WO2010057431A1 - 告警处理方法、装置及系统 - Google Patents

告警处理方法、装置及系统 Download PDF

Info

Publication number
WO2010057431A1
WO2010057431A1 PCT/CN2009/075019 CN2009075019W WO2010057431A1 WO 2010057431 A1 WO2010057431 A1 WO 2010057431A1 CN 2009075019 W CN2009075019 W CN 2009075019W WO 2010057431 A1 WO2010057431 A1 WO 2010057431A1
Authority
WO
WIPO (PCT)
Prior art keywords
alarm
information
similar
time period
duration
Prior art date
Application number
PCT/CN2009/075019
Other languages
English (en)
French (fr)
Inventor
朱健
李凯
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2010057431A1 publication Critical patent/WO2010057431A1/zh
Priority to US13/110,575 priority Critical patent/US20110215920A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to an alarm processing method, apparatus, and system. Background technique
  • the operating state of the communication device can be affected by the quality of its own hardware, and is also susceptible to changes in the external environment. For example, supply voltage, temperature, humidity, vibration, electromagnetic interference, etc. can all act on the communication device, so that the communication device may generate each A variety of faults. However, due to the unstable characteristics of the fault, the fault information that is often detected changes with time. Correspondingly, the fault alarm also changes with time. Failures can be short-lived, long-lasting, and can occur infrequently or infrequently. For example, the board is faulty, and the board communication is completely interrupted. As a result, the board may not work properly. However, the board communication alarm may occur frequently due to poor connector contact, which may affect the normal operation of the board. The board simply can't work.
  • a fault with a short duration is called a flash fault, and a corresponding fault alert is also called a flashing alarm.
  • a fault that repeatedly appears multiple times and meets certain rules in a certain period of time is called an oscillation fault, and the corresponding alarm is also called an oscillation. Alarm. Flashing and oscillating alarms, because of their short duration or many times in a short period of time, will have a negative impact on the monitoring of the communication network and reduce the efficiency of the monitoring personnel. Therefore, the alarms should be filtered, The value of the user is used to determine whether the alarm is to be reported.
  • the embodiment of the invention provides an alarm processing method, device and system, which can accurately and timely screen out valuable alarm information and ensure smooth running of the device.
  • an embodiment of the present invention provides an alarm processing method, including:
  • an embodiment of the present invention further provides an alarm processing apparatus, including:
  • a receiving unit configured to receive the reported alarm information
  • An acquiring unit configured to acquire, from the alarm information received by the receiving unit, similar alarm duration accumulation information within a specified time period
  • a sending unit configured to send an alarm notification when the similar alarm duration accumulated information in the specified time period acquired by the acquiring unit satisfies the reporting condition.
  • an embodiment of the present invention further provides an alarm processing system, including a fault detecting device and an alarm processing device:
  • the fault detecting device is configured to perform fault detection, and report alarm information to the alarm processing device when a fault is detected;
  • the alarm processing device includes:
  • a receiving unit configured to receive the reported alarm information
  • An acquiring unit configured to acquire, from the alarm information received by the receiving unit, similar alarm duration accumulation information within a specified time period
  • a sending unit configured to send an alarm notification when the similar alarm duration accumulated information in the specified time period acquired by the acquiring unit satisfies the reporting condition.
  • the alarm processing method, device, and system provided by the embodiment of the present invention obtain the similar alarm duration cumulative information in a specified time period by receiving the reported alarm information, and the similarity notification is When the cumulative information of the police duration meets the reporting conditions, the alarm notification is sent, so that the fault mode with time-varying characteristics can be adapted, and the valuable alarm information is accurately and timely filtered to ensure the smooth operation of the communication device.
  • FIG. 1 is a flowchart of an alarm processing method according to an embodiment of the present invention
  • FIG. 2 is a schematic diagram of an alarm processing method according to an embodiment of the present invention.
  • FIG. 3 is a schematic structural diagram 1 of an alarm processing apparatus according to an embodiment of the present invention.
  • FIG. 4 is a schematic structural diagram 2 of an alarm processing apparatus according to an embodiment of the present invention.
  • an embodiment of the present invention provides an alarm processing method, including:
  • S103 Send an alarm notification when the accumulated alarm duration cumulative information in the specified time period satisfies the reporting condition.
  • the alarm processing method provided by the embodiment of the present invention obtains the similar alarm duration cumulative information in a specified time period, and sends an alarm notification when the similar alarm duration cumulative information meets the reporting condition, so that the valuable alarm can be accurately and timely filtered.
  • Alarm information ensures smooth communication equipment Run.
  • the method in the embodiment of the present invention obtains the accumulated information of the similar alarm durations in the specified time period, and therefore can effectively reduce the number of alarm information, and achieve a good balance between the number of alarms and the accuracy and timeliness of the alarms. .
  • the present invention provides another embodiment to describe in detail a specific implementation process of the alarm processing method.
  • the method specifically includes:
  • the fault detecting device performs fault detection on the detected communication device, determines whether the communication device has a fault, and the nature of the fault and whether it needs to be reported, etc., for example, the fault detecting device can perform fault detection as follows:
  • the fault detection device Proactively check the status of the detected communication device, that is, the fault detection device periodically detects the status of the communication port.
  • the port is notified of the fault alarm generation message;
  • the unavailable state is changed to the available state, and the available state continues for a period of time, the fault alarm clearing message is reported.
