CN110275815A - A kind of system exception alert processing method and device - Google Patents

A kind of system exception alert processing method and device Download PDF

Info

Publication number
CN110275815A
CN110275815A CN201910581803.3A CN201910581803A CN110275815A CN 110275815 A CN110275815 A CN 110275815A CN 201910581803 A CN201910581803 A CN 201910581803A CN 110275815 A CN110275815 A CN 110275815A
Authority
CN
China
Prior art keywords
data
time series
trading information
abnormality alarming
index
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201910581803.3A
Other languages
Chinese (zh)
Inventor
卢道和
杨军
汪晓雪
陈翼
程志峰
李兴龙
胡仲臣
李慧敏
周佳振
朱嘉伟
陈刚
罗海湾
李勋棋
郭英亚
陈广胜
周琪
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
WeBank Co Ltd
Original Assignee
WeBank Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by WeBank Co Ltd filed Critical WeBank Co Ltd
Priority to CN201910581803.3A priority Critical patent/CN110275815A/en
Publication of CN110275815A publication Critical patent/CN110275815A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/3065Monitoring arrangements determined by the means or processing involved in reporting the monitored data
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/32Monitoring with visual or acoustical indication of the functioning of the machine
    • G06F11/324Display of status information
    • G06F11/327Alarm or error message display
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q40/00Finance; Insurance; Tax strategies; Processing of corporate or income taxes
    • G06Q40/04Trading; Exchange, e.g. stocks, commodities, derivatives or currency exchange

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Accounting & Taxation (AREA)
  • Finance (AREA)
  • General Engineering & Computer Science (AREA)
  • Quality & Reliability (AREA)
  • Development Economics (AREA)
  • General Business, Economics & Management (AREA)
  • Technology Law (AREA)
  • Strategic Management (AREA)
  • Marketing (AREA)
  • Economics (AREA)
  • Debugging And Monitoring (AREA)

Abstract

The present embodiments relate to field of computer technology more particularly to a kind of system exception alert processing methods and device, can not accomplish preparatory alarm and prevention to solve the problem of that abnormality processing timeliness is poor.The embodiment of the present invention includes: using any system in all systems as the first system, for the first system, it executes following procedure: according to corresponding time data, analytical Calculation being carried out to the trading information data of the first system, determines the time series data of system index;Successively judge whether the time series data of the system index meets the abnormality alarming condition of the system index;When the time series data for determining any moment meets the abnormality alarming condition of the system index, second system associated with the first system in all systems is determined;Abnormality alarming instruction is sent to the second system.

