WO2010060327A1 - 告警处理方法、装置和系统 - Google Patents

告警处理方法、装置和系统 Download PDF

Info

Publication number
WO2010060327A1
WO2010060327A1 PCT/CN2009/074562 CN2009074562W WO2010060327A1 WO 2010060327 A1 WO2010060327 A1 WO 2010060327A1 CN 2009074562 W CN2009074562 W CN 2009074562W WO 2010060327 A1 WO2010060327 A1 WO 2010060327A1
Authority
WO
WIPO (PCT)
Prior art keywords
alarm
previous
latest
recovery
similar
Prior art date
Application number
PCT/CN2009/074562
Other languages
English (en)
French (fr)
Inventor
马宁
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2010060327A1 publication Critical patent/WO2010060327A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/069Management of faults, events, alarms or notifications using logs of notifications; Post-processing of notifications

Definitions

  • the embodiments of the present invention relate to the field of communications technologies, and in particular, to an alarm processing method, apparatus, and system.
  • Fault management plays an important role in the daily maintenance of communication equipment. It directly determines whether it can quickly report, locate, and recover equipment faults. It is a key link in serviceability.
  • In the current network operation due to a series of reasons such as environmental changes and aging of the device itself, some faults are recovered immediately after they are generated. Some faults are generated immediately after recovery. The faults are also periodically repeated. After the fault occurs, the communication equipment will be sent to the network administrator. The alarm is generated. After the fault is rectified, the communication device reports the alarm recovery event to the NMS. As a result, the user sees a large number of alarm events on the NMS. The alarm event in the case of immediate recovery after the fault occurs, and the alarm event in the situation immediately after the fault is recovered do not need to be processed by the user, which brings great difficulties to daily equipment maintenance, which seriously affects Serviceability of fault management.
  • the prior art proposes a flashing alarm filtering method, which is configured to process an alarm event in a situation where the fault is immediately recovered after the fault is generated.
  • An embodiment of the present invention provides an alarm processing method, apparatus, and system for processing an alarm event in a situation that occurs immediately after a fault is recovered, and reduces reporting of an invalid alarm recovery event.
  • an embodiment of the present invention provides an alarm processing method, including:
  • the activation time and the previous alarm are restored according to the set latest alarm. Restoring the engraving, determining that the latest alarm of the previous alarm is restored to activate the engraving;
  • an embodiment of the present invention further provides an alarm processing apparatus, including:
  • a determining module configured to: after the previous alarm is restored, restore the activation time of the activation alarm and the previous alarm according to the set latest alarm, and determine that the latest alarm of the previous alarm is activated and activated. ;
  • a judging module configured to determine whether a similar alarm of the previous alarm is generated before or after the latest alarm is resumed
  • the reporting module is configured to report a recovery event of the previous alarm when the determining result of the determining module is negative.
  • an embodiment of the present invention further provides an alarm processing system, including:
  • the communication device is configured to: after the previous alarm is restored, restore the activation time of the activation alarm and the previous alarm according to the set latest alarm, and determine that the latest alarm of the previous alarm is activated and activated. Recovering the recovery event of the previous alarm if the latest alarm is not generated before or after the latest alarm is resumed.
  • the network management device is configured to receive a recovery event of the previous alarm reported by the communication device.
  • the embodiment of the present invention sets the latest alarm recovery activation time. After the previous alarm is restored, the recovery alarm of the activation alarm and the previous alarm is resumed according to the latest alarm, and the latest alarm recovery of the previous alarm is determined. Activate engraving. If the latest alarm is not generated after the latest alarm recovery is activated, the previous alarm is reported.
  • an alarm processing method for generating a fault scenario immediately after fault recovery is proposed, which improves the reporting of invalid alarm recovery events and improves the accuracy of the alarm. Sex and serviceability.
  • FIG. 1 is a schematic flowchart diagram of an alarm processing method according to an embodiment of the present invention
  • FIG. 2 is a schematic diagram of an alarm generated again before the latest alarm recovery activation moment is reached according to an embodiment of the present invention
  • FIG. 3 is a schematic diagram of an alarm generated before the latest alarm recovery activation activation is performed according to an embodiment of the present invention.
  • FIG. 4 is a schematic structural diagram of an alarm processing apparatus according to an embodiment of the present invention.
  • FIG. 5 is a schematic structural diagram of another alarm processing apparatus according to an embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of an alarm processing system according to an embodiment of the present invention.
