steps:
acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
determining an alarm type according to the plurality of pieces of alarm information of the first port and the network topology; wherein the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and performing convergence processing or filtering processing on the plurality of pieces of alarm information according to the alarm types.
2. The method of claim 1, wherein determining an alarm type based on a plurality of pieces of alarm information of the first port and the network topology comprises;
when a plurality of first port available alarms and a plurality of first port unavailable alarms which exceed a preset threshold exist in a preset time length, determining the alarm type as a port stroboscopic alarm;
according to the alarm type, carrying out convergence processing or filtering processing on the plurality of pieces of alarm information, wherein the convergence processing or the filtering processing comprises the following steps:
and converging the plurality of first port available alarms and the plurality of first port unavailable alarms into a first port stroboscopic alarm according to the port stroboscopic alarm.
3. The method of claim 2, further comprising:
after the first port unavailability alarm is obtained, maintaining the unavailability state of the first port within a preset time period, and recording the alarm times;
and comparing the alarm times in the preset time with a preset threshold value, and determining whether a plurality of first port available alarms and a plurality of first port unavailable alarms exceeding the preset threshold value exist in the preset time.
4. The method of claim 3, wherein maintaining the unavailability of the first port for a preset length of time comprises:
setting a survival time length for the unavailable state of the first port;
performing the following operations for each first port available alarm and each first port unavailable alarm: and starting timing, when a first port available alarm and a first port unavailable alarm occur in the survival time, keeping the first port unavailable state, and restarting timing.
5. The method of claim 1, wherein determining an alarm type based on a plurality of pieces of alarm information of the first port and the network topology comprises:
when the first port unavailable alarm is not accompanied by the first port protocol alarm, determining the alarm type as the alarm to be filtered;
according to the alarm type, carrying out convergence processing or filtering processing on the plurality of pieces of alarm information, wherein the convergence processing or the filtering processing comprises the following steps:
and filtering the unavailable alarm of the first port according to the alarm to be filtered.
6. The method of claim 1, wherein determining an alarm type based on a plurality of pieces of alarm information of the first port and the network topology comprises:
if the first port unavailable alarm is accompanied with the first port protocol alarm, and a second port connected with the first port through an IP circuit has a second port unavailable alarm and a second port protocol alarm, determining the alarm type as an IP circuit interruption alarm;
according to the alarm type, carrying out convergence processing or filtering processing on the plurality of pieces of alarm information, wherein the convergence processing or the filtering processing comprises the following steps:
and converging the first port unavailable alarm, the first port protocol alarm, the second port unavailable alarm and the second port protocol alarm into an IP circuit interruption alarm according to the IP circuit interruption alarm.
7. The method of claim 1, wherein determining an alarm type based on a plurality of pieces of alarm information of the first port and the network topology comprises:
if the first port unavailable alarm is accompanied with the first port protocol alarm, and the second port connected with the first port through the IP circuit does not have the second port unavailable alarm and the second port protocol alarm, determining the alarm type as the port protocol alarm;
according to the alarm type, carrying out convergence processing or filtering processing on the plurality of pieces of alarm information, wherein the convergence processing or the filtering processing comprises the following steps:
and converging the first port unavailable alarm and the first port protocol alarm into a first port protocol alarm according to the port protocol alarm.
8. An apparatus for processing network port alarm information, comprising:
the alarm information acquisition module is used for acquiring a plurality of pieces of alarm information and network topology of the first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
the alarm type determining module is used for determining an alarm type according to the plurality of pieces of alarm information of the first port and the network topology; wherein the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and the alarm information processing module is used for carrying out convergence processing or filtering processing on the plurality of pieces of alarm information according to the alarm types.