Description

A kind of system exception alert processing method and device
Technical field
The present invention relates to the field of computer technology more particularly to a kind of system exception announcement in financial technology (Fintech) Alert processing method and processing device.
Background technique
With financial technology, the especially continuous development of internet techno-financial, more and more technologies (as it is distributed, Block chain Blockchain, artificial intelligence etc.) it applies in financial field, but also to technology, more stringent requirements are proposed for financial circles, Such as it is directed to system exception alarming processing process.
In system normal course of operation, system is monitored.When system occurs abnormal, issued to operation maintenance personnel abnormal Alarm, so that operation maintenance personnel is handled for abnormal.In this process, abnormal processing timeliness is poor, can not accomplish Preparatory alarm and prevention.
Summary of the invention
The application provides a kind of system exception alert processing method and device, poor to solve abnormality processing timeliness, The problem of can not accomplishing preparatory alarm and prevention.
A kind of system exception alert processing method provided in an embodiment of the present invention, comprising:
The systematic trading information data of institute is obtained, includes corresponding time data in the trading information data;
Following procedure is executed for the first system using any system in all systems as the first system:
According to corresponding time data, analytical Calculation is carried out to the trading information data of the first system, determines system The time series data of index;
Successively judge whether the time series data of the system index meets the abnormality alarming condition of the system index;
When the time series data for determining any moment meets the abnormality alarming condition of the system index, all systems are determined Second system associated with the first system in system;
Abnormality alarming instruction is sent to the second system.
In a kind of optional embodiment, the systematic trading information data of the acquisition institute, comprising:
Receive the systematic message transmission data of institute that message-oriented middleware is sent;
And/or
The systematic log information of institute is obtained, the systematic Message Processing data of institute are determined from log information.
It further include corresponding mark data in the trading information data in a kind of optional embodiment;
It is described when determine any moment time series data meet the abnormality alarming condition of the system index after, also Include:
Determine the corresponding mark data of time series data for meeting the abnormality alarming condition of the system index;
Obtain trading information data relevant to the mark data in the systematic trading information data of institute;
Show trading information data relevant to the mark data.
In a kind of optional embodiment, the time series data of the determining any moment meets the different of the system index After normal alarm conditions, before the transmission abnormality alarming instruction to the second system, further includes:
According to the corresponding pathological system index of the time series data for meeting the abnormality alarming condition, corresponding place is determined Reason strategy;
Corresponding processing strategie is sent to the first system and the second system.
A kind of system exception alarm treatment device, comprising:
Acquiring unit includes corresponding in the trading information data for obtaining a systematic trading information data Time data;
Resolution unit, for being parsed to the trading information data of the first system according to corresponding time data It calculates, determines the time series data of system index;
Comparison unit, for successively judging whether the time series data of the system index meets the system index Abnormality alarming condition;
Associative cell, for meeting the abnormality alarming item of the system index when the time series data for determining any moment Part determines second system associated with the first system in all systems;
Alarm Unit, for sending abnormality alarming instruction to the second system.
In a kind of optional embodiment, the acquiring unit is specifically used for:
Receive the systematic message transmission data of institute that message-oriented middleware is sent;
And/or
The systematic log information of institute is obtained, the systematic Message Processing data of institute are determined from log information.
It further include corresponding mark data in the trading information data in a kind of optional embodiment;The alarm is single Member is also used to:
Determine the corresponding mark data of time series data for meeting the abnormality alarming condition of the system index;
Obtain trading information data relevant to the mark data in the systematic trading information data of institute;
Show trading information data relevant to the mark data.
In a kind of optional embodiment, the associative cell is also used to:
According to the corresponding pathological system index of the time series data for meeting the abnormality alarming condition, corresponding place is determined Reason strategy;
Corresponding processing strategie is sent to the first system and the second system.
The embodiment of the present invention also provides a kind of electronic equipment, comprising:
At least one processor;And
The memory being connect at least one described processor communication;Wherein,
The memory is stored with the instruction that can be executed by least one described processor, and described instruction is by described at least one A processor executes, so that at least one described processor is able to carry out method as described above.
The embodiment of the present invention also provides a kind of non-transient computer readable storage medium, and the non-transient computer is readable to deposit Storage media stores computer instruction, and the computer instruction is for making the computer execute method as described above.
In the embodiment of the present invention, each system is monitored, the specific available systematic Transaction Information number of institute According to comprising corresponding time data in the trading information data.Using any system in all systems as the first system, for The first system executes following procedure: according to corresponding time data, carrying out parsing meter to the trading information data of the first system It calculates, determines the parsing data of the system index, since parsing data are corresponding with the time, thus, parsing data are time sequence Multiple parsing data of column data, the system index form time series data stream.Sequentially in time, successively judge system Whether the time series data of index meets the abnormality alarming condition of system index, if the time series data of any moment is discontented The abnormality alarming condition of sufficient correspondence system index then shows that the moment the first system is in normal operating condition, then continues to One system is monitored;When the time series data for determining any moment meets the abnormality alarming condition of the system index, then really The fixed moment the first system is in abnormality.At this point, determine second system associated with the first system in all systems, and Abnormality alarming instruction is sent to second system.In this way, exception information to be passed to the interconnected system of the first system in time, allow also not Occur it is abnormal, but i.e. will likely affected normal system can timely learning unexpected message, to win certain time It takes precautions against the generation of failure and starts emergency preplan.It is also possible to significantly shorten fault location time, when improving abnormality processing Effect.