  • the detected communication device When the detected communication device receives the signal at the receiving end of E1/T1, it is in the state of AIS (Alarm Indication Signal). When it detects that the link enters the AIS state for a period of time. The AIS fault information is generated and reported to the fault detection device. When the link exits the AIS state for a period of time, the AIS fault recovery information is generated and reported to the fault detection device.
  • AIS Alarm Indication Signal
  • the fault detecting device reports the detected fault alarm information to the alarm processing device.
  • the duration from the generation of the similar alarm to the time before the similar alarm is cleared is called the duration of the similar alarm generation; from the similar alarm to the next
  • the duration before a similar alarm is generated is called the similar alarm clear duration.
  • the alarm processing device receives the alarm information reported by the fault detecting device, the reported alarm information includes a similar alarm.
  • the alarm processing device obtains the accumulated alarm duration information in the specified time period from the received alarm information.
  • the similar alarm duration accumulation information in the specified time period may include a cumulative sum of the durations of the similar alarms generated in the specified time period, and may also include the accumulation of each similar alarm clear duration occurring within the specified time period.
  • the sum may also include a mathematical processing result of summing the durations of the similar alarms or the cumulative time of the clearing time, such as normalization processing, extremum or logarithm, etc., which is not
  • a mathematical processing result of summing the durations of the similar alarms or the cumulative time of the clearing time such as normalization processing, extremum or logarithm, etc., which is not
  • the limitation is made as long as the purpose of making the mathematical processing result reflect the cumulative duration described above can be achieved.
  • Each of the times mentioned in this embodiment includes a plurality of cases from zero to many times.
  • Mode 1 The similar alarm duration accumulation information may be used to generate duration accumulation information for similar alarms in a specified time period, and the similar alarm generation duration accumulation information may be a specified time period.
  • the sum of the cumulative durations of the similar alarms generated within the period may be the mathematical processing result of the sum of the cumulative durations of the similar alarms generated within the specified time period.
  • the condition may be a threshold value, and the embodiment of the present invention does not limit the specific expression form of the reporting condition, and then sends The alarm generates a notification.
  • the similar alarm duration accumulation information may also be the similar alarm clear duration accumulation information in the specified time period, and the similar alarm clear duration cumulative information may be the similar alarm clearing occurrences occurring in the specified time period.
  • the sum of the cumulative times may also be the mathematical processing result of the sum of the cumulative durations of similar alarms occurring within a specified time period.
  • the condition may be a threshold value, or may be other manifestations, and an alarm generating notification is sent.
  • the similar alarm duration accumulation information may generate continuous accumulation time information for similar alarms in a specified time period, and the similar alarm generation duration accumulation information may be each similar alarm generation duration occurring within a specified time period.
  • the sum of the cumulative sums may also be the mathematical processing result of the sum of the cumulative durations of the similar alarms occurring within the specified time period.
  • the condition may be a threshold value or other representation form, an alarm clearing notification is sent.
  • the similar alarm duration accumulation information may also be a similar alarm clear duration accumulation information in a specified time period, and the similar alarm clear duration cumulative information may be a similar alarm clearing occurrence occurring within a specified time period.
  • the sum of the cumulative times may also be the mathematical processing result of the sum of the cumulative durations of similar alarms occurring within a specified time period.
  • the specified time period mentioned in this embodiment may be a default value or may be manually set, and the start and end time of the specified time period may also be dynamically changed.
  • the specified time period that can be dynamically changed may be referred to as a sliding time window, and the sliding time window for determining whether to send an alarm generation notification is referred to as a front sliding time window; and the sliding for determining whether to send an alarm clearing notification
  • the time window is called the back sliding time window.
  • the horizontal axis shown in Fig. 2 represents time
  • the blocks on the time axis represent similar alarms, as shown in Fig. 2, which are similar alarms 1, similar alarms 2, similar alarms 3 in chronological order.
  • similar alarm X similar alarm 4 and similar alarm 5.
  • Each square is perpendicular to the two sides of the time axis to indicate the needle
  • the alarm generation and alarm clearing of the similar alarms are performed. Therefore, the span of the block 1 on the time axis indicates the duration of the similar alarm 1 generation, and the interval between the block 1 and the block 2 on the time axis indicates that the alarm of the similar alarm 1 is cleared. time.
  • TW1 represents the width of the front sliding time window
  • TW2 represents the width of the rear sliding time window
  • T upedge represents the upper edge of the sliding time window.
  • TT1 indicates the alarm generation notification threshold
  • TT2 indicates the alarm clear notification transmission threshold
  • t indicates a similar alarm alarm generation duration
  • F(t-) indicates a similar alarm alarm clear duration.
  • the alarm generation time ⁇ of the similar alarm X is the upper edge time of the front sliding time window TW1.
  • the front edge of the sliding time window TW1 similar alarm T lo obtain the specified period before the sliding time window of the determined accumulated duration information, i.e., obtaining similar alarms occurring within TW1 1, a similar alarm and similar alarm
  • the alarm of 3 generates a sum of durations Z F (0. If F (0 ⁇ 7 l , it indicates that the similar alarm duration accumulation information satisfies the alarm generation notification transmission condition, then the alarm generation notification is reported. In this embodiment, a similar alarm is selected.
  • the alarm generation time of X is the upper edge of the front sliding time window TW1. It is only exemplary. You can also select the generation time of other similar alarms, or the clearing time of similar alarms, or some time in the duration of similar alarm generation. Or, it is performed at a certain time in the duration of the similar alarm clearing, which is not limited by the embodiment of the present invention.