9. A computer device comprising a memory, a processor and a computer program stored on the memory and executable on the processor, wherein the processor implements the method of any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that the computer-readable storage medium stores a computer program for executing the method of any one of claims 1 to 7.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201911282300.2A CN112994910A (en) | 2019-12-13 | 2019-12-13 | Method and device for processing network port alarm information |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201911282300.2A CN112994910A (en) | 2019-12-13 | 2019-12-13 | Method and device for processing network port alarm information |
Publications (1)
Publication Number | Publication Date |
---|---|
CN112994910A true CN112994910A (en) | 2021-06-18 |
Family
ID=76332412
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201911282300.2A Pending CN112994910A (en) | 2019-12-13 | 2019-12-13 | Method and device for processing network port alarm information |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN112994910A (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN113890815A (en) * | 2021-10-18 | 2022-01-04 | 中国电子科技集团公司第三十四研究所 | Method and system for monitoring and alarming frequent UP/DOWN of network equipment port |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2011002250A2 (en) * | 2009-07-01 | 2011-01-06 | 한국전자통신연구원 | Method for providing and receiving reliable service in wireless communication system |
CN102638375A (en) * | 2012-04-26 | 2012-08-15 | 北京星网锐捷网络技术有限公司 | Network fault recognition method and device |
CN109189736A (en) * | 2018-08-01 | 2019-01-11 | 中国联合网络通信集团有限公司 | A kind of generation method and device of alarm association rule |
CN110493348A (en) * | 2019-08-26 | 2019-11-22 | 山东融为信息科技有限公司 | A kind of intelligent monitoring and alarming system based on Internet of Things |
-
2019
- 2019-12-13 CN CN201911282300.2A patent/CN112994910A/en active Pending
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2011002250A2 (en) * | 2009-07-01 | 2011-01-06 | 한국전자통신연구원 | Method for providing and receiving reliable service in wireless communication system |
CN102638375A (en) * | 2012-04-26 | 2012-08-15 | 北京星网锐捷网络技术有限公司 | Network fault recognition method and device |
CN109189736A (en) * | 2018-08-01 | 2019-01-11 | 中国联合网络通信集团有限公司 | A kind of generation method and device of alarm association rule |
CN110493348A (en) * | 2019-08-26 | 2019-11-22 | 山东融为信息科技有限公司 | A kind of intelligent monitoring and alarming system based on Internet of Things |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN113890815A (en) * | 2021-10-18 | 2022-01-04 | 中国电子科技集团公司第三十四研究所 | Method and system for monitoring and alarming frequent UP/DOWN of network equipment port |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US8347143B2 (en) | Facilitating event management and analysis within a communications environment | |
US6747957B1 (en) | Network availability monitor | |
US8245079B2 (en) | Correlation of network alarm messages based on alarm time | |
US20200007381A1 (en) | Predicting computer network equipment failure | |
CN114172794B (en) | Network fault positioning method and server | |
US20160179598A1 (en) | System and method of visualizing historical event correlations in a data center | |
CN113259168B (en) | Fault root cause analysis method and device | |
US10341182B2 (en) | Method and system for detecting network upgrades | |
CN109034423B (en) | Fault early warning judgment method, device, equipment and storage medium | |
US7995485B1 (en) | Method and apparatus for providing automated diagnostics of networks | |
CN112311580A (en) | Message transmission path determining method, device and system and computer storage medium | |
CN114996090A (en) | Server abnormity detection method and device, electronic equipment and storage medium | |
EP3264634A1 (en) | Automatically detecting an error in a communication and automatically determining a source of the error | |
CN109218050B (en) | Domain name system fault processing method and system | |
CN112994910A (en) | Method and device for processing network port alarm information | |
US7421493B1 (en) | Orphaned network resource recovery through targeted audit and reconciliation | |
CN110943864B (en) | Network anomaly positioning method and device of distributed storage system | |
CN110609761B (en) | Method and device for determining fault source, storage medium and electronic equipment | |
US20060072707A1 (en) | Method and apparatus for determining impact of faults on network service | |
CN108156019B (en) | SDN-based network derived alarm filtering system and method | |
JP2014053658A (en) | Failure site estimation system and failure site estimation program | |
GB2372674A (en) | Network management | |
JP2012249250A (en) | Monitoring device and program | |
CN111343031B (en) | Method and device for determining network fault | |
KR20040001627A (en) | System for managing fault of internet and method thereof |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
RJ01 | Rejection of invention patent application after publication |
Application publication date: 20210618 |
|
RJ01 | Rejection of invention patent application after publication |