Detailed description of the invention
To describe the technical solutions in the embodiments of the present invention more clearly, make required in being described below to embodiment Attached drawing is briefly introduced, it should be apparent that, drawings in the following description are only some embodiments of the invention, for this For the those of ordinary skill in field, without any creative labor, it can also be obtained according to these attached drawings His attached drawing.
Fig. 1 is a kind of structural schematic diagram of possible system architecture provided in an embodiment of the present invention;
Fig. 2 is a kind of flow diagram of system exception alert processing method provided in an embodiment of the present invention;
Fig. 3 is a kind of structural schematic diagram of system exception alarm treatment device provided in an embodiment of the present invention;
Fig. 4 is the structural schematic diagram of electronic equipment provided in an embodiment of the present invention.
Specific embodiment
To make the objectives, technical solutions, and advantages of the present invention clearer, below in conjunction with attached drawing to the present invention make into It is described in detail to one step, it is clear that the described embodiments are only some of the embodiments of the present invention, rather than whole implementation Example.Based on the embodiments of the present invention, obtained by those of ordinary skill in the art without making creative efforts All other embodiment, shall fall within the protection scope of the present invention.
As shown in Figure 1, a kind of system architecture that the embodiment of the present invention is applicable in, including anomaly monitoring device 101 and core Heart unit includes N number of system 102 in core cell.
Wherein, anomaly monitoring device 101 can be mobile phone, tablet computer either dedicated handheld device etc. and have wirelessly The electronic equipment of communication function is also possible to personal computer (personal computer, abbreviation PC), laptop, clothes The equipment of the Wired access modes connection online such as business device.Anomaly monitoring device 101 can be an independent equipment, be also possible to Multiple equipment is formed by cluster.Preferably, anomaly monitoring device 101 can carry out information processing using cloud computing technology.
System 102 can be the network equipments such as computer, can be an independent equipment, is also possible to multiple servers It is formed by server cluster.Preferably, system 102 can carry out information processing using cloud computing technology.
Anomaly monitoring device 101 can be communicated by INTERNET network with system 102, can also be moved by the whole world Dynamic communication system (Global System for Mobile Communications, abbreviation GSM), long term evolution (long Term evolution, abbreviation LTE) mobile communication system such as system are communicated with system 102.
In order to make it easy to understand, the noun that may relate in the embodiment of the present invention is defined and is explained below.
MSS-TRACEAPI: log tracks interface provides the interface that message-oriented middleware log reports for each system, according to connecing Mouth defines reporting message correlation log to message-oriented middleware;
MSS-LOGAGENT: applying log collection plug-in unit, and by disposing agent in each operation system, active collection is all Transaction Information;
WEMQ-BROKRE: message-oriented middleware core, for parsing the critical system of forwarding message;
MSS-IMP ORT: message import system is responsible for pulling message from message-oriented middleware core and importing large data sets Group;
MSS-OLAP: massive logs analysis system is responsible for mass data analysis;
MSS-LOGSTORE: log storage system is applied, a large amount of log informations are stored;
BDAP HBASE: big data system is using hdfs as storage medium, therefore there is distributed storage to possess for it Advantage is able to achieve and is responsible for equilibrium, manages data, interacts with hdfs, and permission control is also relatively good;
MSS-DIAGNOTIC: diagnostic system diagnoses the result data that olap analysis is completed according to rule;
MSS-AGGREGATER: log aggregation conversion system provides the polymerizable functional of log, by trace log, using day Will and statistical system index show the information of same time period, at unified interface for supporting positioning problems;
MSS-TRACEVIEW: information query system provides visualization interface, can be inquired by specific business serial number The tendency of the transaction out, and transaction generate the overall process log information for arriving final state, realize the unified query of log;
Wisdom operational system: the system for total failure alarm and processing method push.
Based on above-mentioned framework, the embodiment of the invention provides a kind of system exception alert processing methods, as shown in Fig. 2, this Inventive embodiments provide system exception alert processing method the following steps are included:
Step 201 obtains the systematic trading information data of institute, includes corresponding time number in the trading information data According to.
Here trading information data can be each system and receive or send data caused by message, Huo Zheye The combination of the data or the two that are generated when can be system processing message.It include the corresponding time in trading information data Data, such as receive the time of message, the time for starting to process message etc., the embodiment of the present invention is by obtaining these time numbers According to, can according to time data generation time sequence data, to be monitored in real time to each system, once discovery has is System is abnormal, and carries out alarm and relevant treatment at once.
Following procedure is executed for the first system using any system in all systems as the first system:
Step 202, according to corresponding time data, analytical Calculation is carried out to the trading information data of the first system, Determine the time series data of system index.
Specifically, the trading information data obtained from each channel is summarized, and is calculated in real time.Pass through calculating The time series data of various system indexs is obtained, system index can be with such as TPS (issued transaction amount per second, Transaction Per Second), theme quantity, queue size, connection number, message forwarding time, message Forwarding Delay etc., these system indexs Time series data can be used to characterize the performance and operating condition of the first system.Wherein, system index it is multiple when Between sequence data form time series data stream sequentially in time;