  • the time window is swiped before the movement, and the similar alarm duration accumulation information is re-acquired. For example, moving the upper edge time of the front sliding time window to the time point, taking ⁇ as the upper edge time of the front sliding time window T upedge , and taking ⁇ /% _7 ⁇ as the lower edge time of the front sliding time window.
  • T loweredge obtains the similar alarm occurrence duration in TW1 of the moving front sliding time window
  • the accumulated information that is, ⁇ F(t), if ⁇ F(0 ⁇ 7 1 , indicates that the similar alarm duration accumulation information satisfies the alarm generation notification transmission condition, then the alarm generation notification is reported.
  • the alarm clearing time of similar alarm X is the lower edge time of the sliding time window TW2
  • the alarm clearing time of the similar alarm X may be the lower edge time T lcmeredge of the rear sliding time window TW2, and the tail sliding time window is T hwedge + TW 2
  • the upper edge time of the TW2 is 7 ⁇ . If no similar alarm occurs in the time period determined by the rear sliding time window, that is, the similar alarm generation duration is accumulated to 0, an alarm clearing notification is sent. When the accumulated alarm duration accumulated information does not satisfy the alarm clearing notification sending condition, further, the sliding time window may be moved, and the similar alarm duration cumulative information is re-acquired. When the similar alarm duration accumulation information in the post-sliding time window after the movement satisfies the alarm clearing notification transmission condition, an alarm clearing notification is sent.
  • the method of moving the sliding time window may be an equally spaced movement over time, such as one second per movement, to calculate similar alarm duration accumulation information within the moved time window.
  • the method of moving the sliding time window may also be an unequal spacing movement.
  • the first step is to move a difference ⁇ from the generation time point of the similar alarm.
  • the method for moving the sliding time window mentioned above is merely exemplary, and the embodiment of the present invention does not limit this.
  • the specific implementation process of the second and fourth modes is similar to that of the first and third modes.
  • the difference is that the accumulated information of the similar alarm clearing duration in the specified time period is obtained, and compared with the corresponding threshold, which will not be described here.
  • the threshold values and the reporting conditions mentioned in the embodiments of the present invention are merely exemplary.
  • the embodiments of the present invention are not limited thereto, and a reasonable threshold value may be set as a reporting condition according to actual conditions.
  • the alarm processing method provided by the embodiment of the present invention obtains the similar alarm duration cumulative information in a specified time period by receiving the alarm information reported by the fault detecting device, and sends an alarm notification when the similar alarm duration cumulative information meets the reporting condition. Therefore, it can be independently implemented by adapting to the fault mode of time-varying characteristics. For alarms generated by unstable faults, stable faults, long-term faults or short faults, valuable alarm information can be accurately and timely filtered to ensure communication. Smooth operation of the equipment.
  • the method in the embodiment of the present invention obtains the accumulated information of the similar alarm durations in the specified time period, and therefore can effectively reduce the number of alarm information, and achieve a good balance between the number of alarms and the accuracy and timeliness of the alarms. .
  • An embodiment of the present invention further provides an alarm processing system, where the system includes: a fault detecting device and an alarm processing device,
  • the fault detecting device is configured to perform fault detection, and report alarm information to the alarm processing device when a fault is detected;
  • the alarm processing device is as shown in FIG. 3, and includes:
  • the receiving unit 301 is configured to receive the reported alarm information.
  • the obtaining unit 302 is configured to obtain, from the alarm information received by the receiving unit, similar alarm duration accumulation information within a specified time period;
  • the sending unit 303 is configured to send an alarm notification when the similar alarm duration accumulation information in the specified time period acquired by the acquiring unit meets the reporting condition.
  • the specified time period may be a time period determined by the time of the upper and lower edges of the sliding time window, and the sliding time window moves with time.
  • the similar alarm duration cumulative information in the specified time period includes: a similar alarm generation duration cumulative information within a specified time period or within a specified time period Similar alarm clear duration accumulation information.
  • the sending unit 303 may include:
  • the alarm generation notification module 3031 is configured to: when the similar alarm duration cumulative information in the specified time period meets the alarm generation notification sending condition, send an alarm generation notification; and/or
  • the alarm clearing notification module 3032 is configured to send an alarm clearing notification when the similar alarm duration cumulative information in the specified time period satisfies the alarm clearing notification sending condition.
  • the obtaining unit 302 may include:
  • a determining module 3021 configured to determine the specified time period
  • the determining module is specifically configured to determine a time period between the time of the upper and lower edges of the sliding time window.
  • the obtaining module 3022 is configured to obtain similar alarm duration accumulation information within a time period determined by the determining module.
  • the alarm processing apparatus and system provided by the embodiments of the present invention obtain the similar alarm duration accumulation information in a specified time period, and send an alarm notification when the similar alarm duration cumulative information meets the reporting condition, thereby being able to adapt to the time varying characteristic.
  • the fault mode is implemented independently. For alarms generated by unstable faults, stable faults, long-term faults or short faults, valuable alarm information can be accurately and timely screened to ensure smooth operation of the communication equipment.
  • the embodiment of the present invention obtains the accumulated information of the similar alarm durations in a specified time period, so that the number of alarm information can be effectively reduced, and a good balance is obtained between the number of alarms and the accuracy and timeliness of the alarms.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Maintenance And Management Of Digital Transmission (AREA)
  • Telephonic Communication Services (AREA)