  • An embodiment of the present invention provides an alarm processing method, where an alarm is generated in an initialization state, and an alarm is added to activate the latest alarm. After the previous alarm is restored, the recovery of the previous alarm is engraved as the starting point, and the engraving after the latest alarm is resumed, that is, the latest alarm is activated and activated. If the similar alarm of the previous alarm is generated again before the latest alarm recovery activation expires, the previous alarm recovery event and the subsequent alarm generation event are not reported; if the latest alarm is resumed before the activation is enacted, there is no A similar alarm is generated for the previous alarm. That is, no alarm is generated or the generated next alarm is not similar to the previous alarm. The previous alarm recovery event is reported, and the alarm status is restored.
  • a flowchart of an alarm processing method according to an embodiment of the present invention includes:
  • Step S101 After the previous alarm is restored, according to the set latest alarm recovery recovery moment and the previous alarm recovery moment, it is determined that the latest alarm of the previous alarm is resumed and activated.
  • the latest alarm recovery activation time is set, and the experience value can be taken, and can be dynamically adjusted according to the alarm data on the network.
  • the embodiment of the present invention updates the latest alarm recovery activation window: the latest boundary of the latest alarm recovery activation window is the recovery engraving of the previous alarm, the upper boundary It is the recovery moment of the previous alarm as the starting point, and the engraving obtained after the latest alarm is resumed, the obtained engraving is the latest alarm to resume the activation engraving. Then wait for the latest alarm to resume the activation engraving
  • Step S102 If the similar alarm of the previous alarm is not generated before the latest alarm is resumed, the recovery event of the previous alarm is reported.
  • the so-called similar alarm that did not generate the previous alarm can include two cases: Case 1, if the alarm is not generated again after the latest alarm is resumed, or if the alarm is generated again; or 2, the next alarm is generated. The generated last alarm is not similar to the previous alarm. In this case, it can be determined that the previous alarm has been restored, and the recovery event of the previous alarm is reported.
  • the filtering parameters and determine the alarm parameters to be compared may specifically include one or more of an alarm identifier, an alarm object, an alarm level, a possible cause of the alarm, and a specific problem;
  • the left line of the block 21 indicates the generation of the previous alarm, and the current alarm is generated.
  • the alarm occurrence event is reported on the engraving shown by the left line of the block 23, and the alarm status is generated.
  • the right-hand line of block 21 indicates the recovery of the previous alarm.
  • the recovery of the previous alarm is the starting point, and the engraving obtained after the latest alarm resumes the activation period is the latest alarm recovery activation. If the last alarm is generated before the latest alarm recovery activation moment expires, the left line of block 22 indicates the generation of the next alarm, and the next alarm is similar to the previous alarm, then the previous alarm is determined. If no recovery occurs, the previous alarm recovery event and the subsequent alarm generation event are not reported, and the alarm status remains unchanged.
  • the right line of block 22 indicates the recovery of the next alarm.
  • the left line of the block 31 indicates the generation of the previous alarm, and the current alarm is generated, and the alarm occurrence event is reported on the engraving shown by the left line of the block 32.
  • the right line of block 31 indicates the recovery of the previous alarm.
  • the recovery of the previous alarm is the starting point, and the latest alarm is resumed.
  • the engraving obtained after the activation of the daytime, that is, the latest alarm is restored to activate the engraving. If the last alarm is not generated or the last alarm generated is not similar to the previous alarm after the latest alarm recovery activation expires, the alarm is reported on the engraving shown on the right-hand line of block 32. Event, update alarm status to recovery.
  • the above alarm processing method starting from the improvement of the serviceability of the fault management of the existing network, proposes a method for processing an alarm event that immediately generates a situation after the fault is recovered, and resets the activation time by setting the latest alarm.
  • the latest alarm recovery activation moment is determined. If the alarm is not generated again after the latest alarm recovery activation is activated, or the generated next alarm is not similar to the previous alarm, the previous alarm recovery event is reported. Therefore, the reporting of invalid alarm recovery events is effectively reduced, and the accuracy and serviceability of the alarms are improved.
  • next alarm can be processed as follows.
  • FIG. 4 is a structural diagram of an alarm processing apparatus according to an embodiment of the present invention, including:
  • the determining module 41 is configured to: after the previous alarm is restored, resume the activation of the daytime and the previous alarm according to the set latest alarm, and determine that the latest alarm of the previous alarm is resumed and activated;
  • the determining module 42 is configured to determine whether a similar alarm of the previous alarm is generated before the latest alarm is resumed, and the reporting module 43 is configured to: when the determining result of the determining module 42 is “No”, report The recovery event of the previous alarm.
  • the judgment result of the judgment module 42 is "NO", that is, the judgment module 42 determines that it is the latest. After the alarm is resumed, the alarm is not generated again or the subsequent alarm generated is not similar to the previous alarm.
  • the determining module 42 may include:
  • the parameter determination sub-module 421 is configured to set a filtering parameter, and determine an alarm parameter to be compared according to the set filtering parameter.
  • the alarm parameters to be compared include one or more of an alarm identifier, an alarm object, an alarm level, an alarm cause, and a specific problem.
  • the parameter comparison sub-module 422 is configured to compare whether the alarm parameters to be compared between the previous alarm and the subsequent alarm are the same when the subsequent alarm is generated;
  • the similarity alarm determination sub-module 423 is configured to determine that the previous alarm and the subsequent alarm are similar alarms when the parameter comparison sub-module 422 determines that the alarm parameters to be compared between the previous alarm and the subsequent alarm are the same.
  • the above alarm processing device processes the alarm event that immediately generates the situation after the fault is recovered, and restores the activation period by setting the latest alarm, and the determining module 4 1 determines the most The late alarm resumes the activation of the previous alarm. If the determination module 42 determines that the alarm is not generated again before the latest alarm is resumed, the subsequent alarm is not similar to the previous alarm, and the reporting module 43 reports the previous alarm. Resume the event. Therefore, the reporting of invalid alarm recovery events is effectively reduced, and the accuracy and serviceability of the alarms are improved.
  • FIG. 6 is a structural diagram of an alarm processing system according to an embodiment of the present invention, including:
  • the communication device 61 is configured to: after the previous alarm is restored, resume the activation of the daytime and the previous alarm according to the set latest alarm, and determine that the latest alarm of the previous alarm is restored to activate the engraving, if the most If the alarm is not activated, the alarm is not generated, and the previous alarm is reported.
  • the similar alarm that generated the previous alarm may be: No alarm is generated, or generated. The latter alarm is not similar to the previous alarm.
  • the communication device 61 may be implemented by the foregoing alarm processing device, and may include all or part of the modules of the foregoing alarm processing device.
  • the network management device 62 is configured to receive a recovery event of the previous alarm reported by the communication device 61.
  • the communication device 61 can be a base station
  • the network management device 62 can be an EMS (Element
  • the base station After the previous alarm is restored, the base station according to the settings The latest alarm recovery activates the daytime and the recovery of the previous alarm, and determines that the latest alarm of the previous alarm is restored to the active moment. If the latest alarm is resumed, the alarm is not generated again or before. The next alarm is not similar to the previous alarm.
  • the base station reports the recovery event of the previous alarm to the E MS to which the base station belongs. Further, the EMS can transmit the recovery event of the previous alarm to the NMS (Network Management System) through the northbound interface for the user to view.
  • NMS Network Management System
  • the communication device 61 may be a base station control device, and the base station control device includes an RNC (Radio Network Controller), a BSC (Base) Station Controller, Base Station Controller 62, Network Management Device 62 can be an EMS.
  • RNC Radio Network Controller
  • BSC Base Station Controller
  • Network Management Device 62 can be an EMS.
  • the base station control device resumes the recovery of the activation of the daytime and the previous alarm according to the set latest alarm, and determines that the latest alarm of the previous alarm is restored to activate the engraving, if the latest alarm is resumed and activated. After the arrival or the previous time, the similar alarm of the previous alarm is not generated again.
  • the base station control device reports the recovery event of the previous alarm to the EMS to which the base station control device belongs. Further, the EMS can transmit the recovery event of the previous alarm to the NMS through the northbound interface for the user to view.
  • the above alarm processing system processes the alarm event immediately after the fault is recovered, and the communication device 61 restores the activation period by setting the latest alarm, and determines the latest.
  • the alarm recovery activates the engraving. If the latest alarm resumes the activation enquiry, and the similar alarm of the previous alarm is not generated, the communication device 61 reports the recovery event of the previous alarm to the network management device 62. Therefore, the reporting of invalid alarm recovery events is effectively reduced, and the accuracy and serviceability of the alarms are improved.
  • the present invention can be implemented by hardware or by software plus a necessary general hardware platform.
  • the technical solution of the present invention may be embodied in the form of a software product, which may be stored in a non-volatile storage medium (which may be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), including several The instructions are for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform the methods described in various embodiments of the present invention.
  • modules in the apparatus in the embodiments may be distributed in the apparatus of the embodiment according to the description of the embodiments, or may be correspondingly changed in one or more apparatuses different from the embodiment.
  • the modules of the above embodiments may be combined into one module, or may be further split into a plurality of sub-modules.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Description