The trading information data being collected into can be stored in big data analysis cluster, for statisticalling analyze.It can also incite somebody to action Calculated time series data is stored in TSDB (timing space-time database, Time Series and Spatial- Temporal Database) etc. in databases, and interface is provided and is called for each system.Different data can be come with needle Source channel provides interface, so that the available data relevant to the data source channel of data source channel, thus as number According to the foundation of the accident analysis of sources, for example, keyword can be extracted from trading information data, as message-oriented middleware Accident analysis data source.Whole trading information datas can also introduce machine-learning device by way of interface, from And keyword, call relation etc. are calculated, restrained and analyzed by machine learning.In addition, all trading information datas It will be stored with archival back-up.
Step 203 successively judges whether the time series data of the system index meets the exception of the system index Alarm conditions.
Here abnormality alarming condition can be operation maintenance personnel and empirically determine, or machine passes through analytic learning Historical data is calculated.There is an abnormality alarming condition generally directed to each system index, for example, averagely adjusting for system Dosage, setting abnormality alarming condition are greater than 100000, and even the average calling amount of system is greater than 100000, then it is assumed that the system There is exception, is handled.
Step 204 meets the abnormality alarming condition of the system index when the time series data for determining any moment, really Second system associated with the first system in fixed all systems.
Specifically, it can be determined according to the corresponding trading information data of time series data for meeting abnormality alarming condition Second system associated with the first system, for example, abnormality alarming condition is met according to trading processing number of retries, i.e., big Mr. Yu A setting value, it is determined that using the account identification of the transaction, the system that the transaction is related in system is determined, so that transaction be related to And all systems in addition to the first system arrived, as second system.It can also be according to other systems in the first system and system Call relation between system such as thinks that the system that the first system can be called directly in system is second system.Here second System can be a system, or multiple systems.
In a kind of optional embodiment, with time sequencing, when discovery first meets the first system of abnormality alarming condition, It determines the transaction that alarm amount is most concentrated in the first system, according to the mark of the transaction, determines what processing this alarm amount was most concentrated Under the scene of transaction, second system associated with the first system.Then alarm relevant information is sent to second system, such as handed over Easily mark, for the first time alarm time, warning information etc..
Step 205, Xiang Suoshu second system send abnormality alarming instruction.
In the embodiment of the present invention, each system is monitored, the specific available systematic Transaction Information number of institute According to comprising corresponding time data in the trading information data.Using any system in all systems as the first system, for The first system executes following procedure: according to corresponding time data, carrying out parsing meter to the trading information data of the first system It calculates, determines the parsing data of the system index, since parsing data are corresponding with the time, thus, parsing data are time sequence Multiple parsing data of column data, the system index form time series data stream.Sequentially in time, successively judge system Whether the time series data of index meets the abnormality alarming condition of system index, if the time series data of any moment is discontented The abnormality alarming condition of sufficient correspondence system index then shows that the moment the first system is in normal operating condition, then continues to One system is monitored;When the time series data for determining any moment meets the abnormality alarming condition of the system index, then really The fixed moment the first system is in abnormality.At this point, determine second system associated with the first system in all systems, and Abnormality alarming instruction is sent to second system.In this way, exception information to be passed to the interconnected system of the first system in time, allow also not Occur it is abnormal, but i.e. will likely affected normal system can timely learning unexpected message, to win certain time It takes precautions against the generation of failure and starts emergency preplan.It is also possible to significantly shorten fault location time, when improving abnormality processing Effect.
Further, the real-time example of the present invention is by message-oriented middleware and proxy server (agent), in each system of Overall Acquisition Trading information data.The systematic trading information data of the acquisition institute, comprising:
Receive the systematic message transmission data of institute that message-oriented middleware is sent;
The systematic log information of institute is obtained, the systematic Message Processing data of institute are determined from log information.
Specifically, trading information data may include message transmission data and Message Processing data.Wherein, message is transmitted When data may include that system interface receives or sends message, leaving relevant to message transmission, message transmission data can Think that the interface of each system is actively sent to message-oriented middleware, the content of the message transmission data is set in advance by message-oriented middleware It is fixed, it mainly include opening, initiator's system identifier, service ID, the scene ID of calling send state, and reciever ID is patrolled Collect region etc..
Message Processing data, for the proxy server disposed in the database of each system, according to unified Log Directory, full dose is obtained The log of system is taken, that is, is directed to and the parsing data of request packet that system docking receives and/or the feedback packet being sent out.Mainly The time of middleware is arrived and departed from including business serial number, Transaction Identification Number, opening, request packet, down-stream system receives Time that request includes, down-stream system handle back packet time, type of transaction, system IP, Transaction Details etc..
The embodiment of the present invention is combined by way of system active transmission and direct access systems log, expands progress The data of alert analysis prediction carry out source range, improve the accuracy and timeliness of alert analysis.
It further include corresponding mark in the trading information data to realize the unified query of pertinent transaction information data Data;It is described when determine any moment time series data meet the abnormality alarming condition of the system index after, also wrap It includes:
Determine the corresponding mark data of time series data for meeting the abnormality alarming condition of the system index;
Obtain trading information data relevant to the mark data in the systematic trading information data of institute;
Show trading information data relevant to the mark data.
