WO2014067439A1 - Method, system and device for monitorring data - Google Patents

Method, system and device for monitorring data Download PDF

Info

Publication number
WO2014067439A1
WO2014067439A1 PCT/CN2013/086100 CN2013086100W WO2014067439A1 WO 2014067439 A1 WO2014067439 A1 WO 2014067439A1 CN 2013086100 W CN2013086100 W CN 2013086100W WO 2014067439 A1 WO2014067439 A1 WO 2014067439A1
Authority
WO
WIPO (PCT)
Prior art keywords
service
client
server
condition
running data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2013/086100
Other languages
French (fr)
Inventor
Wenfeng YU
Yeshang TANG
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tencent Technology Shenzhen Co Ltd
Original Assignee
Tencent Technology Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tencent Technology Shenzhen Co Ltd filed Critical Tencent Technology Shenzhen Co Ltd
Publication of WO2014067439A1 publication Critical patent/WO2014067439A1/en
Priority to US14/698,301 priority Critical patent/US10200506B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/50Network service management, e.g. ensuring proper service fulfilment according to agreements
    • H04L41/5003Managing SLA; Interaction between SLA and QoS
    • H04L41/5009Determining service level performance parameters or violations of service level contracts, e.g. violations of agreed response time or mean time between failures [MTBF]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/10Active monitoring, e.g. heartbeat, ping or trace-route
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network

Definitions

  • the present disclosure relates to an information technology field, and more particularly, to a method, system and device for monitoring data.
  • data running on a monitored device is collected through a data collecting process installed in a peripheral of the monitored device.
  • the data running on the monitored device is recorded in various ways.
  • the peripheral can report the collected data to a monitoring device through a network.
  • the data is displayed in a monitoring interface in the monitoring device.
  • a method, system and device for monitoring data are provided according to examples of the present disclosure to simplify analysis for monitoring data.
  • a method for monitoring data is provided according to an example of the present disclosure, which includes: receiving, by a server, service running data of a service transmitted from a client; acquiring, by the server, a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs; determining, by the server, whether the first condition is satisfied according to the received service running data and the service parameter value; and providing, by the server, an alarm indicator for the service to the client when it is determined that the first condition is satisfied.
  • a server includes: a processor for executing instructions stored in a memory, the instructions comprising: a service running data receiving instruction, to receive service running data of a service transmitted from a client; a strategy acquiring instruction, to acquire a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs; and an alarming instruction, to determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm indicator for the service to the client when it is determined that the first condition is satisfied.
  • a system includes at least one client and a server: each client, to collect service running data of a service running on the client, transmit the service running data to a server; the server, to receive service running data of a service transmitted from the client, acquire a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs, determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm indicator for the service to the client when it is determined that the first condition is satisfied.
  • a system for monitoring data includes a server and at least one client, wherein the client includes: a service running data collecting module, to collect service running data of a service running on the client; and a service running data transmitting module, to transmit the service running data to a server; the server includes: a service running data receiving module, to receive service running data of a service transmitted from a client; a strategy acquiring module, to acquire a first abnormal strategy corresponding to the service; and an alarming module, to provide an alarm for the service when the first abnormal strategy is matched according to the service running data.
  • FIG. 1 is a schematic diagram illustrating a structure of a system for monitoring data in accordance with an example of the present disclosure
  • FIG. 2 is a flowchart illustrating a method for monitoring data in accordance with an example of the present disclosure
  • FIG. 3 is a flowchart illustrating another method for monitoring data in accordance with an example of the present disclosure
  • FIG. 4 is a flowchart illustrating another method for monitoring data in accordance with an example of the present disclosure
  • FIG. 5 is a flowchart illustrating another method for monitoring data in accordance with an example of the present disclosure
  • FIG. 6 is a schematic diagram illustrating a structure of a server in accordance with an example of the present disclosure
  • FIG. 7 is a schematic diagram illustrating another structure of a server in accordance with an example of the present disclosure
  • FIG. 8 is a schematic diagram illustrating another structure of a server in accordance with an example of the present disclosure
  • FIG. 9 is a schematic diagram illustrating a structure of a client in accordance with an example of the present disclosure
  • FIG. 10 is a schematic diagram illustrating another structure of a client in accordance with an example of the present disclosure.
  • FIG. 11 is a schematic diagram illustrating another structure of a server in accordance with an example of the present disclosure.
  • FIG. 12 is a schematic diagram illustrating another structure of a server in accordance with an example of the present disclosure.
  • FIG. 13 is a schematic diagram illustrating another structure of a client in accordance with an example of the present disclosure
  • FIG. 14 is a schematic diagram illustrating another structure of a client in accordance with an example of the present disclosure.
  • a method for monitoring data is provided according to an example of the present disclosure, which is applied to a system for monitoring data as shown in FIG. 1.
  • the system includes at least one client and a server connected with the at least one client.
  • the at least one client is the monitored device that can be a computing device such as a mobile phone, a smartphone, a laptop, a tablet PC, a POS machine and so on.
  • a computing device such as a mobile phone, a smartphone, a laptop, a tablet PC, a POS machine and so on.
  • At least one service can run in a client. That is, a client can include at least one service systems, such as an instant messaging service system and a service system for downloading files and so on.
  • the server can monitor service running data of the at least one service running on the client.
  • a server may monitor service running data of a service running on a client as follows.
  • the server receives service running data of a service running a client, wherein the service running data of the service running on the client is transmitted from the client.
  • the service data transmitted by the client may indicate a detail condition of running the service on the client.
  • the service running data may include a service identifier that uniquely identifies the service, and may also include service performance data acquired during the service's running, e.g., amount of data that is downloaded from a network and processed by a file downloading system in the client, amount of scanned data, data scanning performance and so on.
  • the service performance data in the service running data is collected by the client according to a preset service collection frequency.
  • the service collection frequency may be preset in the client according to a practical requirement.
  • the client may collect the service performance data such as data scanning performance once every 100s.
  • Service collection frequencies preset for different services in the client may be the same or different from each other.
  • the client may collect the service performance data of different services respectively according to different service collection frequencies.
  • the server acquires a first abnormal strategy corresponding to the service.
  • the first abnormal strategy includes a condition that includes a service parameter value when an abnormality of running the service on the client occurs, e.g., amount of service data is larger than the service parameter value. When the abnormality of running the service on the client occurs, the condition including is satisfied.
  • the server can store the first abnormal strategy corresponding to the service. Specifically, a corresponding relation between the service identifier and the first abnormal strategy is stored. For example, for an instant messaging service running on the client, the first abnormal strategy may be that a task requirement speed is lower than or equal to zero.
  • the server may search corresponding relations stored in the server according to the service running data reported by the client for the corresponding relation including the service identifier of the service to acquire the first abnormal strategy corresponding to the service.
  • the server determines whether the service running data received at block 101 matches the first abnormal strategy of the service corresponding to the service running data acquired at block 102, i.e., determines whether the service running data satisfies the condition included in the first abnormal strategy. If the service running data matches the first abnormal strategy, the service running data indicates that an abnormality occurs when the service runs on the client, and block 104 is performed. If the service running data does not match the first abnormal strategy, the server may not provide an alarm.
  • the server provides an alarm for the service corresponding to the matched service running data, e.g., buzzing or popping-up a user interface to provide the alarm through the user interface.
  • the server provides an alarm indicator for the service to the client.
  • a server in a system for monitoring data may receive service running data of at least one service, and acquires a first abnormal strategy corresponding to each service. If service running data of a service matches a first abnormal strategy of the service corresponding to the service running data, the server provides an alarm for the service corresponding to the service running data.
  • the server can determine for which service running on the client the abnormality occurs and an alarm is provided.
  • the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis.
  • the server may not only monitor data corresponding to the service running on the client according to blocks 101-103, but also monitor data based on a device, i.e. a client.
  • the first abnormal strategy acquired at block 102 may not only include the condition including the service parameter value when an abnormality of running the service on the client occurs, e.g., amount of downloaded data is larger than or equal to a preset downloading amount, but also include a condition including a device parameter value of the client, i.e., an hardware parameter value of the client, such as CPU occupancy rate and so on.
  • the device parameter value may not indicate that abnormality of hardware in the client occurs.
  • both the condition including the service parameter value and the condition including the device parameter value are satisfied.
  • blocks 101-104 but also block 105 is performed in the server.
  • block 103 it is determined whether the service running data matches the first abnormal strategy, i.e., the service running data satisfies the condition including the service parameter value in the first abnormal strategy. If the service running data matches the first abnormal strategy, block 106 is performed.
  • the server receives the device running data transmitted from the client, wherein the device running data refers to running data of the hardware in the device i.e., the client, e.g., data related with a CPU, a memory, a network device, and a disk.
  • the client may collect not only service running data of each service running on the client, but also the device running data of the client.
  • the client may collect the device running data according to a preset device collection frequency.
  • the device collection frequencies preset in various clients in the data monitoring system may be the same or different from each other. For one client, the preset device collection frequency and the preset service collection frequency may be also the same or different from each other.
  • the server determines whether the device running data received at block 105 matches the first abnormal strategy, i.e., determining whether the received device running data satisfies the condition including a device parameter value of the client in the first abnormal strategy. If the device running data matches the first abnormal strategy, the server provides an alarm for the service corresponding to the service running data matched at block 104. If the device running data does not match the first abnormal strategy, the server does not provide an alarm. That is, if both the device running data of the client and the service running data corresponding to the service match the first abnormal strategy, the server provides an alarm for the service. Thus, when providing an alarm for the service, the server may consider factors of both the service running on the client and the client. The server provides an alarm only when both the machine running data and the service running data respectively satisfy corresponding conditions in the first abnormal strategies.
  • Block 105 and blocks 101-103 there is no absolute order between block 105 and blocks 101-103. There is also no absolute order between block 106 and block 103. Block 105 and blocks 101-103 can be performed at the same time or in order. Also, Block 106 and block 103 can be performed at the same time or in order. The method as shown in FIG. 3 is only a concrete implementation way.
  • the server may not only monitor service running data of the service running on the client and provide an alarm for the service according to blocks 101-103, but also monitor data of the device and provide an alarm for the device i.e., the client. As shown in FIG. 4, the server can perform not only blocks 101-104, but also blocks 107-109.
  • the server receives the device running data transmitted from at least one client, wherein the device running data refers to running data of the hardware in the client, e.g., data related with a CPU, a memory, a network device, and a disk.
  • the client may collect not only service running data of each service running on the client, but also the device running data of the client.
  • the client may collect the device running data according to a preset device collection frequency.
  • the device collection frequencies preset in various clients in the data monitoring system may be the same or different from each other. For one client, the preset device collection frequency and the preset service collection frequency may be also the same or different from each other.
  • the server determines whether the device running data received in block 107 matches a second abnormal strategy.
  • the second abnormal strategy may include the device parameter value when an abnormality occurs in the client, e.g., the CPU occupancy rate value and the temperature value. When the abnormality of the client on the client occurs, the condition including the device parameter value is satisfied.
  • the server determines whether the device running data received in block 107 satisfies a condition including a device parameter value in the second abnormal strategy. If the device running data matches the second abnormal strategy, block 109 is performed. If the device running data does not match the second abnormal strategy, the server may not provide an alarm. Second abnormal strategies for various clients may be the same or different from each other.
  • the server provides an alarm for the client corresponding to the matched device running data.
  • the server may manage the monitored client.
  • the server may store a list of monitored clients.
  • a network address i.e. IP
  • a client state including abnormal or normal
  • a state of a service running on each monitored client may also be stored in the list, which includes an abnormal state or a normal state.
  • FIG. 4 only illustrates an exemplary implementation way.
  • the first abnormal strategy and the second abnormal strategy indicate different abnormal strategies, but not indicate order relationship of abnormal strategies.
  • both the first abnormal strategy corresponding to the service acquired at block 102 and the second abnormal strategy corresponding to the client acquired at block 108 may be preset in the server by a user according to requirements.
  • the server may acquire first configuration information of the first abnormal strategy corresponding to the service and reconfigure the first abnormal strategy corresponding to the service stored in the server according to the acquired first configuration information.
  • the server may acquire second configuration information of the second abnormal strategy corresponding to the client and reconfigure the second abnormal strategy according to the acquired second configuration information.
  • the first configuration information and the second configuration information may be stored in a script.
  • the server may receive the first configuration information and second configuration information inputted by other devices, or inputted by the user from a user interface.
  • the server can provide an alarm for the abnormal service running on the client, and can also provide an alarm for the client in which the abnormality of the hardware occurs.
  • the server may acquire a recovering command for the service corresponding to the matched service running data, and transmit the recovering command to the client reporting the service running data.
  • the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation such as restarting a service system.
  • the recovering command may be acquired according to the abnormal service. For example, for the abnormal service in a network downloading service system, the service may generate the recovering command to indicate that the client restarts the network downloading service system.
  • the server may acquire a recovering command for the client corresponding to the matched device running data, and transmit the recovering command to the client corresponding to the device running data.
  • the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation such as restarting the client.
  • the recovering command may be acquired according to the specific client. For example, if the abnormality occurs in client 1, the service may generate the recovering command to indicate restarting the client 1.
  • the abnormal client or the client corresponding to the abnormal service is adjusted properly, to make the client recovered to a normal state.
  • a method for monitoring data is provided according to an example of the present disclosure, which applies to a system for monitoring data as shown in FIG. 1. As shown in FIG. 5, the method includes procedures as follows.
  • service running date of at least one service running on the client is collected.
  • At least one service runs on the client.
  • the service running data of a service can indicate a specific condition of running the service.
  • the service running data may include a service identifier that identifies the service uniquely, and the performance data acquired during a process of running the service, e.g., amount of data that is downloaded from a network and processed by a file downloading system in the client, amount of scanned data, scanning performance.
  • the service performance data in the service running data is collected by the client according to a preset service collection frequency.
  • the service collection frequency may be preset in the client according to a practical requirement.
  • the client may collect the service performance data such as data scanning performance once every 100s.
  • Service collection frequencies preset for different services by the client may be same or different.
  • the client may collect the service performance data of different services according to different service collection frequencies.
  • the collected service running data corresponding to the at least one service is transmitted to the server, so that when the service running data matches a first abnormal strategy of the service corresponding to the service running data, the server provides an alarm for the service corresponding to the matched service running data.
  • the method for monitoring data performed by the server is shown as FIG. 2, which is not described repeatedly herein. It can be seen from the above that in a method for monitoring data according to an example of the present disclosure, in a system for monitoring data, a client collects service running data corresponding to at least one service, transmit the collected service running data to the server so that when the service running data matches a first abnormal strategy of the service corresponding to the service running data, the server provides an alarm for the service corresponding to the matched service running data.
  • the server can determine for which service running on the client the abnormality occurs to provide an alarm.
  • the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of a monitoring system, so as to simplify data analysis.
  • the client collects the service running data and transmits the service running data to the server, wherein the data monitoring is based on the service.
  • the client not only performs blocks 201 and 202, but also monitors data based on a device.
  • the client may collect device running data, i.e., a hardware parameter of the client, such as CPU occupancy rate and so on.
  • the collected device running data is transmitted to the server.
  • the server determines that the device running data matches a second abnormal strategy, the server provides an alarm for the client corresponding to the matched device running data.
  • the server may provide an alarm for the abnormal service according to a method for monitoring data as shown in FIG. 3.
  • the client may collect the device running data according to a preset device collection frequency.
  • Device collection frequencies preset in various clients in the system for monitoring data may be same or different.
  • the preset device collection frequency and the preset service collection frequency may be also same or different.
  • the client may not only perform above blocks 201 and 202, but also receive a recovering command transmitted by the server.
  • the recovering command is acquired by the server according to the service corresponding to the service running data matching the first abnormal strategy or the client corresponding to the machine running data matching the second abnormal strategy. For example, if the abnormality in a network downloading service system occurs, the server may generate the recovering command to indicate that the client restarts the network downloading service system. If the abnormality occurs in client 1, the service may generate the recovering command to indicate restarting the client 1.
  • the abnormal client or the client corresponding to the abnormal service is adjusted properly, to make the client recovered to a normal state. Communication between the client and the server may be based on such as User Datagram Protocol (UDP) and so on.
  • UDP User Datagram Protocol
  • a method for monitoring data according to an example of the present disclosure is as shown in FIG. 6, which applies to a system for monitoring data as shown in FIG. 1.
  • the server may include an intercepting proceeding, a monitoring proceeding, a sharing memory, an alarming module and a configuring module.
  • the intercepting proceeding in the server may intercept service running data and device running data reported by a client, and store the service running data and the device running data in the sharing memory.
  • the intercepting proceeding may further feed a response back to the data reported by the client.
  • the intercepting proceeding may further intercept a first abnormal strategy and a second abnormal strategy configured by the configuring module, and store the first abnormal strategy and the second abnormal strategy into the sharing memory.
  • the service running data and the device running data of the client may be as shown in FIG. 1. In FIG. 1, CPU overload, HANDLE and memory are included in the device running data. Other data is included in the service running data.
  • a format of a string is that the string that does not end with zero is started with a uintl6_t to represent the number of characters in the string, and the string follows the uintl6_t.
  • "char" represents integer data. For data of sample scanned unsuccessful, a unique identity code of the sample md5 is added on basis of a scanning result. For data of sample scanned in a long time, the unique identity code of the sample md5 and a scanning time (in seconds) are added on basis of the scanning result.
  • ucDataCmd is a primary command, which indicates a kind of commands to be performed.
  • ucDataSubcmd is a secondary command, which indicates a sub-command in the kind of the commands.
  • the intercepting proceeding in the server may intercept the service running data and the device running data reported by the client, and store the service running data and the device running data into the sharing memory.
  • the monitoring proceeding may read the service running data and the device running data from the sharing memory, and read the first abnormal strategy and the second abnormal strategy from the sharing memory, and monitor data according to the processes as shown in FIG. 2 and FIG. 4, which is not described repeatedly herein.
  • the monitoring proceeding may control the alarming module to provide an alarm for the service and transmit a recovering command corresponding to the service to the client. If the client corresponding to the device running data is to be alarmed, the monitoring proceeding may control the alarming module to provide an alarm for the client and transmit a recovering command corresponding to the client to the client.
  • FIG. 7 is a schematic diagram illustrating a structure of a server according to an example of the present disclosure.
  • the server includes: a service running data receiving module 10, to receive service running data of a service transmitted from a client, wherein at least one service runs on the client; a strategy acquiring module 11, to acquire a first abnormal strategy corresponding to the service; and an alarming module 12, to determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm for the service when the service running data received by the service running data receiving module 10 matches the first abnormal strategy acquired by the strategy acquiring module 11.
  • the server provides an alarm indicator for the service to the client.
  • the service running data receiving module 10 may receive service running data of a service transmitted from a client.
  • the strategy acquiring module 11 may acquire a first abnormal strategy corresponding to the service.
  • the alarming module 12 may determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm for the service when the service running data received by the service running data receiving module 10 matches the first abnormal strategy acquired by the strategy acquiring module 11.
  • the server can determine for which service running on the client the abnormality occurs and an alarm is provided.
  • the server not only includes the service running data receiving module 10, the strategy acquiring module 11 and the alarming module 12, but also includes a device running data receiving module 13, a configuration module 14 and a command transmitting module 15: the device running data receiving module 13, to receive device running data of the client transmitted by the client; the configuration module 14, to acquire first configuration information corresponding to the service, reconfigure the first abnormal strategy according to the first configuration information; the configuration module 14, further to acquire second configuration information corresponding to the service, reconfigure a second abnormal strategy according to the second configuration information; the command transmitting module 15, to transmit a recovering command to the client, wherein the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation indicated by the recovering operation indication.
  • the configuration module 14 may configure the first abnormal strategy and/or the second abnormal strategy stored in the server.
  • the strategy acquiring module 11 may acquire the first abnormal strategy after the first abnormal strategy is configured by the configuration module 14.
  • the alarming module 12 may determine whether the second condition is satisfied according to the received device running data and the device parameter value to consider both the service running on the client and the hardware of the client to provide an alarm for the service.
  • the alarming module 12 may provide an alarm for the service.
  • the process of providing an alarm for the service is the same as that in an example corresponding to FIG. 3.
  • the alarming module 12 may provide an alarm for the client corresponding to the client.
  • the process of providing an alarm for the client is the same as that in an example corresponding to FIG. 4.
  • the command transmitting module 15 may acquire the recovering command according to the service or the client, and transmit the recovering command to the client, wherein the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation indicated by the recovering command indication.
  • the command transmitting module 15 may generate the recovering command that indicates that the client restarts the network downloading service system.
  • the command transmitting module 12 may generate a recovering command indicating restarting the client 1.
  • a server may further include a monitoring management module that is to manage the monitored client.
  • the monitoring management module may store a list of monitored clients.
  • a network address (i.e. IP) and a client state (including abnormal or normal) may be stored in the list for each monitored client.
  • a state of a service running on each monitored client may also be stored in the list, which includes an abnormal state or a normal state.
  • a client is provided according to an example of the present disclosure.
  • the client includes a service running data collecting module 20 and a service running data transmitting module 21.
  • the service running data collecting module 20 is to collect service running data of a service running on the client.
  • the service running data collecting module 20 is to collect the service running data of the service according to a service collection frequency preset in the client. Service collection frequencies preset in the client for different services may be same or different.
  • the service running data transmitting module 21 is to transmit the service running data collected by the service running data collecting module 20 to a server, so that the server provides an alarm for a service corresponding to the service running data when the server determines that the service running data matches a first abnormal strategy.
  • the service running data collecting module 20 collects service running data of a service running on the client.
  • the service running data transmitting module 21 transmits the service running data to a server, so that the server provides an alarm for the service corresponding to the service running data when the server determines that the service running data matches the first abnormal strategy.
  • the server can determine for which service running on the client the abnormality occurs and an alarm is provided.
  • the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis.
  • the client not only includes a service running data collecting module 20 and a service running data transmitting module 21 as shown in FIG. 9, but also includes a device running data collecting module 22, a device running data transmitting module 23 and a command performing module 24.
  • the device running data collecting module 22 is to collect device running data of the client.
  • the device running data collecting module 22 is to collect the device running data of the client according to a device collection frequency preset in the client. Device collection frequencies preset in different clients may be same or different.
  • the device running data transmitting module 23 is to transmit the device running data collected by the device running data collecting module 22 to the server, so that the server provides an alarm for the client corresponding to the device running data when the server determines that the device running data matches a second abnormal strategy.
  • the command performing module 24 is to receive a recovering command corresponding to the service transmitted from the server, wherein the recovering command carries a recovering operation indication, perform a recovering operation indicated by the recovering operation indication.
  • a system for monitoring system is provided according to an example of the present disclosure.
  • the system includes a server and at least one client, wherein each client includes at least one service system and a service runs on a service system.
  • the client is to collect service running data of a service running on the client, transmit the service running data to a server.
  • the server is to receive service running data of a service transmitted from a client, acquire a first abnormal strategy corresponding to the service, and provide an alarm for the service when the service running data matches the first abnormal strategy.
  • the server is further to acquire a recovering command according to the alarmed service, transmit the recovering command to the client to indicate the client to adjust the service, e.g., restarting a service system.
  • the client in the example is as shown in FIG. 9 or FIG. 10.
  • the server in the example is as shown in any of FIG. 6-FIG. 8, which is not described repeatedly herein.
  • a server is provided according to an example of the present disclosure.
  • FIG. 11 is a schematic diagram illustrating a structure of a server according to an example of the present disclosure.
  • the computer device includes a processor for executing instructions stored in a memory.
  • the instructions include a service running data receiving instruction 30, a strategy acquiring instruction 31 and an alarming instruction 32.
  • the service running data receiving instruction 30 is to receive service running data of a service transmitted from a client, wherein at least one service runs on the client
  • the strategy acquiring instruction 31 is to acquire a first abnormal strategy corresponding to the service
  • the alarming instruction 32 to determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm for the service when the service running data received by the service running data receiving instruction 30 matches the first abnormal strategy acquired by the strategy acquiring instruction 31.
  • the server provides an alarm indicator for the service to the client.
  • the service running data receiving instruction 30 may receive service running data of a service transmitted from a client.
  • the strategy acquiring instruction 31 may acquire a first abnormal strategy corresponding to the service.
  • the alarming instruction 32 may determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm for the service when the service running data received by the service running data receiving instruction 30 matches the first abnormal strategy acquired by the strategy acquiring instruction 31.
  • the server can determine for which service running on the client the abnormality occurs and an alarm is provided.
  • the instructions not only include the service running data receiving instruction 30, the strategy acquiring instruction 31 and the alarming instruction 32, but also include a device running data receiving instruction 33, a configuration instruction 34 and a command transmitting instruction 35.
  • the device running data receiving instruction 33 is to receive device running data of the client transmitted by the client.
  • the configuration instruction 34 is to acquire first configuration information corresponding to the service, reconfigure the first abnormal strategy according to the first configuration information. the configuration instruction 34, further to acquire second configuration information corresponding to the service, reconfigure a second abnormal strategy according to the second configuration information;
  • the command transmitting instruction 35 is to transmit a recovering command to the client, wherein the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation indicated by the recovering operation indication.
  • the configuration instruction 34 may be to configure the first abnormal strategy and/or the second abnormal strategy.
  • the strategy acquiring instruction 31 may be to acquire the first abnormal strategy after the first abnormal strategy is configured by the configuration instruction 34.
  • the alarming instruction 32 may be to determine whether the second condition is satisfied according to the received device running data and the device parameter value to consider both the service running on the client and the hardware of the client to provide an alarm for the service.
  • the alarming instruction 32 may be to provide an alarm for the service.
  • the process of providing an alarm for the service is the same as that in an example corresponding to FIG. 3.
  • the alarming instruction 32 may be to provide an alarm for the client corresponding to the client.
  • the process of providing an alarm for the client is the same as that in an example corresponding to FIG. 4.
  • the command transmitting instruction 35 may be to acquire the recovering command according to the service or the client, and transmit the recovering command to the client, wherein the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation indicated by the recovering command indication.
  • the command transmitting instruction 35 may generate the recovering command that indicates that the client restarts the network downloading service system.
  • the command transmitting instruction 32 may generate a recovering command indicating restarting the client 1.
  • a server may further include a monitoring management instruction that is to manage the monitored client.
  • the monitoring management instruction may store a list of monitored clients.
  • a network address i.e. IP
  • a client state including abnormal or normal
  • a state of a service running on each monitored client may also be stored in the list, which includes an abnormal state or a normal state.
  • a client is provided according to an example of the present disclosure. As shown in FIG. 13, the client includes a processor for executing instructions stored in a memory.
  • the instructions includes a service running data collecting instruction 40 and a service running data transmitting instruction 41.
  • the service running data collecting instruction 40 is to collect service running data of a service running on the client.
  • the service running data collecting instruction 40 is to collect the service running data of the service according to a service collection frequency preset in the client. Service collection frequencies preset in the client for different services may be same or different.
  • the service running data transmitting instruction 41 is to transmit the service running data collected by the service running data collecting instruction 40 to a server, so that the server provides an alarm for a service corresponding to the service running data when the server determines that the service running data matches a first abnormal strategy.
  • the service running data collecting instruction 40 is to collect service running data of a service running on the client.
  • the service running data transmitting instruction 41 is to transmit the service running data to a server, so that the server provides an alarm for the service corresponding to the service running data when the server determines that the service running data matches the first abnormal strategy.
  • the server can determine for which service running on the client the abnormality occurs and an alarm is provided.
  • the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis.
  • the instructions not only include a service running data collecting instruction 40 and a service running data transmitting instruction 41 as shown in FIG. 13, but also include a device running data collecting instruction 42, a device running data transmitting instruction 43 and a command performing instruction 44.
  • the device running data collecting instruction 42 is to collect device running data of the client.
  • the device running data collecting instruction 42 is to collect the device running data of the client according to a device collection frequency preset in the client. Device collection frequencies preset in different clients may be same or different.
  • the device running data transmitting instruction 43 is to transmit the device running data collected by the device running data collecting instruction 42.
  • the command performing instruction 44 is to receive a recovering command corresponding to the service transmitted from the server, wherein the recovering command carries a recovering operation indication, perform a recovering operation indicated by the recovering operation indication.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Health & Medical Sciences (AREA)
  • Cardiology (AREA)
  • General Health & Medical Sciences (AREA)
  • Debugging And Monitoring (AREA)
  • Computer And Data Communications (AREA)

Abstract

The present disclosure discloses a method, system and device for monitoring data. A server receives service running data of a service transmitted from a client. The server acquires a first abnormal strategy corresponding to the service, and provides an alarm for the service when the first abnormal strategy is matched according to the service running data. As the method for monitoring data is based on the service running on the client, the server can determine for which service running on the client the abnormality occurs and an alarm is provided. Thus, the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis.

Description

METHOD, SYSTEM AND DEVICE FOR MONITORRING
DATA
Field of the Invention
The present disclosure relates to an information technology field, and more particularly, to a method, system and device for monitoring data.
Background of the Invention
At present, in a monitoring system, data running on a monitored device is collected through a data collecting process installed in a peripheral of the monitored device. In detail, the data running on the monitored device is recorded in various ways. Afterwards, the peripheral can report the collected data to a monitoring device through a network. The data is displayed in a monitoring interface in the monitoring device.
In a conventional monitoring system, all data from the monitored device is displayed in the monitoring interface of the monitoring device, and is analyzed manually to determine whether there is a problem in the monitored device. Thus, analysis of the monitoring data is complex.
Summary of the Invention
A method, system and device for monitoring data are provided according to examples of the present disclosure to simplify analysis for monitoring data. A method for monitoring data is provided according to an example of the present disclosure, which includes: receiving, by a server, service running data of a service transmitted from a client; acquiring, by the server, a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs; determining, by the server, whether the first condition is satisfied according to the received service running data and the service parameter value; and providing, by the server, an alarm indicator for the service to the client when it is determined that the first condition is satisfied.
A server is provided according to an example of the present disclosure, which includes: a processor for executing instructions stored in a memory, the instructions comprising: a service running data receiving instruction, to receive service running data of a service transmitted from a client; a strategy acquiring instruction, to acquire a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs; and an alarming instruction, to determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm indicator for the service to the client when it is determined that the first condition is satisfied.
A system is provided according to an example of the present disclosure, which includes at least one client and a server: each client, to collect service running data of a service running on the client, transmit the service running data to a server; the server, to receive service running data of a service transmitted from the client, acquire a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs, determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm indicator for the service to the client when it is determined that the first condition is satisfied..
A system for monitoring data is provided according to an example of the present disclosure, which includes a server and at least one client, wherein the client includes: a service running data collecting module, to collect service running data of a service running on the client; and a service running data transmitting module, to transmit the service running data to a server; the server includes: a service running data receiving module, to receive service running data of a service transmitted from a client; a strategy acquiring module, to acquire a first abnormal strategy corresponding to the service; and an alarming module, to provide an alarm for the service when the first abnormal strategy is matched according to the service running data.
Brief Description of Drawings
In order to make examples of the present disclosure clearer, drawings for examples of the present disclosure are briefly described. Obviously, the following drawings are only for partial examples of the present invention, but are not all examples. Those skilled in the art can obtain other drawings without creative labor.
FIG. 1 is a schematic diagram illustrating a structure of a system for monitoring data in accordance with an example of the present disclosure;
FIG. 2 is a flowchart illustrating a method for monitoring data in accordance with an example of the present disclosure;
FIG. 3 is a flowchart illustrating another method for monitoring data in accordance with an example of the present disclosure;
FIG. 4 is a flowchart illustrating another method for monitoring data in accordance with an example of the present disclosure; FIG. 5 is a flowchart illustrating another method for monitoring data in accordance with an example of the present disclosure;
FIG. 6 is a schematic diagram illustrating a structure of a server in accordance with an example of the present disclosure; FIG. 7 is a schematic diagram illustrating another structure of a server in accordance with an example of the present disclosure;
FIG. 8 is a schematic diagram illustrating another structure of a server in accordance with an example of the present disclosure; FIG. 9 is a schematic diagram illustrating a structure of a client in accordance with an example of the present disclosure;
FIG. 10 is a schematic diagram illustrating another structure of a client in accordance with an example of the present disclosure;
FIG. 11 is a schematic diagram illustrating another structure of a server in accordance with an example of the present disclosure;
FIG. 12 is a schematic diagram illustrating another structure of a server in accordance with an example of the present disclosure;
FIG. 13 is a schematic diagram illustrating another structure of a client in accordance with an example of the present disclosure; FIG. 14 is a schematic diagram illustrating another structure of a client in accordance with an example of the present disclosure.
Detailed Description of the Invention
Technical solutions in accordance with examples of the present disclosure will become apparent and integrated from the following detailed description, taken in conjunction with the accompanying drawings, illustrating by way of example the principles of the present disclosure. Obviously, the described examples are only partial examples of the present disclosure, but are not all examples. The present disclosure may be represented as different forms, and thus is not limited to the described examples. According to the examples of the present disclosure, those skilled in the art can obtain other examples without creative labor, which belong to the protection scope of the present disclosure.
A method for monitoring data is provided according to an example of the present disclosure, which is applied to a system for monitoring data as shown in FIG. 1. The system includes at least one client and a server connected with the at least one client. The at least one client is the monitored device that can be a computing device such as a mobile phone, a smartphone, a laptop, a tablet PC, a POS machine and so on. In an example shown in FIG. 1, there are multiple clients. At least one service can run in a client. That is, a client can include at least one service systems, such as an instant messaging service system and a service system for downloading files and so on. In an example shown in FIG. 1, there are multiple service systems in a client. The server can monitor service running data of the at least one service running on the client.
As shown in FIG. 2, in a monitoring system, a server may monitor service running data of a service running on a client as follows.
At block 101, the server receives service running data of a service running a client, wherein the service running data of the service running on the client is transmitted from the client. The service data transmitted by the client may indicate a detail condition of running the service on the client. Specifically, the service running data may include a service identifier that uniquely identifies the service, and may also include service performance data acquired during the service's running, e.g., amount of data that is downloaded from a network and processed by a file downloading system in the client, amount of scanned data, data scanning performance and so on.
In a practical application, the service performance data in the service running data is collected by the client according to a preset service collection frequency. The service collection frequency may be preset in the client according to a practical requirement. For example, the client may collect the service performance data such as data scanning performance once every 100s. Service collection frequencies preset for different services in the client may be the same or different from each other. The client may collect the service performance data of different services respectively according to different service collection frequencies. At block 102, the server acquires a first abnormal strategy corresponding to the service. The first abnormal strategy includes a condition that includes a service parameter value when an abnormality of running the service on the client occurs, e.g., amount of service data is larger than the service parameter value. When the abnormality of running the service on the client occurs, the condition including is satisfied.
The server can store the first abnormal strategy corresponding to the service. Specifically, a corresponding relation between the service identifier and the first abnormal strategy is stored. For example, for an instant messaging service running on the client, the first abnormal strategy may be that a task requirement speed is lower than or equal to zero. When acquiring the first abnormal strategy corresponding to the service, the server may search corresponding relations stored in the server according to the service running data reported by the client for the corresponding relation including the service identifier of the service to acquire the first abnormal strategy corresponding to the service.
At block 103, the server determines whether the service running data received at block 101 matches the first abnormal strategy of the service corresponding to the service running data acquired at block 102, i.e., determines whether the service running data satisfies the condition included in the first abnormal strategy. If the service running data matches the first abnormal strategy, the service running data indicates that an abnormality occurs when the service runs on the client, and block 104 is performed. If the service running data does not match the first abnormal strategy, the server may not provide an alarm.
At block 104, the server provides an alarm for the service corresponding to the matched service running data, e.g., buzzing or popping-up a user interface to provide the alarm through the user interface. In an example, the server provides an alarm indicator for the service to the client. It can be seen from the above that in the method for monitoring data according to the example of the present disclosure, a server in a system for monitoring data may receive service running data of at least one service, and acquires a first abnormal strategy corresponding to each service. If service running data of a service matches a first abnormal strategy of the service corresponding to the service running data, the server provides an alarm for the service corresponding to the service running data. As the method for monitoring data is based on the service running on the client, the server can determine for which service running on the client the abnormality occurs and an alarm is provided. Thus, the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis. In another example, the server may not only monitor data corresponding to the service running on the client according to blocks 101-103, but also monitor data based on a device, i.e. a client. Thus, the first abnormal strategy acquired at block 102 may not only include the condition including the service parameter value when an abnormality of running the service on the client occurs, e.g., amount of downloaded data is larger than or equal to a preset downloading amount, but also include a condition including a device parameter value of the client, i.e., an hardware parameter value of the client, such as CPU occupancy rate and so on. The device parameter value may not indicate that abnormality of hardware in the client occurs. When an abnormality of running the service on the client occurs, both the condition including the service parameter value and the condition including the device parameter value are satisfied. As shown in FIG. 3, not only blocks 101-104 but also block 105 is performed in the server. Moreover, at block 103, it is determined whether the service running data matches the first abnormal strategy, i.e., the service running data satisfies the condition including the service parameter value in the first abnormal strategy. If the service running data matches the first abnormal strategy, block 106 is performed.
At block 105, the server receives the device running data transmitted from the client, wherein the device running data refers to running data of the hardware in the device i.e., the client, e.g., data related with a CPU, a memory, a network device, and a disk. The client may collect not only service running data of each service running on the client, but also the device running data of the client. The client may collect the device running data according to a preset device collection frequency. The device collection frequencies preset in various clients in the data monitoring system may be the same or different from each other. For one client, the preset device collection frequency and the preset service collection frequency may be also the same or different from each other.
At block 106, the server determines whether the device running data received at block 105 matches the first abnormal strategy, i.e., determining whether the received device running data satisfies the condition including a device parameter value of the client in the first abnormal strategy. If the device running data matches the first abnormal strategy, the server provides an alarm for the service corresponding to the service running data matched at block 104. If the device running data does not match the first abnormal strategy, the server does not provide an alarm. That is, if both the device running data of the client and the service running data corresponding to the service match the first abnormal strategy, the server provides an alarm for the service. Thus, when providing an alarm for the service, the server may consider factors of both the service running on the client and the client. The server provides an alarm only when both the machine running data and the service running data respectively satisfy corresponding conditions in the first abnormal strategies.
It should be noted that there is no absolute order between block 105 and blocks 101-103. There is also no absolute order between block 106 and block 103. Block 105 and blocks 101-103 can be performed at the same time or in order. Also, Block 106 and block 103 can be performed at the same time or in order. The method as shown in FIG. 3 is only a concrete implementation way.
In another example, the server may not only monitor service running data of the service running on the client and provide an alarm for the service according to blocks 101-103, but also monitor data of the device and provide an alarm for the device i.e., the client. As shown in FIG. 4, the server can perform not only blocks 101-104, but also blocks 107-109.
At block 107, the server receives the device running data transmitted from at least one client, wherein the device running data refers to running data of the hardware in the client, e.g., data related with a CPU, a memory, a network device, and a disk. The client may collect not only service running data of each service running on the client, but also the device running data of the client. The client may collect the device running data according to a preset device collection frequency. The device collection frequencies preset in various clients in the data monitoring system may be the same or different from each other. For one client, the preset device collection frequency and the preset service collection frequency may be also the same or different from each other.
At block 108, the server determines whether the device running data received in block 107 matches a second abnormal strategy. The second abnormal strategy may include the device parameter value when an abnormality occurs in the client, e.g., the CPU occupancy rate value and the temperature value. When the abnormality of the client on the client occurs, the condition including the device parameter value is satisfied. In detail, the server determines whether the device running data received in block 107 satisfies a condition including a device parameter value in the second abnormal strategy. If the device running data matches the second abnormal strategy, block 109 is performed. If the device running data does not match the second abnormal strategy, the server may not provide an alarm. Second abnormal strategies for various clients may be the same or different from each other.
At block 109, the server provides an alarm for the client corresponding to the matched device running data.
It should be noted that in the example, the server may manage the monitored client. In detail, the server may store a list of monitored clients. A network address (i.e. IP) and a client state (including abnormal or normal) may be stored in the list for each monitored client. A state of a service running on each monitored client may also be stored in the list, which includes an abnormal state or a normal state.
There is no absolute order between blocks 107-109 and blocks 101-103 that can be performed at the same time or in order. FIG. 4 only illustrates an exemplary implementation way. The first abnormal strategy and the second abnormal strategy indicate different abnormal strategies, but not indicate order relationship of abnormal strategies.
It should be noted that, both the first abnormal strategy corresponding to the service acquired at block 102 and the second abnormal strategy corresponding to the client acquired at block 108 may be preset in the server by a user according to requirements. For the first abnormal strategy, the server may acquire first configuration information of the first abnormal strategy corresponding to the service and reconfigure the first abnormal strategy corresponding to the service stored in the server according to the acquired first configuration information. For the second abnormal strategy, the server may acquire second configuration information of the second abnormal strategy corresponding to the client and reconfigure the second abnormal strategy according to the acquired second configuration information. The first configuration information and the second configuration information may be stored in a script. The server may receive the first configuration information and second configuration information inputted by other devices, or inputted by the user from a user interface. According to the above example from block 101 to block 109, the server can provide an alarm for the abnormal service running on the client, and can also provide an alarm for the client in which the abnormality of the hardware occurs. In an example, after providing an alarm for the abnormal service, i.e., after block 104 is performed, the server may acquire a recovering command for the service corresponding to the matched service running data, and transmit the recovering command to the client reporting the service running data. The recovering command carries a recovering operation indication to indicate the client to perform a recovering operation such as restarting a service system. The recovering command may be acquired according to the abnormal service. For example, for the abnormal service in a network downloading service system, the service may generate the recovering command to indicate that the client restarts the network downloading service system.
After providing an alarm for the abnormal client, i.e., after block 109 is performed, the server may acquire a recovering command for the client corresponding to the matched device running data, and transmit the recovering command to the client corresponding to the device running data. The recovering command carries a recovering operation indication to indicate the client to perform a recovering operation such as restarting the client. The recovering command may be acquired according to the specific client. For example, if the abnormality occurs in client 1, the service may generate the recovering command to indicate restarting the client 1. Thus, through interaction between the client and the server, the abnormal client or the client corresponding to the abnormal service is adjusted properly, to make the client recovered to a normal state.
A method for monitoring data is provided according to an example of the present disclosure, which applies to a system for monitoring data as shown in FIG. 1. As shown in FIG. 5, the method includes procedures as follows.
At block 201, service running date of at least one service running on the client is collected. At least one service runs on the client. The service running data of a service can indicate a specific condition of running the service. Specifically, the service running data may include a service identifier that identifies the service uniquely, and the performance data acquired during a process of running the service, e.g., amount of data that is downloaded from a network and processed by a file downloading system in the client, amount of scanned data, scanning performance. In a practical application, the service performance data in the service running data is collected by the client according to a preset service collection frequency. The service collection frequency may be preset in the client according to a practical requirement. For example, the client may collect the service performance data such as data scanning performance once every 100s. Service collection frequencies preset for different services by the client may be same or different. The client may collect the service performance data of different services according to different service collection frequencies.
At block 202, the collected service running data corresponding to the at least one service is transmitted to the server, so that when the service running data matches a first abnormal strategy of the service corresponding to the service running data, the server provides an alarm for the service corresponding to the matched service running data. The method for monitoring data performed by the server is shown as FIG. 2, which is not described repeatedly herein. It can be seen from the above that in a method for monitoring data according to an example of the present disclosure, in a system for monitoring data, a client collects service running data corresponding to at least one service, transmit the collected service running data to the server so that when the service running data matches a first abnormal strategy of the service corresponding to the service running data, the server provides an alarm for the service corresponding to the matched service running data. As the method for monitoring data is based on the service running on the client, the server can determine for which service running on the client the abnormality occurs to provide an alarm. Thus, the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of a monitoring system, so as to simplify data analysis.
According to block 201 and block 202, the client collects the service running data and transmits the service running data to the server, wherein the data monitoring is based on the service. In another example, the client not only performs blocks 201 and 202, but also monitors data based on a device. Specifically, the client may collect device running data, i.e., a hardware parameter of the client, such as CPU occupancy rate and so on. The collected device running data is transmitted to the server. Thus, when the server determines that the device running data matches a second abnormal strategy, the server provides an alarm for the client corresponding to the matched device running data. Or the server may provide an alarm for the abnormal service according to a method for monitoring data as shown in FIG. 3.
The client may collect the device running data according to a preset device collection frequency. Device collection frequencies preset in various clients in the system for monitoring data may be same or different. For one client, the preset device collection frequency and the preset service collection frequency may be also same or different.
In another example, the client may not only perform above blocks 201 and 202, but also receive a recovering command transmitted by the server. The recovering command is acquired by the server according to the service corresponding to the service running data matching the first abnormal strategy or the client corresponding to the machine running data matching the second abnormal strategy. For example, if the abnormality in a network downloading service system occurs, the server may generate the recovering command to indicate that the client restarts the network downloading service system. If the abnormality occurs in client 1, the service may generate the recovering command to indicate restarting the client 1. Thus, through interaction between the client and the server, the abnormal client or the client corresponding to the abnormal service is adjusted properly, to make the client recovered to a normal state. Communication between the client and the server may be based on such as User Datagram Protocol (UDP) and so on.
A method for monitoring data according to an example of the present disclosure is as shown in FIG. 6, which applies to a system for monitoring data as shown in FIG. 1. In the example, the server may include an intercepting proceeding, a monitoring proceeding, a sharing memory, an alarming module and a configuring module.
(1) The intercepting proceeding in the server may intercept service running data and device running data reported by a client, and store the service running data and the device running data in the sharing memory. The intercepting proceeding may further feed a response back to the data reported by the client. The intercepting proceeding may further intercept a first abnormal strategy and a second abnormal strategy configured by the configuring module, and store the first abnormal strategy and the second abnormal strategy into the sharing memory. The service running data and the device running data of the client may be as shown in FIG. 1. In FIG. 1, CPU overload, HANDLE and memory are included in the device running data. Other data is included in the service running data.
A format of a string is that the string that does not end with zero is started with a uintl6_t to represent the number of characters in the string, and the string follows the uintl6_t. "char" represents integer data. For data of sample scanned unsuccessful, a unique identity code of the sample md5 is added on basis of a scanning result. For data of sample scanned in a long time, the unique identity code of the sample md5 and a scanning time (in seconds) are added on basis of the scanning result. "ucDataCmd" is a primary command, which indicates a kind of commands to be performed. "ucDataSubcmd" is a secondary command, which indicates a sub-command in the kind of the commands.
Table 1
Figure imgf000014_0001
Engine Version 0x02 0x02 string
Virus database version 0x02 0x03 string
CPU load 0x03 0x01 uint32_t
Memory 0x03 0x02 uint32_t
HANDLE 0x03 0x03 uint32_t uint8_t+char[32
Sample scanned unsuccessful 0x04 0x01
]
uint8_t+char[32
Sample scanned in a long time 0x05 0x01
]+uint64_t
(2) the intercepting proceeding in the server may intercept the service running data and the device running data reported by the client, and store the service running data and the device running data into the sharing memory. Thus, the monitoring proceeding may read the service running data and the device running data from the sharing memory, and read the first abnormal strategy and the second abnormal strategy from the sharing memory, and monitor data according to the processes as shown in FIG. 2 and FIG. 4, which is not described repeatedly herein.
(3) If the service corresponding to the service running data is to be alarmed, the monitoring proceeding may control the alarming module to provide an alarm for the service and transmit a recovering command corresponding to the service to the client. If the client corresponding to the device running data is to be alarmed, the monitoring proceeding may control the alarming module to provide an alarm for the client and transmit a recovering command corresponding to the client to the client.
A server is provided according to an example of the present disclosure. FIG. 7 is a schematic diagram illustrating a structure of a server according to an example of the present disclosure. The server includes: a service running data receiving module 10, to receive service running data of a service transmitted from a client, wherein at least one service runs on the client; a strategy acquiring module 11, to acquire a first abnormal strategy corresponding to the service; and an alarming module 12, to determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm for the service when the service running data received by the service running data receiving module 10 matches the first abnormal strategy acquired by the strategy acquiring module 11. In an example, the server provides an alarm indicator for the service to the client.
In the example of the present disclosure, the service running data receiving module 10 may receive service running data of a service transmitted from a client. The strategy acquiring module 11 may acquire a first abnormal strategy corresponding to the service. And the alarming module 12 may determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm for the service when the service running data received by the service running data receiving module 10 matches the first abnormal strategy acquired by the strategy acquiring module 11. As the method for monitoring data is based on the service running on the client, the server can determine for which service running on the client the abnormality occurs and an alarm is provided. Thus, the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis. As shown in FIG. 8, in an example of the present disclosure, the server not only includes the service running data receiving module 10, the strategy acquiring module 11 and the alarming module 12, but also includes a device running data receiving module 13, a configuration module 14 and a command transmitting module 15: the device running data receiving module 13, to receive device running data of the client transmitted by the client; the configuration module 14, to acquire first configuration information corresponding to the service, reconfigure the first abnormal strategy according to the first configuration information; the configuration module 14, further to acquire second configuration information corresponding to the service, reconfigure a second abnormal strategy according to the second configuration information; the command transmitting module 15, to transmit a recovering command to the client, wherein the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation indicated by the recovering operation indication. In an example of the present disclosure, the configuration module 14 may configure the first abnormal strategy and/or the second abnormal strategy stored in the server. The strategy acquiring module 11 may acquire the first abnormal strategy after the first abnormal strategy is configured by the configuration module 14. When the first abnormal strategy acquired by the strategy acquiring module 11 includes a condition including a service parameter value and a condition including a device parameter value, the alarming module 12 may determine whether the second condition is satisfied according to the received device running data and the device parameter value to consider both the service running on the client and the hardware of the client to provide an alarm for the service. In detail, when the service running data satisfies the condition including the service parameter value and the device running data satisfies the condition including the device parameter value, the alarming module 12 may provide an alarm for the service. The process of providing an alarm for the service is the same as that in an example corresponding to FIG. 3. In another example, when the device running data received by the device running data receiving module 13 matches the second abnormal strategy, the alarming module 12 may provide an alarm for the client corresponding to the client. The process of providing an alarm for the client is the same as that in an example corresponding to FIG. 4.
After the alarming module 12 provides an alarm, the command transmitting module 15 may acquire the recovering command according to the service or the client, and transmit the recovering command to the client, wherein the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation indicated by the recovering command indication. For example, when the alarming module 12 provides an alarm for the service in a network downloading service system, the command transmitting module 15 may generate the recovering command that indicates that the client restarts the network downloading service system. When the alarming 12 provides an alarming for client 1, the command transmitting module 12 may generate a recovering command indicating restarting the client 1. It should be noted that, in an example, a server may further include a monitoring management module that is to manage the monitored client. In detail, the monitoring management module may store a list of monitored clients. A network address (i.e. IP) and a client state (including abnormal or normal) may be stored in the list for each monitored client. A state of a service running on each monitored client may also be stored in the list, which includes an abnormal state or a normal state.
A client is provided according to an example of the present disclosure. As shown in FIG. 9, the client includes a service running data collecting module 20 and a service running data transmitting module 21. The service running data collecting module 20 is to collect service running data of a service running on the client. The service running data collecting module 20 is to collect the service running data of the service according to a service collection frequency preset in the client. Service collection frequencies preset in the client for different services may be same or different. The service running data transmitting module 21 is to transmit the service running data collected by the service running data collecting module 20 to a server, so that the server provides an alarm for a service corresponding to the service running data when the server determines that the service running data matches a first abnormal strategy. In an example of the client, the service running data collecting module 20 collects service running data of a service running on the client. The service running data transmitting module 21 transmits the service running data to a server, so that the server provides an alarm for the service corresponding to the service running data when the server determines that the service running data matches the first abnormal strategy. As the method for monitoring data is based on the service running on the client, the server can determine for which service running on the client the abnormality occurs and an alarm is provided. Thus, the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis.
As shown in FIG. 10, in an example of the present disclosure, the client not only includes a service running data collecting module 20 and a service running data transmitting module 21 as shown in FIG. 9, but also includes a device running data collecting module 22, a device running data transmitting module 23 and a command performing module 24.
The device running data collecting module 22 is to collect device running data of the client. The device running data collecting module 22 is to collect the device running data of the client according to a device collection frequency preset in the client. Device collection frequencies preset in different clients may be same or different.
The device running data transmitting module 23 is to transmit the device running data collected by the device running data collecting module 22 to the server, so that the server provides an alarm for the client corresponding to the device running data when the server determines that the device running data matches a second abnormal strategy.
The command performing module 24 is to receive a recovering command corresponding to the service transmitted from the server, wherein the recovering command carries a recovering operation indication, perform a recovering operation indicated by the recovering operation indication.
A system for monitoring system is provided according to an example of the present disclosure. As shown in FIG. 1, the system includes a server and at least one client, wherein each client includes at least one service system and a service runs on a service system.
The client is to collect service running data of a service running on the client, transmit the service running data to a server.
The server is to receive service running data of a service transmitted from a client, acquire a first abnormal strategy corresponding to the service, and provide an alarm for the service when the service running data matches the first abnormal strategy.
The server is further to acquire a recovering command according to the alarmed service, transmit the recovering command to the client to indicate the client to adjust the service, e.g., restarting a service system. The client in the example is as shown in FIG. 9 or FIG. 10. The server in the example is as shown in any of FIG. 6-FIG. 8, which is not described repeatedly herein. A server is provided according to an example of the present disclosure. FIG. 11 is a schematic diagram illustrating a structure of a server according to an example of the present disclosure. The computer device includes a processor for executing instructions stored in a memory. The instructions include a service running data receiving instruction 30, a strategy acquiring instruction 31 and an alarming instruction 32.
The service running data receiving instruction 30 is to receive service running data of a service transmitted from a client, wherein at least one service runs on the client The strategy acquiring instruction 31 is to acquire a first abnormal strategy corresponding to the service; and
The alarming instruction 32, to determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm for the service when the service running data received by the service running data receiving instruction 30 matches the first abnormal strategy acquired by the strategy acquiring instruction 31. In an example, the server provides an alarm indicator for the service to the client.
In the example of the present disclosure, the service running data receiving instruction 30 may receive service running data of a service transmitted from a client. The strategy acquiring instruction 31 may acquire a first abnormal strategy corresponding to the service. And the alarming instruction 32 may determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm for the service when the service running data received by the service running data receiving instruction 30 matches the first abnormal strategy acquired by the strategy acquiring instruction 31. As the method for monitoring data is based on the service running on the client, the server can determine for which service running on the client the abnormality occurs and an alarm is provided. Thus, the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis. As shown in FIG. 12, in an example of the present disclosure, the instructions not only include the service running data receiving instruction 30, the strategy acquiring instruction 31 and the alarming instruction 32, but also include a device running data receiving instruction 33, a configuration instruction 34 and a command transmitting instruction 35.
The device running data receiving instruction 33 is to receive device running data of the client transmitted by the client.
The configuration instruction 34 is to acquire first configuration information corresponding to the service, reconfigure the first abnormal strategy according to the first configuration information. the configuration instruction 34, further to acquire second configuration information corresponding to the service, reconfigure a second abnormal strategy according to the second configuration information;
The command transmitting instruction 35 is to transmit a recovering command to the client, wherein the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation indicated by the recovering operation indication.
In an example of the present disclosure, the configuration instruction 34 may be to configure the first abnormal strategy and/or the second abnormal strategy. The strategy acquiring instruction 31 may be to acquire the first abnormal strategy after the first abnormal strategy is configured by the configuration instruction 34. When the first abnormal strategy acquired by the strategy acquiring instruction 31 includes a condition including a service parameter value and a condition including a device parameter value, the alarming instruction 32 may be to determine whether the second condition is satisfied according to the received device running data and the device parameter value to consider both the service running on the client and the hardware of the client to provide an alarm for the service. In detail, when the service running data satisfies the condition including the service parameter value and the device running data satisfies the condition including the device parameter value, the alarming instruction 32 may be to provide an alarm for the service. The process of providing an alarm for the service is the same as that in an example corresponding to FIG. 3. In another example, when the device running data received by the device running data receiving instruction 33 may be to match the second abnormal strategy, the alarming instruction 32 may be to provide an alarm for the client corresponding to the client. The process of providing an alarm for the client is the same as that in an example corresponding to FIG. 4. The command transmitting instruction 35 may be to acquire the recovering command according to the service or the client, and transmit the recovering command to the client, wherein the recovering command carries a recovering operation indication to indicate the client to perform a recovering operation indicated by the recovering command indication. For example, the command transmitting instruction 35 may generate the recovering command that indicates that the client restarts the network downloading service system. The command transmitting instruction 32 may generate a recovering command indicating restarting the client 1.
It should be noted that, in an example, a server may further include a monitoring management instruction that is to manage the monitored client. In detail, the monitoring management instruction may store a list of monitored clients. A network address (i.e. IP) and a client state (including abnormal or normal) may be stored in the list for each monitored client. A state of a service running on each monitored client may also be stored in the list, which includes an abnormal state or a normal state.
A client is provided according to an example of the present disclosure. As shown in FIG. 13, the client includes a processor for executing instructions stored in a memory. The instructions includes a service running data collecting instruction 40 and a service running data transmitting instruction 41.
The service running data collecting instruction 40 is to collect service running data of a service running on the client. The service running data collecting instruction 40 is to collect the service running data of the service according to a service collection frequency preset in the client. Service collection frequencies preset in the client for different services may be same or different.
The service running data transmitting instruction 41 is to transmit the service running data collected by the service running data collecting instruction 40 to a server, so that the server provides an alarm for a service corresponding to the service running data when the server determines that the service running data matches a first abnormal strategy. In an example of the client, the service running data collecting instruction 40 is to collect service running data of a service running on the client. The service running data transmitting instruction 41 is to transmit the service running data to a server, so that the server provides an alarm for the service corresponding to the service running data when the server determines that the service running data matches the first abnormal strategy. As the method for monitoring data is based on the service running on the client, the server can determine for which service running on the client the abnormality occurs and an alarm is provided. Thus, the user does not need to determine a failure of the service running on the client by manually analyzing data that corresponds to all services running on the client and displays on an interface of the monitoring system, so as to simplify data analysis.
As shown in FIG. 14, in an example of the present disclosure, the instructions not only include a service running data collecting instruction 40 and a service running data transmitting instruction 41 as shown in FIG. 13, but also include a device running data collecting instruction 42, a device running data transmitting instruction 43 and a command performing instruction 44.
The device running data collecting instruction 42 is to collect device running data of the client. The device running data collecting instruction 42 is to collect the device running data of the client according to a device collection frequency preset in the client. Device collection frequencies preset in different clients may be same or different.
The device running data transmitting instruction 43 is to transmit the device running data collected by the device running data collecting instruction 42.
The command performing instruction 44 is to receive a recovering command corresponding to the service transmitted from the server, wherein the recovering command carries a recovering operation indication, perform a recovering operation indicated by the recovering operation indication.
Those skilled in the art know that all or part of blocks in above examples can be implemented through a processor for executing instructions stored in a memory. The instructions can be stored in a readable storage medium, such as Read-only memory (ROM), Random Access Memory (RAM), Magnetic, Optical Disk and so on. Obviously, the described embodiments are only partial embodiments of the present invention, but are not all embodiments. The present invention may be represented as different forms, and thus is not limited to the described embodiments. According to the embodiments of the present invention, those skilled in the art can obtain other embodiments without creative labor, which belong to the protection scope of the present invention.

Claims

What is claimed is:
1. A method for monitoring data, comprising: receiving, by a server, service running data of a service transmitted from a client; acquiring, by the server, a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs; determining, by the server, whether the first condition is satisfied according to the received service running data and the service parameter value; and providing, by the server, an alarm indicator for the service to the client when it is determined that the first condition is satisfied.
2. The method according to claim 1, wherein the first abnormal strategy further comprises a second condition comprising a device parameter value, wherein satisfaction of both the first condition and the second condition indicates that an abnormality of running the service on the client occurs, the method further comprising: receiving, by the server, device running data transmitted by the client; determining, by the server, whether the second condition is satisfied according to the received device running data and the device parameter value; a process of providing an alarm for the service when it is determined that the first condition is satisfied comprises: providing, by the server, an alarm indicator for the service to the client when it is determined that both the first condition and the second condition are satisfied.
3. The method according to claim 1, further comprising: receiving, by the server, device running data of the client; determining, by the server, whether a third condition comprised in a second abnormal strategy corresponding to the client is satisfied according to the received device running data and a device parameter value comprised in the third condition, wherein satisfaction of the third condition indicates that an abnormality of the client occurs; providing, by the server, an alarm indicator to the client when it is determined that the third condition is satisfied.
4. The method according to claim 1, further comprising: acquiring, by the server, first configuration information corresponding to the service; and reconfiguring, by the server, the first abnormal strategy according to the first configuration information.
5. The method according to claim 3, further comprising: acquiring, by the server, second configuration information corresponding to the service; and reconfiguring, by the server, the second abnormal strategy according to the second configuration information.
6. The method according to claim 1, further comprising: transmitting, by the server, to the client a recovering command carrying a recovering operation indication.
7. A server, comprising: a processor for executing instructions stored in a memory, the instructions comprising: a service running data receiving instruction, to receive service running data of a service transmitted from a client; a strategy acquiring instruction, to acquire a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs; and an alarming instruction, to determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm indicator for the service to the client when it is determined that the first condition is satisfied.
8. The server according to claim 7, wherein the first abnormal strategy acquired by the strategy acquiring instruction further comprises a second condition comprising a device parameter value, wherein satisfaction of both the first condition and the second condition indicates that an abnormality of running the service on the client occurs; the server further comprising: a device running data receiving instruction, to receive device running data of the client; the alarming instruction is further to determine whether the second condition is satisfied according to the received device running data and the device parameter value, the alarming instruction is to provide an alarm indicator for the service to the client when it is determined that both the first condition and the second condition are satisfied.
9. The server according to claim 7, further comprising: a device running data receiving instruction, to receive device running data of the client; the alarming instruction, further to determine whether a third condition comprised in a second abnormal strategy corresponding to the client is satisfied according to the received device running data and a device parameter value comprised in the third condition, wherein satisfaction of the third condition indicates that an abnormality of the client occurs, provide an alarm indicator to the client when it is determined that the third condition is satisfied.
10. The server according to claim 7, further comprising: a configuration instruction, to acquire first configuration information corresponding to the service, reconfigure the first abnormal strategy according to the first configuration information.
11. The server according to claim 9, further comprising: a configuration instruction, to acquire second configuration information corresponding to the service, reconfigure the second abnormal strategy according to the second configuration information.
12. The server according to claim 7, further comprising: a command transmitting instruction, to transmit to the client a recovering command carrying a recovering operation indication.
13. A system for monitoring data, comprising at least one client and a server, wherein each client, to collect service running data of a service running on the client, transmit the service running data to a server; the server, to receive service running data of a service transmitted from the client, acquire a first abnormal strategy corresponding to the service, wherein the first abnormal strategy comprises a first condition comprising a service parameter value wherein satisfaction of the first condition indicates that an abnormality of running the service on the client occurs, determine whether the first condition is satisfied according to the received service running data and the service parameter value, provide an alarm indicator for the service to the client when it is determined that the first condition is satisfied.
14. The system according to claim 13, wherein the first abnormal strategy acquired by the strategy acquiring instruction further comprises a second condition comprising a device parameter value, wherein satisfaction of both the first condition and the second condition indicates that an abnormality of running the service on the client occurs, the server is further to receive device running data of the client, determine whether the second condition is satisfied according to the received device running data and the device parameter value; the server is to provide an alarm indicator for the service to the client when it is determined that both the first condition and the second condition are satisfied.
15. The system according to claim 13, wherein the server is further to receive device running data of the client, determine whether a third condition comprised in a second abnormal strategy corresponding to the client is satisfied according to the received device running data and a device parameter value comprised in the third condition, wherein satisfaction of the third condition indicates that an abnormality of the client occurs, provide an alarm indicator to the client when it is determined that the third condition is satisfied.
16. The system according to claim 13, wherein the client is further to collect device running data of the client, transmit the device running data to the server.
PCT/CN2013/086100 2012-10-29 2013-10-29 Method, system and device for monitorring data Ceased WO2014067439A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US14/698,301 US10200506B2 (en) 2012-10-29 2015-04-28 Method, system and device for monitoring data

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210420759.6A CN103795580B (en) 2012-10-29 2012-10-29 A kind of data monitoring method, system and relevant device
CN201210420759.6 2012-10-29

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US14/698,301 Continuation US10200506B2 (en) 2012-10-29 2015-04-28 Method, system and device for monitoring data

Publications (1)

Publication Number Publication Date
WO2014067439A1 true WO2014067439A1 (en) 2014-05-08

Family

ID=50626486

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/086100 Ceased WO2014067439A1 (en) 2012-10-29 2013-10-29 Method, system and device for monitorring data

Country Status (4)

Country Link
US (1) US10200506B2 (en)
CN (1) CN103795580B (en)
TW (1) TWI510955B (en)
WO (1) WO2014067439A1 (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2017101606A1 (en) * 2015-12-15 2017-06-22 北京奇虎科技有限公司 System and method for collecting and analyzing data
CN113254330A (en) * 2021-05-11 2021-08-13 苏州玩蜂软件科技有限公司 Method, system and medium for automatically controlling multiple sets of Tomcat services
CN113965781A (en) * 2020-07-21 2022-01-21 武汉斗鱼网络科技有限公司 Wind control strategy execution method and device
WO2024065238A1 (en) * 2022-09-28 2024-04-04 Yu Wenfeng Systems, methods, and media for protecting application programming interfaces

Families Citing this family (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104581806B (en) * 2014-12-19 2018-05-18 联动优势电子商务有限公司 A kind of method and terminal for monitoring operation system
CN105471973A (en) * 2015-11-18 2016-04-06 深圳云联讯数据科技有限公司 Remote monitoring method and remote monitoring system based on indicating lamp color of monitored object
US9843474B2 (en) 2015-12-23 2017-12-12 Intel Corporation Telemetry adaptation
CN107797902B (en) * 2016-09-06 2021-07-30 北京百度网讯科技有限公司 Method and apparatus for monitoring message transmission frequency of robot operating system
CN107181639A (en) * 2017-03-31 2017-09-19 北京奇艺世纪科技有限公司 The monitoring method and device of a kind of communications status
CN107563713A (en) * 2017-06-20 2018-01-09 华迪计算机集团有限公司 A kind of electronic document system and its method for operation monitoring
CN107943662A (en) * 2017-12-12 2018-04-20 联想(北京)有限公司 A kind of information processing method and server
TWI644228B (en) * 2017-12-25 2018-12-11 中華電信股份有限公司 Server and its monitoring method
CN110300136B (en) * 2018-03-22 2021-12-24 杭州萤石软件有限公司 Cloud deck control optimization method and system
CN109165137A (en) * 2018-07-27 2019-01-08 曙光信息产业(北京)有限公司 data analysis and alarm method and system
CN111555896B (en) * 2019-02-12 2023-01-20 昆山纬绩资通有限公司 Data transmission monitoring method and system
CN109842631A (en) * 2019-03-21 2019-06-04 安徽威尔信通信科技有限责任公司 A kind of network information security intelligent analysis system
CN110513252B (en) * 2019-08-30 2020-11-24 湘电风能有限公司 A wind farm SCADA system data abnormal alarm repair system and method
CN112532404B (en) * 2019-09-17 2023-09-22 中国移动通信集团广东有限公司 A data monitoring method, device and electronic equipment
CN110650055A (en) * 2019-09-30 2020-01-03 凌云天博光电科技股份有限公司 Broadcast television network equipment monitoring method and system
CN110990903B (en) * 2019-11-29 2023-07-18 腾讯科技(深圳)有限公司 Cloud system and cloud system protection method
CN111209165B (en) * 2020-01-05 2021-03-16 光大兴陇信托有限责任公司 A two-level monitoring and processing method based on channel
CN111327492B (en) * 2020-01-21 2020-12-15 光大兴陇信托有限责任公司 A full-link monitoring and processing method
CN111901140A (en) * 2020-06-11 2020-11-06 北京百度网讯科技有限公司 Exception handling method and device, electronic equipment and storage medium
CN113835698A (en) * 2020-06-23 2021-12-24 腾讯科技(深圳)有限公司 Safety control method and system
CN112016125B (en) * 2020-09-08 2023-10-10 杭州海康威视数字技术股份有限公司 Exception handling methods, devices and equipment for recorders
CN112650644A (en) * 2020-12-22 2021-04-13 南方电网深圳数字电网研究院有限公司 Monitoring method and system based on prometheus
CN112685256B (en) * 2020-12-30 2023-05-09 上海掌门科技有限公司 Server monitoring method, device and medium
CN113190200B (en) * 2021-05-10 2023-04-07 郑州魔王大数据研究院有限公司 Exhibition data security protection method and device
CN115941443A (en) * 2022-12-06 2023-04-07 天翼电子商务有限公司 A message queue-based service exception alarm method and system

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2098970A1 (en) * 2008-03-07 2009-09-09 British Telecommunications public limited company Abnormal event time thresholds
CN101668301A (en) * 2008-09-03 2010-03-10 中兴通讯股份有限公司 Method and device for monitoring operation state of node in short message center
CN102547807A (en) * 2010-12-21 2012-07-04 中兴通讯股份有限公司 Failure detection method and system for mobile communication equipment
CN102609346A (en) * 2012-01-16 2012-07-25 深信服网络科技(深圳)有限公司 Monitoring method and monitoring device on basis of service operation

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7197559B2 (en) * 2001-05-09 2007-03-27 Mercury Interactive Corporation Transaction breakdown feature to facilitate analysis of end user performance of a server system
US8974304B2 (en) * 2004-12-22 2015-03-10 Wms Gaming Inc. System, method, and apparatus for detecting abnormal behavior of a wagering game machine
US7647430B2 (en) * 2005-01-19 2010-01-12 Microsoft Corporation Remote command framework for devices
GB0624168D0 (en) * 2006-12-04 2007-01-10 Axiom Systems Ltd Service assembly and delivery
CN101202649A (en) * 2006-12-14 2008-06-18 英业达股份有限公司 Method for collecting and managing computer equipment information
TWI318283B (en) * 2007-07-06 2009-12-11 Chunghwa Telecom Co Ltd Network-based air-conditioning equipment remote monitoring and management system
TWI439855B (en) * 2007-11-09 2014-06-01 Inventec Appliances Corp Real-time monitoring system and method of database
CN201213268Y (en) * 2008-05-15 2009-03-25 研华股份有限公司 Information service server with monitoring remote equipment
TWI369623B (en) * 2008-11-07 2012-08-01 Chunghwa Telecom Co Ltd Control system and protection method for integrated information security service
CN101714930B (en) * 2009-12-30 2012-05-23 北京云快线软件服务有限公司 Method and system for realizing network monitoring
CN101826993A (en) * 2010-02-04 2010-09-08 蓝盾信息安全技术股份有限公司 Method, system and device for monitoring security event
US9629012B2 (en) * 2010-09-20 2017-04-18 Empire Technology Development Llc Dynamic mobile application quality-of-service monitor

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2098970A1 (en) * 2008-03-07 2009-09-09 British Telecommunications public limited company Abnormal event time thresholds
CN101668301A (en) * 2008-09-03 2010-03-10 中兴通讯股份有限公司 Method and device for monitoring operation state of node in short message center
CN102547807A (en) * 2010-12-21 2012-07-04 中兴通讯股份有限公司 Failure detection method and system for mobile communication equipment
CN102609346A (en) * 2012-01-16 2012-07-25 深信服网络科技(深圳)有限公司 Monitoring method and monitoring device on basis of service operation

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2017101606A1 (en) * 2015-12-15 2017-06-22 北京奇虎科技有限公司 System and method for collecting and analyzing data
CN113965781A (en) * 2020-07-21 2022-01-21 武汉斗鱼网络科技有限公司 Wind control strategy execution method and device
CN113965781B (en) * 2020-07-21 2023-11-24 东初智能科技(上海)有限公司 Wind control strategy execution method and device
CN113254330A (en) * 2021-05-11 2021-08-13 苏州玩蜂软件科技有限公司 Method, system and medium for automatically controlling multiple sets of Tomcat services
WO2024065238A1 (en) * 2022-09-28 2024-04-04 Yu Wenfeng Systems, methods, and media for protecting application programming interfaces

Also Published As

Publication number Publication date
CN103795580A (en) 2014-05-14
US20150304457A1 (en) 2015-10-22
TWI510955B (en) 2015-12-01
CN103795580B (en) 2016-10-26
US10200506B2 (en) 2019-02-05
TW201416898A (en) 2014-05-01

Similar Documents

Publication Publication Date Title
WO2014067439A1 (en) Method, system and device for monitorring data
JP5736881B2 (en) Log collection system, apparatus, method and program
CN107704360B (en) Monitoring data processing method, equipment, server and storage medium
CN105165054B (en) Network service fault handling method, service management system and system management module
CN108965049B (en) Method, device, system and storage medium for providing cluster exception solution
WO2015180291A1 (en) Method and system for monitoring server cluster
CN101154181A (en) Computer maintenance support system and analysis server
CN111162950B (en) Fault event processing method, device and system
CN113760634B (en) A data processing method and device
US20080155346A1 (en) Network fault pattern analyzer
CN110275815A (en) A system abnormal alarm processing method and device
CN115545452A (en) Operation and maintenance method, operation and maintenance system, equipment and storage medium
Priovolos et al. Using anomaly detection techniques for securing 5G infrastructure and applications
CN103347005A (en) Data report control method, client end device and server device
CN116192607B (en) Fault alarm method and device
CN110198230B (en) Application monitoring method and device, storage medium and electronic device
CN107341086B (en) Method and system for monitoring running state of server
CN112118140B (en) CDN configuration method, CDN configuration device, computer equipment and storage medium
CN111818154B (en) Service pushing system and method based on network layer message analysis
JP2018160020A (en) Monitoring system, program, and monitoring method
CN120218545B (en) Metadata-driven ubiquitous equipment access and monitoring system
US10296967B1 (en) System, method, and computer program for aggregating fallouts in an ordering system
CN115865910B (en) Equipment control method, device and server
CN114374534B (en) Test sample set updating method and device and electronic equipment
CN121262119A (en) Method and device for detecting state of client, storage medium and computer equipment

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13850990

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 14/09/2015)

122 Ep: pct application non-entry in european phase

Ref document number: 13850990

Country of ref document: EP

Kind code of ref document: A1