说明书
Title of Invention:告警处理方法、 装置和系统
[I] 本申请要求了 2008年 11月 3日提交的、 申请号为 200810172366.1、 发明名称为" 告警处理方法、 装置和系统"的中国申请的优先权, 其全部内容通过引用结合在 本申请中。
[2] 技术领域
[3] 本发明实施例涉及通信技术领域, 特别涉及一种告警处理方法、 装置和系统。
[4] 发明背景
[5] 故障管理在通信设备的日常维护中发挥着重要的作用, 直接决定了能否快速上 报、 定位、 恢复设备故障, 是可服务性中的关键一环。 在现网运行中, 由于环 境变化和设备自身老化等一系列原因, 有些故障产生后又立即恢复, 有些故障 恢复后又立即产生, 有吋还周期性反复, 故障产生后通信设备会向网管上报告 警产生事件, 故障恢复后通信设备会向网管上报告警恢复事件, 从而导致用户 在网管上看到大量的告警事件。 而故障产生后又立即恢复的情形下的告警事件 , 以及故障恢复后又立即产生的情形下的告警事件不需要用户进行处理, 这就 给日常的设备维护带来很大的困难, 严重影响了故障管理的可服务性。
[6] 现有技术提出了一种闪断告警过滤方法, 通过设置延吋, 对故障产生后又立即 恢复的情形下的告警事件进行处理。
[7] 在实现本发明的过程中, 发明人发现现有技术至少存在以下问题:
[8] 现有技术只能对故障产生后又立即恢复的情形下的告警事件进行处理, 不能对 故障恢复后又立即产生的情形下的告警事件进行处理, 从而导致上报了很多无 效的告警恢复事件。
[9] 发明内容
[10] 本发明实施例提供一种告警处理方法、 装置和系统, 以对故障恢复后又立即产 生的情形下的告警事件进行处理, 减少无效的告警恢复事件的上报。
[I I] 为达到上述目的, 本发明实施例一方面提供一种告警处理方法, 包括:
[12] 在前一次告警恢复之后, 根据设置的最迟告警恢复激活吋间和所述前一次告警 的恢复吋刻, 确定所述前一次告警的最迟告警恢复激活吋刻;
[13] 如果所述最迟告警恢复激活吋刻到来吋或之前, 没有产生前一次告警的相似告 警, 则上报所述前一次告警的恢复事件。
[14] 另一方面, 本发明实施例还提供一种告警处理装置, 包括:
[15] 确定模块, 用于在前一次告警恢复之后, 根据设置的最迟告警恢复激活吋间和 所述前一次告警的恢复吋刻, 确定所述前一次告警的最迟告警恢复激活吋刻;
[16] 判断模块, 用于判断在所述最迟告警恢复激活吋刻到来吋或之前, 是否产生前 一次告警的相似告警;
[17] 上报模块, 用于当所述判断模块的判断结果为否吋, 上报所述前一次告警的恢 复事件。
[18] 再一方面, 本发明实施例还提供一种告警处理系统, 包括:
[19] 通信设备, 用于在前一次告警恢复之后, 根据设置的最迟告警恢复激活吋间和 所述前一次告警的恢复吋刻, 确定所述前一次告警的最迟告警恢复激活吋刻, 如果所述最迟告警恢复激活吋刻到来吋或之前, 没有产生前一次告警的相似告 警, 则上报所述前一次告警的恢复事件;
[20] 网络管理设备, 用于接收所述通信设备上报的前一次告警的恢复事件。
[21] 与现有技术相比, 本发明实施例具有以下优点:
[22] 本发明实施例设置最迟告警恢复激活吋间, 在前一次告警恢复之后, 根据该最 迟告警恢复激活吋间和前一次告警的恢复吋刻, 确定前一次告警的最迟告警恢 复激活吋刻。 如果最迟告警恢复激活吋刻到来吋或之前, 没有产生前一次告警 的相似告警, 则上报前一次告警的恢复事件。 本发明实施例从提高现网故障管 理的可服务性出发, 提出了一种支持故障恢复后又立即产生故障场景的告警处 理方法, 有效地减少了无效告警恢复事件的上报, 提高了告警的准确性和可服 务性。
[23] 附图简要说明
[24] 图 1为本发明实施例一种告警处理方法的流程示意图;
[25] 图 2为本发明实施例在最迟告警恢复激活吋刻到来前, 再次产生了告警的示意 图; [26] 图 3为本发明实施例在最迟告警恢复激活吋刻到来前, 并没有产生告警的示意
[27] 图 4为本发明实施例一种告警处理装置的结构示意图;
[28] 图 5为本发明实施例另一种告警处理装置的结构示意图;
[29] 图 6为本发明实施例一种告警处理系统的结构示意图。
[30] 实施本发明的方式
[31] 本发明实施例提供一种告警处理方法, 对于初始化状态为产生的告警, 增设最 迟告警恢复激活吋间。 在前一次告警恢复之后, 以前一次告警的恢复吋刻为起 点, 顺延最迟告警恢复激活吋间后得到的吋刻, 即为最迟告警恢复激活吋刻。 如果在最迟告警恢复激活吋刻到来之前, 又再次产生前一次告警的相似告警, 则不上报前一次告警恢复事件和后一次告警产生事件; 如果在最迟告警恢复激 活吋刻到来之前, 没有产生前一次告警的相似告警, 即无告警产生或者产生的 后一次告警与前一次告警不是相似告警, 则上报前一次告警恢复事件, 更新告 警状态为恢复。
[32] 如图 1所示, 为本发明实施例一种告警处理方法的流程图, 具体包括:
[33] 步骤 S101 , 在前一次告警恢复之后, 根据设置的最迟告警恢复激活吋间和前一 次告警的恢复吋刻, 确定前一次告警的最迟告警恢复激活吋刻。