In the embodiment of the present invention, message identification can be transaction journal number or business service ID etc..The system of acquisition It further include corresponding transaction journal number in trading information data, so as to by the time series data being calculated and transaction flow Water number establishes corresponding relationship.It, can be by transaction journal number, from All Activity when operation maintenance personnel needs to consult total system log The systematic trading information data of institute related to the message identification is obtained in information data.In this way, especially going out in daily maintenance When existing abnormality alarming, it can facilitate the lookup of total system log, can be inquired since transaction according to a transaction serial number To the processing overall process of final state, the unified query of log is realized, be conducive to the maintenance of data and quickly positions abnormal position.
Further, the time series data of the determining any moment meets the abnormality alarming condition of the system index Later, before the transmission abnormality alarming instruction to the second system, further includes:
According to the corresponding pathological system index of the time series data for meeting the abnormality alarming condition, corresponding place is determined Reason strategy;
Corresponding processing strategie is sent to the first system and the second system.
In specific implementation process, the corresponding relationship between pathological system index and processing strategie can be pre-established, this is right Should be related to can be stored according to the corresponding relationship between the keyword of pathological system index and the mark of processing strategie.Processing Strategy can be determining according to process experience, or obtain from history process record.When the pathological system for determining the first system After index, according to the keyword of the pathological system index, corresponding processing strategie can be quickly found, and will alarm and processing Strategy is sent to all relevant systems.To which specific processing method is conveyed to each system in most fast mode, in certain journey Abnormal ranges are controlled on degree and degree expands.
For a clearer understanding of the present invention, above-mentioned process is described in detail with specific embodiment below, it is specific to walk It is rapid as follows, comprising:
Step S301: trading information data is collected.Interface is specifically included to report and proxy server acquisition.
Setting reports interface in each interface, and each system is by interface actively to message-oriented middleware reporting message sending and receiving number According to content is set by message-oriented middleware, mainly covers opening, initiator's system identifier, the service ID of calling, scene ID, transmission state, reciever ID, logic region etc..
Proxy server is disposed in each system of upstream and downstream, according to unified Log Directory, full dose collection system institute is systematic Log obtains Message Processing data, the i.e. parsing of request packet and time package informatin from log.Mainly have: business serial number, transaction Number, opening, the time for arriving and departing from middleware, down-stream system receiving time and handle back packet the time, transaction class Type, system IP.Transaction Details etc..
In addition, also filing to the log of acquisition.It will be obtained in log according to the important level of system and memory capacity The unified storage of Message Processing data is got up, and setting saves duration, schedule backup.
Step S302: the trading information data obtained from message-oriented middleware and proxy server is summarized, and is analyzed It calculates, obtains the parsing data of each system index.Specific system index can be TPS, theme quantity, message queue rule Mould, connection number, message forwarding time, message Forwarding Delay etc..
Step S303: sequentially in time, successively the parsing data of each system index and the abnormal of system index are accused Alert condition compares.When the abnormality alarming condition of system index is not satisfied in all parsing data, step 301 is continued to execute. If any parsing data meet the abnormality alarming condition of system index, determine that alarm amount is most concentrated in systems for parsing data institute Transaction mark, the interconnected system in system is determined according to transaction ID.
Step S304: generating abnormality alarming instruction, may include early warning system ID in abnormality alarming instruction, system name, is System mark, service ID, scene ID, for the first time alarm time, warning information and interconnected system mark.Such as certain in WAPI system Following abnormality alarming instruction can be generated in the case where system calling amount is uprushed:
WAPI hits the year-on-year bump amount 302% of the amount of opening an account
SystermID:3510
System name: PAFS-WAPI front end interface service
DCN:1A0
Service ID:03200215
Scene ID:01
Alarm time for the first time: 2019-03-22 15:13:02
Warning information: 1A0/s/03200215/01 nearly 3 minutes average calling amounts: 230783, unsuccessfully measure: 0, alarm: call Amount rises 302% on year-on-year basis
Interconnected system: PAFS-AMS
As can be seen that interconnected system is PAFS-AMS, it is therefore desirable to indicate to send abnormality alarming to PAFS-AMS.
It uprushes and abnormal conditions that calling amount is uprushed in another example unsuccessfully being measured for certain system queries in CTAC system, it can To generate following abnormality alarming instruction:
Unsuccessfully amount is uprushed for CTAC hit inquiry, and calling amount is uprushed
SystermID:1013
System name: RCS-CTAC customer information inquiry
DCN:1B1
Service ID:09300010
Scene ID:01
Alarm time for the first time: 2019-03-21 09:00:00
Warning information: 1E0/s/09300010/01 nearly 3 minutes average calling amounts: 302543, unsuccessfully measure: 56, alarm: 1 ,/ data/appsystems/rcs-ctac/logs/rcs-ctac.log[tryQurey ecif ct stat file failed]_92936:2019-03-21 09:00:00,196 INFO pool-2-thread-1 CTStatEcifDAOImpl (152)-isFileDealFinishedV3_redis_bill|1065:1E0:rcs-ctac:ctstat:fi nished: 2019/4/16:kfzxZhRg|null;2, calling amount uprushes 118%
By interconnected system: ECIF-CORE, AISP-SRSC
As can be seen that interconnected system is ECIF-CORE and AISP-SRSC, it is therefore desirable to indicate abnormality alarming to ECIF- CORE and AISP-SRSC is sent.
Step S305: according to the keyword for the system index for meeting abnormality alarming condition, corresponding processing strategie is determined.
Step S305: instruction message is generated according to abnormality alarming instruction and corresponding processing strategie, is sent out to interconnected system It send.Specific message structure can be such that
[major] [DIAGNOTIC:rcs-ctac calling amount uprush alarm]
===generates alarm just because of analysis
It alerts for the first time: 2019-03-21 09:00:00
Warning system for the first time: rcs--ctac customer information inquiry
Warning information: 1E0/s/09300010/01 nearly 3 minutes average calling amounts: 302543, unsuccessfully measure: 56, alarm: 1 ,/ data/appsystems/rcs-ctac/logs/rcs-ctac.log[tryQurey ecif ct stat file failed]_92936:
2019-03-21 09:00:00,196 INFO pool-2-thread-1CTStatEcifDAOImpl(152)- isFileDealFinishedV3_redis_bill|1065:1E0:rcs-ctac:ctstat:fi nished:2019/4/16: kfzxZhRg|null;2, calling amount uprushes 118%
The alarm that===this system occurs
Alert keyword: discard timeout message
Subsystem: ecif-core
Alarming host: 10.106.143.4
SOP number: ECIF-A0032
