CN112994910A - Method and device for processing network port alarm information - Google Patents

Method and device for processing network port alarm information Download PDF

Info

Publication number
CN112994910A
CN112994910A CN201911282300.2A CN201911282300A CN112994910A CN 112994910 A CN112994910 A CN 112994910A CN 201911282300 A CN201911282300 A CN 201911282300A CN 112994910 A CN112994910 A CN 112994910A
Authority
CN
China
Prior art keywords
alarm
port
unavailable
pieces
protocol
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201911282300.2A
Other languages
Chinese (zh)
Inventor
王小冬
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Zhongying Youchuang Information Technology Co Ltd
Original Assignee
Zhongying Youchuang Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhongying Youchuang Information Technology Co Ltd filed Critical Zhongying Youchuang Information Technology Co Ltd
Priority to CN201911282300.2A priority Critical patent/CN112994910A/en
Publication of CN112994910A publication Critical patent/CN112994910A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0604Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0604Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
    • H04L41/0613Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time based on the type or category of the network elements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0604Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
    • H04L41/0618Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time based on the physical or logical position
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • H04L41/065Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis involving logical or physical relationship, e.g. grouping and hierarchies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/12Discovery or management of network topologies

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses a method and a device for processing network port alarm information, wherein the method comprises the following steps: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm; determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered; according to the method and the device, the convergence processing or the filtering processing is carried out on the plurality of pieces of alarm information according to the alarm types, the fault sources of the alarm information can be identified based on the plurality of pieces of alarm information of the ports and the plurality of dimensionalities of the network topology, the convergence or the filtering processing is carried out on the alarm information, the reporting frequency of the alarm information is reduced, the reporting reliability of the alarm information is improved, and the fault processing can be carried out by network maintenance personnel more easily.