Description

告警处理方法、 装置及系统 本申请要求于 2008 年 11 月 18 日提交中国专利局、 申请号为 200810217807. 5 , 发明名称为 "告警处理方法、 装置及系统" 的中国专利申 请的优先权, 其全部内容通过引用结合在本申请中。
技术领域
本发明涉及通信技术领域, 尤其涉及一种告警处理方法、 装置及系统。 背景技术
通信设备的运行状态可以受自身硬件质量的影响, 也容易受外界环境的 变化影响, 例如, 供电电压, 温度, 湿度, 震动, 电磁干扰等因素均可作用 于通信设备, 使得通信设备可能产生各种各样的故障。 然而由于故障具有不 稳定的特性, 往往检测到的故障信息会随时间的变化而变化, 相应的, 故障 告警也随时间的变化而变化。 故障可能持续时间很短, 也可能持续时间很长, 可能出现的次数很少, 也可能出现的次数很多。 例如由于接插件故障, 单板 通信就此彻底中断, 这样就可能会使得单板无法正常工作; 然而也有可能由 于接插件接触不良而频繁发生板间通信告警, 从而影响单板正常工作, 甚至 使得单板根本无法工作。
持续时间短的故障称为闪断故障, 相应的故障告警也称为闪断告警; 在 一定的时间内反复出现多次且满足一定的规律的故障称为振荡故障, 相应的 告警也称为振荡告警。 闪断和振荡告警, 由于其持续时间很短, 或者在短时 间内出现的次数很多, 会给通信网络的监控带来负面影响, 降低监控人员的 效率, 所以, 要对告警进行筛选, 按照对用户的价值来判断告警是否要上报。
发明人在实现本发明的过程中发现, 现有技术提供的告警处理方法不能 解决由于相似告警时变性所带来的问题, 导致对于相似告警信息不能进行准 确及时有效的 选与处理, 造成有价值的告警信息的丟失, 甚至造成故障隐 、 发明内容
本发明实施例提供一种告警处理方法、 装置及系统, 能够准确及时的筛 选出有价值的告警信息, 保障设备的平稳运行。
一方面, 本发明实施例提供了一种告警处理方法, 包括:
接收检测到故障时上报的告警信息;
根据接收的告警信息获取指定时间段内的相似告警持续时间累计信息; 当所述指定时间段内的相似告警持续时间累计信息满足上报条件时, 发 送告警通知。
另一方面, 本发明实施例还提供了一种告警处理装置, 包括:
接收单元, 用于接收上报的告警信息;
获取单元, 用于从所述接收单元接收的告警信息中获取指定时间段内的 相似告警持续时间累计信息;
发送单元, 用于当所述获取单元获取的指定时间段内的相似告警持续时 间累计信息满足上报条件时, 发送告警通知。
另一方面, 本发明实施例还提供了一种告警处理系统, 包括故障检测装 置和告警处理装置:
所述故障检测装置用于进行故障检测, 当检测到故障时向所述告警处理 装置上报告警信息;
所述告警处理装置包括:
接收单元, 用于接收上报的告警信息;
获取单元, 用于从所述接收单元接收的告警信息中获取指定时间段内的 相似告警持续时间累计信息;
发送单元, 用于当所述获取单元获取的指定时间段内的相似告警持续时 间累计信息满足上报条件时, 发送告警通知。
本发明实施例提供的告警处理方法、 装置及系统, 通过接收上报的告警 信息, 从中获取指定时间段内相似告警持续时间累计信息, 并在所述相似告 警持续时间累计信息满足上报条件时发送告警通知, 因而能够适应时变特性 的故障模式, 准确及时地筛选出有价值的告警信息, 保证了通信设备的平稳 运行。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实 施例或现有技术描述中所需要使用的附图作简单地介绍, 显而易见地, 下面 描述中的附图仅仅是本发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动性的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明实施例的告警处理方法的流程图;
图 2为本发明实施例的告警处理方法的示意图;
图 3为本发明实施例的告警处理装置结构示意图一;
图 4为本发明实施例的告警处理装置结构示意图二。
具体实施方式
下面结合附图对本发明的实施方式做出具体的说明。 显然, 所描述的实 施例仅仅是本发明一部分实施例, 而不是全部的实施例。 基于本发明中的实 施例, 本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他 实施例, 都属于本发明保护的范围。
如图 1所示, 本发明实施例提供了一种告警处理方法, 包括:
5101,接收检测到故障时上报的告警信息;
5102,根据接收的告警信息获取指定时间段内的相似告警持续时间累计信 息;
5103,当所述指定时间段内的相似告警持续时间累计信息满足上报条件 时, 发送告警通知。
本发明实施例提供的告警处理方法, 通过获取指定时间段内相似告警持 续时间累计信息, 并在所述相似告警持续时间累计信息满足上报条件时发送 告警通知, 能准确及时地筛选出有价值的告警信息, 保证了通信设备的平稳 运行。 同时, 本发明实施例所述方法获取的是指定时间段内相似告警持续时 间的累计信息, 因此也能够有效地降低告警信息数量, 在告警数量和告警准 确性、 及时性上取得很好的平衡。
本发明提供另一实施例, 以详细说明告警处理方法的具体实现过程。 该 方法具体包括:
1 )进行故障检测并上报告警信息;
故障检测装置对被检测的通信设备进行故障检测, 判断该通信设备是否 存在故障, 以及存在故障的性质和是否需要上报等等, 例如, 故障检测装置 可以釆用如下方式进行故障检测:
方式一: 主动查询方式
主动对被检测的通信设备的状态进行检查, 即故障检测装置定时检测通 信端口的状态, 当发现端口的状态为不可用而且持续一段时间后, 则上报该 端口故障告警产生消息; 当此端口从不可用转变为可用状态时, 并且可用状 态持续一段时间后, 上报故障告警清除消息。
方式二: 告警数据上报方式
当被检测的通信设备在 E1/T1 的接收端收到的信号是全 "Γ 时, 进入 AIS ( Alarm Indication Signal, El/Tl告警指示信号)状态。 当检测到链路进 入 AIS状态持续一段时间时, 产生 AIS故障信息并上报给故障检测装置; 当 链路退出 AIS状态且持续一段时间时, 产生 AIS故障恢复信息并上报给故障 检测装置。