SOP respective operations: 1. this for system processing time-out, be confirmed whether there is hair version
2. should be noted whether request amount increases leads to processing time-out such as without version, a failure flowing water is looked for use Traceview interface queries failure details
3. if appearing in some region unsuccessfully concentrate, it please check whether firewall policy has altered, whether host has alarm
Recent release: nearest five days without version
Alert dcn:4U2
Home domain: retail domain
It alerts for the first time: 19/03/21 09:01:51
Alarm recently: 19/03/21 09:01:51
Warning information: the keyword hit in the period are as follows: discard timeout message;[major] Alert- weeks In phase keyword number alarm the Alert- period in keyword number be greater than 1 continue minute: 1;Keyword number in period: 16 [unified major]
Sending time: 2019-03-21 09:01:33
The embodiment of the invention also provides a kind of system exception alarm treatment devices, as shown in Figure 3, comprising:
Acquiring unit 31 includes correspondence in the trading information data for obtaining a systematic trading information data Time data;
Resolution unit 32, for being solved to the trading information data of the first system according to corresponding time data Analysis calculates, and determines the time series data of system index;
Comparison unit 33, for successively judging whether the time series data of the system index meets the system index Abnormality alarming condition;
Associative cell 34, for meeting the abnormality alarming of the system index when the time series data for determining any moment Condition determines second system associated with the first system in all systems;
Alarm Unit 35, for sending abnormality alarming instruction to the second system.
Optionally, the acquiring unit, is specifically used for:
Receive the systematic message transmission data of institute that message-oriented middleware is sent;
And/or
The systematic log information of institute is obtained, the systematic Message Processing data of institute are determined from log information.
It optionally, further include corresponding mark data in the trading information data;The Alarm Unit, is also used to:
Determine the corresponding mark data of time series data for meeting the abnormality alarming condition of the system index;
Obtain trading information data relevant to the mark data in the systematic trading information data of institute;
Show trading information data relevant to the mark data.
Optionally, the associative cell, is also used to:
According to the corresponding pathological system index of the time series data for meeting the abnormality alarming condition, corresponding place is determined Reason strategy;
Corresponding processing strategie is sent to the first system and the second system.
Based on identical principle, the present invention also provides a kind of electronic equipment, as shown in Figure 4, comprising:
Including processor 401, memory 402, transceiver 403, bus interface 404, wherein processor 401, memory 402 It is connect between transceiver 403 by bus interface 404;
The processor 401 executes following method for reading the program in the memory 402:
The systematic trading information data of institute is obtained, includes corresponding time data in the trading information data;
Following procedure is executed for the first system using any system in all systems as the first system:
According to corresponding time data, analytical Calculation is carried out to the trading information data of the first system, determines system The time series data of index;
Successively judge whether the time series data of the system index meets the abnormality alarming condition of the system index;
When the time series data for determining any moment meets the abnormality alarming condition of the system index, all systems are determined Second system associated with the first system in system;
Abnormality alarming instruction is sent to the second system.
The processor 401, is also used to:
Receive the systematic message transmission data of institute that message-oriented middleware is sent;
And/or
The systematic log information of institute is obtained, the systematic Message Processing data of institute are determined from log information.
The processor 401, is also used to:
Determine the corresponding mark data of time series data for meeting the abnormality alarming condition of the system index;
Obtain All Activity information data relevant to the mark data in the systematic trading information data of institute;
Show trading information data relevant to the mark data.
The processor 401, is also used to:
According to the corresponding pathological system index of the time series data for meeting the abnormality alarming condition, corresponding place is determined Reason strategy;
Corresponding processing strategie is sent to the first system and the second system.
The present invention be referring to according to the method for the embodiment of the present invention, the process of equipment (system) and computer program product Figure and/or block diagram describe.It should be understood that every one stream in flowchart and/or the block diagram can be realized by computer program instructions The combination of process and/or box in journey and/or box and flowchart and/or the block diagram.It can provide these computer programs Instruct the processor of general purpose computer, special purpose computer, Embedded Processor or other programmable data processing devices to produce A raw machine, so that being generated by the instruction that computer or the processor of other programmable data processing devices execute for real The device for the function of being specified in present one or more flows of the flowchart and/or one or more blocks of the block diagram.
These computer program instructions, which may also be stored in, is able to guide computer or other programmable data processing devices with spy Determine in the computer-readable memory that mode works, so that it includes referring to that instruction stored in the computer readable memory, which generates, Enable the manufacture of device, the command device realize in one box of one or more flows of the flowchart and/or block diagram or The function of being specified in multiple boxes.
These computer program instructions also can be loaded onto a computer or other programmable data processing device, so that counting Series of operation steps are executed on calculation machine or other programmable devices to generate computer implemented processing, thus in computer or The instruction executed on other programmable devices is provided for realizing in one or more flows of the flowchart and/or block diagram one The step of function of being specified in a box or multiple boxes.
Although preferred embodiments of the present invention have been described, it is created once a person skilled in the art knows basic Property concept, then additional changes and modifications may be made to these embodiments.So it includes excellent that the following claims are intended to be interpreted as It selects embodiment and falls into all change and modification of the scope of the invention.
Obviously, various changes and modifications can be made to the invention without departing from essence of the invention by those skilled in the art Mind and range.In this way, if these modifications and changes of the present invention belongs to the range of the claims in the present invention and its equivalent technologies Within, then the invention is also intended to include including these modification and variations.