[34] 本发明实施例中, 设置最迟告警恢复激活吋间吋, 可以取经验值, 并可以结合 网上的告警数据进行动态调整。
[35] 在前一次告警恢复之后, 以前一次告警的恢复吋刻为起点, 顺延最迟告警恢复 激活吋间后得到的吋刻, 即为最迟告警恢复激活吋刻。
[36] 具体地, 在前一次告警恢复之后, 本发明实施例更新最迟告警恢复激活吋间窗 : 该最迟告警恢复激活吋间窗的下边界是前一次告警的恢复吋刻, 上边界是以 前一次告警的恢复吋刻为起点, 顺延最迟告警恢复激活吋间后得到的吋刻, 该 得到的吋刻为最迟告警恢复激活吋刻。 然后等待最迟告警恢复激活吋刻的到来
[37] 步骤 S102, 如果最迟告警恢复激活吋刻到来之前, 没有产生前一次告警的相似 告警, 则上报前一次告警的恢复事件。 [38] 所谓没有产生前一次告警的相似告警可以包括两种情况: 情况 1, 如果在最迟 告警恢复激活吋刻到来吋或之前, 没有再次产生告警; 或者, 情况 2, 产生了后 一次告警, 产生的后一次告警与前一次告警不是相似告警。 这吋, 可以确定上 述前一次告警已恢复, 上报前一次告警的恢复事件。
[39] 如果在最迟告警恢复激活吋刻到来吋或之前, 产生了后一次告警, 并且判断产 生的后一次告警和前一次告警为相似告警, 则确定前一次告警没有恢复, 不上 报前一次告警的恢复事件和后一次告警的产生事件。
[40] 其中, 判断产生的后一次告警和前一次告警为相似告警具体可以为:
[41] 设置过滤参数, 根据设置的过滤参数确定需要比较的告警参数。 其中, 该需要 比较的告警参数可以具体包括告警标识、 告警对象、 告警级别、 告警可能原因 和具体问题中的一种或几种;
[42] 如果前一次告警和后一次告警的需要比较的告警参数相同, 则确定前一次告警 和后一次告警为相似告警。
[43] 如图 2所示, 方块 21的左边线表示前一次告警的产生吋刻, 当前一次告警产生 吋, 在方块 23的左边线所示的吋刻上报告警产生事件, 这吋告警状态为产生。 方块 21的右边线表示前一次告警的恢复吋刻, 以前一次告警的恢复吋刻为起点 , 顺延最迟告警恢复激活吋间后得到的吋刻, 即为最迟告警恢复激活吋刻。 如 果在最迟告警恢复激活吋刻到来之前, 产生了后一次告警, 方块 22的左边线表 示后一次告警的产生吋刻, 并且后一次告警与前一次告警为相似告警, 则确定 前一次告警并没有恢复, 前一次告警恢复事件和后一次告警产生事件均不上报 , 告警状态保持不变。 方块 22的右边线表示后一次告警的恢复吋刻。
[44] 后续在某一次告警恢复之后, 如果以该次告警恢复吋刻确定的最迟告警恢复激 活吋刻到来之前, 并没有再次产生告警或者产生的后一次告警与前一次告警不 是相似告警, 则可以确定上述前一次告警恢复, 在方块 23的右边线所示的吋刻 上报告警恢复事件。
[45] 请继续参考图 3, 方块 31的左边线表示前一次告警的产生吋刻, 当前一次告警 产生吋, 在方块 32的左边线所示的吋刻上报告警产生事件。 方块 31的右边线表 示前一次告警的恢复吋刻, 以前一次告警的恢复吋刻为起点, 顺延最迟告警恢 复激活吋间后得到的吋刻, 即为最迟告警恢复激活吋刻。 如果在最迟告警恢复 激活吋刻到来吋或之前, 并没有产生后一次告警或者产生的后一次告警与前一 次告警不是相似告警, 则在方块 32的右边线所示的吋刻上报告警恢复事件, 更 新告警状态为恢复。
[46] 上述告警处理方法, 从提高现网故障管理的可服务性出发, 提出了一种对故障 恢复后又立即产生情形的告警事件进行处理的方法, 通过设置最迟告警恢复激 活吋间, 确定最迟告警恢复激活吋刻, 如果最迟告警恢复激活吋刻到来之前, 没有再次产生告警或者产生的后一次告警与前一次告警不是相似告警, 则上报 前一次告警的恢复事件。 从而有效地减少了无效的告警恢复事件的上报, 提高 了告警的准确性和可服务性。
[47] 另外, 当最迟告警恢复激活吋刻到来吋或之前, 如果产生了后一次告警, 但是 后一次告警与前一次告警不是相似告警, 则可以对该后一次告警进行如下处理
[48] (1) 如果在出现该后一次告警之前, 并没有出现过与该后一次告警相似的告 警, 或者先前出现过与该后一次告警相似的告警, 但是先前出现的与该后一次 告警相似的告警均确定已恢复, 则可以判断该后一次告警的持续吋间是否小于 指定的闪断门限 T, 如果小于 Τ则确定该后一次告警是无意义告警, 对该后一次 告警的产生和恢复都不进行上报; 否则确定该后一次告警是有意义的告警, 上 报后一次告警的产生事件。
[49] (2) 如果在出现该后一次告警之前, 出现过与该后一次告警相似的告警, 并 且先前出现的与该后一次告警相似的告警尚未恢复, 则可以釆用本发明实施例 提供的方法对该后一次告警进行处理。
[50] 如图 4所示, 为本发明实施例一种告警处理装置的结构图, 包括:
[51] 确定模块 41, 用于在前一次告警恢复之后, 根据设置的最迟告警恢复激活吋间 和前一次告警的恢复吋刻, 确定前一次告警的最迟告警恢复激活吋刻;