在检测完毕后, 故障检测装置将检测到的故障告警信息上报给告警处理 装置。
2 )接收所述上报的告警信息, 获取指定时间段内的相似告警持续时间累 计信息
对于每次相似告警而言 , 从该次相似告警产生到该次相似告警清除前的 这段持续时间, 称为该次相似告警产生持续时间; 从该次相似告警清除到下 一次相似告警产生前的这段持续时间, 称为该次相似告警清除持续时间。 告警处理装置接收故障检测装置上报的告警信息后, 所述上报的告警信 息中包含有相似告警; 告警处理装置从所述接收的告警信息中获取指定时间 段内的相似告警持续时间累计信息, 所述指定时间段内的相似告警持续时间 累计信息可以包括指定时间段内出现的各次相似告警产生持续时间的累计之 和, 也可以包括指定时间段内出现的各次相似告警清除持续时间的累计之和, 也可以包括对所述相似告警产生持续时间或清除时间的累计之和的数学处理 结果, 例如进行归一化处理、 求极值或者求对数等等, 本发明实施例并不对 此做出限定, 只要能够实现使得该数学处理结果亦能反映上述累计持续时间 的目的即可。 本实施例中所提到的各次包括零次到多次的多种情形。
3 )根据获取的指定时间段内的相似告警持续时间累计信息判断是否满足 上报条件, 如果满足, 则向其它网络设备发送告警通知
根据所述获取的指定时间段内的相似告警持续时间累计信息判断是否满 足上报条件, 如果满足条件, 则向其它网络设备, 例如其它网元、 网元管理 系统或者网络管理系统发送告警通知。 具体的, 可以包括以下几种情况: 方式一: 所述相似告警持续时间累计信息可以为指定时间段内的相似告 警产生持续时间累计信息, 所述相似告警产生持续时间累计信息可以是指定 时间段内发生的各次相似告警产生持续时间的累计之和, 也可以是指定时间 段内发生的各次相似告警产生持续时间的累计之和的数学处理结果。 当判定 所述指定时间段内的相似告警产生持续时间累计信息满足告警产生通知上报 条件时, 例如, 该条件可以是一个门限值, 本发明实施例不限定上报条件的 具体表现形式, 则发送告警产生通知。
方式二: 所述相似告警持续时间累计信息也可以为指定时间段内的相似 告警清除持续时间累计信息, 所述相似告警清除持续时间累计信息可以是指 定时间段内发生的各次相似告警清除持续时间的累计之和, 也可以是指定时 间段内发生的各次相似告警清除持续时间的累计之和的数学处理结果。 当判 定所述指定时间段内的相似告警清除持续时间累计信息满足告警产生通知上 报条件时, 例如, 该条件可以是一个门限值, 也可以是其它的表现形式, 则 发送告警产生通知。
方式三: 所述相似告警持续时间累计信息可以为指定时间段内的相似告 警产生持续累计时间信息, 所述相似告警产生持续时间累计信息可以是指定 时间段内发生的各次相似告警产生持续时间的累计之和, 也可以是指定时间 段内发生的各次相似告警产生持续时间的累计之和的数学处理结果。 当判定 所述指定时间段内的相似告警产生持续时间累计信息满足告警清除通知上报 条件时, 例如, 该条件可以是一个门限值, 也可以是其它的表现形式, 则发 送告警清除通知。
方式四: 所述相似告警持续时间累计信息也可以为指定时间段内的相似 告警清除持续时间累计信息, 所述相似告警清除持续时间累计信息可以是指 定时间段内发生的各次相似告警清除持续时间的累计之和, 也可以是指定时 间段内发生的各次相似告警清除持续时间的累计之和的数学处理结果。 当判 定所述指定时间段内的相似告警清除持续时间累计信息满足告警清除通知上 报条件时, 例如, 该条件可以是一个门限值, 也可以是其它的表现形式, 则 发送告警清除通知。
本实施例所提到的指定时间段, 可以是缺省值, 也可以人工设置, 该指 定时间段的起止时间也可以是动态变化的。
为了叙述的方便, 可以将这个可以动态变化的指定时间段称为滑动时间 窗, 用于判断是否发送告警产生通知的滑动时间窗称为前滑动时间窗; 用于 判断是否发送告警清除通知的滑动时间窗称为后滑动时间窗。
下面结合附图对上述方式一、 三的具体实现过程进行详细说明。 如图 2 所示, 图 2 中所示横轴表示时间, 时间轴上的各方块表示各次相似告警, 如 图 2所示, 按时间顺序分别为相似告警 1、 相似告警 2、 相似告警 3、 相似告 警 X、相似告警 4和相似告警 5。 每个方块垂直于时间轴的两条边分别表示针 对该次相似告警的告警产生与告警清除, 因此方块 1 在时间轴上的跨度即表 示相似告警 1产生持续时间, 方块 1与方块 2在时间轴上的间隔即表示相似 告警 1的告警清除持续时间。
TW1表示前滑动时间窗的宽度, TW2表示后滑动时间窗的宽度, Tupedge 示滑动时间窗的上边沿, 。were 表示滑动时间窗的下边沿, TT1表示告警产 生通知发送门限, TT2表示告警清除通知发送门限, t)表示一次相似告警告 警产生持续时间, F(t—)表示一次相似告警告警清除持续时间。 如图 1所示, 以相似告警 X的告警产生时刻 ^为前滑动时间窗 TW1的上 边沿时刻
Figure imgf000009_0001
为前滑动时间窗 TW1的下边沿时刻 Tlo 获取所述前滑动时间窗所确定的指定时间段内的相似告警持续时间累计信 息, 即获取 TW1内出现的相似告警 1、相似告警 1和相似告警 3的告警产生持 续时间之和 ZF(0 , 如果 F(0≥7 l , 则表明相似告警持续时间累计信息满 足告警产生通知发送条件,则上报告警产生通知。本实施例中选取相似告警 X 的告警产生时刻为前滑动时间窗 TW1的上边沿仅是示例性的, 也可以选取其 他相似告警的产生时刻, 或者相似告警的清除时刻, 或者在相似告警产生持 续时间内的某个时间点, 或者在相似告警清除持续时间内的某个时间点进行, 本发明实施例并不对此进行限定。
当在 获取的相似告警持续时间累计信息不满足告警产生通知发送条件 时, 则进一步的, 移动前滑动时间窗, 并重新获取相似告警持续时间累计信 息。 例如, 将前滑动时间窗的上边沿时刻移动到时间点 , 以^为前滑动时 间窗的上边沿时刻 Tupedge , 以 Μ/% _7 ^为前滑动时间窗的下边沿时刻