Claims (10)

1. a kind of system exception alert processing method characterized by comprising
The systematic trading information data of institute is obtained, includes corresponding time data in the trading information data;
Following procedure is executed for the first system using any system in all systems as the first system:
According to corresponding time data, analytical Calculation is carried out to the trading information data of the first system, determines system index Time series data;
Successively judge whether the time series data of the system index meets the abnormality alarming condition of the system index;
When the time series data for determining any moment meets the abnormality alarming condition of the system index, determine in all systems Second system associated with the first system;
Abnormality alarming instruction is sent to the second system.
2. the method as described in claim 1, which is characterized in that the systematic trading information data of the acquisition institute, comprising:
Receive the systematic message transmission data of institute that message-oriented middleware is sent;
And/or
The systematic log information of institute is obtained, the systematic Message Processing data of institute are determined from log information.
3. the method as described in claim 1, which is characterized in that further include corresponding mark number in the trading information data According to;
It is described when determine any moment time series data meet the abnormality alarming condition of the system index after, also wrap It includes:
Determine the corresponding mark data of time series data for meeting the abnormality alarming condition of the system index;
Obtain trading information data relevant to the mark data in the systematic trading information data of institute;
Show trading information data relevant to the mark data.
4. the method as described in claim 1, which is characterized in that described in the time series data of the determining any moment meets After the abnormality alarming condition of system index, before the transmission abnormality alarming instruction to the second system, further includes:
According to the corresponding pathological system index of the time series data for meeting the abnormality alarming condition, corresponding processing plan is determined Slightly;
Corresponding processing strategie is sent to the first system and the second system.
5. a kind of system exception alarm treatment device characterized by comprising
Acquiring unit includes the corresponding time in the trading information data for obtaining a systematic trading information data Data;
Resolution unit, for carrying out analytical Calculation to the trading information data of the first system according to corresponding time data, Determine the time series data of system index;
Comparison unit, for successively judging whether the time series data of the system index meets the exception of the system index Alarm conditions;
Associative cell, for meeting the abnormality alarming condition of the system index when the time series data for determining any moment, Determine second system associated with the first system in all systems;
Alarm Unit, for sending abnormality alarming instruction to the second system.
6. device as claimed in claim 5, which is characterized in that the acquiring unit is specifically used for:
Receive the systematic message transmission data of institute that message-oriented middleware is sent;
And/or
The systematic log information of institute is obtained, the systematic Message Processing data of institute are determined from log information.
7. device as claimed in claim 5, which is characterized in that further include corresponding mark number in the trading information data According to;The Alarm Unit, is also used to:
Determine the corresponding mark data of time series data for meeting the abnormality alarming condition of the system index;
Obtain trading information data relevant to the mark data in the systematic trading information data of institute;
Show trading information data relevant to the mark data.
8. device as claimed in claim 5, which is characterized in that the associative cell is also used to:
According to the corresponding pathological system index of the time series data for meeting the abnormality alarming condition, corresponding processing plan is determined Slightly;
Corresponding processing strategie is sent to the first system and the second system.
9. a kind of electronic equipment characterized by comprising
At least one processor;And
The memory being connect at least one described processor communication;Wherein,
The memory is stored with the instruction that can be executed by least one described processor, and described instruction is by described at least one It manages device to execute, so that at least one described processor is able to carry out any method of claim 1-4.
10. a kind of non-transient computer readable storage medium, which is characterized in that the non-transient computer readable storage medium is deposited Computer instruction is stored up, the computer instruction is for making the computer perform claim require 1~4 any the method.
CN201910581803.3A 2019-06-30 2019-06-30 A kind of system exception alert processing method and device Pending CN110275815A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910581803.3A CN110275815A (en) 2019-06-30 2019-06-30 A kind of system exception alert processing method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910581803.3A CN110275815A (en) 2019-06-30 2019-06-30 A kind of system exception alert processing method and device