Description

Method and device for processing network port alarm information
Technical Field
The present invention relates to the field of data processing technologies, and in particular, to a method and an apparatus for processing network port alarm information.
Background
The network port alarm is the most common alarm in the alarm monitoring of the IP domain of the operator and has the largest number, and the types of the port class alarm generally include "port Down" and "port protocol Down", where the "port protocol Down" further includes various alarm types such as specific protocol alarm "ISIS protocol Down", "PIM protocol Down" and "PFD session Down".
A port of a network device may generate a port alarm due to link interruption, port failure, protocol configuration error, port looseness, and the like, and a large amount of port alarms may cause congestion of circuit flow and even interruption of services, resulting in serious failures. Furthermore, the occurrence of a port alarm may be accompanied by a series of alarms, such as: a certain port is frequently flashed off, a large amount of repeated alarms can be generated in a short time, so that a large amount of repeated alarm information appears on an alarm panel, maintenance personnel is influenced to carry out fault positioning and fault processing, and some major faults are even missed to be processed because of being buried by a large amount of repeated alarm information.
In view of the above problems, no effective solution has been proposed.
Disclosure of Invention
The embodiment of the invention provides a method for processing network port alarm information, which is used for reducing the alarm reporting frequency and improving the alarm reporting reliability and comprises the following steps:
acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and performing convergence processing or filtering processing on the plurality of pieces of alarm information according to the alarm types.
The embodiment of the invention provides a processing device of network port alarm information, which is used for reducing the alarm reporting frequency and improving the alarm reporting reliability, and comprises the following components:
the alarm information acquisition module is used for acquiring a plurality of pieces of alarm information and network topology of the first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
the alarm type determining module is used for determining an alarm type according to the plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and the alarm information processing module is used for carrying out convergence processing or filtering processing on a plurality of pieces of alarm information according to the alarm types.
The embodiment of the invention also provides computer equipment which comprises a memory, a processor and a computer program which is stored on the memory and can run on the processor, wherein the processor realizes the processing method of the network port alarm information when executing the computer program.
The embodiment of the invention also provides a computer readable storage medium, which stores a computer program for executing the processing method of the network port alarm information.
The embodiment of the invention comprises the following steps: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm; determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered; according to the method and the device, the convergence processing or the filtering processing is carried out on the plurality of pieces of alarm information according to the alarm types, the fault sources of the alarm information can be identified based on the plurality of pieces of alarm information of the ports and the plurality of dimensionalities of the network topology, the convergence or the filtering processing is carried out on the alarm information, the reporting frequency of the alarm information is reduced, the reporting reliability of the alarm information is improved, and the fault processing can be carried out by network maintenance personnel more easily.
Drawings
In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly described below, it is obvious that the drawings in the following description are only some embodiments of the present invention, and for those skilled in the art, other drawings can be obtained according to the drawings without creative efforts. In the drawings:
FIG. 1 is a schematic diagram of a processing method flow of network port alarm information in an embodiment of the present invention;
fig. 2 is a schematic diagram of a network port alarm information processing method flow according to an embodiment of the present invention;
fig. 3 is a schematic diagram of a structure of a device for processing network port alarm information according to an embodiment of the present invention.
Detailed Description
The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present invention.
In order to solve the technical problem that a large number of port alarms cause IP circuit traffic congestion and even service interruption, which causes serious failures, an embodiment of the present invention provides a method for processing network port alarm information, so as to reduce the frequency of alarm reporting and improve the reliability of alarm reporting, fig. 1 is a schematic diagram of a flow of a method for processing network port alarm information in an embodiment of the present invention, as shown in fig. 1, the method includes:
step 101: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
step 102: determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
step 103: and performing convergence processing or filtering processing on the plurality of pieces of alarm information according to the alarm types.
As shown in fig. 1, an embodiment of the present invention is implemented by: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm; determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered; according to the method and the device, the convergence processing or the filtering processing is carried out on the plurality of pieces of alarm information according to the alarm types, the fault sources of the alarm information can be identified based on the plurality of pieces of alarm information of the ports and the plurality of dimensionalities of the network topology, the convergence or the filtering processing is carried out on the alarm information, the reporting frequency of the alarm information is reduced, the reporting reliability of the alarm information is improved, and the fault processing can be carried out by network maintenance personnel more easily.
In specific implementation, in step 101, multiple pieces of alarm information of the first port may be obtained according to the following method, including: when a network device fails, the failure is reported to a network management system in a Syslog (system log or system record) or snmp trap (simple network management protocol trap) manner, an alarm receiving and analyzing unit in the network management system can actively acquire a failure message reported by the network device, and the failure message is analyzed into alarm information conforming to the definition of the network management system through a preset Syslog analysis rule or snmp analysis rule. The alarm information of the port may include "port Down", "port protocol Down", and the like, where the "port protocol Down" may include specific protocol alarms such as "ISIS protocol Down", "PIM protocol Down", and "PFD session Down", the first port unavailable alarm is the "port Down" alarm, and the network topology may be a connection relationship between ports.
In one embodiment, step 102 may comprise:
and when a plurality of first port available alarms and a plurality of first port unavailable alarms which exceed a preset threshold exist in a preset time length, determining the alarm type as a port stroboscopic alarm.
In one embodiment, step 103 may comprise:
and converging the plurality of first port available alarms and the plurality of first port unavailable alarms into one first port stroboscopic alarm according to the port stroboscopic alarm.
In one embodiment, step 102 may further comprise:
the first step is as follows: after the first port unavailability alarm is obtained, maintaining the unavailability state of the first port within a preset time period, and recording the alarm times;
the second step is that: and comparing the alarm times in the preset time with a preset threshold value, and determining whether a plurality of first port available alarms and a plurality of first port unavailable alarms exceeding the preset threshold value exist in the preset time.
In one embodiment, the step 102 of maintaining the unavailable state of the first port for the preset time period in the first step may include:
setting a survival time length for the unavailable state of the first port;
performing the following operations for each first port available alarm and each first port unavailable alarm: and starting timing, when a first port available alarm and a first port unavailable alarm appear in the survival time, keeping the first port unavailable state, and restarting timing.
In specific implementation, when a fault of port looseness occurs, the port can always perform Down/up state turnover in a short time, and then a large amount of repeated port Down/port up alarm information can be generated, frequent turnover of the port state can cause frequent route convergence for an IP network, and the time efficiency of alarm analysis can be slowed Down for a network management system by the large amount of repeated alarm information. Aiming at the large amount of repeated alarms, a layer of cache can be added, the inversion times of the alarms are counted in the cache, and the alarm state is kept, so that the large amount of repeated alarms are subjected to convergence processing.
The network management system may generate a port Down alarm of the first port when receiving the "port Down" of the first port for the first time, and store the Down state of the first port in a database (the msyql cluster may be used as the database) and a cache (the Redis cluster may be used as the cache of the system), if receiving the "port up" again, the Down state of the first port in the cache may be set to be recovered, but the cache is not recovered immediately, and the result is not synchronized to the database, but a survival time duration, i.e. ttl (time to live), may be set to 1 minute, if the "port Down" does not appear in the first port within 1 minute, the Down state of the first port is recovered to the up state, if the "port Down" appears in the first port within 1 minute again, the number of inversion times of the alarm is recorded in the cache, and updating the ttl in the cache and recalculating the purge time of the Down state of the first port. If the number of inversion times of the alarms in the cache within the preset time duration reaches a preset threshold, it may be determined that the alarm type is a port strobe alarm, and the "port Down" and the "port up" of the plurality of first ports may be converged into one "port flipping" alarm of the first port, that is, the first port strobe alarm, and all repeated alarms occurring in the first port within the preset time duration are converged into one alarm.
In one embodiment, step 102 may comprise:
when the first port unavailable alarm is not accompanied by the first port protocol alarm, determining the alarm type as the alarm to be filtered;
in one embodiment, step 103 may comprise:
and filtering the unavailable alarm of the first port according to the alarm to be filtered.
In specific implementation, when the network management system receives an alarm of a port Down of a certain network element and does not receive any protocol type alarm corresponding to the port, i.e., "port protocol Down", which indicates that the port is an unoccupied port and does not configure any IP service, it may determine that the alarm type is an alarm to be filtered, and may perform filtering processing on the alarm of this type without performing subsequent alarm processing.
In one embodiment, step 102 may comprise:
if the first port unavailable alarm is accompanied with the first port protocol alarm, and a second port connected with the first port through an IP circuit has a second port unavailable alarm and a second port protocol alarm, determining the alarm type as an IP circuit interruption alarm;
in one embodiment, step 103 may comprise:
and converging the first port unavailable alarm, the first port protocol alarm, the second port unavailable alarm and the second port protocol alarm into an IP circuit interruption alarm according to the IP circuit interruption alarm.
In particular, in the operator network, the two end ports of the "IP circuit" may be respectively identified by the middle two addresses of the 30 mask, for example: the 4 addresses 172.10.10.4, 172.10.10.5, 172.10.10.6, 172.10.10.7 represented by "172.10.10.4/30" can identify an IP circuit with the middle two addresses 172.10.10.5, 172.10.10.6, where 172.10.10.5 identifies a first port and 172.10.10.6 identifies a second port. For a double-ended port of an IP circuit, if a first port appears ' port Down ', a protocol enabled by the port is accompanied by a corresponding ' port protocol Down ', and a second port connected with the first port through the IP circuit also appears ' port Down ' and a corresponding ' port protocol Down ', the alarm type can be determined to be an IP circuit interruption alarm, the first port ' port Down ', the port protocol Down ' and the ' port Down ' of the second port can be converged into an alarm of ' IP circuit interruption ', and the alarm is more fit for a fault source, so that a fault processing person can more easily locate a fault and know the influence caused by the fault.
In one embodiment, step 102 may comprise:
if the first port unavailable alarm is accompanied with the first port protocol alarm, and the second port connected with the first port through the IP circuit does not have the second port unavailable alarm and the second port protocol alarm, determining the alarm type as the port protocol alarm;
in one embodiment, step 103 may comprise:
and converging the first port unavailable alarm and the first port protocol alarm into a first port protocol alarm according to the port protocol alarm.
In specific implementation, when the network management system receives an alarm of a port Down of a first port and simultaneously receives a port protocol Down of the first port, which indicates that the first port starts a routing protocol and configures an IP service, and the second port connected to the first port through the IP circuit does not have the port Down and the port protocol Down, which indicates that the port Down occurs in the first port and causes a port protocol abnormality and possibly causes an IP service interruption, it may be determined that the alarm type is a port protocol alarm, and the port Down and the port protocol Down of the first port may be converged into a port protocol Down of the first port, which requires a worker to perform subsequent processing. In addition, if the first port does not belong to an IP circuit already incorporated in the network management system, the first port "port Down" and the "port protocol Down" may also be converged into a first port "port protocol Down", and a series of alarms generated on the first port may be used as sub-alarms of the "port protocol Down".
In specific implementation, when the network management system receives the port protocol Down and does not receive the corresponding port Down, it indicates that the devices and ports at the two ends of the IP circuit have no fault, but the protocol is interrupted due to the fault of a device in the middle, which affects the IP service.
In specific implementation, the alarm generated after the convergence processing by the network management system may be defined as a derived alarm, the alarm reported by the network device is a sub-alarm of the derived alarm, and when all sub-alarms corresponding to the derived alarm are recovered, the derived alarm is recovered.
A specific example is given below to facilitate an understanding of how the invention may be carried out, as shown in fig. 2:
step 201: obtaining a "port Down" of the first port;
step 202: judging whether a plurality of first ports 'port Down' and 'port up' exceeding a preset threshold exist in a preset time length, if so, performing step 203, and if not, performing step 204;
step 203: determining the alarm type as a port stroboscopic alarm, converging the 'port Down' and 'port up' of a plurality of first ports into an alarm of 'port flipping' of the first port,
step 204: judging whether the port Down of the first port has a port protocol Down, if not, performing the step 205, and if so, performing the step 206;
step 205: determining the alarm type as the alarm to be filtered, and filtering the alarm to be filtered;
step 206: according to the network topology, judging whether a second port connected with the first port through an IP circuit has a second port 'Port Down' and a 'Port protocol Down', if yes, performing step 207, and if not, performing step 208;
step 207: determining that the alarm type is an IP circuit interruption alarm, and converging a first port 'port Down', a port protocol Down 'and a second port' port Down 'and a port protocol Down' into an alarm of 'IP circuit interruption';
step 208: and determining that the alarm type is a port protocol alarm, and converging the first port ' port Down ' and the port protocol Down ' into a first port ' port protocol Down '.
Based on the same inventive concept, the embodiment of the present invention further provides a device for processing network port alarm information, as in the following embodiments. Because the principle of the device for processing the network port alarm information to solve the problem is similar to the method for processing the network port alarm information, the implementation of the device can refer to the implementation of the method, and repeated parts are not described again. As used hereinafter, the term "unit" or "module" may be a combination of software and/or hardware that implements a predetermined function. Although the means described in the embodiments below are preferably implemented in software, an implementation in hardware, or a combination of software and hardware is also possible and contemplated.
Fig. 3 is a schematic diagram of a structure of a device for processing network port alarm information according to an embodiment of the present invention, and as shown in fig. 3, the device may include:
the alarm information acquisition module 01 is used for acquiring a plurality of pieces of alarm information and network topology of the first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
the alarm type determining module 02 is used for determining an alarm type according to the plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and the alarm information processing module 03 is configured to perform convergence processing or filtering processing on multiple pieces of alarm information according to the alarm types.
In one embodiment, the alarm type determining module 02 is specifically configured to:
and when a plurality of first port available alarms and a plurality of first port unavailable alarms which exceed a preset threshold exist in a preset time length, determining the alarm type as a port stroboscopic alarm.
In one embodiment, the alarm information processing module 03 is specifically configured to:
and converging the plurality of first port available alarms and the plurality of first port unavailable alarms into one first port stroboscopic alarm according to the port stroboscopic alarm.
In one embodiment, the alarm type determination module 02 is further configured to:
after the first port unavailability alarm is obtained, maintaining the unavailability state of the first port within a preset time period, and recording the alarm times;
and comparing the alarm times in the preset time with a preset threshold value, and determining whether a plurality of first port available alarms and a plurality of first port unavailable alarms exceeding the preset threshold value exist in the preset time.
In one embodiment, the maintaining of the unavailable state of the first port by the alarm type determining module 02 for the preset time period may include:
setting a survival time length for the unavailable state of the first port;
performing the following operations for each first port available alarm and each first port unavailable alarm: and starting timing, when a first port available alarm and a first port unavailable alarm appear in the survival time, keeping the first port unavailable state, and restarting timing.
In one embodiment, the alarm type determining module 02 is specifically configured to:
and when the unavailable alarm of the first port is not accompanied by the protocol alarm of the first port, determining the alarm type as the alarm to be filtered.
In one embodiment, the alarm information processing module 03 is specifically configured to:
and filtering the unavailable alarm of the first port according to the alarm to be filtered.
In one embodiment, the alarm type determining module 02 is specifically configured to:
and if the unavailable alarm of the first port is accompanied by the protocol alarm of the first port, and the unavailable alarm of the second port and the protocol alarm of the second port exist in the second port connected with the first port through the IP circuit, determining the alarm type as the IP circuit interruption alarm.
In one embodiment, the alarm information processing module 03 is specifically configured to:
and converging the first port unavailable alarm, the first port protocol alarm, the second port unavailable alarm and the second port protocol alarm into an IP circuit interruption alarm according to the IP circuit interruption alarm.
In one embodiment, the alarm type determining module 02 is specifically configured to:
and if the first port unavailable alarm is accompanied with the first port protocol alarm and the second port connected with the first port through the IP circuit does not have the second port unavailable alarm and the second port protocol alarm, determining the alarm type as the port protocol alarm.
In one embodiment, the alarm information processing module 03 is specifically configured to:
and converging the first port unavailable alarm and the first port protocol alarm into a first port protocol alarm according to the port protocol alarm.
The embodiment of the invention also provides computer equipment which comprises a memory, a processor and a computer program which is stored on the memory and can run on the processor, wherein the processor realizes the processing method of the network port alarm information when executing the computer program.
The embodiment of the invention also provides a computer readable storage medium, and the computer readable storage medium stores a computer program for executing the processing method of the network port alarm information.
In summary, the embodiment of the present invention provides: acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm; determining an alarm type according to a plurality of pieces of alarm information of the first port and the network topology; wherein, the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered; according to the method and the device, the convergence processing or the filtering processing is carried out on the plurality of pieces of alarm information according to the alarm types, the fault sources of the alarm information can be identified based on the plurality of pieces of alarm information of the ports and the plurality of dimensionalities of the network topology, the convergence or the filtering processing is carried out on the alarm information, the reporting frequency of the alarm information is reduced, the reporting reliability of the alarm information is improved, and the fault processing can be carried out by network maintenance personnel more easily.
As will be appreciated by one skilled in the art, embodiments of the present invention may be provided as a method, system, or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, and the like) having computer-usable program code embodied therein.
The present invention is described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each flow and/or block of the flow diagrams and/or block diagrams, and combinations of flows and/or blocks in the flow diagrams and/or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means which implement the function specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
The above is only a preferred embodiment of the present invention, and is not intended to limit the present invention, and various modifications and variations of the embodiment of the present invention may occur to those skilled in the art. Any modification, equivalent replacement, or improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims (10)

1. A method for processing network port alarm information is characterized by comprising the following steps:
acquiring a plurality of pieces of alarm information and network topology of a first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
determining an alarm type according to the plurality of pieces of alarm information of the first port and the network topology; wherein the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and performing convergence processing or filtering processing on the plurality of pieces of alarm information according to the alarm types.
2. The method of claim 1, wherein determining an alarm type based on a plurality of pieces of alarm information of the first port and the network topology comprises;
when a plurality of first port available alarms and a plurality of first port unavailable alarms which exceed a preset threshold exist in a preset time length, determining the alarm type as a port stroboscopic alarm;
according to the alarm type, carrying out convergence processing or filtering processing on the plurality of pieces of alarm information, wherein the convergence processing or the filtering processing comprises the following steps:
and converging the plurality of first port available alarms and the plurality of first port unavailable alarms into a first port stroboscopic alarm according to the port stroboscopic alarm.
3. The method of claim 2, further comprising:
after the first port unavailability alarm is obtained, maintaining the unavailability state of the first port within a preset time period, and recording the alarm times;
and comparing the alarm times in the preset time with a preset threshold value, and determining whether a plurality of first port available alarms and a plurality of first port unavailable alarms exceeding the preset threshold value exist in the preset time.
4. The method of claim 3, wherein maintaining the unavailability of the first port for a preset length of time comprises:
setting a survival time length for the unavailable state of the first port;
performing the following operations for each first port available alarm and each first port unavailable alarm: and starting timing, when a first port available alarm and a first port unavailable alarm occur in the survival time, keeping the first port unavailable state, and restarting timing.
5. The method of claim 1, wherein determining an alarm type based on a plurality of pieces of alarm information of the first port and the network topology comprises:
when the first port unavailable alarm is not accompanied by the first port protocol alarm, determining the alarm type as the alarm to be filtered;
according to the alarm type, carrying out convergence processing or filtering processing on the plurality of pieces of alarm information, wherein the convergence processing or the filtering processing comprises the following steps:
and filtering the unavailable alarm of the first port according to the alarm to be filtered.
6. The method of claim 1, wherein determining an alarm type based on a plurality of pieces of alarm information of the first port and the network topology comprises:
if the first port unavailable alarm is accompanied with the first port protocol alarm, and a second port connected with the first port through an IP circuit has a second port unavailable alarm and a second port protocol alarm, determining the alarm type as an IP circuit interruption alarm;
according to the alarm type, carrying out convergence processing or filtering processing on the plurality of pieces of alarm information, wherein the convergence processing or the filtering processing comprises the following steps:
and converging the first port unavailable alarm, the first port protocol alarm, the second port unavailable alarm and the second port protocol alarm into an IP circuit interruption alarm according to the IP circuit interruption alarm.
7. The method of claim 1, wherein determining an alarm type based on a plurality of pieces of alarm information of the first port and the network topology comprises:
if the first port unavailable alarm is accompanied with the first port protocol alarm, and the second port connected with the first port through the IP circuit does not have the second port unavailable alarm and the second port protocol alarm, determining the alarm type as the port protocol alarm;
according to the alarm type, carrying out convergence processing or filtering processing on the plurality of pieces of alarm information, wherein the convergence processing or the filtering processing comprises the following steps:
and converging the first port unavailable alarm and the first port protocol alarm into a first port protocol alarm according to the port protocol alarm.
8. An apparatus for processing network port alarm information, comprising:
the alarm information acquisition module is used for acquiring a plurality of pieces of alarm information and network topology of the first port; wherein, the plurality of alarm messages of the first port at least comprise: an unavailable first port alarm;
the alarm type determining module is used for determining an alarm type according to the plurality of pieces of alarm information of the first port and the network topology; wherein the alarm types include: a port stroboscopic alarm, a port protocol alarm, an IP circuit interruption alarm or an alarm to be filtered;
and the alarm information processing module is used for carrying out convergence processing or filtering processing on the plurality of pieces of alarm information according to the alarm types.
9. A computer device comprising a memory, a processor and a computer program stored on the memory and executable on the processor, wherein the processor implements the method of any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that the computer-readable storage medium stores a computer program for executing the method of any one of claims 1 to 7.
CN201911282300.2A 2019-12-13 2019-12-13 Method and device for processing network port alarm information Pending CN112994910A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201911282300.2A CN112994910A (en) 2019-12-13 2019-12-13 Method and device for processing network port alarm information

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201911282300.2A CN112994910A (en) 2019-12-13 2019-12-13 Method and device for processing network port alarm information

Publications (1)

Publication Number Publication Date
CN112994910A true CN112994910A (en) 2021-06-18

Family

ID=76332412

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201911282300.2A Pending CN112994910A (en) 2019-12-13 2019-12-13 Method and device for processing network port alarm information

Country Status (1)

Country Link
CN (1) CN112994910A (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113890815A (en) * 2021-10-18 2022-01-04 中国电子科技集团公司第三十四研究所 Method and system for monitoring and alarming frequent UP/DOWN of network equipment port

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2011002250A2 (en) * 2009-07-01 2011-01-06 한국전자통신연구원 Method for providing and receiving reliable service in wireless communication system
CN102638375A (en) * 2012-04-26 2012-08-15 北京星网锐捷网络技术有限公司 Network fault recognition method and device
CN109189736A (en) * 2018-08-01 2019-01-11 中国联合网络通信集团有限公司 A kind of generation method and device of alarm association rule
CN110493348A (en) * 2019-08-26 2019-11-22 山东融为信息科技有限公司 A kind of intelligent monitoring and alarming system based on Internet of Things

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2011002250A2 (en) * 2009-07-01 2011-01-06 한국전자통신연구원 Method for providing and receiving reliable service in wireless communication system
CN102638375A (en) * 2012-04-26 2012-08-15 北京星网锐捷网络技术有限公司 Network fault recognition method and device
CN109189736A (en) * 2018-08-01 2019-01-11 中国联合网络通信集团有限公司 A kind of generation method and device of alarm association rule
CN110493348A (en) * 2019-08-26 2019-11-22 山东融为信息科技有限公司 A kind of intelligent monitoring and alarming system based on Internet of Things

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113890815A (en) * 2021-10-18 2022-01-04 中国电子科技集团公司第三十四研究所 Method and system for monitoring and alarming frequent UP/DOWN of network equipment port

Similar Documents

Publication Publication Date Title
US8347143B2 (en) Facilitating event management and analysis within a communications environment
US6747957B1 (en) Network availability monitor
US8245079B2 (en) Correlation of network alarm messages based on alarm time
US20200007381A1 (en) Predicting computer network equipment failure
CN114172794B (en) Network fault positioning method and server
US20160179598A1 (en) System and method of visualizing historical event correlations in a data center
CN113259168B (en) Fault root cause analysis method and device
US10341182B2 (en) Method and system for detecting network upgrades
CN109034423B (en) Fault early warning judgment method, device, equipment and storage medium
US7995485B1 (en) Method and apparatus for providing automated diagnostics of networks
CN112311580A (en) Message transmission path determining method, device and system and computer storage medium
CN114996090A (en) Server abnormity detection method and device, electronic equipment and storage medium
EP3264634A1 (en) Automatically detecting an error in a communication and automatically determining a source of the error
CN109218050B (en) Domain name system fault processing method and system
CN112994910A (en) Method and device for processing network port alarm information
US7421493B1 (en) Orphaned network resource recovery through targeted audit and reconciliation
CN110943864B (en) Network anomaly positioning method and device of distributed storage system
CN110609761B (en) Method and device for determining fault source, storage medium and electronic equipment
US20060072707A1 (en) Method and apparatus for determining impact of faults on network service
CN108156019B (en) SDN-based network derived alarm filtering system and method
JP2014053658A (en) Failure site estimation system and failure site estimation program
GB2372674A (en) Network management
JP2012249250A (en) Monitoring device and program
CN111343031B (en) Method and device for determining network fault
KR20040001627A (en) System for managing fault of internet and method thereof

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20210618

RJ01 Rejection of invention patent application after publication