Tloweredge , 获取移动后的前滑动时间窗的 TW1 内出现的相似告警产生持续时 间累计信息, 即∑F(t) , 如果∑F(0≥7 1 , 则表明相似告警持续时间累计信 息满足告警产生通知发送条件, 则上报告警产生通知。
以相似告警 X 的告警清除时刻 为后滑动时间窗 TW2 的下边沿时刻
Tloweredge , 以7 + ^为后滑动时间窗 TW2的上边沿时刻 7^e , 获取 所述后滑动时间窗所确定的时间段内的相似告警产生持续时间累计信息, 例 如, TW2 内的出现的各次相似告警的产生持续时间累计之和∑F(t) , 如果 /{ί)≤ΤΤ2 , 则表明相似告警持续时间累计信息满足告警清除通知发送条 件,则发送告警清除通知。特别的,也可以以相似告警 X的告警清除时刻 为 后滑动时间窗 TW2的下边沿时刻 Tlcmeredge, 以 Thwedge + TW2为后滑动时间窗
TW2的上边沿时刻 7 ^ , 若所述后滑动时间窗所确定的时间段内没有发生 相似告警, 即相似告警产生持续时间累计为 0 , 则发送告警清除通知。 当在 ^获取的相似告警持续时间累计信息不满足告警清除通知发送条件 时, 则进一步的, 可以移动后滑动时间窗, 并重新获取相似告警持续时间累 计信息。 当在移动后的后滑动时间窗内的相似告警持续时间累计信息满足告 警清除通知发送条件时, 则发送告警清除通知。
移动滑动时间窗的方法可以是随着时间的推移进行的等间距的移动, 比 如每次移动 1 秒, 计算移动后的时间窗内的相似告警持续时间累计信息。 移 动滑动时间窗的方法也可以是不等间距的移动, 当然也可以是上述两种方式 的结合, 比如第一步就从相似告警的产生时间点 ^向后移动一个差值 Δί (该
^为告警通知产生门限与 TW1内相似告警累计时间的差值), 进行相似告警 持续时间累计信息的计算, 如果不满足上报告警通知的门限, 则再以 1 秒的 步长均匀移动等等。 上述提到的移动滑动时间窗的方法仅是示例性的, 本发 明实施例并不对此进行限定。 方式二、 四的具体实现过程与方式一、 三类似, 不同的是获取的是指定 时间段内的相似告警清除持续时间累计信息, 并与相应的门限进行比较, 此 处就不再赘述。
本发明实施例所提到的门限值和上报条件, 仅是示例性的, 本发明实施 例并不对此进行限定, 可根据实际情况设置合理的门限值作为上报条件。
本发明实施例提供的告警处理方法, 通过接收故障检测装置上报的告警 信息, 从中获取指定时间段内相似告警持续时间累计信息, 并在所述相似告 警持续时间累计信息满足上报条件时发送告警通知, 因而能够适应时变特性 的故障模式而独立实施, 对于不稳定故障、 稳定故障、 持续时间长或者短的 故障所产生的告警, 都能准确及时地筛选出有价值的告警信息, 保证了通信 设备的平稳运行。 同时, 本发明实施例所述方法获取的是指定时间段内相似 告警持续时间的累计信息, 因此也能够有效地降低告警信息数量, 在告警数 量和告警准确性、 及时性上取得很好的平衡。
本发明实施例还提供了一种告警处理系统, 所述系统包括: 故障检测装 置和告警处理装置,
所述故障检测装置用于进行故障检测, 当检测到故障时向所述告警处理 装置上报告警信息;
所述告警处理装置如图 3所示, 包括:
接收单元 301 , 用于接收上报的告警信息;
获取单元 302 ,用于从所述接收单元接收的告警信息中获取指定时间段内 的相似告警持续时间累计信息;
发送单元 303 ,用于当所述获取单元获取的指定时间段内的相似告警持续 时间累计信息满足上报条件时, 发送告警通知。
所述指定时间段可以为滑动时间窗的上下边沿时刻确定的时间段, 所述 滑动时间窗随时间进行移动。 所述指定时间段内的相似告警持续时间累计信 息包括: 指定时间段内的相似告警产生持续时间累计信息或者指定时间段内 的相似告警清除持续时间累计信息。
具体的, 结合图 4所示, 所述发送单元 303可以包括:
告警产生通知模块 3031 , 用于当所述指定时间段内的相似告警持续时间 累计信息满足告警产生通知发送条件时, 发送告警产生通知; 和 /或
告警清除通知模块 3032 , 用于当所述指定时间段内的相似告警持续时间 累计信息满足告警清除通知发送条件时, 发送告警清除通知。
具体的, 所述获取单元 302可以包括:
确定模块 3021 , 用于确定所述指定时间段;
另外, 所述确定模块具体用于确定滑动时间窗的上下边沿时刻之间的时 间段。
获取模块 3022 , 用于获取所述确定模块确定的时间段内的相似告警持续 时间累计信息。
应用本发明实施例提供的装置及系统实现告警处理的具体过程与前述方 法实施例基本相似, 此处不再赘述。
本发明实施例提供的告警处理装置及系统, 通过获取指定时间段内相似 告警持续时间累计信息, 并在所述相似告警持续时间累计信息满足上报条件 时发送告警通知, 因而能够适应时变特性的故障模式而独立实施, 对于不稳 定故障、 稳定故障、 持续时间长或者短的故障所产生的告警, 都能准确及时 地筛选出有价值的告警信息, 保证了通信设备的平稳运行。 同时, 本发明实 施例获取的是指定时间段内相似告警持续时间的累计信息, 因此也能够有效 地降低告警信息数量, 在告警数量和告警准确性、 及时性上取得很好的平衡。
通过以上的实施方式的描述, 本领域的技术人员可以清楚地了解到本发 明可借助软件加必需的硬件平台的方式来实现, 当然也可以全部通过硬件来 实施, 但很多情况下前者是更佳的实施方式。 基于这样的理解, 本发明的技 术方案对背景技术做出贡献的全部或者部分可以以软件产品的形式体现出 来,该计算机软件产品可以存储在存储介质中,如 ROM/RAM、磁碟、光盘等, 包括若干指令用以使得一台计算机设备(可以是个人计算机, 服务器, 或者 网络设备等)执行本发明各个实施例或者实施例的某些部分所述的方法。
以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并不局限 于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易 想到变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护 范围应所述以权利要求的保护范围为准。