Publications (1)

Publication Number Publication Date
CN110275815A true CN110275815A (en) 2019-09-24

Family

ID=67963788

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910581803.3A Pending CN110275815A (en) 2019-06-30 2019-06-30 A kind of system exception alert processing method and device

Country Status (1)

Country Link
CN (1) CN110275815A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111626860A (en) * 2020-07-24 2020-09-04 成都寻道数财科技有限公司 System and method for judging high-frequency transaction by combining historical and real-time financial data
CN111752816A (en) * 2020-06-30 2020-10-09 深圳前海微众银行股份有限公司 Operating system analysis method and device
CN112416724A (en) * 2020-12-04 2021-02-26 中国建设银行股份有限公司 Alarm processing method, system, computer equipment and storage medium

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111752816A (en) * 2020-06-30 2020-10-09 深圳前海微众银行股份有限公司 Operating system analysis method and device
CN111626860A (en) * 2020-07-24 2020-09-04 成都寻道数财科技有限公司 System and method for judging high-frequency transaction by combining historical and real-time financial data
CN112416724A (en) * 2020-12-04 2021-02-26 中国建设银行股份有限公司 Alarm processing method, system, computer equipment and storage medium
CN112416724B (en) * 2020-12-04 2024-05-07 中国建设银行股份有限公司 Alarm processing method, system, computer device and storage medium

Similar Documents

Publication Publication Date Title
CN111049705B (en) Method and device for monitoring distributed storage system
CN110275815A (en) A kind of system exception alert processing method and device
CN111464336B (en) High-concurrency data processing method and system based on electric power communication machine room
CN107888452B (en) 24-hour distributed website performance monitoring and real-time alarming method
CN108335075A (en) A kind of processing system and method for Logistics Oriented big data
CN109117941A (en) Alarm prediction method, system, storage medium and computer equipment
CN111740860B (en) Log data transmission link monitoring method and device
CN108964995A (en) Log correlation analysis method based on time shaft event
CN103761309A (en) Operation data processing method and system
CN108259270A (en) A kind of data center's system for unified management design method
CN107704387B (en) Method, device, electronic equipment and computer readable medium for system early warning
CN112039701B (en) Interface call monitoring method, device, equipment and storage medium
CN105262210A (en) System and method for analysis and early warning of substation network security
CN108989136A (en) Business end to end performance monitoring method and device
CN112130999A (en) Electric power heterogeneous data processing method based on edge calculation
CN102929773A (en) Information collection method and device
CN101668301A (en) Method and device for monitoring operation state of node in short message center
US10733514B1 (en) Methods and apparatus for multi-site time series data analysis
CN106789270A (en) Method and system for realizing centralized operation and maintenance management of information system
CN110633191B (en) Method and system for monitoring service health of software system in real time
CN109067576A (en) The maintenance system and method for Railway Information System based on mobile terminal application
CN110099116B (en) Big data-based subnet security evaluation method
CN117370053A (en) Information system service operation-oriented panoramic monitoring method and system
CN110647070A (en) Power environment monitoring system for super-large-scale data center
CN111399749A (en) Data processing system and method

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination