WO2021136247A1 - 一种告警处理方法、装置以及存储介质 - Google Patents

一种告警处理方法、装置以及存储介质 Download PDF

Info

Publication number
WO2021136247A1
WO2021136247A1 PCT/CN2020/140727 CN2020140727W WO2021136247A1 WO 2021136247 A1 WO2021136247 A1 WO 2021136247A1 CN 2020140727 W CN2020140727 W CN 2020140727W WO 2021136247 A1 WO2021136247 A1 WO 2021136247A1
Authority
WO
WIPO (PCT)
Prior art keywords
alarm
target
reporting
event
configuration
Prior art date
Application number
PCT/CN2020/140727
Other languages
English (en)
French (fr)
Inventor
贾晓倩
王姗姗
周伟健
具睿
梁涛涛
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2021136247A1 publication Critical patent/WO2021136247A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0604Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
    • H04L41/0609Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time based on severity or priority
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • H04L41/065Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis involving logical or physical relationship, e.g. grouping and hierarchies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0677Localisation of faults
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/06Generation of reports

Definitions

  • This application relates to the field of communication technology, and in particular to an alarm processing method, device, and storage medium.
  • the network structure is becoming larger and more complex.
  • the network contains a large number of network element equipment.
  • In daily network maintenance it is necessary to discover the faults of the network element equipment in time, generate fault alarms and deal with the faults accordingly.
  • the types of faults include: X2 interface failure, S1 port Faults, standing wave faults, power supply faults, etc.
  • the generation and reporting of massive alarms brought about by the complex network structure puts tremendous pressure on network operation and maintenance personnel, and the workload of fault analysis is large and the efficiency is low.
  • AI artificial intelligence
  • a machine learning algorithm based on powerful storage and computing capabilities can be used to help solve large amounts of data processing and analysis and data-based learning.
  • the introduction of AI technology in network operation and maintenance has become the trend of future network intelligent operation and maintenance. For example, through various adaptive algorithms, such as frequent item mining, adaptive parameter optimization algorithms, intelligent analysis and processing of network fault alarms and reporting them Provide network management units to improve network operation and maintenance efficiency.
  • an alarm is generated on the network side for each fault, and it is reported to the network management unit at the same time, and the operation and maintenance personnel perform manual analysis and process a large number of alarm events.
  • alarm flashing and alarm oscillations set the alarm flashing period and oscillation period with fixed values on the network element side to avoid reporting a large number of redundant and repeated alarms.
  • the embodiment of the application provides an alarm processing method, which can improve the efficiency of alarm analysis, locate fault information more accurately, or when processing a single alarm problem repeatedly reported or intermittently reported, it can be set flexibly based on the alarm object/alarm type/alarm priority According to the reporting conditions, important alarms are received in time, and the reporting of redundant and repeated alarms can be effectively and accurately suppressed.
  • the first aspect of the present application provides an alarm processing method that can be applied to network operation and maintenance in network systems of various standards.
  • the method includes: receiving an alarm report configuration sent by a network management unit, where the alarm report configuration includes first configuration information or The second configuration information, where the first configuration information is used to indicate the reporting of alarm events.
  • the alarm event is used as an alarm reporting method, which means that the network unit needs to use the alarm event reporting method for alarm reporting.
  • the alarm event reporting method is Refers to the network unit using the target association relationship to correlate multiple alarms with the association relationship to generate an alarm event, and then report the alarm event.
  • the second configuration information is used to indicate the target alarm object and/or the target alarm type and/or the report condition of the alarm corresponding to the target alarm priority; the target alarm is determined according to the alarm report configuration.
  • the network management unit can send an alarm reporting configuration to the network unit, and the alarm reporting configuration can include the first configuration information or the second configuration information, and the network unit can associate multiple associations with an associated relationship based on the first configuration information.
  • the alarms are correlated and reported, so that the efficiency of alarm analysis can be improved, and the fault information can be located more accurately.
  • the network unit can also identify the target alarm object and/or target alarm type and/or target alarm priority based on the second configuration information.
  • determining the target alarm according to the alarm reporting configuration includes: according to the target Correlation rules correlate multiple alarms and generate alarm events; determine target alarms, and target alarms include alarm events.
  • the target alarm contains only the alarm event, the alarm event is the target alarm.
  • the target alarm can also contain other information.
  • the target association rule may be pre-defined by the network unit. When an alarm event needs to be reported, the network unit directly determines the alarm event according to the predetermined target association rule.
  • the target association rule may also be configured by the network management unit through the indication information included in the first configuration information.
  • the first configuration information includes one or more of the following information: The reporting mode, the first indication information, and the second indication information, where the first indication information is used to indicate whether the target alarm carries alarm information of multiple alarms, and the second indication information is used to indicate the target association rule.
  • the target association rule belongs to multiple association rules, and the multiple association rules Including frequency association and network topology association.
  • Frequent correlation refers to correlation based on the alarm correlation frequency of the alarm.
  • the alarm correlation frequency is used to indicate that multiple alarms frequently appear in the same time period, and the network unit associates multiple alarms in the alarm data with frequency according to a frequent mining algorithm in a certain time period.
  • the network topology association refers to the association according to the association relationship of the alarmed network topology structure, and the network topology structure may include the logical topology or derivative relationship of the network topology, etc.
  • the method before receiving the alarm report configuration sent by the network management unit, the method further includes: receiving network management The third indication information sent by the unit, where the third indication information is used to indicate whether to report the multiple association rules to the network management unit.
  • the multiple association rules may be available association rules stored in the network unit, and the network management unit may send third indication information to the network unit to instruct the network unit to report the multiple association rules to the network management unit.
  • the alarm event may include one of the following information Or more: the root cause of the alarm event, the identification of the alarm event, the name of the alarm event, the alarm object, the alarm type of the alarm event, the fault source of the alarm event, the virtualization identification of the fault source, the occurrence time of the alarm event, the alarm event Eliminate the alarm information of events and multiple alarms.
  • determining the target alarm according to the alarm reporting configuration includes: 2.
  • the configuration information determines the target alarm that meets the reporting conditions.
  • the second configuration information includes the alarm flash cycle
  • the alarm reporting configuration determines that the reporting is satisfied
  • the conditional target alarm includes: judging whether the first alarm is restored within the alarm flash cycle; if it is not restored, determining that the first alarm is the target alarm.
  • the second configuration information includes an alarm oscillation period, an input oscillation condition, an output oscillation period, and Out of the shock condition, determine the target alarm that meets the reporting conditions according to the alarm reporting configuration, including: judging whether the second alarm meets the reporting conditions according to the alarm shock period, incoming shock condition, out shock period, and out shock condition; if so, determine the second alarm For the target alarm.
  • the target alarm after the target alarm is determined according to the alarm reporting configuration, It also includes: sending target alarms to the network management unit.
  • the method further includes: receiving a transmission from the network management unit The alarm elimination instruction is determined by the network management unit according to the target alarm.
  • the method further includes: Eliminate the instructions to deal with the target alarm.
  • the method further includes: The network management unit sends the processing result of the target alarm.
  • the alarm report configuration includes the first configuration information After processing the target alarm according to the alarm elimination instruction, it also includes: updating the association relationship of multiple alarms according to the processing result of the target alarm.
  • the second aspect of the present application provides an alarm processing method that can be applied to network operation and maintenance in network systems of various standards.
  • the method includes: sending an alarm report configuration to a network unit, and the alarm report configuration includes first configuration information or second configuration Information, where the first configuration information is used to indicate the reporting of an alarm event, and the second configuration information is used to indicate the target alarm object and/or the target alarm type and/or the reporting condition of the alarm corresponding to the target alarm priority; the receiving network unit sends The target alarm is determined by the network unit according to the alarm reporting configuration.
  • the target alarm when the alarm reporting configuration includes the first configuration information, the target alarm includes an alarm event, and the alarm event is based on the network unit Target association rules are generated by associating multiple alarms.
  • the first configuration information includes one or more of the following information: alarm The reporting mode of the event, the first indication information, and the second indication information, where the first indication information is used to indicate whether the target alarm carries alarm information of multiple alarms, and the second indication information is used to indicate the target association rule.
  • the target association rule belongs to multiple association rules, and the multiple associations
  • the rules include frequency association and network topology association.
  • the method further includes: sending the second aspect to the network unit Three indication information, where the third indication information is used to indicate whether the network unit reports the multiple association rules.
  • the multiple association rules may be available association rules stored in the network unit, and the network management unit may send third indication information to the network unit to instruct the network unit to report the multiple association rules to the network management unit.
  • the alarm event includes one of the following information or Multiple: the root cause of the alarm event, the identification of the alarm event, the name of the alarm event, the alarm object, the alarm type of the alarm event, the fault source of the alarm event, the virtualization identification of the fault source, the occurrence time of the alarm event, and the status of the alarm event Eliminate the alarm information of events and multiple alarms.
  • the target alarm when the alarm reporting configuration includes the second configuration information, the target alarm is determined by the network unit according to the second configuration information , The target alarm meets the reporting conditions.
  • the second configuration information includes the alarm flash period
  • the target alarm is the judgment of the network unit If the first alarm is determined after it is not recovered within the alarm flash period, the first alarm is the target alarm.
  • the second configuration information includes an alarm oscillation period, an input oscillation condition, an output oscillation period, and Out of the shock condition
  • the target alarm is determined by the network unit according to the alarm shock period, incoming shock condition, out shock period, and out shock condition to determine whether the second alarm meets the reporting conditions.
  • the second alarm is Target alert.
  • the ninth possible implementation manner of the second aspect of the present application after receiving the target alarm sent by the network unit, It also includes: determining the alarm elimination instruction according to the target alarm.
  • the method further includes: sending an alarm to the network unit Elimination instructions, so that the network unit processes the target alarms according to the alarm elimination instructions.
  • the method further includes: receiving The processing result of the target alarm.
  • the third aspect of the present application provides an alarm processing device that can be applied to network operation and maintenance in network systems of various standards.
  • the device includes: a receiving module for receiving an alarm reporting configuration sent by a network management unit.
  • the alarm reporting configuration includes the first One configuration information or second configuration information, where the first configuration information is used to indicate the reporting of an alarm event, and the second configuration information is used to indicate the target alarm object and/or the target alarm type and/or the alarm corresponding to the target alarm priority Reporting conditions; the determining module is used to determine the target alarm according to the alarm report configuration received by the receiving module.
  • the determining module when the alarm reporting configuration includes the first configuration information, is configured to perform multiple The alarms are correlated and an alarm event is generated; the target alarm is determined, and the target alarm includes the alarm event.
  • the first configuration information includes one or more of the following information: The reporting mode, the first indication information, and the second indication information, where the first indication information is used to indicate whether the target alarm carries alarm information of multiple alarms, and the second indication information is used to indicate the target association rule.
  • the target association rule belongs to multiple association rules, and the multiple association rules Including frequency association and network topology association.
  • the receiving module is further configured to receive an alarm report sent by the network management unit Before configuration, receiving third indication information sent by the network management unit, where the third indication information is used to indicate whether to report the multiple association rules to the network management unit.
  • the alarm event includes one of the following information or Multiple: the root cause of the alarm event, the identification of the alarm event, the name of the alarm event, the alarm object, the alarm type of the alarm event, the fault source of the alarm event, the virtualization identification of the fault source, the occurrence time of the alarm event, the alarm Elimination of events, alarm information of multiple alarms.
  • the determining module when the alarm report configuration includes the second configuration information, is configured to determine that the Target alarm for reporting conditions.
  • the second configuration information includes an alarm flash cycle, a determination module, and is used to determine the Whether an alarm is restored within the alarm flash cycle; if it is not restored, it is determined that the first alarm is the target alarm.
  • the second configuration information includes an alarm oscillation period, an input oscillation condition, an output oscillation period, and Out-of-oscillation condition, determining module, used for judging whether the second alarm meets the reporting condition according to the alarm-oscillation period, in-oscillation condition, out-oscillation period, and out-oscillation condition; if so, the second alarm is determined to be the target alarm.
  • the alarm processing device also It includes: a sending module, which is used to send the target alarm to the network management unit after the determining module determines the target alarm.
  • the receiving module is further configured to: after the sending module sends the target alarm to the network management unit , Receiving the alarm elimination instruction sent by the network management unit, where the alarm elimination instruction is determined by the network management unit according to the target alarm.
  • the alarm processing device further includes: a processing module for receiving in the receiving module After the alarm elimination instruction sent by the network management unit, the target alarm is processed according to the alarm elimination instruction.
  • the sending module is further configured to respond to the target according to the alarm elimination instruction in the processing module. After the alarm is processed, the processing result of the target alarm is sent to the network management unit.
  • the alarm processing device further includes: an update module, After the processing module processes the target alarm according to the alarm elimination instruction, it is used to update the association relationship of multiple alarms according to the processing result of the target alarm.
  • the fourth aspect of the present application provides an alarm processing device that can be applied to network operation and maintenance in network systems of various standards.
  • the device includes: a sending module for sending an alarm report configuration to a network unit, and the alarm report configuration includes the first configuration Information or second configuration information, where the first configuration information is used to indicate the reporting of an alarm event, and the second configuration information is used to indicate the target alarm object and/or the target alarm type and/or the reporting condition of the alarm corresponding to the target alarm priority
  • the receiving module is configured to receive the target alarm sent by the network unit after the sending module sends the alarm reporting configuration, and the target alarm is determined by the network unit according to the alarm reporting configuration.
  • the target alarm when the alarm reporting configuration includes the first configuration information, the target alarm includes an alarm event, and the alarm event is a network unit Multiple alarms are correlated and generated according to target correlation rules.
  • the first configuration information includes one or more of the following information: The reporting mode, the first indication information, and the second indication information, where the first indication information is used to indicate whether the target alarm carries alarm information of multiple alarms, and the second indication information is used to indicate the target association rule.
  • the target association rule belongs to multiple association rules, and the multiple associations
  • the rules include frequency association and network topology association.
  • the sending module is further configured to send the alarm report configuration to the network unit before sending the alarm report configuration to the network unit.
  • the unit sends third indication information, where the third indication information is used to indicate whether the network unit reports the multiple association rules.
  • the alarm event includes one of the following information or Multiple: the root cause of the alarm event, the identification of the alarm event, the name of the alarm event, the alarm object, the alarm type of the alarm event, the fault source of the alarm event, the virtualization identification of the fault source, the occurrence time of the alarm event, and the status of the alarm event Eliminate the alarm information of events and multiple alarms.
  • the target alarm when the alarm reporting configuration includes the second configuration information, the target alarm is determined by the network unit according to the second configuration information , The target alarm meets the reporting conditions.
  • the second configuration information includes the alarm flash period
  • the target alarm is the judgment of the network unit If the first alarm is determined after it is not recovered within the alarm flash period, the first alarm is the target alarm.
  • the second configuration information includes an alarm oscillation period, an input oscillation condition, an output oscillation period, and Out of shock conditions
  • the target alarm is determined by the network unit when it determines whether the second alarm meets the reporting conditions based on the alarm shock period, incoming shock conditions, out shock periods, and out shock conditions.
  • the second alarm is the target Alarm.
  • the alarm processing apparatus further includes: a determining module , After the receiving module receives the target alarm sent by the network unit, determine the alarm elimination instruction according to the target alarm.
  • the sending unit is further configured to, after the determining unit determines the alarm clearing instruction, send to the network unit Send the alarm elimination instruction so that the network unit can process the target alarm according to the alarm elimination instruction.
  • the receiving module is further configured to send an alarm elimination instruction to the network unit in the transmitting module After that, the processing result of the target alarm sent by the network unit is received.
  • a fifth aspect of the present application provides a network unit, which includes a processor and a memory.
  • the memory is used to store computer-readable instructions (or referred to as computer programs), and the processor is used to read the computer-readable instructions to implement the foregoing first aspect or the method provided by any one of the first aspects.
  • the network unit also includes a transceiver for receiving and sending information.
  • a fifth aspect of the present application provides a network management unit.
  • the network management unit includes a processor and a memory.
  • the memory is used to store computer-readable instructions (or referred to as computer programs), and the processor is used to read the computer-readable instructions to implement the foregoing second aspect or the method provided by any one of the second aspects.
  • the network management unit further includes a transceiver for receiving and sending information.
  • the seventh aspect of the present application provides a computer storage medium, which may be non-volatile.
  • the computer storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by a processor, the first aspect or the method in any possible implementation manner of the first aspect is implemented.
  • the eighth aspect of the present application provides a computer storage medium, and the computer storage medium may be non-volatile.
  • the computer storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by a processor, the second aspect or the method in any possible implementation manner of the second aspect is implemented.
  • the embodiment of the application adopts an alarm processing method.
  • the network management unit can send an alarm report configuration to the network unit.
  • the alarm report configuration can include the first configuration information or the second configuration information, and the network unit can be associated according to the first configuration information.
  • the multiple alarms of the relationship are correlated and reported, which can improve the efficiency of alarm analysis and locate fault information more accurately.
  • the network unit can also prioritize the target alarm object and/or target alarm type and/or target alarm according to the second configuration information.
  • the alarms corresponding to the alarm level are screened and reported after meeting the reporting conditions, so that when a single alarm problem is repeatedly reported or reported in an interruption, flexible reporting conditions can be set based on the alarm object/alarm type/alarm priority to receive important information in a timely manner. Alarms, effectively and accurately suppress the reporting of redundant and repeated alarms.
  • Figure 1 is a schematic diagram of a network management system provided by an embodiment of the present application.
  • Figure 2 is a schematic diagram of an embodiment of an alarm processing method provided by an embodiment of the present application.
  • Fig. 3 is a schematic diagram of another embodiment of an alarm processing method provided by an embodiment of the present application.
  • FIG. 4 is a schematic diagram of another embodiment of an alarm processing method provided by an embodiment of the present application.
  • Figure 5 is a schematic structural diagram of an alarm processing device provided by an embodiment of the present application.
  • FIG. 6 is a schematic structural diagram of a network unit provided by an embodiment of the present application.
  • FIG. 7 is a schematic structural diagram of another alarm processing device provided by an embodiment of the present application.
  • Fig. 8 is a schematic structural diagram of a network management unit provided by an embodiment of the present application.
  • the embodiment of the present application provides an alarm processing method.
  • the network management unit can send an alarm reporting configuration to the network unit.
  • the alarm reporting configuration can include first configuration information or second configuration information, and the network unit can associate with the first configuration information.
  • the multiple alarms of the relationship are correlated and reported, which can improve the efficiency of alarm analysis and locate fault information more accurately.
  • the network unit can also prioritize the target alarm object and/or target alarm type and/or target alarm according to the second configuration information.
  • the alarms corresponding to the alarm level are screened and reported after meeting the reporting conditions, so that when a single alarm problem is repeatedly reported or reported in an interruption, flexible reporting conditions can be set based on the alarm object/alarm type/alarm priority to receive important information in a timely manner. Alarms, effectively and accurately suppress the reporting of redundant and repeated alarms.
  • the embodiments of the present application also provide corresponding devices and storage media. Detailed descriptions are given below.
  • the naming or numbering of steps appearing in this application does not mean that the steps in the method flow must be executed in the time/logical sequence indicated by the naming or numbering.
  • the named or numbered process steps can be implemented according to the The technical purpose changes the execution order, as long as the same or similar technical effects can be achieved.
  • the division of modules presented in this application is a logical division. In actual applications, there may be other divisions. For example, multiple modules can be combined or integrated in another system, or some features can be ignored
  • the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces, and the indirect coupling or communication connection between the modules may be electrical or other similar forms. There are no restrictions in the application.
  • modules or sub-modules described as separate components may or may not be physically separated, may or may not be physical modules, or may be distributed to multiple circuit modules, and some or all of them may be selected according to actual needs. Module to achieve the purpose of this application program.
  • Fig. 1 is a schematic diagram of a network management system provided by an embodiment of the application.
  • the network management system may include a network management unit 101 and one or more network units 102.
  • the network management unit (NM) 101 in the embodiment of the present application is used for network management, and its configuration meets all requirements for network management.
  • the network unit 102 in the embodiment of the present application may be a network element (managed function, MF) device included in the network, or a network element management unit (element management, EM) that manages the network element device.
  • MF managed function
  • EM network element management unit
  • the network management unit 101 receives the network unit 102 to generate an alarm for a fault generated in the network, then analyzes and makes decisions on the alarm sent by the network unit 102, generates corresponding processing instructions, and sends the processing instructions to the network
  • the unit 102 eliminates the alarm.
  • the alarm processing method provided in the embodiment of the present application will be specifically introduced in the following.
  • Fig. 2 is a schematic diagram of an embodiment of an alarm processing method provided by an embodiment of the application.
  • an embodiment of the alarm processing method provided by the embodiment of the present application may include:
  • the network management unit sends an alarm reporting configuration to the network unit, the alarm reporting configuration includes first configuration information or second configuration information, where the first configuration information is used to indicate the reporting of an alarm event, and the second configuration information is used to indicate the target The reporting conditions of the alarm corresponding to the alarm object and/or target alarm type and/or target alarm priority.
  • the network management unit first sends an alarm reporting configuration to the network unit.
  • the alarm reporting configuration may include first configuration information, and the first configuration information is used to indicate the reporting of an alarm event.
  • the network unit generates an alarm for each failure, and reports the alarms corresponding to each failure one by one.
  • the alarm event is used as an alarm reporting method, which means that the network unit needs to use the alarm event reporting method for alarm reporting.
  • the reporting method of the alarm event in the embodiment of the present application refers to that the network unit uses the target association relationship to associate multiple alarms to generate an alarm event, and then reports the alarm event.
  • the alarm reporting configuration sent by the network management unit to the network unit may also include second configuration information.
  • the second configuration information is used to indicate the target alarm object and/or the target alarm type and/or the target alarm priority. The reporting conditions of the alarms.
  • the alarm object may include an S1 interface, an X2 interface, a cell, a base station, a radio frequency unit, and a power module, etc.
  • Alarm types can include communication alarm, processing error alarm, environment alarm, quality of service alarm, etc.
  • Alarm priority can include critical, major, minor, warning, indeterminate, cleared, etc.
  • the target alarm object may be any of the above-mentioned alarm objects
  • the target alarm type may be any of the above-mentioned alarm types
  • the target alarm priority may be any one of the above-mentioned alarm priorities.
  • the second configuration information sent by the network management unit to the network unit is used to indicate the alarm reporting conditions corresponding to the target alarm object and/or target alarm type and/or target alarm priority.
  • the alarm reporting configuration sent by the network management unit to the network unit may not only include the above-mentioned first configuration information or second configuration information, but also other configuration information.
  • the alarm reporting configuration sent by the network management unit to the network unit includes third configuration information, and the third configuration information is used to instruct the network unit to report the alarm through the above-mentioned traditional alarm reporting method.
  • the embodiment of the present application does not specifically limit the type of configuration information that can be included in the alarm reporting configuration.
  • the network unit determines a target alarm according to the alarm reporting configuration, and the target alarm is used to send to the network management unit.
  • the network unit after receiving the alarm reporting configuration sent by the network management unit, the network unit determines a target alarm according to the alarm reporting configuration, and the target alarm is used to report to the network management unit.
  • the network unit determines that the alarm reporting method is the alarm event reporting, and the network unit will follow the target association rules from The alarm data determines multiple alarms, and then correlates the multiple alarms, and finally generates an alarm event corresponding to the multiple alarms.
  • the target alarm in the embodiment of the present application includes the alarm event, and when the target alarm only includes the alarm event, the alarm event is the target alarm.
  • the target alarm may also include other information, which is not limited in the embodiment of the present application. It should be noted that the above-mentioned alarm data may refer to historical alarm data in the network unit, and the historical alarm data may include a large number of alarms.
  • the network unit when the network unit receives the alarm report configuration sent by the network management unit, and the alarm report configuration contains the second configuration information, the network unit will filter out the alarm data based on the reporting conditions indicated by the second configuration information Unnecessary alarms, filter out the alarms that meet the reporting conditions as target alarms.
  • the second configuration information is used to indicate the reporting conditions of the alarm corresponding to the alarm object A.
  • the network unit When the alarm object A generates an alarm, the network unit will determine whether the generated alarm meets the reporting conditions.
  • the target alarm is used for reporting.
  • the alarm priority of the alarm type B corresponding to the alarm object A is "serious"
  • the network management unit sends the second configuration information to the network unit based on the priority of the alarm type B corresponding to the alarm object A to indicate The reporting condition of the alarm corresponding to the alarm type B corresponding to the alarm object A.
  • the network unit will determine whether the alarm meets the reporting conditions. The target alarm is used for reporting.
  • the network unit after receiving the alarm reporting configuration sent by the network management unit, the network unit can report the target alarm according to the alarm reporting configuration until the new alarm reporting configuration is issued.
  • the network management unit may send an alarm report configuration to the network unit.
  • the alarm report configuration may include the first configuration information or the second configuration information, and the network unit may associate multiple alarms with an association relationship according to the first configuration information. After the association is reported, the efficiency of alarm analysis can be improved, and the fault information can be located more accurately.
  • the network unit can also perform alarms on the target alarm object and/or target alarm type and/or target alarm priority according to the second configuration information. Filtering and reporting after meeting the reporting conditions, so that when a single alarm problem is repeatedly reported or reported in a flash, flexible reporting conditions can be set based on the alarm object/alarm type/alarm priority, and important alarms can be received in time, effectively and accurately Suppress the reporting of redundant and repeated alarms.
  • Fig. 3 is a schematic diagram of another embodiment of an alarm processing method provided by an embodiment of the application.
  • another embodiment of the alarm processing method provided by the embodiment of the present application may include:
  • the network management unit sends first configuration information to the network unit, where the first configuration information is used to indicate the reporting of an alarm event.
  • the network management unit first sends first configuration information to the network unit, and the first configuration information is used to indicate the reporting of an alarm event.
  • the network unit generates an alarm for each failure, and reports the alarms corresponding to each failure one by one.
  • the alarm event is used as an alarm reporting method, which means that the network unit needs to use the alarm event reporting method for alarm reporting.
  • the reporting method of the alarm event in the embodiment of the present application refers to that the network unit uses the target association relationship to associate multiple alarms to generate an alarm event, and then reports the alarm event.
  • the first configuration information in the embodiment of the present application may include one or more of the following information: the reporting mode of the alarm event, the first indication information, and the second indication information, where the first indication The information is used to indicate whether it is necessary to carry the alarm information of multiple alarms associated with the alarm event when the alarm event is reported.
  • the second indication information is used to indicate the target association rule, and the target association rule is used for the network unit to associate multiple alarms. Generate an alarm event.
  • the network unit After receiving the first configuration information, the network unit associates multiple alarms according to the target association rule and generates an alarm event.
  • the network unit after receiving the first configuration information sent by the network management unit, the network unit determines that the alarm reporting mode is alarm event reporting, and the network unit will determine multiple association relationships from the alarm data according to the target association rule Alarms, and then correlate the multiple alarms, and finally generate alarm events corresponding to the multiple alarms.
  • the target alarm in the embodiment of the present application includes the alarm event. When the target alarm only contains the alarm event, the alarm event is the target alarm.
  • the target alarm may also include other information, which is not limited in the embodiment of the present application. It should be noted that the above-mentioned alarm data may refer to historical alarm data in the network unit, and the historical alarm data may include a large number of alarms.
  • the target association rule in the embodiment of the present application may be pre-defined by the network unit.
  • the network unit directly determines the alarm event according to the predetermined target association rule.
  • the target association rule may also be configured by the network management unit through the second indication information in the first configuration information. The embodiment of the application does not limit this.
  • the target association rule in the embodiment of the present application may be one of a plurality of association rules, and the plurality of association rules may include frequency association and network topology structure association. It should be noted that, in addition to the two association rules of frequency association and network topology association, other association rules may be included for alarm association, which is not limited in the embodiment of the present application.
  • the multiple association rules may be association rules stored in the network unit and available, and the network management unit may also send a third instruction like the network unit before sending the first configuration information to the network unit The information is used to instruct the network unit to report the multiple available association rules to the network management unit.
  • the frequency association in the embodiment of the present application refers to the association according to the alarm association frequency of the alarm.
  • the alarm correlation frequency is used to indicate that multiple alarms frequently appear in the same time period.
  • the multiple alarms may be different types of alarms.
  • the network unit frequently associates multiple alarms in the alarm data according to a frequent mining algorithm in a certain period of time. For example, if the number of simultaneous occurrences of alarms 1, 2, and 3 within 5 minutes is 101 times, the alarm frequency is 101.
  • the network unit correlates alarms 1, 2, and 3 according to the alarm frequency.
  • the network topology structure association in the embodiments of the present application refers to the association based on the association relationship of the alarmed network topology structure.
  • the network topology may include logical topology or derivative relationships of the network topology.
  • the multiple alarms can be associated. For example, if there is a network topology connection relationship or a bearer relationship between the alarm 1 and the alarm 2, the alarm 1 and the alarm 2 may belong to one alarm event.
  • the network unit sends a target alarm to the network management unit, where the target alarm includes an alarm event.
  • the network unit after generating the alarm event, the network unit sends a target alarm to the network management unit, and the target alarm includes the alarm event.
  • the alarm event contained in the target alarm may include one or more of the following information: the root cause of the alarm event, the identification of the alarm event, the name of the alarm event, the alarm object, and the alarm event
  • the target alarm may also contain other types of information, which is not limited in the embodiment of the present application.
  • the network management unit determines an alarm elimination instruction according to the target alarm.
  • the network management unit after receiving the target alarm sent by the network unit, the network management unit analyzes the target alarm and determines an alarm elimination instruction to resolve the target alarm.
  • the network management unit sends an alarm elimination instruction to the network unit.
  • the network management unit after determining the alarm elimination instruction to resolve the target alarm, the network management unit sends the alarm elimination instruction to the network unit.
  • the network unit processes the target alarm according to the alarm elimination instruction.
  • the network unit after receiving the alarm elimination instruction sent by the network management unit, the network unit processes the target alarm according to the alarm elimination instruction.
  • the network unit sends the processing result of the target alarm to the network management unit.
  • the network unit sends the processing result of the target alarm to the network management unit after processing the target alarm according to the alarm elimination instruction.
  • the network unit updates the association relationship of the multiple alarms according to the processing result of the target alarm.
  • the network unit after processing the target alarm according to the alarm elimination instruction, updates the association relationship between the multiple alarms associated with the alarm event according to the processing result of the target alarm. For example, the network unit associates alarm 1, alarm 2 and alarm 3 according to the target association rule, and generates an alarm event for reporting. After processing the alarm event according to the alarm elimination instruction sent by the network management unit, only the alarm is eliminated If the problems of 1 and alarm 2, and alarm 3 are not resolved, the network unit update cancels the association between alarm 1, alarm 2 and alarm 3, and only associates alarm 1 and alarm 2.
  • the network unit may associate multiple alarms with an association relationship and report them according to the first configuration information sent by the network management unit, so as to improve the efficiency of alarm analysis and locate fault information more accurately.
  • Fig. 4 is a schematic diagram of another embodiment of an alarm processing method provided by an embodiment of the application.
  • another embodiment of the alarm processing method provided by the embodiment of the present application may include:
  • the network management unit sends second configuration information to the network unit, where the second configuration information is used to indicate the target alarm object and/or the target alarm type and/or the reporting condition of the alarm corresponding to the target alarm priority.
  • the network management unit first sends second configuration information to the network unit, and the second configuration information is used to indicate the target alarm object and/or the target alarm type and/or the reporting condition of the alarm corresponding to the target alarm priority.
  • the alarm object, alarm type, and alarm priority can be understood with reference to the relevant content in step 201 in FIG. 2, and will not be repeated here.
  • the target alarm object may be any of the above-mentioned alarm objects
  • the target alarm type may be any of the above-mentioned alarm types
  • the target alarm priority may be any one of the above-mentioned alarm priorities.
  • the second configuration information sent by the network management unit to the network unit is used to indicate the alarm reporting conditions corresponding to the target alarm object and/or target alarm type and/or target alarm priority.
  • the second configuration information is used to indicate the reporting conditions of the alarm corresponding to the alarm object A.
  • the network unit When the alarm object A generates an alarm, the network unit will determine whether the generated alarm meets the reporting conditions. If the alarm is not met, it will be filtered out, and if it is met, it will be determined Report the target alarm. For example, the alarm priority of the alarm type B corresponding to the alarm object A is "critical", and the network management unit sends the second configuration information to the network unit based on the priority of the alarm type B corresponding to the alarm object A Indicate the reporting condition of the alarm corresponding to the alarm type B corresponding to the alarm object A. When the alarm object A generates an alarm of the alarm type B, the network unit will determine whether the alarm meets the reporting conditions. If the alarm is not met, it will be screened out. Determine to report as the target alarm.
  • the second configuration information may include the alarm flash period T1.
  • the function of the alarm flash cycle T1 is: for the target alarm object and/or target alarm type and/or target alarm priority, if the alarm is automatically restored within the alarm flash cycle TI, the reporting conditions are not met. There is no need to report; within the alarm flash cycle TI, if the alarm is not recovered, the reporting conditions are met. After the flash cycle ends, the network unit determines the alarm as the target alarm.
  • the second configuration information may include parameters: alarm oscillation period T2, incoming oscillation condition N1, out oscillation period T2, and out oscillation condition N2.
  • the above parameters are used to solve the problem that the same alarm is repeatedly reported in large numbers.
  • a specific function of the above parameters may be: for the target alarm object and/or target alarm type and/or target alarm priority corresponding to the alarm, when the alarm is generated, it is determined as the target alarm, and the oscillation process is immediately triggered. In the alarm oscillation period T2, if the number of occurrences of the alarm reaches N1 times, the oscillation process is immediately triggered.
  • the next oscillation period T2 is entered, and the alarm oscillation period is issued until N2 times are not reached in a certain oscillation period T2.
  • the alarm does not meet the reporting conditions and will not be repeatedly reported.
  • the alarm oscillation period T1 is 50S
  • the incoming oscillation condition N3 is 3 occurrences
  • the out oscillation period T2 is 20S
  • the out oscillation period N2 is 2 occurrences.
  • the shock is triggered. If the number of shocks is reached 3 times in 30s, the shock process will be triggered immediately. If it exceeds 2 times within 20S, it will enter the next 20S oscillation period. Until there is a 20S period that does not reach 2 times, an alarm oscillation period is issued. After entering the alarm oscillation period and before exiting the oscillation period, the alarm will not be reported repeatedly.
  • the network unit determines, according to the second configuration information, a target alarm that meets the reporting condition.
  • the network unit filters the alarm data according to the second configuration information, and determines the target alarm that meets the reporting conditions.
  • the network unit sends a target alarm to the network management unit.
  • the network unit after generating an alarm event, the network unit sends a target alarm to the network management unit.
  • the network management unit determines an alarm elimination instruction according to the target alarm.
  • the network management unit after receiving the target alarm sent by the network unit, the network management unit analyzes the target alarm and determines an alarm elimination instruction to resolve the target alarm.
  • the network management unit sends an alarm elimination instruction to the network unit.
  • the network management unit after determining the alarm elimination instruction to resolve the target alarm, the network management unit sends the alarm elimination instruction to the network unit.
  • the network unit processes the target alarm according to the alarm elimination instruction.
  • the network unit after receiving the alarm elimination instruction sent by the network management unit, the network unit processes the target alarm according to the alarm elimination instruction.
  • the network unit sends the processing result of the target alarm to the network management unit.
  • the network unit sends the processing result of the target alarm to the network management unit after processing the target alarm according to the alarm elimination instruction.
  • the network management unit can perform flexible reporting configurations for different alarm objects, alarm types, or alarm priorities, so that important alarms can be received in time, and redundant and repeated alarm reporting can be effectively and accurately suppressed.
  • Fig. 5 is a schematic structural diagram of an alarm processing device provided by an embodiment of the application.
  • the alarm processing device 50 provided by the embodiment of the present application includes:
  • the receiving module 501 is configured to receive an alarm reporting configuration sent by a network management unit, where the alarm reporting configuration includes first configuration information or second configuration information, where the first configuration information is used to indicate the reporting of an alarm event.
  • the second configuration information is used to indicate the target alarm object and/or the target alarm type and/or the reporting condition of the alarm corresponding to the target alarm priority;
  • the determining module 502 is configured to determine a target alarm according to the alarm reporting configuration received by the receiving module 501.
  • the network management unit may send an alarm reporting configuration to the alarm processing device, and the alarm reporting configuration may include the first configuration information or the second configuration information, and the alarm processing device may associate multiple information with an association relationship according to the first configuration information.
  • the alarms are correlated and reported, so that the efficiency of alarm analysis can be improved, and the fault information can be located more accurately.
  • the alarm processing device can also correspond to the target alarm object and/or target alarm type and/or target alarm priority according to the second configuration information.
  • the alarms are filtered and reported after meeting the reporting conditions, so that when a single alarm problem is repeatedly reported or reported in an interruption, flexible reporting conditions can be set based on the alarm object/alarm type/alarm priority to receive important alarms in a timely manner. Effectively and accurately suppress the reporting of redundant and repeated alarms.
  • the determining module 502 is configured to associate multiple alarms and generate an alarm event according to the target association rule; determine the A target alarm, and the target alarm includes the alarm event.
  • the first configuration information includes one or more of the following information: a reporting method of the alarm event, first indication information, and second indication information, where the first indication Information is used to indicate whether the target alarm carries alarm information of the multiple alarms, and the second indication information is used to indicate the target association rule.
  • the target association rule belongs to multiple association rules, and the multiple association rules include frequency association and network topology association.
  • the receiving unit 501 is further configured to receive third indication information sent by the network management unit, where the third indication information is used to indicate whether to report the network management unit to the network management unit. Multiple association rules.
  • the alarm event includes one or more of the following information: the root cause of the alarm event, the identifier of the alarm event, the name of the alarm event, the alarm object, the The alarm type of the alarm event, the fault source of the alarm event, the virtualization identification of the fault source, the occurrence time of the alarm event, the elimination event of the alarm event, and the alarm information of the multiple alarms.
  • the determining module 502 is configured to determine a target alarm that meets the reporting condition according to the second configuration information.
  • the second configuration information includes an alarm flash period
  • the determining module is configured to determine whether the first alarm is restored within the alarm flash period; if it is not restored, determine all The first alarm is the target alarm.
  • the second configuration information includes an alarm oscillation period, an in-oscillation condition, an out-oscillation period, and an out-oscillation condition.
  • the determining module 502 is configured to be configured according to the alarm oscillation period, the in- The oscillation condition, the oscillation period, and the oscillation condition determine whether the second alarm satisfies the reporting condition; if so, it is determined that the second alarm is the target alarm.
  • the alarm processing apparatus 50 further includes: a sending module 503, configured to send the target alarm to the network management unit after the determining module 502 determines the target alarm according to the alarm reporting configuration.
  • the receiving module 501 is further configured to receive an alarm elimination instruction sent by the network management unit after the sending module 503 sends the target alarm to the network management unit, where the alarm elimination instruction is network management The unit is determined based on the target alarm.
  • the alarm processing apparatus further includes: a processing module 504 configured to process the target alarm according to the alarm elimination instruction after the receiving module 501 receives the alarm elimination instruction sent by the network management unit.
  • the sending module 503 is further configured to send the target alarm to the network management unit after the processing module 504 processes the target alarm according to the alarm elimination instruction The result of processing.
  • the alarm processing device further includes: an update module 505, configured to process the target alarm according to the target alarm after the processing module 504 processes the target alarm according to the alarm elimination instruction As a result, the association relationship of the multiple alarms is updated.
  • the embodiment of the present application further provides a network unit 60, which includes a processor 610, a memory 620, and a transceiver 630.
  • the memory 620 stores instructions or programs, and the processor 610 is used to execute instructions stored in the memory 620. Or program.
  • the processor 610 is configured to execute the operations performed by the determining module 502, the processing module 504, and the updating module 505 in the foregoing embodiment, and the transceiver 630 is configured to execute the receiving module in the foregoing embodiment 501 and the operation performed by the sending module 503.
  • the alarm processing apparatus 50 or the network unit 60 may correspond to the network unit in the alarm processing method of the embodiment of the present application, and the operation and/or operation of each module in the alarm processing apparatus 50 or the network unit 60 Or the function is to realize the corresponding process of each method in FIG. 2 to FIG. 4, and for the sake of brevity, it will not be repeated here.
  • FIG. 7 is a schematic structural diagram of an alarm processing apparatus provided by an embodiment of the application.
  • the alarm processing device 70 provided by the embodiment of the present application includes:
  • the sending module 701 is configured to send an alarm reporting configuration to a network unit, where the alarm reporting configuration includes first configuration information or second configuration information, where the first configuration information is used to indicate the reporting of an alarm event, and the second The configuration information is used to indicate the reporting conditions of the target alarm object and/or the target alarm type and/or the alarm corresponding to the target alarm priority;
  • the receiving module 702 is configured to receive a target alarm sent by the network unit after the sending module 701 sends the alarm reporting configuration, where the target alarm is determined by the network unit according to the alarm reporting configuration.
  • the target alarm when the alarm reporting configuration includes the first configuration information, the target alarm includes an alarm event, and the alarm event is that the network unit performs a check on the multiple The alarms are correlated and generated.
  • the first configuration information includes one or more of the following information: a reporting method of the alarm event, first indication information, and second indication information, where the first indication Information is used to indicate whether the target alarm carries alarm information of the multiple alarms, and the second indication information is used to indicate the target association rule.
  • the target association rule belongs to multiple association rules, and the multiple association rules include frequency association and network topology association.
  • the sending module 701 is further configured to send third indication information to the network unit before sending the alarm report configuration to the network unit, where the third indication information is used to indicate whether the network unit reports the multiple Association rules.
  • the alarm event includes one or more of the following information: the root cause of the alarm event, the identifier of the alarm event, the name of the alarm event, the alarm object, the The alarm type of the alarm event, the fault source of the alarm event, the virtualization identification of the fault source, the occurrence time of the alarm event, the elimination event of the alarm event, and the alarm information of the multiple alarms.
  • the target alarm is determined by the network element according to the second configuration information, and the target alarm satisfies the Escalation conditions.
  • the second configuration information includes an alarm flash cycle
  • the target alarm is determined by the network unit after judging that the first alarm has not recovered within the alarm flash cycle, so The first alarm is the target alarm.
  • the second configuration information includes an alarm oscillation period, an in-oscillation condition, an out-oscillation period, and an out-oscillation condition
  • the target alarm is when the network unit is operating according to the alarm oscillation period
  • the input oscillation condition, the oscillation period, and the oscillation condition are determined when it is determined whether the second alarm satisfies the reporting condition, and when the second alarm satisfies the reporting condition, the second alarm Alarm for the target.
  • the alarm processing device 70 further includes: a determining module 703, configured to determine an alarm elimination instruction according to the target alarm after the receiving module 702 receives the target alarm sent by the network unit.
  • the sending module 701 is further configured to send the alarm elimination instruction determined by the determining module 703 to the network unit, so that the network unit responds to the alarm elimination instruction according to the alarm elimination instruction.
  • the target alarm is processed.
  • the receiving module 702 is further configured to receive the target alarm sent by the network unit after the sending module 701 sends the alarm clearing instruction to the network unit. result.
  • the embodiment of the present application also provides a network management unit 80.
  • the network management unit 80 includes a processor 810, a memory 820, and a transceiver 830.
  • the memory 820 stores instructions or programs, and the processor 810 is configured to execute Instructions or procedures.
  • the processor 810 is used to perform the operations performed by the determining module 703 in the foregoing embodiment
  • the transceiver 830 is used to perform the operations performed by the sending module 701 and the receiving module 702 in the foregoing embodiment .
  • the alarm processing device 70 or the network management unit 80 may correspond to the network management unit in the alarm processing method of the embodiment of the present application, and the alarm processing device 70 or each module in the network management unit 80
  • the operations and/or functions are used to implement the corresponding procedures of the methods in FIGS. 2 to 4, and are not repeated here for the sake of brevity.
  • an embodiment of the present application further provides a chip system
  • the chip system includes a processor, and is configured to support a network unit to implement the above alarm processing method.
  • the chip system also includes memory.
  • the memory is used to store the necessary program instructions and data of the network unit.
  • the chip system may be composed of a chip, or may include a chip and other discrete devices, which is not specifically limited in the embodiment of the present application.
  • an embodiment of the present application further provides a chip system
  • the chip system includes a processor, and is configured to support the network management unit to implement the above-mentioned alarm processing method.
  • the chip system also includes memory.
  • the memory is used to store the necessary program instructions and data of the network management unit.
  • the chip system may be composed of a chip, or may include a chip and other discrete devices, which is not specifically limited in the embodiment of the present application.
  • the processor in the embodiments of the present application may be a central processing unit (Central Processing Unit, CPU), or other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits. (Application Specific Integrated Circuit, ASIC), Field Programmable Gate Array (Field Programmable Gate Array, FPGA) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof.
  • the general-purpose processor may be a microprocessor or any conventional processor.
  • the method steps in the embodiments of the present application can be implemented by hardware, and can also be implemented by a processor executing software instructions.
  • Software instructions can be composed of corresponding software modules, which can be stored in random access memory (Random Access Memory, RAM), flash memory, read-only memory (Read-Only Memory, ROM), and programmable read-only memory (Programmable ROM) , PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), register, hard disk, mobile hard disk, CD-ROM or well-known in the art Any other form of storage medium.
  • RAM Random Access Memory
  • ROM read-only memory
  • PROM programmable read-only memory
  • Erasable PROM Erasable PROM
  • EPROM electrically erasable programmable read-only memory
  • register hard disk, mobile hard disk, CD-ROM or well-known in the art Any other form of storage medium.
  • An exemplary storage medium is coupled to the processor, so that the processor can read information from the storage medium and write information to the storage medium.
  • the storage medium may also be an integral part of the processor.
  • the processor and the storage medium may be located in the ASIC.
  • the ASIC may be located in the network unit or the network management unit.
  • the processor and the storage medium may also exist as discrete components in the network unit or the network management unit.
  • the above embodiments it may be implemented in whole or in part by software, hardware, firmware, or any combination thereof.
  • software it can be implemented in the form of a computer program product in whole or in part.
  • the computer program product includes one or more computer programs or instructions.
  • the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
  • the computer program or instruction may be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium.
  • the computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server integrating one or more available media.
  • the usable medium may be a magnetic medium, such as a floppy disk, a hard disk, and a magnetic tape; it may also be an optical medium, such as a DVD; and it may also be a semiconductor medium, such as a solid state disk (SSD).
  • “at least one” refers to one or more, and “multiple” refers to two or more.
  • “And/or” describes the association relationship of the associated objects, indicating that there can be three relationships, for example, A and/or B, which can mean: A alone exists, A and B exist at the same time, and B exists alone, where A, B can be singular or plural.
  • the character "/” generally indicates that the associated objects before and after are in an "or” relationship.

Abstract

本申请公开了一种告警处理方法,包括:网络单元接收网络管理单元发送的告警上报配置,告警上报配置包括用于指示告警事件上报的第一配置信息,或用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警上报条件的第二配置信息;网络单元根据告警上报配置确定目标告警并发送给网络管理单元以使网络管理单元确定对应的告警消除指示。本申请技术方案可以提升告警分析效率,精准地定位故障信息,还可以有效抑制冗余和重复告警的上报。

Description

一种告警处理方法、装置以及存储介质
本申请要求于2019年12月31日提交中国专利局、申请号为201911422159.1、发明名称为“一种告警处理方法、装置以及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信技术领域,具体涉及一种告警处理方法、装置以及存储介质。
背景技术
随着通信网络的发展,网络组网结构日趋庞大和复杂。网络中包含了大量的网元设备,在日常的网络维护中,需要及时发现网元设备发生的故障,生成故障告警并对故障做相应的处理,其中故障的类型包括:X2接口故障,S1口故障,驻波故障,电源类故障等等。复杂的网络结构带来的海量告警的产生和上报对网络运维人员造成了巨大的压力,故障分析工作量大,效率低。
随着人工智能(artificial intelligence,AI)的发展,越来越多的机器学习算法,智能算法被应用到各个领域。AI技术基于强大的存储和计算能力可以用来帮助解决人工应对的大量数据处理和分析以及基于数据的学习工作。在网络运维中引入AI技术已经成为未来网络智能化运维的趋势,如通过各类自适应算法,如频繁项挖掘,自适应参数寻优算法对网络故障告警做智能化分析和处理并上报给网络管理单元,提升网络运维效率。
传统技术中,网络侧针对每个故障都会生成一个告警,同时上报给网络管理单元,由运维人员进行人工分析以及处理大量的告警事件。对于告警闪断和告警震荡,在网元侧固定数值设置告警的闪断周期和震荡周期,避免上报大量冗余和重复告警。
传统的告警技术中,告警独立呈现,有逻辑关系或衍生关系的多个告警问题并未关联起来,因此所产生的海量告警使得人工分析工作量大且效率低。在处理单个告警问题重复上报或闪断告警问题上报时,并未根据告警对象及告警类型设置灵活上报配置,可能导致某些重要的告警信息未及时上报,或者非重要告警过量上报。
发明内容
本申请实施例提供一种告警处理方法,能够提升告警分析的效率,更加精准的定位故障信息或在处理单个告警问题重复上报或闪断上报时,基于告警对象/告警类型/告警优先级设置灵活的上报条件,及时收到重要的告警,有效精确的抑制冗余和重复告警的上报。
为了达到上述目的,本申请提供如下技术方案:
本申请第一方面提供一种告警处理方法,可以应用于各个制式的网络系统中的网络运维,该方法包括:接收网络管理单元发送的告警上报配置,该告警上报配置包括第一配置信息或第二配置信息,其中,第一配置信息用于指示告警事件的上报,告警事件是作为一种告警上报方式,是指网络单元需要采用告警事件的上报方式进行告警上报,告警事件的上报方式是指网络单元采用目标关联关系将多个具备关联关系告警进行关联生成告警事 件,然后进行该告警事件的上报。第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;根据告警上报配置确定目标告警。
由以上第一方面可知,网络管理单元可以向网络单元发送告警上报配置,该告警上报配置可以包括第一配置信息或第二配置信息,网络单元可以根据第一配置信息将具备关联关系的多个告警进行关联后上报,从而可以提升告警分析的效率,更加精准的定位故障信息,网络单元也可以根据第二配置信息对目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警进行筛选,满足上报条件后再上报,从而能够在处理单个告警问题重复上报或闪断上报时,基于告警对象/告警类型/告警优先级设置灵活的上报条件,及时收到重要的告警,有效精确的抑制冗余和重复告警的上报。
可选地,结合本申请的第一方面,在本申请第一方面第一种可能的实现方式中,当告警上报配置包括第一配置信息时,根据告警上报配置确定目标告警,包括:根据目标关联规则对多个告警进行关联并生成告警事件;确定目标告警,目标告警包括告警事件。当目标告警只包含告警事件时,该告警事件即为目标告警。目标告警中除了包含告警事件外,还可以包含其他的信息。目标关联规则可以是网络单元预先规定好的,当需要进行告警事件上报时,网络单元直接根据该预先规定的目标关联规则确定告警事件。目标关联规则也可以是网络管理单元通过第一配置信息包含的指示信息配置的。
可选地,结合本申请第一方面第一种可能的实现方式,在本申请第一方面第二种可能的实现方式中,第一配置信息包括如下信息中的一个或多个:告警事件的上报方式、第一指示信息和第二指示信息,其中,第一指示信息用于指示目标告警中是否携带多个告警的告警信息,第二指示信息用于指示目标关联规则。
可选地,结合本申请第一方面第一种或第二种可能的实现方式,在本申请第一方面第三种可能的实现方式中,目标关联规则属于多个关联规则,多个关联规则包括频繁度关联和网络拓扑结构关联。频繁度关联是指根据告警的告警关联频繁度进行关联。该告警关联频繁度用于指示多个告警在同一个时间段内频繁出现,网络单元根据某个时间段内频繁挖掘算法对告警数据中的多个告警进行频繁度关联。网络拓扑结构关联是指根据告警的网络拓扑结构的关联关系进行关联,该网络拓扑结构可以包括网络拓扑的逻辑拓扑或衍生关系等。
可选地,结合本申请第一方面第三种可能的实现方式,在本申请第一方面第四种可能的实现方式中,接收网络管理单元发送的告警上报配置之前,还包括:接收网络管理单元发送的第三指示信息,该第三指示信息用于指示是否向网络管理单元上报该多个关联规则。该多个关联规则可以是存储在网络单元中可用的关联规则,网络管理单元可以通过向网络单元发送第三指示信息,指示网络单元向网络管理单元上报该多个关联规则。
可选地,结合本申请第一方面第一种至第四种中任意一种可能的实现方式,在本申请第一方面第五种可能的实现方式中,告警事件可以包括如下信息中的一个或多个:告警事件的根因、告警事件的标识、告警事件的名称、告警对象、告警事件的告警类型、告警事件的故障源、故障源的虚拟化标识、告警事件的发生时间、告警事件的消除事件、多个告警的告警信息。
可选地,结合本申请的第一方面,在本申请第一方面第六种可能的实现方式中,当告警上报配置包括第二配置信息时,根据告警上报配置确定目标告警,包括:根据第二配置信息确定满足上报条件的目标告警。
可选地,结合本申请第一方面第六种可能的实现方式,在本申请第一方面第七种可能的实现方式中,第二配置信息包括告警闪断周期,根据告警上报配置确定满足上报条件的目标告警,包括:判断第一告警在告警闪断周期内是否恢复;若未恢复,则确定第一告警为目标告警。
可选地,结合本申请第一方面第六种可能的实现方式,在本申请第一方面第八种可能的实现方式中,第二配置信息包括告警震荡周期、入震荡条件、出震荡周期和出震荡条件,根据告警上报配置确定满足上报条件的目标告警,包括:根据告警震荡周期、入震荡条件、出震荡周期和出震荡条件判断第二告警是否满足上报条件;若是,则确定第二告警为目标告警。
可选地,结合本申请第一方面、第一方面第一种至第八种可能的实现方式,在本申请第一方面第九种可能的实现方式中,根据告警上报配置确定目标告警之后,还包括:向网络管理单元发送目标告警。
可选地,结合本申请第一方面第九种可能的实现方式,在本申请第一方面第十种可能的实现方式中,向网络管理单元发送目标告警之后,还包括:接收网络管理单元发送的告警消除指示,告警消除指示是网络管理单元根据目标告警确定的。
可选地,结合本申请第一方面第十种可能的实现方式,在本申请第一方面第十一种可能的实现方式中,接收网络管理单元发送的告警消除指示之后,还包括:根据告警消除指示对目标告警进行处理。
可选地,结合本申请第一方面第十一种可能的实现方式,在本申请第一方面第十二种可能的实现方式中,根据告警消除指示对目标告警进行处理之后,还包括:向网络管理单元发送目标告警的处理结果。
可选地,结合本申请第一方面第十一种或第十二种可能的实现方式,在本申请第一方面第十三种可能的实现方式中,当告警上报配置包括第一配置信息时,根据告警消除指示对目标告警进行处理之后,还包括:根据目标告警的处理结果更新多个告警的关联关系。
本申请第二方面提供一种告警处理方法,可以应用于各个制式的网络系统中的网络运维,该方法包括:向网络单元发送告警上报配置,告警上报配置包括第一配置信息或第二配置信息,其中,第一配置信息用于指示告警事件的上报,第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;接收网络单元发送的目标告警,目标告警是网络单元根据告警上报配置确定的。
可选地,结合本申请的第二方面,在本申请第二方面第一种可能的实现方式中,当告警上报配置包括第一配置信息时,目标告警包括告警事件,告警事件是网络单元根据目标关联规则对多个告警进行关联并生成的。
可选地,结合本申请第二方面第一种可能的实现方式,在本申请第二方面第二种可能的实现方式中,所述第一配置信息包括如下信息中的一个或多个:告警事件的上报方式、 第一指示信息和第二指示信息,其中,第一指示信息用于指示目标告警中是否携带多个告警的告警信息,第二指示信息用于指示目标关联规则。
可选地,结合本申请第二方面第一种或第二种可能的实现方式,在本申请第二方面第三种可能的实现方式中,目标关联规则属于多个关联规则,该多个关联规则包括频繁度关联和网络拓扑结构关联。
可选地,结合本申请第二方面第三种可能的实现方式,结合本申请第二方面第三种可能的实现方式中,向网络单元发送告警上报配置之前,还包括:向网络单元发送第三指示信息,该第三指示信息用于指示网络单元是否上报该多个关联规则。该多个关联规则可以是存储在网络单元中可用的关联规则,网络管理单元可以通过向网络单元发送第三指示信息,指示网络单元向网络管理单元上报该多个关联规则。
可选地,结合本申请第二方面第一种至第四种中任意一种可能的实现方式,在本申请第二方面第五种可能的实现方式中,告警事件包括如下信息中的一个或多个:告警事件的根因、告警事件的标识、告警事件的名称、告警对象、告警事件的告警类型、告警事件的故障源、故障源的虚拟化标识、告警事件的发生时间、告警事件的消除事件、多个告警的告警信息。
可选地,结合本申请的第二方面,在本申请第二方面第六种可能的实现方式中,当告警上报配置包括第二配置信息时,目标告警是网络单元根据第二配置信息确定的,目标告警满足该上报条件。
可选地,结合本申请第二方面第六种可能的实现方式,在本申请第二方面第七种可能的实现方式中,第二配置信息包括告警闪断周期,目标告警是网络单元在判断第一告警在告警闪断周期内未恢复后确定的,第一告警为目标告警。
可选地,结合本申请第二方面第七种可能的实现方式,在本申请第二方面第八种可能的实现方式中,第二配置信息包括告警震荡周期、入震荡条件、出震荡周期和出震荡条件,目标告警是网络单元根据该告警震荡周期、入震荡条件、出震荡周期和出震荡条件判断第二告警是否满足上报条件确定的,当第二告警满足上报条件时,第二告警为目标告警。
可选地,结合本申请第二方面、第二方面第一种至第八种可能的实现方式,在本申请第二方面第九种可能的实现方式中,接收网络单元发送的目标告警之后,还包括:根据目标告警确定告警消除指示。
可选地,结合本申请第二方面第九种可能的实现方式,在本申请第二方面第十种可能的实现方式中,根据目标告警确定告警消除指示之后,还包括:向网络单元发送告警消除指示,以使网络单元根据告警消除指示对目标告警进行处理。
可选地,结合本申请第二方面第十种可能的实现方式,在本申请第二方面第十一种可能的实现方式中,向网络单元发送告警消除指示之后,还包括:接收网络单元发送的目标告警的处理结果。
本申请第三方面提供一种告警处理装置,可以应用于各个制式的网络系统中的网络运维,该装置包括:接收模块,用于接收网络管理单元发送的告警上报配置,告警上报配置包括第一配置信息或第二配置信息,其中,第一配置信息用于指示告警事件的上报,第二 配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;确定模块,用于根据接收模块接收的告警上报配置确定目标告警。
可选地,结合本申请的第三方面,在本申请第三方面第一种可能的实现方式中,当告警上报配置包括第一配置信息时,确定模块,用于根据目标关联规则对多个告警进行关联并生成告警事件;确定目标告警,目标告警包括该告警事件。
可选地,结合本申请第三方面第一种可能的实现方式,在本申请第三方面第二种可能的实现方式中,第一配置信息包括如下信息中的一个或多个:告警事件的上报方式、第一指示信息和第二指示信息,其中,第一指示信息用于指示目标告警中是否携带多个告警的告警信息,第二指示信息用于指示目标关联规则。
可选地,结合本申请第三方面第一种或第二种可能的实现方式,在本申请第三方面第三种可能的实现方式中,目标关联规则属于多个关联规则,多个关联规则包括频繁度关联和网络拓扑结构关联。
可选地,结合本申请第三方面第三种可能的实现方式,在本申请第三方面第四种可能的实现方式中,所述接收模块,还用于在接收网络管理单元发送的告警上报配置之前,接收网络管理单元发送的第三指示信息,该第三指示信息用于指示是否向网络管理单元上报该多个关联规则。
可选地,结合本申请第三方面第一种至第四种中任意一种可能的实现方式,在本申请第三方面第五种可能的实现方式中,告警事件包括如下信息中的一个或多个:告警事件的根因、告警事件的标识、所述告警事件的名称、告警对象、告警事件的告警类型、告警事件的故障源、故障源的虚拟化标识、告警事件的发生时间、告警事件的消除事件、多个告警的告警信息。
可选地,结合本申请的第三方面,在本申请第三方面第六种可能的实现方式中,当告警上报配置包括第二配置信息时,确定模块,用于根据第二配置信息确定满足上报条件的目标告警。
可选地,结合本申请第三方面第六种可能的实现方式,在本申请第三方面第七种可能的实现方式中,第二配置信息包括告警闪断周期,确定模块,用于判断第一告警在告警闪断周期内是否恢复;若未恢复,则确定第一告警为所述目标告警。
可选地,结合本申请第三方面第六种可能的实现方式,在本申请第三方面第八种可能的实现方式中,第二配置信息包括告警震荡周期、入震荡条件、出震荡周期和出震荡条件,确定模块,用于根据告警震荡周期、入震荡条件、出震荡周期和出震荡条件判断第二告警是否满足上报条件;若是,则确定第二告警为目标告警。
可选地,结合本申请第三方面、第三方面第一种至第八种中任意一种可能的实现方式,在本申请第三方面第九种可能的实现方式中,该告警处理装置还包括:发送模块,用于在确定模块确定目标告警之后,向网络管理单元发送该目标告警。
可选地,结合本申请第三方面第九种可能的实现方式,在本申请第三方面第十种可能的实现方式中,接收模块还用于在发送模块向网络管理单元发送该目标告警之后,接收网络管理单元发送的告警消除指示,该告警消除指示是网络管理单元根据目标告警确定的。
可选地,结合本申请第三方面第十种可能的实现方式,在本申请第三方面第十一种可能的实现方式中,该告警处理装置还包括:处理模块,用于在接收模块接收网络管理单元发送的告警消除指示之后,根据该告警消除指示对目标告警进行处理。
可选地,结合本申请第三方面第十一种可能的实现方式,在本申请第三方面第十二种可能的实现方式中,发送模块,还用于在处理模块根据告警消除指示对目标告警进行处理之后,向网络管理单元发送目标告警的处理结果。
可选地,结合本申请第三方面第十一种或第十二种可能的实现方式,在本申请第三方面第十三种可能的实现方式中,该告警处理装置还包括:更新模块,用于在处理模块根据告警消除指示对目标告警进行处理之后,根据目标告警的处理结果更新多个告警的关联关系。
本申请第四方面提供一种告警处理装置,可以应用于各个制式的网络系统中的网络运维,该装置包括:发送模块,用于向网络单元发送告警上报配置,告警上报配置包括第一配置信息或第二配置信息,其中,第一配置信息用于指示告警事件的上报,第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;接收模块,用于在发送模块发送所述告警上报配置之后,接收网络单元发送的目标告警,目标告警是网络单元根据告警上报配置确定的。
可选地,结合本申请的第四方面,在本申请第四方面第一种可能的实现方式中,当告警上报配置包括第一配置信息时,该目标告警包括告警事件,告警事件是网络单元根据目标关联规则对多个告警进行关联并生成的。
可选地,结合本申请第四方面第一种可能的实现方式,在本申请第四方面第二种可能的实现方式中,第一配置信息包括如下信息中的一个或多个:告警事件的上报方式、第一指示信息和第二指示信息,其中,第一指示信息用于指示目标告警中是否携带多个告警的告警信息,第二指示信息用于指示目标关联规则。
可选地,结合本申请第四方面第一种或第二种可能的实现方式,在本申请第四方面第三种可能的实现方式中,目标关联规则属于多个关联规则,该多个关联规则包括频繁度关联和网络拓扑结构关联。
可选地,结合本申请第四方面第三种可能的实现方式,本申请第四方面第五种可能的实现方式中,发送模块还用于在向网络单元发送告警上报配置之前,向网路单元发送第三指示信息,该第三指示信息用于指示网络单元是否上报该多个关联规则。
可选地,结合本申请第四方面第一种至第四种中任意一种可能的实现方式,在本申请第四方面第五种可能的实现方式中,告警事件包括如下信息中的一个或多个:告警事件的根因、告警事件的标识、告警事件的名称、告警对象、告警事件的告警类型、告警事件的故障源、故障源的虚拟化标识、告警事件的发生时间、告警事件的消除事件、多个告警的告警信息。
可选地,结合本申请的第四方面,在本申请第四方面第六种可能的实现方式中,当告警上报配置包括第二配置信息时,目标告警是网络单元根据第二配置信息确定的,目标告警满足上报条件。
可选地,结合本申请第四方面第六种可能的实现方式,在本申请第四方面第七种可能的实现方式中,第二配置信息包括告警闪断周期,目标告警是网络单元在判断第一告警在告警闪断周期内未恢复后确定的,第一告警为目标告警。
可选地,结合本申请第四方面第六种可能的实现方式,在本申请第四方面第八种可能的实现方式中,第二配置信息包括告警震荡周期、入震荡条件、出震荡周期和出震荡条件,目标告警是网络单元在根据告警震荡周期、入震荡条件、出震荡周期和出震荡条件判断第二告警是否满足上报条件时确定的,当满足上报条件时,该第二告警为目标告警。
可选地,结合本申请第四方面、第四方面第一种至第八种可能的实现方式,在本申请第四方面第九种可能的实现方式中,该告警处理装置还包括:确定模块,用于在接收模块接收网络单元发送的目标告警之后,根据目标告警确定告警消除指示。
可选地,结合本申请第四方面第九种可能的实现方式,在本申请第四方面第十种可能的实现方式中,发送单元还用于在确定单元确定告警消除指示之后,向网络单元发送告警消除指示,以使网络单元根据告警消除指示对目标告警进行处理。
可选地,结合本申请第四方面第十种可能的实现方式,在本申请第四方面第十一种可能的实现方式中,接收模块,还用于在发送模块向网络单元发送告警消除指示之后,接收网络单元发送的目标告警的处理结果。
本申请第五方面提供一种网络单元,该网络单元包括处理器和存储器。存储器用于存储计算机可读指令(或者称之为计算机程序),处理器用于读取所述计算机可读指令以实现前述第一方面或第一方面任意一种实现方式提供的方法。
在一些实现方式下,该网络单元还包括收发器,用于接收和发送信息。
本申请第五方面提供一种网络管理单元,该网络管理单元包括处理器和存储器。存储器用于存储计算机可读指令(或者称之为计算机程序),处理器用于读取所述计算机可读指令以实现前述第二方面或第二方面任意一种实现方式提供的方法。
在一些实现方式下,该网络管理单元还包括收发器,用于接收和发送信息。
本申请第七方面提供一种计算机存储介质,该计算机存储介质可以是非易失性的。该计算机存储介质中存储有计算机可读指令,当该计算机可读指令被处理器执行时实现第一方面或第一方面的任一可能的实现方式中的方法。
本申请第八方面提供一种计算机存储介质,该计算机存储介质可以是非易失性的。该计算机存储介质中存储有计算机可读指令,当该计算机可读指令被处理器执行时实现第二方面或第二方面的任一可能的实现方式中的方法。
本申请实施例采用一种告警处理方法,网络管理单元可以向网络单元发送告警上报配置,该告警上报配置可以包括第一配置信息或第二配置信息,网络单元可以根据第一配置信息将具备关联关系的多个告警进行关联后上报,从而可以提升告警分析的效率,更加精准的定位故障信息,网络单元也可以根据第二配置信息对目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警进行筛选,满足上报条件后再上报,从而能够在处理单个告警问题重复上报或闪断上报时,基于告警对象/告警类型/告警优先级设置灵活的上报条件,及时收到重要的告警,有效精确的抑制冗余和重复告警的上报。
附图说明
图1是本申请实施例提供的网络管理系统的示意图;
图2是本申请实施例提供的告警处理方法的一个实施例示意图;
图3是本申请实施例提供的告警处理方法的另一个实施例示意图;
图4是本申请实施例提供的告警处理方法的另一个实施例示意图;
图5是本申请实施例提供的告警处理装置的结构示意图;
图6是本申请实施例提供的网络单元的结构示意图;
图7是本申请实施例提供的另一个告警处理装置的结构示意图;
图8是本申请实施例提供的网络管理单元的结构示意图。
具体实施方式
为了使本发明的目的、技术方案及优点更加清楚明白,下面结合附图,对本申请的实施例进行描述,显然,所描述的实施例仅仅是本发明一部分的实施例,而不是全部的实施例。本领域普通技术人员可知,随着新应用场景的出现,本发明实施例提供的技术方案对于类似的技术问题,同样适用。
本申请实施例提供一种告警处理方法,网络管理单元可以向网络单元发送告警上报配置,该告警上报配置可以包括第一配置信息或第二配置信息,网络单元可以根据第一配置信息将具备关联关系的多个告警进行关联后上报,从而可以提升告警分析的效率,更加精准的定位故障信息,网络单元也可以根据第二配置信息对目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警进行筛选,满足上报条件后再上报,从而能够在处理单个告警问题重复上报或闪断上报时,基于告警对象/告警类型/告警优先级设置灵活的上报条件,及时收到重要的告警,有效精确的抑制冗余和重复告警的上报。本申请实施例还提供相应的装置及存储介质。以下分别进行详细说明。
本申请的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的实施例能够以除了在这里图示或描述的内容以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或模块的过程、方法、系统、产品或设备不必限于清楚地列出的那些步骤或模块,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或模块。在本申请中出现的对步骤进行的命名或者编号,并不意味着必须按照命名或者编号所指示的时间/逻辑先后顺序执行方法流程中的步骤,已经命名或者编号的流程步骤可以根据要实现的技术目的变更执行次序,只要能达到相同或者相类似的技术效果即可。本申请中所出现的模块的划分,是一种逻辑上的划分,实际应用中实现时可以有另外的划分方式,例如多个模块可以结合成或集成在另一个系统中,或一些特征可以忽略,或不执行,另外,所显示的或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,模块之间的间接耦合或通信连接可以是电性或其他类似的形式,本申请中均不作限定。并 且,作为分离部件说明的模块或子模块可以是也可以不是物理上的分离,可以是也可以不是物理模块,或者可以分布到多个电路模块中,可以根据实际的需要选择其中的部分或全部模块来实现本申请方案的目的。
图1为本申请实施例提供的网络管理系统的示意图。
参阅图1,本申请实施例提供的网络管理系统,可以包括网络管理单元101,以及一个或多个网络单元102。
本申请实施例中的网络管理单元(network management,NM)101用于进行网络管理,其配置满足网络管理的所有要求。本申请实施例中的网络单元102可以是网络中包含的网元(managed function,MF)设备,或者对网元设备进行管理的网元管理单元(element management,EM)。
本申请实施例中,网络管理单元101接收网络单元102针对网络中产生的故障生成告警,然后对网络单元102发送的告警进行分析和决策,生成对应的处理指示,并将处理指示下发给网络单元102进行告警的消除。基于图1中的网络管理系统,接下来将对本申请实施例提供的告警处理方法进行具体的介绍。
图2为本申请实施例提供的告警处理方法的一个实施例示意图。
参阅图2,本申请实施例提供的告警处理方法的一个实施例,可以包括:
201、网络管理单元向网络单元发送告警上报配置,该告警上报配置包括第一配置信息或第二配置信息,其中,第一配置信息用于指示告警事件的上报,第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件。
本申请实施例中,网络管理单元首先向网络单元发送告警上报配置,该告警上报配置可以包括第一配置信息,该第一配置信息用于指示告警事件的上报。需要说明的是,传统的告警上报方式中,网络单元针对每个故障都会生成一个告警,对于该每个故障对应的告警都进行一一上报。而本申请实施例中,告警事件是作为一种告警上报方式,是指网络单元需要采用告警事件的上报方式进行告警上报。本申请实施例中告警事件的上报方式是指网络单元采用目标关联关系将多个告警进行关联生成告警事件,然后进行该告警事件的上报。
本申请实施例中,网络管理单元向网络单元发送的告警上报配置也可以包括第二配置信息,该第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件。
本申请实施例中,告警对象可以包括S1接口、X2接口、小区、基站、射频单元和电源模块等,除此之外,还可以包含其他的告警对象。告警类型可以包括传输告警(communication alarm)、进程错误告警(processing error alarm)、环境告警(environment alarm)、业务质量告警(quality of service alarm)等,除此之外,还可以包含其他的告警类型。告警优先级可以包括严重(critical)、主要(major)、次要(minor)、警告(warning)、不确定(indeterminate)和消除(cleared)等,除此之外,也可以是其他的优先级等级划分。本申请实施例中,目标告警对象可以是上述告警对象中的任意一个,目标告警类型可以是上述告警类型中的任意一种,目标告警优先级可以是上 述告警优先级中的任意一个级别。本申请实施例中,网络管理单元向网络单元发送的第二配置信息,用于指示对应于该目标告警对象和/或目标告警类型和/或目标告警优先级的告警的上报条件。
需要说明的是,本申请实施例中,网络管理单元向网络单元发送的告警上报配置除了可以包含上述的第一配置信息或第二配置信息,还可以是包含其他的配置信息。例如,网络管理单元向网络单元发送的告警上报配置包含第三配置信息,该第三配置信息用于指示网络单元通过上述传统的告警上报方式进行告警上报。本申请实施例对告警上报配置可以包含的配置信息的类型不作具体的限定。
202、网络单元根据告警上报配置确定目标告警,该目标告警用于发送给网络管理单元。
本申请实施例中,网络单元在接收到网络管理单元发送的告警上报配置后,根据该告警上报配置确定目标告警,该目标告警用于上报给网络管理单元。
具体的,当网络单元接收到网络管理单元发送的告警上报配置,该告警上报配置包含的是第一配置信息时,网络单元确定告警上报方式为告警事件上报,网络单元将会根据目标关联规则从告警数据确定出多个告警,然后对该多个告警进行关联,最终生成该多个告警对应的告警事件。本申请实施例中的目标告警包含该告警事件,当目标告警只包含该告警事件时,该告警事件即为目标告警。目标告警还可以包含其他的信息,本申请实施例对此不作限定。需要说明的是,上述的告警数据可以是指网络单元中历史的告警数据,该历史的告警数据中可以包含大量的告警。
具体的,当网络单元接收到网络管理单元发送的告警上报配置,该告警上报配置包含的是第二配置信息时,网络单元将会基于第二配置信息所指示的上报条件,过滤掉告警数据中不必要的告警,筛选出满足上报条件的告警为目标告警。例如,第二配置信息用于指示告警对象A对应的告警的上报条件,当告警对象A产生告警时,网络单元将会根据该产生的告警是否满足上报条件,不满足则筛除,满足则确定为目标告警用于上报。例如,告警对象A所对应的告警类型B的告警优先级为“严重”,网络管理单元基于该告警对象A所对应的告警类型B的优先级,向网络单元发送第二配置信息,用于指示该告警对象A所对应的告警类型B对应的告警的上报条件,当告警对象A产生了告警类型B的告警,网络单元将会判断该告警是否满足上报条件,不满足则筛除,满足则确定为目标告警用于上报。
需要说明的是,本申请实施例中,网络单元在接收到网络管理单元发送的告警上报配置后,可以一直根据该告警上报配置进行目标告警的上报,直到新的告警上报配置的下发。
本申请实施例中,网络管理单元可以向网络单元发送告警上报配置,该告警上报配置可以包括第一配置信息或第二配置信息,网络单元可以根据第一配置信息将具备关联关系的多个告警进行关联后上报,从而可以提升告警分析的效率,更加精准的定位故障信息,网络单元也可以根据第二配置信息对目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警进行筛选,满足上报条件后再上报,从而能够在处理单个告警问题重复上报或闪断上报时,基于告警对象/告警类型/告警优先级设置灵活的上报条件,及时收到重要的告警,有效精确的抑制冗余和重复告警的上报。
图3为本申请实施例提供的告警处理方法的另一个实施例示意图。
参阅图3,本申请实施例提供的告警处理方法的另一个实施例,可以包括:
301、网络管理单元向网络单元发送第一配置信息,该第一配置信息用于指示告警事件的上报。
本申请实施例中,网络管理单元首先向网络单元发送第一配置信息,该第一配置信息用于指示告警事件的上报。需要说明的是,传统的告警上报方式中,网络单元针对每个故障都会生成一个告警,对于该每个故障对应的告警都进行一一上报。而本申请实施例中,告警事件是作为一种告警上报方式,是指网络单元需要采用告警事件的上报方式进行告警上报。本申请实施例中告警事件的上报方式是指网络单元采用目标关联关系将多个告警进行关联生成告警事件,然后进行该告警事件的上报。
可选地,可选地,本申请实施例中的第一配置信息可以包括如下信息中的一个或多个:告警事件的上报方式、第一指示信息和第二指示信息,其中,第一指示信息用于指示上报告警事件时是否需要携带告警事件所关联的多个告警的告警信息,第二指示信息用于指示目标关联规则,该目标关联规则用于网络单元对多个告警进行关联并生成告警事件。
302、网络单元在接收到第一配置信息后,根据目标关联规则对多个告警进行关联并生成告警事件。
本申请实施例中,网络单元在接收到网络管理单元发送的第一配置信息后,确定告警上报方式为告警事件上报,网络单元将会根据目标关联规则从告警数据确定出多个具备关联关系的告警,然后对该多个告警进行关联,最终生成该多个告警对应的告警事件。本申请实施例中的目标告警包含该告警事件。当目标告警只包含该告警事件时,该告警事件即为目标告警。目标告警还可以包含其他的信息,本申请实施例对此不作限定。需要说明的是,上述的告警数据可以是指网络单元中历史的告警数据,该历史的告警数据中可以包含大量的告警。
需要说明的是,本申请实施例中的目标关联规则可以是网络单元预先规定好的,当需要进行告警事件上报时,网络单元直接根据该预先规定的目标关联规则确定告警事件。该目标关联规则也可以是网络管理单元通过第一配置信息中的第二指示信息配置的。本申请实施例对此不作限定。
可选地,本申请实施例中的目标关联规则可以是多个关联规则中的一个,该多个关联规则可以包括频繁度关联和网络拓扑结构关联。需要说明的是,除了频繁度关联和网络拓扑结构关联这两种关联规则,还可以包含其他的关联规则用于告警的关联,本申请实施例对此不作限定。
可选地,本申请实施例中,该多个关联规则可以是存储在网络单元中可用的关联规则,网络管理单元在向网络单元发送第一配置信息之前,还可以像网络单元发送第三指示信息,用于指示网络单元向网络管理单元上报该多个可用的关联规则。
本申请实施例中的频繁度关联是指根据告警的告警关联频繁度进行关联。该告警关联频繁度用于指示多个告警在同一个时间段内频繁出现。该多个告警可以是不同类型的告警。具体的,网络单元根据某个时间段内频繁挖掘算法对告警数据中的多个告警进行频繁度关联。例如,告警1、2、3在5分钟内同时出现的次数是101次,则告警频繁度为101。网 络单元根据该告警频繁度对告警1、2、3进行关联。
本申请实施例中的网络拓扑结构关联是指根据告警的网络拓扑结构的关联关系进行关联。该网络拓扑结构可以包括网络拓扑的逻辑拓扑或衍生关系等。当多个告警存在网络拓扑结构的关联关系,则可以将该多个告警进行关联。例如,告警1和告警2之间存在网络拓扑的连接关系或者承载关系,则该告警1和告警2可以归属于一个告警事件中。
303、网络单元向网络管理单元发送目标告警,该目标告警包括告警事件。
本申请实施例中,网络单元在生成告警事件之后,向网络管理单元发送目标告警,该目标告警包括该告警事件。
可选地,本申请实施例中,目标告警中包含的告警事件,可以包括如下信息中的一个或多个:告警事件的根因、告警事件的标识、告警事件的名称、告警对象、告警事件的告警类型、告警事件的故障源、故障源的虚拟化标识、告警事件的发生时间、告警事件的消除事件、该告警事件对应的多个告警的告警信息。除此之外,该目标告警中还可以包含其他类型的信息,本申请实施例对此不作限定。
304、网络管理单元根据目标告警确定告警消除指示。
本申请实施例中,网络管理单元在接收到网络单元发送的目标告警之后,会对该目标告警进行分析,确定出解决该目标告警的告警消除指示。
305、网络管理单元向网络单元发送告警消除指示。
本申请实施例中,网络管理单元在确定出解决该目标告警的告警消除指示之后,将该告警消除指示发送给网络单元。
306、网络单元根据告警消除指示对目标告警进行处理。
本申请实施例中,本申请实施例中,网络单元在接收到网络管理单元发送的告警消除指示之后,根据该告警消除指示对目标告警进行处理。
307、网络单元向网络管理单元发送目标告警的处理结果。
本申请实施例中,网络单元在根据告警消除指示对目标告警进行处理之后,向网络管理单元发送目标告警的处理结果。
308、网络单元根据目标告警的处理结果更新多个告警的关联关系。
本申请实施例中,网络单元在根据告警消除指示对目标告警进行处理之后,根据目标告警的处理结果对该告警事件关联的多个告警之间的关联关系进行更新。例如,网络单元根据目标关联规则将告警1、告警2和告警3进行关联,并生成告警事件进行上报,当在根据网络管理单元发送的告警消除指示对该告警事件进行处理后,只消除了告警1和告警2,告警3的问题没有得到解决,则网络单元更新取消该告警1、告警2和告警3之间的关联,只关联告警1和告警2。
需要说明的是,本申请实施例中的步骤303-步骤308均是可选的步骤。
本申请实施例中,网络单元可以根据网络管理单元发送的第一配置信息将具备关联关系的多个告警进行关联后上报,从而提升告警分析的效率,更加精准的定位故障信息。
图4为本申请实施例提供的告警处理方法的另一个实施例示意图。
参阅图4,本申请实施例提供的告警处理方法的另一个实施例,可以包括:
401、网络管理单元向网络单元发送第二配置信息,第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件。
本申请实施例中,网络管理单元首先向网络单元发送第二配置信息,该第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件。
本申请实施例中,告警对象、告警类型和告警优先级可以参阅图2中的步骤201中的相关内容进行理解,此处不再赘述。本申请实施例中,目标告警对象可以是上述告警对象中的任意一个,目标告警类型可以是上述告警类型中的任意一种,目标告警优先级可以是上述告警优先级中的任意一个级别。本申请实施例中,网络管理单元向网络单元发送的第二配置信息,用于指示对应于该目标告警对象和/或目标告警类型和/或目标告警优先级的告警的上报条件。例如,第二配置信息用于指示告警对象A对应的告警的上报条件,当告警对象A产生告警时,网络单元将会根据该产生的告警是否满足上报条件,不满足则筛除,满足则确定为目标告警进行上报。例如,告警对象A所对应的告警类型B的告警优先级为“严重”,网络管理单元基于该告警对象A所对应的告警类型B的优先级,向网络单元发送了第二配置信息,用于指示该告警对象A所对应的告警类型B对应的告警的上报条件,当告警对象A产生了告警类型B的告警,网络单元将会判断该告警是否满足上报条件,不满足则筛除,满足则确定为目标告警进行上报。
可选地,本申请实施例中,第二配置信息可以包括告警闪断周期T1。该告警闪断周期T1的作用是:对于该目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警,在告警闪断周期TI内若告警自动恢复,则不满足上报条件,不需要上报;在告警闪断周期TI内,若告警未恢复,则满足上报条件,闪断周期结束后,网络单元将该告警确定为目标告警。
可选地,本申请实施例中,第二配置信息可以包括参数:告警震荡周期T2,入震荡条件N1,出震荡周期T2,出震荡条件N2。以上参数用于解决同一告警反复大量上报的问题。上述参数的一种具体作用可以是:对于该目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警,当该告警生成时,被确定为目标告警,立刻触发入震荡流程,在告警震荡周期T2内,若该告警的产生次数达到N1次,则立刻触发出震荡流程。如果在出震荡周期T2内,该告警达到N2次,则进入下一个出震荡周期T2,直到某一个出震荡周期T2内,没有达到N2次,则出告警震荡周期。在进入告警震荡周期后和出震荡周期之前,该告警不满足上报条件,不会进行重复上报。例如,告警震荡周期T1为50S,入震荡条件N3为出现次数3次;出震荡周期T2为20S,出震荡周期N2为出现2次。在第一次告警产生后,触发入震荡,如果在30S时达到入震荡次数3次,立即触发出震荡流程。如果在20S内超过2次,则进入下一个20S出震荡周期。直到有一个20S周期次数没有达到2次,出告警震荡周期。在进入告警震荡周期后出震荡周期前,该条告警不进行重复上报。
402、网络单元根据第二配置信息确定满足上报条件的目标告警。
本申请实施例中,网络单元根据第二配置信息对告警数据进行筛选,确定出满足上报条件的目标告警。
403、网络单元向网络管理单元发送目标告警。
本申请实施例中,网络单元在生成告警事件之后,向网络管理单元发送目标告警。
404、网络管理单元根据目标告警确定告警消除指示。
本申请实施例中,网络管理单元在接收到网络单元发送的目标告警之后,会对该目标告警进行分析,确定出解决该目标告警的告警消除指示。
405、网络管理单元向网络单元发送告警消除指示。
本申请实施例中,网络管理单元在确定出解决该目标告警的告警消除指示之后,将该告警消除指示发送给网络单元。
406、网络单元根据告警消除指示对目标告警进行处理。
本申请实施例中,本申请实施例中,网络单元在接收到网络管理单元发送的告警消除指示之后,根据该告警消除指示对目标告警进行处理。
407、网络单元向网络管理单元发送目标告警的处理结果。
本申请实施例中,网络单元在根据告警消除指示对目标告警进行处理之后,向网络管理单元发送目标告警的处理结果。
需要说明的是,本申请实施例中的步骤403-步骤407均是可选的步骤。
本申请实施例中,网络管理单元能够针对不同的告警对象、告警类型或告警优先级进行灵活的上报配置,从而能够及时收到重要的告警,有效精确的抑制冗余和重复告警的上报。
以上对本申请实施例提供的告警处理方法进行了介绍,接下来介绍本申请实施例提供的告警处理装置。
图5为本申请实施例提供的告警处理装置的结构示意图。
参阅图5,本申请实施例提供的告警处理装置50,包括:
接收模块501,用于接收网络管理单元发送的告警上报配置,所述告警上报配置包括第一配置信息或第二配置信息,其中,所述第一配置信息用于指示告警事件的上报,所述第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;
确定模块502,用于根据所述接收模块501接收的所述告警上报配置确定目标告警。
本申请实施例中,网络管理单元可以向告警处理装置发送告警上报配置,该告警上报配置可以包括第一配置信息或第二配置信息,告警处理装置可以根据第一配置信息将具备关联关系的多个告警进行关联后上报,从而可以提升告警分析的效率,更加精准的定位故障信息,告警处理装置也可以根据第二配置信息对目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警进行筛选,满足上报条件后再上报,从而能够在处理单个告警问题重复上报或闪断上报时,基于告警对象/告警类型/告警优先级设置灵活的上报条件,及时收到重要的告警,有效精确的抑制冗余和重复告警的上报。
可选地,作为一个实施例,当所述告警上报配置包括所述第一配置信息时,所述确定模块502,用于根据目标关联规则对多个告警进行关联并生成告警事件;确定所述目标告警,所述目标告警包括所述告警事件。
可选地,作为一个实施例,所述第一配置信息包括如下信息中的一个或多个:所述告 警事件的上报方式、第一指示信息和第二指示信息,其中,所述第一指示信息用于指示所述目标告警中是否携带所述多个告警的告警信息,所述第二指示信息用于指示所述目标关联规则。
可选地,作为一个实施例,所述目标关联规则属于多个关联规则,所述多个关联规则包括频繁度关联和网络拓扑结构关联。
可选地,作为一个实施例,所述接收单元501,还用于接收所述网络管理单元发送的第三指示信息,所述第三指示信息用于指示是否向所述网络管理单元上报所述多个关联规则。
可选地,作为一个实施例,所述告警事件包括如下信息中的一个或多个:所述告警事件的根因、所述告警事件的标识、所述告警事件的名称、告警对象、所述告警事件的告警类型、所述告警事件的故障源、所述故障源的虚拟化标识、所述告警事件的发生时间、所述告警事件的消除事件、所述多个告警的告警信息。
可选地,作为一个实施例,当所述告警上报配置包括所述第二配置信息时,所述确定模块502,用于根据所述第二配置信息确定满足所述上报条件的目标告警。
可选地,作为一个实施例,所述第二配置信息包括告警闪断周期,所述确定模块,用于判断第一告警在所述告警闪断周期内是否恢复;若未恢复,则确定所述第一告警为所述目标告警。
可选地,作为一个实施例,所述第二配置信息包括告警震荡周期、入震荡条件、出震荡周期和出震荡条件,所述确定模块502,用于根据所述告警震荡周期、所述入震荡条件、所述出震荡周期和所述出震荡条件判断第二告警是否满足所述上报条件;若是,则确定所述第二告警为所述目标告警。
可选地,作为一个实施例,所述告警处理装置50还包括:发送模块503,用于在所述确定模块502根据告警上报配置确定目标告警之后,向网络管理单元发送该目标告警。
可选地,作为一个实施例,所述接收模块501还用于在所述发送模块503向网络管理单元发送该目标告警之后,接收网络管理单元发送的告警消除指示,该告警消除指示是网络管理单元根据目标告警确定的。
可选地,作为一个实施例,该告警处理装置还包括:处理模块504,用于在接收模块501接收网络管理单元发送的告警消除指示之后,根据该告警消除指示对目标告警进行处理。
可选地,作为一个实施例,所述发送模块503,还用于在所述处理模块504根据所述告警消除指示对所述目标告警进行处理之后,向所述网络管理单元发送所述目标告警的处理结果。
可选地,作为一个实施例,告警处理装置,还包括:更新模块505,用于在所述处理模块504根据所述告警消除指示对所述目标告警进行处理之后,根据所述目标告警的处理结果更新所述多个告警的关联关系。
本申请实施例还提供一种网络单元60,该网络单元60包括处理器610,存储器620与收发器630,其中,存储器620中存储指令或程序,处理器610用于执行存储器620中存 储的指令或程序。存储器620中存储的指令或程序被执行时,该处理器610用于执行上述实施例中确定模块502、处理模块504、更新模块505执行的操作,收发器630用于执行上述实施例中接收模块501和发送模块503执行的操作。
应理解,根据本申请实施例的告警处理装置50或网络单元60可对应于本申请实施例的告警处理方法中的网络单元,并且告警处理装置50或网络单元60中的各个模块的操作和/或功能分别为了实现图2至图4中的各个方法的相应流程,为了简洁,在此不再赘述。
图7为本申请实施例提供的告警处理装置的结构示意图。
参阅图7,本申请实施例提供的告警处理装置70,包括:
发送模块701,用于向网络单元发送告警上报配置,所述告警上报配置包括第一配置信息或第二配置信息,其中,所述第一配置信息用于指示告警事件的上报,所述第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;
接收模块702,用于在所述发送模块701发送所述告警上报配置之后,接收所述网络单元发送的目标告警,所述目标告警是所述网络单元根据所述告警上报配置确定的。
可选地,作为一个实施例,当所述告警上报配置包括所述第一配置信息时,所述目标告警包括告警事件,所述告警事件是所述网络单元根据目标关联规则对所述多个告警进行关联并生成的。
可选地,作为一个实施例,所述第一配置信息包括如下信息中的一个或多个:所述告警事件的上报方式、第一指示信息和第二指示信息,其中,所述第一指示信息用于指示所述目标告警中是否携带所述多个告警的告警信息,所述第二指示信息用于指示所述目标关联规则。
可选地,作为一个实施例,所述目标关联规则属于多个关联规则,所述多个关联规则包括频繁度关联和网络拓扑结构关联。
可选地,作为一个实施例,发送模块701还用于在向网络单元发送告警上报配置之前,向网路单元发送第三指示信息,该第三指示信息用于指示网络单元是否上报该多个关联规则。
可选地,作为一个实施例,所述告警事件包括如下信息中的一个或多个:所述告警事件的根因、所述告警事件的标识、所述告警事件的名称、告警对象、所述告警事件的告警类型、所述告警事件的故障源、所述故障源的虚拟化标识、所述告警事件的发生时间、所述告警事件的消除事件、所述多个告警的告警信息。
可选地,作为一个实施例,当所述告警上报配置包括所述第二配置信息时,所述目标告警是所述网络单元根据所述第二配置信息确定的,所述目标告警满足所述上报条件。
可选地,作为一个实施例,所述第二配置信息包括告警闪断周期,所述目标告警是所述网络单元在判断第一告警在所述告警闪断周期内未恢复后确定的,所述第一告警为所述目标告警。
可选地,作为一个实施例,所述第二配置信息包括告警震荡周期、入震荡条件、出震荡周期和出震荡条件,所述目标告警是所述网络单元在根据所述告警震荡周期、所述入震 荡条件、所述出震荡周期和所述出震荡条件判断所述第二告警是否满足所述上报条件时确定的,当所述第二告警满足所述上报条件时,所述第二告警为所述目标告警。
可选地,作为一个实施例,告警处理装置70还包括:确定模块703,用于在接收模块702接收网络单元发送的目标告警之后,根据目标告警确定告警消除指示。
可选地,作为一个实施例,所述发送模块701,还用于向所述网络单元发送所述确定模块703确定的所述告警消除指示,以使所述网络单元根据所述告警消除指示对所述目标告警进行处理。
可选地,作为一个实施例,所述接收模块702,还用于在所述发送模块701向所述网络单元发送所述告警消除指示之后,接收所述网络单元发送的所述目标告警的处理结果。
本申请实施例还提供一种网络管理单元80,该网络管理单元80包括处理器810,存储器820与收发器830,其中,存储器820中存储指令或程序,处理器810用于执行存储器820中存储的指令或程序。存储器820中存储的指令或程序被执行时,该处理器810用于执行上述实施例中确定模块703执行的操作,收发器830用于执行上述实施例中发送模块701和接收模块702执行的操作。
应理解,根据本申请实施例的告警处理装置70或网络管理单元80可对应于本申请实施例的告警处理方法中的网络管理单元,并且告警处理装置70或网络管理单元80中的各个模块的操作和/或功能分别为了实现图2至图4中的各个方法的相应流程,为了简洁,在此不再赘述。
可选的,本申请实施例还提供一种芯片系统,该芯片系统包括处理器,用于支持网络单元实现上述告警处理方法。在一种可能的设计中,该芯片系统还包括存储器。该存储器,用于保存网络单元必要的程序指令和数据。该芯片系统,可以由芯片构成,也可以包含芯片和其他分立器件,本申请实施例对此不作具体限定。
可选的,本申请实施例还提供一种芯片系统,该芯片系统包括处理器,用于支持网络管理单元实现上述告警处理方法。在一种可能的设计中,该芯片系统还包括存储器。该存储器,用于保存网络管理单元必要的程序指令和数据。该芯片系统,可以由芯片构成,也可以包含芯片和其他分立器件,本申请实施例对此不作具体限定。
可以理解的是,本申请的实施例中的处理器可以是中央处理单元(Central Processing Unit,CPU),还可以是其它通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现场可编程门阵列(Field Programmable Gate Array,FPGA)或者其它可编程逻辑器件、晶体管逻辑器件,硬件部件或者其任意组合。通用处理器可以是微处理器,也可以是任何常规的处理器。
本申请的实施例中的方法步骤可以通过硬件的方式来实现,也可以由处理器执行软件指令的方式来实现。软件指令可以由相应的软件模块组成,软件模块可以被存放于随机存取存储器(Random Access Memory,RAM)、闪存、只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)、寄存器、硬盘、移 动硬盘、CD-ROM或者本领域熟知的任何其它形式的存储介质中。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于ASIC中。另外,该ASIC可以位于网络单元或网络管理单元中。当然,处理器和存储介质也可以作为分立组件存在于网络单元或网络管理单元中。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机程序或指令。在计算机上加载和执行所述计算机程序或指令时,全部或部分地执行本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其它可编程装置。所述计算机程序或指令可以存储在计算机可读存储介质中,或者通过所述计算机可读存储介质进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是集成一个或多个可用介质的服务器等数据存储设备。所述可用介质可以是磁性介质,例如,软盘、硬盘、磁带;也可以是光介质,例如,DVD;还可以是半导体介质,例如,固态硬盘(solid state disk,SSD)。
在本申请的各个实施例中,如果没有特殊说明以及逻辑冲突,不同的实施例之间的术语和/或描述具有一致性、且可以相互引用,不同的实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
本申请中,“至少一个”是指一个或者多个,“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B的情况,其中A,B可以是单数或者复数。在本申请的文字描述中,字符“/”,一般表示前后关联对象是一种“或”的关系。
可以理解的是,在本申请的实施例中涉及的各种数字或字母编号仅为描述方便进行的区分,并不用来限制本申请的实施例的范围。上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定。
以上对本申请实施例所提供的告警处理方法、装置及系统进行了详细介绍,本文中应用了具体个例对本申请的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本申请的方法及其核心思想;同时,对于本领域的一般技术人员,依据本申请的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本申请的限制。

Claims (30)

  1. 一种告警处理方法,其特征在于,包括:
    接收网络管理单元发送的告警上报配置,所述告警上报配置包括第一配置信息或第二配置信息,其中,所述第一配置信息用于指示告警事件的上报,所述第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;
    根据所述告警上报配置确定目标告警,所述目标告警用于发送给所述网络管理单元。
  2. 根据权利要求1所述的方法,其特征在于,当所述告警上报配置包括所述第一配置信息时,所述根据所述告警上报配置确定目标告警,包括:
    根据目标关联规则对多个告警进行关联并生成告警事件;
    确定所述目标告警,所述目标告警包括所述告警事件。
  3. 根据权利要求2所述的方法,其特征在于,所述第一配置信息包括如下信息中的一个或多个:所述告警事件的上报方式、第一指示信息和第二指示信息,其中,所述第一指示信息用于指示所述目标告警中是否携带所述多个告警的告警信息,所述第二指示信息用于指示所述目标关联规则。
  4. 根据权利要求2或3所述的方法,其特征在于,所述目标关联规则属于多个关联规则,所述多个关联规则包括频繁度关联和网络拓扑结构关联。
  5. 根据权利要求4所述的方法,所述接收网络管理单元发送的告警上报配置之前,还包括:
    接收所述网络管理单元发送的第三指示信息,所述第三指示信息用于指示是否向所述网络管理单元上报所述多个关联规则。
  6. 根据权利要求2-5任一所述的方法,其特征在于,所述告警事件包括如下信息中的一个或多个:所述告警事件的根因、所述告警事件的标识、所述告警事件的名称、告警对象、所述告警事件的告警类型、所述告警事件的故障源、所述故障源的虚拟化标识、所述告警事件的发生时间、所述告警事件的消除事件、所述多个告警的告警信息。
  7. 根据权利要求1所述的方法,其特征在于,当所述告警上报配置包括所述第二配置信息时,所述根据所述告警上报配置确定目标告警,包括:
    根据所述第二配置信息确定满足所述上报条件的目标告警。
  8. 根据权利要求7所述的方法,其特征在于,所述第二配置信息包括告警闪断周期,所述根据所述告警上报配置确定满足所述上报条件的目标告警,包括:
    判断第一告警在所述告警闪断周期内是否恢复;
    若未恢复,则确定所述第一告警为所述目标告警。
  9. 根据权利要求7所述的方法,其特征在于,所述第二配置信息包括告警震荡周期、入震荡条件、出震荡周期和出震荡条件,所述根据所述告警上报配置确定满足所述上报条件的目标告警,包括:
    根据所述告警震荡周期、所述入震荡条件、所述出震荡周期和所述出震荡条件判断第二告警是否满足上报条件;
    若是,则确定所述第二告警为所述目标告警。
  10. 根据权利要求1-9任一所述的方法,其特征在于,所述根据所述告警上报配置确定目标告警之后,还包括:
    向所述网络管理单元发送所述目标告警。
  11. 根据权利要求10所述的方法,其特征在于,所述向所述网络管理单元发送所述目标告警之后,还包括:
    接收所述网络管理单元发送的告警消除指示,所述告警消除指示是网络管理单元根据所述目标告警确定的。
  12. 根据权利要求11所述的方法,其特征在于,所述接收所述网络管理单元发送的告警消除指示之后,还包括:
    根据所述告警消除指示对所述目标告警进行处理。
  13. 根据权利要求12所述的方法,其特征在于,所述根据所述告警消除指示对所述目标告警进行处理之后,还包括:
    向所述网络管理单元发送所述目标告警的处理结果。
  14. 根据权利要求12或13所述的方法,其特征在于,当所述告警上报配置包括所述第一配置信息时,所述根据所述告警消除指示对所述目标告警进行处理之后,还包括:
    根据所述目标告警的处理结果更新所述多个告警的关联关系。
  15. 一种告警处理方法,其特征在于,包括:
    向网络单元发送告警上报配置,所述告警上报配置包括第一配置信息或第二配置信息,其中,所述第一配置信息用于指示告警事件的上报,所述第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;
    接收所述网络单元发送的目标告警,所述目标告警是所述网络单元根据所述告警上报配置确定的。
  16. 根据权利要求15所述的方法,其特征在于,当所述告警上报配置包括所述第一配置信息时,所述目标告警包括告警事件,所述告警事件是所述网络单元根据目标关联规则对所述多个告警进行关联并生成的。
  17. 根据权利要求16所述的方法,其特征在于,所述第一配置信息包括如下信息中的一个或多个:所述告警事件的上报方式、第一指示信息和第二指示信息,其中,所述第一指示信息用于指示所述目标告警中是否携带所述多个告警的告警信息,所述第二指示信息用于指示所述目标关联规则。
  18. 根据权利要求16或17所述的方法,其特征在于,所述目标关联规则属于多个关联规则,所述多个关联规则包括频繁度关联和网络拓扑结构关联。
  19. 根据权利要求18所述的方法,其特征在于,所述向网络单元发送告警上报配置之前,还包括:
    向所述网路单元发送第三指示信息,所述第三指示信息用于指示所述网络单元是否上报所述多个关联规则。
  20. 根据权利要求16-19任一所述的方法,其特征在于,所述告警事件包括如下信息中的一个或多个:所述告警事件的根因、所述告警事件的标识、所述告警事件的名称、告 警对象、所述告警事件的告警类型、所述告警事件的故障源、所述故障源的虚拟化标识、所述告警事件的发生时间、所述告警事件的消除事件、所述多个告警的告警信息。
  21. 根据权利要求15所述的方法,其特征在于,当所述告警上报配置包括所述第二配置信息时,所述目标告警是所述网络单元根据所述第二配置信息确定的,所述目标告警满足所述上报条件。
  22. 根据权利要求21所述的方法,其特征在于,所述第二配置信息包括告警闪断周期,所述目标告警是所述网络单元在判断第一告警在所述告警闪断周期内未恢复后确定的,所述第一告警为所述目标告警。
  23. 根据权利要求21所述的方法,其特征在于,所述第二配置信息包括告警震荡周期、入震荡条件、出震荡周期和出震荡条件,所述目标告警是所述网络单元在根据所述告警震荡、所述入震荡条件、所述出震荡周期和所述出震荡条件判断第二告警是否满足所述上报条件时确定的,当所述第二告警满足所述上报条件时,所述第二告警为所述目标告警。
  24. 根据权利要求15-23任一所述的方法,其特征在于,所述接收所述网络单元发送的目标告警之后,还包括:
    根据所述目标告警确定告警消除指示。
  25. 根据权利要求24所述的方法,其特征在于,所述根据所述目标告警确定告警消除指示之后,还包括:
    向所述网络单元发送所述告警消除指示,以使所述网络单元根据所述告警消除指示对所述目标告警进行处理。
  26. 根据权利要求25所述的方法,其特征在于,所述向所述网络单元发送所述告警消除指示之后,还包括:
    接收所述网络单元发送的所述目标告警的处理结果。
  27. 一种告警处理装置,其特征在于,包括:
    接收模块,用于接收网络管理单元发送的告警上报配置,所述告警上报配置包括第一配置信息或第二配置信息,其中,所述第一配置信息用于指示告警事件的上报,所述第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;
    确定模块,用于根据所述接收模块接收的所述告警上报配置确定目标告警。
  28. 一种告警处理装置,其特征在于,包括:
    发送模块,用于向网络单元发送告警上报配置,所述告警上报配置包括第一配置信息或第二配置信息,其中,所述第一配置信息用于指示告警事件的上报,所述第二配置信息用于指示目标告警对象和/或目标告警类型和/或目标告警优先级对应的告警的上报条件;
    接收模块,用于在所述发送模块发送所述告警上报配置之后,接收所述网络单元发送的目标告警,所述目标告警是所述网络单元根据所述告警上报配置确定的。
  29. 一种计算机可读存储介质,其上存储有计算机程序,其特征在于,所述程序被处理器执行时实现如权利要求1至14中任一项所述的方法。
  30. 一种计算机可读存储介质,其上存储有计算机程序,其特征在于,所述程序被处 理器执行时实现如权利要求15至26中任一项所述的方法。
PCT/CN2020/140727 2019-12-31 2020-12-29 一种告警处理方法、装置以及存储介质 WO2021136247A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201911422159.1A CN113132144B (zh) 2019-12-31 2019-12-31 一种告警处理方法、装置以及存储介质
CN201911422159.1 2019-12-31

Publications (1)

Publication Number Publication Date
WO2021136247A1 true WO2021136247A1 (zh) 2021-07-08

Family

ID=76687093

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/140727 WO2021136247A1 (zh) 2019-12-31 2020-12-29 一种告警处理方法、装置以及存储介质

Country Status (2)

Country Link
CN (1) CN113132144B (zh)
WO (1) WO2021136247A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113923103A (zh) * 2021-12-06 2022-01-11 深圳市城市交通规划设计研究中心股份有限公司 一种告警方法、装置、云服务平台和可读存储介质
CN114116282A (zh) * 2021-11-12 2022-03-01 苏州浪潮智能科技有限公司 一种网络附加存储故障上报并修复的方法和装置
CN114760185A (zh) * 2022-03-15 2022-07-15 深信服科技股份有限公司 告警信息处理方法、装置、电子设备及存储介质
CN115333916A (zh) * 2022-07-19 2022-11-11 广州爱浦路网络技术有限公司 通信网络中的网元告警信息处理方法、装置及存储介质

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114389938B (zh) * 2021-12-14 2023-09-29 武汉光迅科技股份有限公司 一种告警方法、告警装置及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101022638A (zh) * 2007-03-12 2007-08-22 华为技术有限公司 一种告警上报方法和告警装置
WO2014089809A1 (zh) * 2012-12-13 2014-06-19 华为技术有限公司 告警相关信息的传输方法和装置
WO2015070917A1 (en) * 2013-11-15 2015-05-21 Nokia Solutions And Networks Oy Correlation of event reports
CN105790972A (zh) * 2014-12-18 2016-07-20 中兴通讯股份有限公司 一种控制器及告警关联性处理的方法

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101222725A (zh) * 2007-01-08 2008-07-16 中兴通讯股份有限公司 一种利用告警归并减少北向接口告警数量的方法
CN104935456B (zh) * 2015-04-08 2016-01-20 熊莹 通信网络告警系统的告警消息传输和处理方法
CN109218097A (zh) * 2018-09-19 2019-01-15 山东浪潮云投信息科技有限公司 一种云平台可配置告警规则的告警系统及告警方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101022638A (zh) * 2007-03-12 2007-08-22 华为技术有限公司 一种告警上报方法和告警装置
WO2014089809A1 (zh) * 2012-12-13 2014-06-19 华为技术有限公司 告警相关信息的传输方法和装置
WO2015070917A1 (en) * 2013-11-15 2015-05-21 Nokia Solutions And Networks Oy Correlation of event reports
CN105790972A (zh) * 2014-12-18 2016-07-20 中兴通讯股份有限公司 一种控制器及告警关联性处理的方法

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114116282A (zh) * 2021-11-12 2022-03-01 苏州浪潮智能科技有限公司 一种网络附加存储故障上报并修复的方法和装置
CN114116282B (zh) * 2021-11-12 2023-08-18 苏州浪潮智能科技有限公司 一种网络附加存储故障上报并修复的方法和装置
CN113923103A (zh) * 2021-12-06 2022-01-11 深圳市城市交通规划设计研究中心股份有限公司 一种告警方法、装置、云服务平台和可读存储介质
CN114760185A (zh) * 2022-03-15 2022-07-15 深信服科技股份有限公司 告警信息处理方法、装置、电子设备及存储介质
CN115333916A (zh) * 2022-07-19 2022-11-11 广州爱浦路网络技术有限公司 通信网络中的网元告警信息处理方法、装置及存储介质
CN115333916B (zh) * 2022-07-19 2023-07-25 广州爱浦路网络技术有限公司 通信网络中的网元告警信息处理方法、装置及存储介质

Also Published As

Publication number Publication date
CN113132144B (zh) 2022-05-31
CN113132144A (zh) 2021-07-16

Similar Documents

Publication Publication Date Title
WO2021136247A1 (zh) 一种告警处理方法、装置以及存储介质
US9571334B2 (en) Systems and methods for correlating alarms in a network
WO2021169064A1 (zh) 一种基于边缘网络的异常处理方法及装置
CN108512689A (zh) 微服务业务监控方法及服务器
US20140189086A1 (en) Comparing node states to detect anomalies
US20200134421A1 (en) Assurance of policy based alerting
CN104521270B (zh) 自组织网络操作诊断功能
US20180227210A1 (en) Methods Providing Performance Management Using A Proxy Baseline And Related Systems And Computer Program Products
CN101136799A (zh) 一种实现通讯设备故障集中告警处理的方法
CN107660289A (zh) 自动网络控制
CN100433647C (zh) 一种告警管理方法和系统
CN112764956B (zh) 数据库的异常处理系统、数据库的异常处理方法及装置
CN109039795B (zh) 一种云服务器资源监控方法和系统
WO2014169869A1 (zh) 一种告警处理的方法及告警系统
CN112559237B (zh) 运维系统排障方法、装置、服务器和存储介质
CN109391526B (zh) 一种网络环路的检测方法及装置
US10862738B2 (en) System and method for alarm correlation and root cause determination
CN111669282B (zh) 识别疑似根因告警的方法、装置及计算机存储介质
CN108171265A (zh) 一种标签获得方法、装置及电子设备
CN115037653B (zh) 业务流量监控方法、装置、电子设备和存储介质
WO2016188500A1 (zh) 一种业务割接的方法、装置及设备
US11314573B2 (en) Detection of event storms
CN101938380B (zh) 一种告警处理方法及装置
CN113810242A (zh) 系统日志分析方法及装置
CN107615708A (zh) 告警信息上报方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20911070

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20911070

Country of ref document: EP

Kind code of ref document: A1