Claims

权 利 要求 书
1、 一种告警处理方法, 其特征在于, 包括:
接收检测到故障时上报的告警信息;
根据接收的告警信息获取指定时间段内的相似告警持续时间累计信息; 当所述指定时间段内的相似告警持续时间累计信息满足上报条件时, 发送 告警通知。
2、 如权利要求 1所述的方法, 其特征在于, 所述当指定时间段内的相似告 警持续时间累计信息满足上报条件时, 发送告警通知包括:
当所述指定时间段内的相似告警持续时间累计信息满足告警产生通知发送 条件时, 发送告警产生通知; 或者
当所述指定时间段内的相似告警持续时间累计信息满足告警清除通知发送 条件时, 发送告警清除通知。
3、 如权利要求 2所述的方法, 其特征在于, 所述告警产生通知发送条件或 告警清除通知发送条件包括门限值。
4、 如权利要求 2所述的方法, 其特征在于, 所述获取指定时间段内的相似 告警持续时间累计信息包括:
确定滑动时间窗的上下边沿, 获取所述滑动时间窗的上下边沿时刻之间的 时间段内的相似告警持续时间累计信息。
5、 如权利要求 4所述的方法, 其特征在于, 确定所述滑动时间窗的下边沿 时刻为相似告警的清除时刻。
6、 如权利要求 4所述的方法, 其特征在于, 所述滑动时间窗随时间进行移 动。
7、 如权利要求 1至 6中任意一项所述的方法, 其特征在于, 所述获取指定 时间段内的相似告警持续时间累计信息包括:
获取指定时间段内的相似告警产生持续时间累计信息; 或者
获取指定时间段内的相似告警清除持续时间累计信息。
8、 一种告警处理装置, 其特征在于, 包括:
接收单元, 用于接收上报的告警信息;
获取单元, 用于从所述接收单元接收的告警信息中获取指定时间段内的相 似告警持续时间累计信息;
发送单元, 用于当所述获取单元获取的指定时间段内的相似告警持续时间 累计信息满足上报条件时, 发送告警通知。
9、 如权利要求 8所述的告警处理装置, 其特征在于, 所述发送单元包括: 告警产生通知模块, 用于当所述指定时间段内的相似告警持续时间累计信 息满足告警产生通知发送条件时, 发送告警产生通知; 和 /或
告警清除通知模块, 用于当所述指定时间段内的相似告警持续时间累计信 息满足告警清除通知发送条件时, 发送告警清除通知。
10、 如权利要求 8所述的告警处理装置, 其特征在于, 所述获取单元包括: 确定模块, 用于确定所述指定时间段;
获取模块, 用于获取所述确定模块确定的时间段内的相似告警持续时间累 计信息。
11、 如权利要求 10所述的告警处理装置, 其特征在于, 所述确定模块具体 用于确定滑动时间窗的上下边沿时刻之间的时间段。
12、 如权利要求 8 所述的告警处理装置, 其特征在于, 所述指定时间段内 的相似告警持续时间累计信息包括:
指定时间段内的相似告警产生持续时间累计信息; 或者
指定时间段内的相似告警清除持续时间累计信息。
1 3、 一种告警处理系统, 其特征在于, 包括故障检测装置和如权利要求 8 至 12中任意一项所述的告警处理装置, 所述故障检测装置用于进行故障检测, 当检测到故障时向所述告警处理装置上报告警信息。
PCT/CN2009/075019 2008-11-18 2009-11-18 告警处理方法、装置及系统 WO2010057431A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US13/110,575 US20110215920A1 (en) 2008-11-18 2011-05-18 Alarm processing method, device, and system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200810217807A CN101741991A (zh) 2008-11-18 2008-11-18 告警处理方法、装置及系统
CN200810217807.5 2008-11-18

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US13/110,575 Continuation US20110215920A1 (en) 2008-11-18 2011-05-18 Alarm processing method, device, and system

Publications (1)

Publication Number Publication Date
WO2010057431A1 true WO2010057431A1 (zh) 2010-05-27

Family

ID=42197844

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/075019 WO2010057431A1 (zh) 2008-11-18 2009-11-18 告警处理方法、装置及系统

Country Status (3)

Country Link
US (1) US20110215920A1 (zh)
CN (1) CN101741991A (zh)
WO (1) WO2010057431A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113965452A (zh) * 2021-11-02 2022-01-21 烽火通信科技股份有限公司 一种设备倒换状态获取方法及装置

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102348220B (zh) * 2010-07-30 2015-08-12 中兴通讯股份有限公司 无线网络系统中监控接入信道工作状态的方法和装置
CN101958803A (zh) * 2010-09-09 2011-01-26 中兴通讯股份有限公司 基于通讯网络的告警压缩系统及方法
CN102209341B (zh) * 2011-06-17 2018-03-27 中兴通讯股份有限公司 一种基站故障检测方法及装置
CN102904737B (zh) * 2011-07-25 2018-09-11 中兴通讯股份有限公司 网络管理系统中告警提示的处理方法和装置
CN105101243B (zh) * 2014-05-23 2018-11-23 中国移动通信集团四川有限公司 一种派发告警工单的方法、设备和系统
CN104581662B (zh) * 2014-12-24 2018-07-17 北京奇艺世纪科技有限公司 一种短信报警方法、装置及系统
CN105471661A (zh) * 2015-12-28 2016-04-06 福建星网锐捷网络有限公司 一种告警处理方法和系统
CN106872168A (zh) * 2017-03-09 2017-06-20 武汉科技大学 一种用于滚动轴承的故障诊断方法
CN107038835A (zh) * 2017-06-13 2017-08-11 安徽讯桥信息科技有限公司 一种智能楼宇报警系统
CN110928255B (zh) * 2019-11-20 2021-02-05 珠海格力电器股份有限公司 数据异常统计报警方法、装置、存储介质及电子设备
CN115412422B (zh) * 2022-08-08 2024-02-20 浪潮云信息技术股份公司 一种动态窗口调整系统
CN117056177A (zh) * 2023-08-09 2023-11-14 中移互联网有限公司 测试巡检的告警方法、装置及系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20020043337A (ko) * 2000-12-02 2002-06-10 이대영 통신시스템에서 경보계위를 이용한 경보 처리 방법
JP2006067129A (ja) * 2004-08-25 2006-03-09 Fujitsu Ltd ネットワーク監視方法及び装置
CN1921636A (zh) * 2006-09-28 2007-02-28 华为技术有限公司 长时间静音告警方法及装置
CN101098349A (zh) * 2006-06-27 2008-01-02 中兴通讯股份有限公司 一种网络管理系统和网元管理系统之间的告警计数过滤方法
CN101222361A (zh) * 2008-01-22 2008-07-16 中兴通讯股份有限公司 一种告警频率监控器及告警处理方法

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5262758A (en) * 1991-09-19 1993-11-16 Nam Young K System and method for monitoring temperature

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20020043337A (ko) * 2000-12-02 2002-06-10 이대영 통신시스템에서 경보계위를 이용한 경보 처리 방법
JP2006067129A (ja) * 2004-08-25 2006-03-09 Fujitsu Ltd ネットワーク監視方法及び装置
CN101098349A (zh) * 2006-06-27 2008-01-02 中兴通讯股份有限公司 一种网络管理系统和网元管理系统之间的告警计数过滤方法
CN1921636A (zh) * 2006-09-28 2007-02-28 华为技术有限公司 长时间静音告警方法及装置
CN101222361A (zh) * 2008-01-22 2008-07-16 中兴通讯股份有限公司 一种告警频率监控器及告警处理方法

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113965452A (zh) * 2021-11-02 2022-01-21 烽火通信科技股份有限公司 一种设备倒换状态获取方法及装置
CN113965452B (zh) * 2021-11-02 2023-11-03 烽火通信科技股份有限公司 一种设备倒换状态获取方法及装置

Also Published As

Publication number Publication date
US20110215920A1 (en) 2011-09-08
CN101741991A (zh) 2010-06-16

Similar Documents

Publication Publication Date Title
WO2010057431A1 (zh) 告警处理方法、装置及系统
US9917741B2 (en) Method and system for processing network activity data
JP7293270B2 (ja) 障害回復方法および障害回復装置、ならびに記憶媒体
WO2018148104A1 (en) Near real-time detection of suspicious outbound traffic
CN108418710B (zh) 一种分布式监控系统、方法及装置
US9009305B1 (en) Network host inference system
JP2011526126A (ja) 監視システムにおけるメッセージ管理及び抑制
WO2022001751A1 (zh) 虚拟云桌面监测方法、客户端、服务端和存储介质
CN102820995A (zh) 告警处理方法、装置及系统
CN112511456A (zh) 流量控制方法、装置、设备、存储介质和计算机程序产品
CN103856344B (zh) 一种告警事件信息处理方法及装置
CN112116123A (zh) 一种基于动态基线的智能告警方法和系统
JP2019159729A (ja) 故障予測システム
WO2020129610A1 (ja) 検知装置、検知方法、および、検知プログラム
US10671708B2 (en) Periodicity detection of network traffic
WO2016177048A1 (zh) 产生操作、管理和维护告警的方法、装置及存储介质
US20120163212A1 (en) Apparatus and method for detecting abnormal traffic
JP4578371B2 (ja) 監視情報取得装置
JPH11353819A (ja) ディスク装置およびディスク装置の予防保守方法
CN115080362A (zh) 一种pcie设备降速上报方法、系统、设备以及存储介质
JP5623449B2 (ja) 報告書作成装置、報告書作成プログラムおよび報告書作成方法
CN113381884B (zh) 用于监控告警系统的全链路监控方法及装置
CN112817686B (zh) 检测虚拟机异常的方法、装置、设备和计算机存储介质
JP6984299B2 (ja) 通信中継装置
JP2005236813A (ja) ネットワーク装置の制御装置及び通信システム並びに異常検出方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09827180

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09827180

Country of ref document: EP

Kind code of ref document: A1