[52] 判断模块 42, 用于判断在最迟告警恢复激活吋刻到来之前, 是否产生前一次告 警的相似告警; 上报模块 43, 用于当判断模块 42的判断结果为 "否"吋, 上报前一 次告警的恢复事件。 判断模块 42的判断结果为 "否"即为判断模块 42确定在最迟告 警恢复激活吋刻到来吋或之前, 没有再次产生告警或者产生的后一次告警与前 一次告警不是相似告警。
[53] 本发明的另一实施例中, 如图 5所示, 该判断模块 42可以包括:
[54] 参数确定子模块 421, 用于设置过滤参数, 并根据设置的过滤参数确定需要比 较的告警参数。 其中, 需要比较的告警参数具体包括告警标识、 告警对象、 告 警级别、 告警可能原因和具体问题中的一种或几种;
[55] 参数比较子模块 422, 用于在产生了后一次告警的情况下, 比较前一次告警和 后一次告警的需要比较的告警参数是否相同;
[56] 相似告警确定子模块 423, 用于当参数比较子模块 422确定前一次告警和后一次 告警的需要比较的告警参数相同吋, 确定前一次告警和后一次告警为相似告警
[57] 上述告警处理装置, 从提高现网故障管理的可服务性出发, 对故障恢复后又立 即产生情形的告警事件进行处理, 通过设置最迟告警恢复激活吋间, 确定模块 4 1确定最迟告警恢复激活吋刻, 如果判断模块 42判断在最迟告警恢复激活吋刻到 来之前, 没有再次产生告警或者产生的后一次告警与前一次告警不是相似告警 , 则上报模块 43上报前一次告警的恢复事件。 从而有效地减少了无效的告警恢 复事件的上报, 提高了告警的准确性和可服务性。
[58] 如图 6所示, 为本发明实施例提供的一种告警处理系统的结构图, 包括:
[59] 通信设备 61, 用于在前一次告警恢复之后, 根据设置的最迟告警恢复激活吋间 和前一次告警的恢复吋刻, 确定前一次告警的最迟告警恢复激活吋刻, 如果最 迟告警恢复激活吋刻到来吋或之前, 没有产生前一次告警的相似告警, 则上报 前一次告警的恢复事件; 其中, 没有产生前一次告警的相似告警可以为: 没有 产生告警, 或者, 产生的后一次告警与前一次告警不是相似告警。 其中, 通信 设备 61可以由上述告警处理装置实现, 可以包括上述告警处理装置中的全部或 部分模块。
[60] 网络管理设备 62, 用于接收通信设备 61上报的前一次告警的恢复事件。
其中, 通信设备 61可以为基站, 网络管理设备 62可以为 EMS (Element
Management Systems , 网元管理系统) 。 在前一次告警恢复之后, 基站根据设置 的最迟告警恢复激活吋间和前一次告警的恢复吋刻, 确定前一次告警的最迟告 警恢复激活吋刻, 如果最迟告警恢复激活吋刻到来吋或之前, 没有再次产生告 警或者产生的后一次告警与前一次告警不是相似告警, 则基站向该基站所属的 E MS上报前一次告警的恢复事件。 进一步地, EMS可以将前一次告警的恢复事件 通过北向接口传递给 NMS (Network Management Systems , 网元管理系统) , 以 供用户査看。
[62] 另外, 在 3G (3rd Generation, 第三代通信系统) 网络中, 该通信设备 61可以为 基站控制设备, 该基站控制设备包括 RNC (Radio Network Controller, 无线网络 控制器) 、 BSC (Base Station Controller, 基站控制器) , 网络管理设备 62可以 为 EMS。 在前一次告警恢复之后, 基站控制设备根据设置的最迟告警恢复激活 吋间和前一次告警的恢复吋刻, 确定前一次告警的最迟告警恢复激活吋刻, 如 果最迟告警恢复激活吋刻到来吋或之前, 没有再次产生前一次告警的相似告警 , 贝 I」基站控制设备向该基站控制设备所属的 EMS上报前一次告警的恢复事件。 进一步地, EMS可以将前一次告警的恢复事件通过北向接口传递给 NMS, 以供 用户査看。
[63] 上述告警处理系统, 从提高现网故障管理的可服务性出发, 对故障恢复后又立 即产生情形的告警事件进行处理, 通信设备 61通过设置最迟告警恢复激活吋间 , 确定最迟告警恢复激活吋刻, 如果最迟告警恢复激活吋刻到来吋, 没有产生 前一次告警的相似告警, 则通信设备 61向网络管理设备 62上报前一次告警的恢 复事件。 从而有效地减少了无效的告警恢复事件的上报, 提高了告警的准确性 和可服务性。
[64] 通过以上的实施方式的描述, 本领域的技术人员可以清楚地了解到本发明可以 通过硬件实现, 也可以借助软件加必要的通用硬件平台的方式来实现。 基于这 样的理解, 本发明的技术方案可以以软件产品的形式体现出来, 该软件产品可 以存储在一个非易失性存储介质 (可以是 CD-ROM, U盘, 移动硬盘等) 中, 包 括若干指令用以使得一台计算机设备 (可以是个人计算机, 服务器, 或者网络 设备等) 执行本发明各个实施例所述的方法。
本领域技术人员可以理解附图只是一个优选实施例的示意图, 附图中的模块或 流程并不一定是实施本发明所必须的。
[66] 本领域技术人员可以理解实施例中的装置中的模块可以按照实施例描述进行分 布于实施例的装置中, 也可以进行相应变化位于不同于本实施例的一个或多个 装置中。 上述实施例的模块可以合并为一个模块, 也可以进一步拆分成多个子 模块。
[67] 上述本发明实施例序号仅仅为了描述, 不代表实施例的优劣。

Claims

权利要求书
一种告警处理方法, 其特征在于, 包括:
在前一次告警恢复之后, 根据设置的最迟告警恢复激活吋间和所 述前一次告警的恢复吋刻, 确定所述前一次告警的最迟告警恢复 激活吋刻;
如果所述最迟告警恢复激活吋刻到来吋或之前, 没有产生前一次 告警的相似告警, 则上报所述前一次告警的恢复事件。
根据权利要求 1所述的方法, 其特征在于, 所述没有产生前一次告 警的相似告警包括:
没有再次产生告警, 或
产生了后一次告警, 但后一次告警和前一次告警为非相似告警。 根据权利要求 1或 2所述的方法, 其特征在于, 还包括: 如果在所述最迟告警恢复激活吋刻到来吋或之前, 产生了后一次 告警, 并且判断产生的后一次告警和前一次告警为相似告警, 则 确定所述前一次告警没有恢复, 不上报所述前一次告警的恢复事 件和所述后一次告警的产生事件。
根据权利要求 3所述的方法, 其特征在于, 还包括: 所述判断产生 的后一次告警和前一次告警为相似告警包括:
设置过滤参数, 根据设置的过滤参数确定需要比较的告警参数; 如果所述前一次告警和所述后一次告警的需要比较的告警参数相 同, 则确定前一次告警和后一次告警为相似告警。
根据权利要求 4所述的方法, 其特征在于, 所述需要比较的告警参 数包括告警标识、 告警对象、 告警级别、 告警可能原因和具体问 题中的一种或几种。
一种告警处理装置, 其特征在于, 包括:
确定模块, 用于在前一次告警恢复之后, 根据设置的最迟告警恢 复激活吋间和所述前一次告警的恢复吋刻, 确定所述前一次告警 的最迟告警恢复激活吋刻; 判断模块, 用于判断在所述最迟告警恢复激活吋刻到来吋或之前 , 是否产生前一次告警的相似告警;
上报模块, 用于当所述判断模块的判断结果为否吋, 上报所述前 一次告警的恢复事件。
[Claim 7] 根据权利要求 6所述的装置, 其特征在于, 所述判断模块包括: 参数确定子模块, 用于设置过滤参数, 并根据设置的过滤参数确 定需要比较的告警参数;
参数比较子模块, 用于在产生了后一次告警的情况下, 比较所述 前一次告警和所述后一次告警的需要比较的告警参数是否相同; 相似告警确定子模块, 用于当所述参数比较子模块确定所述前一 次告警和所述后一次告警的需要比较的告警参数相同吋, 确定所 述前一次告警和所述后一次告警为相似告警。
[Claim S] 一种告警处理系统, 其特征在于, 包括:
通信设备, 用于在前一次告警恢复之后, 根据设置的最迟告警恢 复激活吋间和所述前一次告警的恢复吋刻, 确定所述前一次告警 的最迟告警恢复激活吋刻, 如果所述最迟告警恢复激活吋刻到来 吋或之前, 没有产生前一次告警的相似告警, 则上报所述前一次 告警的恢复事件;
网络管理设备, 用于接收所述通信设备上报的前一次告警的恢复 事件。
[Claim 9] 根据权利要求 8所述的系统, 其特征在于, 所述通信设备具体为基 站, 所述网络管理设备具体为网元管理系统 EMS。
[Claim 10] 根据权利要求 8所述的系统, 其特征在于, 所述通信设备具体为基 站控制设备, 所述网络管理设备具体为网元管理系统 EMS。
PCT/CN2009/074562 2008-11-03 2009-10-22 告警处理方法、装置和系统 WO2010060327A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CNA2008101723661A CN101389112A (zh) 2008-11-03 2008-11-03 告警处理方法、装置和系统
CN200810172366.1 2008-11-03

Publications (1)

Publication Number Publication Date
WO2010060327A1 true WO2010060327A1 (zh) 2010-06-03

Family

ID=40478226

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/074562 WO2010060327A1 (zh) 2008-11-03 2009-10-22 告警处理方法、装置和系统

Country Status (2)

Country Link
CN (1) CN101389112A (zh)
WO (1) WO2010060327A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103052105A (zh) * 2012-12-07 2013-04-17 大唐移动通信设备有限公司 一种基站告警的处理方法和装置
CN105659530A (zh) * 2014-09-29 2016-06-08 华为技术有限公司 一种告警处理的方法和设备

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101389112A (zh) * 2008-11-03 2009-03-18 华为技术有限公司 告警处理方法、装置和系统
CN101808023A (zh) * 2010-05-06 2010-08-18 瑞斯康达科技发展股份有限公司 一种网络监测系统及网络监测方法
CN104486106A (zh) * 2014-12-04 2015-04-01 珠海金山网络游戏科技有限公司 一种分级告警服务系统
CN106411557A (zh) * 2015-08-03 2017-02-15 中兴通讯股份有限公司 告警的处理方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1179245A1 (en) * 1999-05-21 2002-02-13 Telefonaktiebolaget LM Ericsson (publ) Method and apparatus for displaying information in a fault management system
CN1503508A (zh) * 2002-11-20 2004-06-09 华为技术有限公司 网管系统的故障相关性分析及实现方法
CN1967474A (zh) * 2006-04-21 2007-05-23 华为技术有限公司 一种内存保护方法及其系统
CN101389112A (zh) * 2008-11-03 2009-03-18 华为技术有限公司 告警处理方法、装置和系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1179245A1 (en) * 1999-05-21 2002-02-13 Telefonaktiebolaget LM Ericsson (publ) Method and apparatus for displaying information in a fault management system
CN1503508A (zh) * 2002-11-20 2004-06-09 华为技术有限公司 网管系统的故障相关性分析及实现方法
CN1967474A (zh) * 2006-04-21 2007-05-23 华为技术有限公司 一种内存保护方法及其系统
CN101389112A (zh) * 2008-11-03 2009-03-18 华为技术有限公司 告警处理方法、装置和系统

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103052105A (zh) * 2012-12-07 2013-04-17 大唐移动通信设备有限公司 一种基站告警的处理方法和装置
CN105659530A (zh) * 2014-09-29 2016-06-08 华为技术有限公司 一种告警处理的方法和设备
CN105659530B (zh) * 2014-09-29 2019-04-12 华为技术有限公司 一种告警处理的方法和设备

Also Published As

Publication number Publication date
CN101389112A (zh) 2009-03-18

Similar Documents

Publication Publication Date Title
WO2010060327A1 (zh) 告警处理方法、装置和系统
EP3974986A1 (en) Nf service consumer restart detection using direct signaling between nfs
CN1747438A (zh) 一种保证以太网自动保护系统环正常工作的方法
CN118449838A (zh) 自动故障恢复系统、控制设备、程序创建设备及计算机可读存储介质
US10740142B2 (en) System and method for obtaining task trigger information by a baseband processor of an intelligent device and triggering a hosting task
CN1788475A (zh) 网络攻击缓解方法,网络攻击缓解设备,和网络攻击缓解程序
WO2015100962A1 (zh) 一种基站设备自愈的实现方法及装置
CN103475696A (zh) 云计算集群服务器状态监控系统和方法
WO2014036724A1 (zh) 一种操作维护通道的故障恢复方法和网络管理终端
US20170317910A1 (en) Heartbeat period setting method, and terminal
WO2011150699A1 (zh) 流媒体服务器的资源控制方法及流媒体服务器
CN106557033A (zh) 一种智能家居设备控制方法、装置及系统
CN101076174A (zh) 告警风暴的处理方法
CN105469772A (zh) 一种远程kvm控制方法、远程kvm控制端及系统
CN101854253B (zh) 一种自动恢复监控和存储的方法及其监控系统
CN109451560B (zh) 一种基于终端移动速度的小区搜索间隔的优化方法
WO2013097503A1 (zh) 拥塞控制方法和设备
WO2013037314A1 (zh) 用于数据处理中心容灾备份的系统及方法
WO2014107836A1 (zh) 网络告警的方法和装置
EP2922331B1 (en) Method and system for performing dual-homing automatic switching decision according to the number of registered gateways
CN103414591B (zh) 一种端口故障恢复时的快速收敛方法和系统
CN1913493A (zh) 避免路由设备频繁切换状态的方法和一种路由设备
CN117215829A (zh) 政务服务数据库系统及其备份方法、装置、存储介质
EP2899934A1 (en) Traffic grooming method and system
AU2003259114A1 (en) Alarm recovery method and system

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09828588

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09828588

Country of ref document: EP

Kind code of ref document: A1