WO2016127482A1 - 一种告警信息处理方法、相关设备和系统 - Google Patents

一种告警信息处理方法、相关设备和系统 Download PDF

Info

Publication number
WO2016127482A1
WO2016127482A1 PCT/CN2015/075796 CN2015075796W WO2016127482A1 WO 2016127482 A1 WO2016127482 A1 WO 2016127482A1 CN 2015075796 W CN2015075796 W CN 2015075796W WO 2016127482 A1 WO2016127482 A1 WO 2016127482A1
Authority
WO
WIPO (PCT)
Prior art keywords
alarm
alarm information
identifier
information
vnf
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/075796
Other languages
English (en)
French (fr)
Inventor
王姗姗
支炳立
朱健
韩文勇
邹兰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority to JP2017542440A priority Critical patent/JP6742327B2/ja
Priority to CN201580000952.6A priority patent/CN106170947B/zh
Priority to EP19192023.0A priority patent/EP3633922B1/en
Priority to AU2015382846A priority patent/AU2015382846B2/en
Priority to RU2017131583A priority patent/RU2679344C1/ru
Priority to BR112017017330-1A priority patent/BR112017017330B1/pt
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to EP15881643.9A priority patent/EP3255833B1/en
Priority to KR1020177025614A priority patent/KR102001898B1/ko
Publication of WO2016127482A1 publication Critical patent/WO2016127482A1/zh
Priority to US15/675,105 priority patent/US10771323B2/en
Anticipated expiration legal-status Critical
Priority to US16/997,609 priority patent/US20200382362A1/en
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • H04L41/0645Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis by additionally acting on or stimulating the network after receiving notifications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • H04L41/065Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis involving logical or physical relationship, e.g. grouping and hierarchies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0695Management of faults, events, alarms or notifications the faulty arrangement being the maintenance, administration or management system
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/40Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using virtualisation of network functions or resources, e.g. SDN or NFV entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/06Generation of reports

Definitions

  • the embodiments of the present invention relate to the field of communications, and in particular, to a method, a related device, and a system for processing alarm information.
  • NFV Network Function Virtualization
  • VIM Virtualized Infrastructure Manager
  • VNFM Virtualized Network Function Manager
  • Virtual Network Function Manager is added to the network architecture defined by the NFV system standard.
  • NFVO NFV Management and Orchestration, network function virtualization management and orchestration
  • the virtualization layer and the business layer are introduced in the NFV system, and each application VNF runs on the NFVI.
  • the EMS Element Management System
  • the network element may be a physical object in the virtualization layer or a virtual object in the service layer.
  • the physical object includes: a memory, a hard disk, a link, a board, a CPU, a network card
  • the virtual object includes: a virtual machine and a virtual network card. , applications, etc.
  • the EMS monitors the alarm information of a single layer, and cannot judge the fault of the entire network.
  • the EMS will send the same work order to the maintenance personnel for multiple work orders distributed by the alarm information.
  • the monitoring personnel need to spend a lot of time analyzing the faults, dispatching the work orders, and tracking the work orders.
  • the maintenance personnel also need to process a large number of work orders, and the operation and maintenance costs are greatly increased.
  • the technical problem to be solved by the embodiments of the present invention is to provide an alarm information processing method, a related device and a system, which can solve the problem of high operation and maintenance cost in the prior art.
  • the first aspect of the embodiments of the present invention provides an alarm information processing.
  • Methods including:
  • the network element management system EMS receives the first alarm message reported by the virtualized network function manager VNFM, wherein the first alarm message includes first alarm association information, and the first alarm association information includes at least one of the following: The relationship between the object identifier and the preset object identifier;
  • the EMS receives the second alarm message reported by the virtual network function VNF, where the second alarm message includes second alarm association information, and the second alarm association information includes at least one of the following: a second object identifier and the The association relationship of the preset object identifiers;
  • the EMS performs correlation analysis on the first alarm message and the second alarm message according to the first alarm association information and the second alarm association information.
  • the first object identifier includes at least one of the following: a VNF identifier, a virtual machine VM identifier, and a virtual transmission resource identifier of the VM;
  • the second object identifier includes at least one of the following: a VNF identifier, a VM identifier, and a virtual transmission resource identifier of the VM;
  • the association relationship of the preset object identifiers is used to indicate an association relationship between different object identifiers
  • the VNF identifier includes a VNF identifier ID or a VNF name name; the VM identifier includes a VM ID or a VM name; and the virtual transmission resource identifier includes a virtual transmission resource ID or a virtual transmission resource name.
  • the first alarm message further includes a first alarm information set; the first alarm information set includes the following At least one type: NFVI alarm information, VM alarm information, and VNFM alarm information.
  • the second alarm message further includes a second alarm information set, the second alarm The information set contains at least one VNF alarm information.
  • the EMS when the first alarm message includes a first alarm information set, and the second When the alarm information includes the second alarm information set, the EMS performs correlation analysis on the first alarm message and the second alarm message according to the first alarm association information and the second alarm association information, including :
  • the third alarm information set is composed of alarm information having an association relationship between the object identifiers; and performing correlation analysis on the third alarm information set according to the preset correlation rule.
  • a second aspect of the present invention provides a method for processing alarm information, including:
  • the virtualized network function manager VNFM receives the virtual machine VM alarm information reported by the virtualization infrastructure management VIM, where the VM alarm information includes a third object identifier;
  • the VNFM generates a first alarm message according to the VM alarm information, where the first alarm message includes first alarm association information, and the first alarm association information includes at least one of the following: a first object identifier and a preset The association of object identifiers;
  • the VNFM sends the first alarm message to the network element management system (EMS), so that the EMS performs correlation analysis on the first alarm message and the second alarm information reported by the VNF.
  • EMS network element management system
  • the third object identifier includes at least one of the following: a VM identifier, a host HOST identifier of the NFVI infrastructure layer, and a virtual transmission resource identifier of the VM;
  • the VM identifier includes a VM identifier ID or a VM name name; the HOST identifier includes a HOST ID or a HOST name; and the virtual transmission resource identifier of the VM includes a virtual transmission resource ID or a virtual transmission resource name.
  • the first object identifier includes at least one of the following: a VNF identifier, a VM identifier, and a virtual transmission resource of the VM. Identification
  • the association relationship of the preset object identifiers is used to indicate an association relationship between different object identifiers.
  • the first alarm message further includes first alarm set information, the first alarm The information set includes at least one of the following: NFVI alarm information, VM alarm information, and VNFM alarm information.
  • the generating, by the VNFM, the first alarm message according to the VM alarm information includes:
  • Correlation analysis is performed on the VM alarm information to generate the first alarm message.
  • a third aspect of the present invention provides a method for processing alarm information, including:
  • the virtualized infrastructure management VIM performs correlation analysis on at least two pieces of alarm information to generate virtual machine VM alarm information
  • the generated VM alarm information is reported to the virtualized network function manager VNFM, so that the VNFM reports the first alarm message to the network element management system EMS according to the VM alarm information, and the EMS pairs the first alarm.
  • the message is correlated with the second alarm information reported by the VNF.
  • the at least two pieces of alarm information include:
  • At least one network function virtualized infrastructure NFVI alarm information and at least one VM alarm information At least one network function virtualized infrastructure NFVI alarm information and at least one VM alarm information;
  • At least two NFVI alarms At least two NFVI alarms; or,
  • At least two VM alarms At least two VM alarms.
  • the method further includes:
  • NFVI alarm information reported by the NFVI, where the NFVI alarm information includes an NFVI identifier
  • the VIM performs correlation analysis on at least two pieces of alarm information to generate virtual machine VM alarm information, including:
  • the NFVI identifier includes at least one of a VM identifier, a host HOST identifier, and a virtual transmission resource identifier of the virtual machine; the VM identifier includes a VM identifier ID or a VM name; the HOST identifier includes a HOST ID or a HOST The virtual transmission resource identifier of the VM includes a virtual transmission resource ID or a virtual transmission resource name.
  • a fourth aspect of the present invention provides an alarm information processing apparatus, where the apparatus is a network element management system (EMS), including:
  • EMS network element management system
  • the first receiving unit is configured to receive the first alarm message that is reported by the virtualized network function manager VNFM, where the first alarm message includes first alarm association information, and the first alarm association information includes at least one of the following: An association relationship between the first object identifier and the preset object identifier;
  • a second receiving unit configured to receive a second alarm message reported by the virtual network function VNF, where the second alarm message includes second alarm association information, where the second alarm association information includes at least one of the following: a second object An association between the identifier and the preset object identifier;
  • a processing unit configured to: according to the first alarm association information and the second alarm association information, the first alarm message received by the first receiving unit and the second received by the second receiving unit The alarm message is analyzed for correlation.
  • the first object identifier includes at least one of the following: a VNF identifier, a virtual machine VM identifier, and a virtual transmission resource identifier of the VM;
  • the second object identifier includes at least one of the following: a VNF identifier, a VM identifier, and a virtual transmission resource identifier of the VM;
  • the association relationship of the preset object identifiers is used to indicate an association relationship between different object identifiers
  • the VNF identifier includes a VNF identifier ID or a VNF name name; the VM identifier includes a VM ID or a VM name; and the virtual transmission resource identifier includes a virtual transmission resource ID or a virtual transmission resource name.
  • the first alarm message further includes a first alarm information set, where the first alarm information set includes the following At least one type: NFVI alarm information, VM alarm information, and VNFM alarm information.
  • the second alarm message further includes a second alarm information set, the second alarm The information set contains at least one VNF alarm information.
  • the first alarm message includes a first alarm information set
  • the second alarm information includes
  • the processing unit is specifically configured to:
  • the third alarm information set is composed of alarm information having an association relationship between the object identifiers; and performing correlation analysis on the third alarm information set according to the preset correlation rule.
  • a fifth aspect of the present invention provides an alarm information processing apparatus, where the apparatus is a virtualized network function manager VNFM, including:
  • a receiving unit configured to receive virtual machine VM alarm information reported by the virtualization infrastructure management VIM, where the VM alarm information includes a third object identifier;
  • a processing unit configured to generate, according to the VM alarm information received by the receiving unit, a first alarm message, where the first alarm message includes first alarm association information, where the first alarm association information includes at least one of the following: An association relationship between the first object identifier and the preset object identifier;
  • a sending unit configured to send the first alarm message generated by the processing unit to the network element management system (EMS), so that the EMS performs correlation analysis on the first alarm message and the second alarm information reported by the VNF.
  • EMS network element management system
  • the third object identifier includes at least one of the following: a VM identifier, a host HOST identifier of the NFVI infrastructure layer, and a virtual transmission resource identifier of the VM;
  • the VM identifier includes a VM identifier ID or a VM name name; the HOST identifier includes a HOST ID or a HOST name; and the virtual transmission resource identifier of the VM includes a virtual transmission resource ID or a virtual transmission resource name.
  • the first object identifier is used to uniquely identify the first object, where the first object identifier includes At least one of the following: a VNF identifier, a VM identifier, and a virtual transmission resource identifier of the VM;
  • the association relationship of the preset object identifiers is used to indicate an association relationship between different object identifiers.
  • the first alarm message further includes first alarm set information, the first alarm The information set includes at least one of the following: NFVI alarm information, VM alarm information, and VNFM alarm information.
  • the processing unit is specifically configured to:
  • Correlation analysis is performed on the VM alarm information to generate the first alarm message.
  • a sixth aspect of the present invention provides an alarm information processing apparatus, which is a virtualization infrastructure management VIM, including:
  • a processing unit configured to perform correlation analysis on at least two pieces of alarm information, and generate virtual machine VM alarm information
  • a sending unit configured to report the VM alarm information generated by the processing unit to the virtualized network function manager VNFM, so that the VNFM reports the first alarm message to the network element management system EMS according to the VM alarm information,
  • the EMS performs correlation analysis on the first alarm message and the second alarm information reported by the VNF.
  • the at least two pieces of alarm information include:
  • At least one network function virtualized infrastructure NFVI alarm information and at least one VM alarm information At least one network function virtualized infrastructure NFVI alarm information and at least one VM alarm information;
  • At least two NFVI alarms At least two NFVI alarms; or,
  • At least two VM alarms At least two VM alarms.
  • the method further includes:
  • a receiving unit configured to receive NFVI alarm information reported by the NFVI, where the NFVI alarm information includes an NFVI identifier
  • the processing unit is configured to perform correlation analysis on the NFVI alarm information received by the receiving unit, and generate the VM alarm information;
  • the NFVI identifier includes at least one of a VM identifier, a host HOST identifier, and a virtual transmission resource identifier of the virtual machine; the VM identifier includes a VM identifier ID or a VM name; the HOST identifier includes a HOST ID or a HOST The virtual transmission resource identifier of the VM includes a virtual transmission resource ID or a virtual transmission resource name.
  • the alarm information of different layers can be analyzed for correlation, and the alarm information with correlation information in different layers can be determined, and the correlation of the alarm information across layers can be realized, and the same work order can be distributed for the same root cause alarm information. Therefore, the number of work orders can be reduced, thereby reducing the operation and maintenance costs of the network.
  • FIG. 1 is a schematic structural diagram of an NFV system according to an embodiment of the present invention.
  • FIG. 2 is a schematic flowchart of a method for processing alarm information according to an embodiment of the present invention
  • FIG. 3 is a schematic diagram of interaction of an alarm information processing system according to an embodiment of the present invention.
  • FIG. 4 is a schematic structural diagram of a network element management system according to an embodiment of the present invention.
  • FIG. 5 is a schematic structural view of the work order dispatching module of FIG. 4.
  • FIG. 6 is another schematic structural diagram of a network element management system according to an embodiment of the present disclosure.
  • FIG. 7 is a schematic flowchart of a method for processing alarm information according to an embodiment of the present invention.
  • FIG. 8 is a schematic flowchart diagram of another method for processing alarm information according to an embodiment of the present invention.
  • FIG. 9 is a schematic flowchart diagram of still another method for processing alarm information according to an embodiment of the present invention.
  • FIG. 10 is a schematic diagram of interaction of another alarm information processing system according to an embodiment of the present invention.
  • FIG. 11 is a schematic structural diagram of an alarm information processing apparatus according to an embodiment of the present invention.
  • FIG. 12 is a schematic structural diagram of another alarm information processing apparatus according to an embodiment of the present invention.
  • FIG. 13 is a schematic structural diagram of still another alarm information processing apparatus according to an embodiment of the present invention.
  • FIG. 14 is a schematic structural diagram of an alarm information processing apparatus according to an embodiment of the present invention.
  • FIG. 15 is a schematic structural diagram of another alarm information processing apparatus according to an embodiment of the present invention.
  • FIG. 16 is a schematic structural diagram of still another alarm information processing apparatus according to an embodiment of the present invention.
  • FIG. 1 is a network architecture diagram of an embodiment of the present invention.
  • the technical solution of the embodiment of the present invention is applied to an NFV system, where the NFV system includes a Network Function Virtualization Infrastructure (NFVI).
  • Functional nodes such as VIM, VNF, EMS, VNFM, and NFVO.
  • the VNF corresponds to a physical network function (PNF) in a traditional non-virtualized network, and the functional behavior and state of the network function are independent of the virtualization.
  • PNF physical network function
  • the VNF and the PNF have The same functional behavior and external interface.
  • the EMS is used to monitor alarm information of multiple network elements in the service layer and the virtualization layer in the NFV system.
  • VIM is a virtualized entity that includes resources for controlling and managing computing, storage, and networking;
  • NFVO is a virtualized entity responsible for network side arranging and management of NFV resources and implementing NFV service topologies on NFV infrastructure;
  • NFVI consists of hardware resources and virtual resources and a virtualization layer. From a VNF perspective, the virtualization layer and hardware resources appear to be an entity that can provide the required virtual resources.
  • the NFVI management control unit is responsible for the management and control of the virtual machine VM within the NFVI.
  • VNFM is responsible for the management of the life cycle of the VNF.
  • the VI-Ha interface between the virtual layer and the hardware resource can request hardware resources and collect related hardware resource status information through the VI-Ha interface.
  • Vn-Nf interface between VNF and NFVI Describes the execution environment that NFVI provides to VNF.
  • NFVO NFVO
  • VNFM VNFM
  • the VNFM sends resource-related requests: for example, authorization, verification, reservation, allocation, etc. of resources, used as lifecycle management of the VNF;
  • the NFVO sends the configuration information to the VNFM, so that the VNF can be reasonably configured according to the VNF forwarding map (forwarding gragh);
  • VNF status information (such as fault information) is used as the lifecycle management of the VNF.
  • the Vi-Vnfm interface between the VIM and the VNFM is an internal interface of the MANO, and is specifically used for: the VNFM sends a resource configuration request;
  • the Or-Vi interface between NFVO and VIM is the internal interface of NFVO, specifically for: NFVO transmission resource reservation request; NFVO resource allocation request; virtual hardware resource configuration and status information exchange.
  • Nf-Vi interface between NFVI and VIM is specifically used to:
  • Os-Ma interface between OSS/BSS and NFVO specifically for:
  • Request lifecycle management of service gragh request VNF lifecycle management; forward NFV related status information; exchange policy management information; exchange data analysis information; forward NFV related billing and usage records; exchange capacity and inventory information.
  • VNF/EMS The Ve-Vnfm interface between VNF/EMS and VNFM, specifically for:
  • Service, VNF and Infrastructure Description and Se-Ma interface between NFVO used to retrieve information related to VNF forwarding maps, business-related information, VNF-related information, and information related to the NFVI information model. This information is provided to NFVO for use.
  • the alarm information of the service layer and the alarm information of the infrastructure layer and the virtualization layer are analyzed, the number of alarm information is reduced, and the alarm information of the cross-layer is analyzed, and the same work is distributed for the same root cause alarm information.
  • Single reduce the number of work orders, thereby reducing the cost of network operation and maintenance.
  • FIG. 2 is a schematic diagram of a method for processing alarm information according to an embodiment of the present invention.
  • the method includes:
  • the network element management system EMS obtains the first alarm information set reported by the virtualized network function manager VNFM.
  • the first alarm information set is an alarm information of the VNFM to the at least one network function virtualization infrastructure NFVI.
  • at least one virtualization infrastructure manager The VIM alarm information is generated after correlation analysis.
  • the NFVI is divided into an infrastructure layer and a virtualization layer, and the infrastructure layer and the virtualization layer contain different management objects.
  • the infrastructure layer includes management objects such as a physical host, a memory, a switch, a physical network card, and a physical port.
  • the virtualization layer includes management objects such as virtual machines, virtual network cards, and virtual ports.
  • the VIM is responsible for managing the NFVI.
  • the VIM also generates a VIM alarm.
  • the VIM reports at least one NFVI alarm and at least one VIM alarm to the VNFM.
  • the VNFM alerts the at least one NFVI. Correlation analysis is performed between the information and the alarm information of at least one VIM.
  • the VNFM may perform correlation analysis on the at least one NFVI alarm information and the at least one VIM alarm information according to the correlation rule, determine the relevant alarm information, and compose the related alarm information into a group, and the VNFM may The at least one NFVI alarm information and the at least one VIM alarm information are masked to reduce the number of alarm information.
  • the first alarm information set is generated, and the VNFM reports the first alarm information set to the EMS, where the first alarm is generated.
  • the collection of information can be represented in the form of a fault tree.
  • the EMS obtains a second alarm information set reported by the virtual network function VNF.
  • the second alarm information set includes at least one alarm information of the virtualized network function VNF.
  • the VNF when the VNF detects its own fault, it generates multiple VNF alarms, and the multiple alarms form a second alarm set, and the VNF reports the second alarm set to the EMS.
  • S103 The EMS performs correlation analysis on the first alarm information set and the second alarm information set, and distributes the configured work order for the alarm information having a correlation relationship.
  • the EMS performs correlation analysis on the alarm information in the first alarm set and the second alarm set, where the alarm information in the first alarm set includes alarm information generated by the infrastructure layer and the virtualization layer, and the second alarm set
  • the alarm information is an alarm information including a service layer
  • the EMS performs correlation analysis on the alarm information in the first alarm set and the second alarm set according to a preset correlation rule, and distributes the configuration for the alarm information having the correlation relationship.
  • the work order in this way, correlates the alarm information of multiple layers, and distributes work orders for the alarm information with correlation relationship, which reduces the number of work orders.
  • the EMS collects the first alarm information set and the second alarm information
  • the line correlation analysis, the work order for distributing the alarm information for the correlation relationship includes:
  • a configured work order is dispatched for the alarm information with a correlation relationship.
  • the management layer, the virtualization layer, and the service layer are distributed with different management objects
  • the service layer is the upper layer
  • the virtualization layer is the middle layer
  • the infrastructure layer is the lower layer.
  • the management objects of each layer have a certain correspondence.
  • the management object in the infrastructure layer fails, the corresponding management object in the virtualization layer and the service layer also fails.
  • the management object in each layer fails, the management object identifier is carried in the alarm information.
  • the management object identifier of the management object having such a correspondence relationship is bound in advance to form an association relationship.
  • Application1 in the service layer, VM1 in the virtualization layer, and Host1 in the infrastructure layer have an association relationship, and the identifier of Application1 is determined.
  • the identifier of VM1 and the identifier of Host1 are bound to form an association relationship.
  • the EMS extracts the management object identifier carried in the alarm information in the first alarm set, and queries the alarm information having the correlation relationship between the first alarm information set and the second alarm information set based on the association relationship, and distributes the configuration of the alarm information having the correlation relationship. Work order.
  • the first alarm set includes: alarm information 1, alarm information 2, alarm information 3, and alarm information 4;
  • the second alarm set includes alarm information 5, alarm information 6, alarm information 7, and alarm information 8;
  • the alarm information 1 and the alarm information 2 in the set have a correlation relationship
  • the alarm information 3 and the alarm information 4 have a correlation relationship
  • the management object identifier carried by the EMS extraction alarm information 1 is the identifier of VM1, according to the association relationship: Application1-VM1-Host1
  • the EMS determines that the alarm information, the alarm information 2, the alarm information 4, and the alarm information 5 have a correlation relationship, and the EMS is based on the foregoing four alarms, and the identifier of the management object carried in the alarm information 5 in the second alarm set is the identifier of the host1.
  • the information analyzes the cause of the failure and distributes the configured work order.
  • the method before the acquiring, by the network element management system, the EMS, the first alarm information set reported by the virtualized network function manager VNFM, the method further includes:
  • the MANO configures the association relationship of the management object identifiers for the VNF, where the management object identifier carried in the alarm information in the first alarm information set includes: an identifier of the VM or an identifier of the vNIC, and the second alarm
  • the management object identifier carried in the alarm information of the information set includes the The logo of the VNF.
  • the MANO configures the association relationship of the management object identifiers for the VNF, and the alarm information of the second alarm information set reported by the VNF to the EMS carries the association relationship of the management object identifier, and the alarm information of the second alarm information set is further
  • the alarm information of the first alarm information set also carries the management object identifier of the management object that has failed
  • the EMS can associate the management object identifier according to the alarm information in the second alarm set. Querying the alarm information having a correlation relationship between the first alarm set and the second alarm set.
  • the identifier of the management object carried in the alarm information in the first alarm information set includes, for example, the association relationship of the management object identifier carried in the alarm information in the second alarm information set is: VNF ID-VM ID-vNIC ID, management object
  • the identified association relationship represents an identifier of a management object having a corresponding relationship in the business layer, the virtualization layer, and the infrastructure layer.
  • the identifier of the VM includes an identifier of the NFVI assignment or an identifier of the MANO assignment.
  • the alarm information having the correlation relationship between the first alarm set and the second alarm set is divided into the same group, each group is assigned a group identifier, and root cause alarm information and derivatives in each group are selected.
  • the alarm information is assigned a corresponding alarm type identifier.
  • the VNFM may divide the alarm information having the correlation relationship in the first alarm set into the same group according to a preset correlation rule, and each group is assigned a group identifier, and the correlation rule is divided into a time correlation rule and a space.
  • the correlation rule, the VNFM determines the type of the correlation relationship according to the idle correlation rule, for example, the parent-child alarm and the sibling alarm, and determines the root-source alarm information and the derivative alarm information from the alarm information having the correlation relationship, and respectively assign different alarm types.
  • logo the VNF can perform the foregoing processing on the alarm information in the first alarm set, and details are not described herein again.
  • the relevant rules can be used after being opened on site, eliminating the need for customers to summarize rules and tests on the spot.
  • the default correlation rules are verified by experts and tested, and the accuracy is high.
  • the correlation rule can be enabled or disabled according to requirements.
  • the correlation rule consists of several sub-rules. You can also enable or disable one or more sub-rules as needed.
  • the alarm information of different layers can be analyzed for correlation, and the alarm information having the correlation relationship in different layers can be determined, and the association of the alarm information of the cross-layer is realized, and the alarm is the same root cause.
  • Information distributes the same work order, which can reduce the number of work orders distributed, This reduces the operation and maintenance costs of the network.
  • FIG. 3 is a schematic diagram of interaction of an alarm information processing system according to an embodiment of the present invention.
  • the functional entities involved include: EMS, VNF, VNFM, VIM, and NFVI, between the functional entities.
  • the interaction process is as follows:
  • the NFVI is divided into an infrastructure layer and a virtualization layer.
  • the infrastructure layer is composed of physical management objects
  • the virtualization layer is composed of virtual management objects.
  • the infrastructure layer includes a physical host, a memory, a switch, a physical network card, and a physical layer. Management objects such as ports.
  • the virtualization layer includes management objects such as virtual machines, virtual network cards, and virtual ports.
  • the NFVI reports at least one NFVI alarm information to the VIM.
  • S203 and VIM are faulty, and at least one VIM alarm information is generated.
  • the VIM when the NFVI is faulty, the VIM generates alarm information according to its own state information and fault information.
  • the alarm information carries parameters such as the management object identifier, alarm time, and alarm level.
  • the VIM reports at least one NFVI alarm information and at least one VIM alarm information to the VNFM.
  • the VNFM performs correlation analysis on the at least one NFVI alarm information and the at least one VIM alarm information to generate a first alarm information set.
  • the VNFM may perform correlation analysis on the at least one NFVI alarm information and the at least one VIM alarm information according to the correlation rule, determine the relevant alarm information, and compose the related alarm information into a group.
  • the VNFM can block the at least one NFVI alarm information and the at least one VIM alarm information to reduce the number of alarm information.
  • the first alarm information set is generated, and the VNFM reports the first alarm information set to the EMS.
  • the first set of alarm information may be in the form of a fault tree.
  • the VNFM reports the first alarm information set to the EMS.
  • the VNF fails, and generates at least one VNF alarm information.
  • the management object in the NFVI has a corresponding relationship with the management object in the VNF.
  • the management object in the VNF also fails accordingly.
  • the VNF fails, at least one VNF alarm information is generated.
  • the VNF performs correlation analysis on the alarm information of the at least one VNF to generate a second alarm.
  • Information collection Specifically, the VNF may divide the alarm information having the correlation relationship in the second alarm set into the same group according to the preset correlation rule, and each group is assigned a group identifier, and the correlation rule is divided into a time correlation rule and a space.
  • the VNF determines the type of the correlation relationship according to the idle correlation rule, for example, the parent-child alarm and the sibling alarm, and determines the root-source alarm information and the derivative alarm information from the alarm information having the correlation relationship, and respectively assign different alarm types.
  • logo the type of the correlation relationship according to the idle correlation rule, for example, the parent-child alarm and the sibling alarm
  • the VNF reports the second alarm information set to the EMS.
  • S210 The EMS performs correlation analysis on the alarm information in the combination of the first alarm information set and the second alarm information, and distributes the work order.
  • the EMS performs correlation analysis on the alarm information in the first alarm set and the second alarm set, where the alarm information in the first alarm set includes alarm information generated by the infrastructure layer and the virtualization layer, and the second alarm set
  • the alarm information is an alarm information including a service layer
  • the EMS performs correlation analysis on the alarm information in the first alarm set and the second alarm set according to a preset correlation rule, and distributes the configuration for the alarm information having the correlation relationship.
  • the work order in this way, correlates the alarm information of multiple layers, and distributes work orders for the alarm information with correlation relationship, which reduces the number of work orders.
  • the EMS performs correlation analysis on the first alarm information set and the second alarm information set, and distributes the configured work order for the alarm information having the correlation relationship, including:
  • a configured work order is dispatched for the alarm information with a correlation relationship.
  • the management layer, the virtualization layer, and the service layer are distributed with different management objects
  • the service layer is the upper layer
  • the virtualization layer is the middle layer
  • the infrastructure layer is the lower layer.
  • the management objects of each layer have a certain correspondence.
  • the management object in the infrastructure layer fails, the corresponding management object in the virtualization layer and the service layer also fails.
  • the management object in each layer fails, the management object identifier is carried in the alarm information.
  • the management object identifier of the management object having such a correspondence relationship is bound in advance to form an association relationship.
  • Application1 in the service layer, VM1 in the virtualization layer, and Host1 in the infrastructure layer have an association relationship, and the identifier of Application1 is determined.
  • the identifier of VM1 and the identifier of Host1 are bound to form an association relationship.
  • the EMS extracts the management object identifier carried in the alarm information in the first alarm set, and queries the alarm information having the correlation relationship between the first alarm information set and the second alarm information set based on the association relationship, and distributes the configuration of the alarm information having the correlation relationship. Work order.
  • the first alarm set includes: alarm information 1, alarm information 2, alarm information 3, and alarm information 4;
  • the second alarm set includes alarm information 5, alarm information 6, alarm information 7, and alarm information 8;
  • the alarm information 1 and the alarm information 2 in the set have a correlation relationship
  • the alarm information 3 and the alarm information 4 have a correlation relationship
  • the management object identifier carried by the EMS extraction alarm information 1 is the identifier of VM1, according to the association relationship: Application1-VM1-Host1
  • the EMS determines that the alarm information, the alarm information 2, the alarm information 4, and the alarm information 5 have a correlation relationship, and the EMS is based on the foregoing four alarms, and the identifier of the management object carried in the alarm information 5 in the second alarm set is the identifier of the host1.
  • the information analyzes the cause of the failure and distributes the configured work order.
  • the alarm information of different layers can be analyzed for correlation, and the alarm information having the correlation relationship in different layers can be determined, and the association of the alarm information of the cross-layer is realized, and the alarm is the same root cause.
  • Information distributes the same work order, which can reduce the number of work orders distributed, thereby reducing the operation and maintenance costs of the network.
  • FIG. 4 is a schematic structural diagram of a network element management system according to an embodiment of the present invention.
  • the network element management system includes: a first obtaining module 10, a second obtaining module 11, and a work order.
  • the first obtaining module 10 is configured to obtain a first alarm information set reported by the virtualized network function manager VNFM, where the first alarm information set is an alarm that is used by the VNFM to at least one network function virtualization infrastructure NFVI.
  • the information is generated after correlation analysis is performed with the alarm information of at least one virtualized infrastructure manager VIM.
  • the second obtaining module 11 is configured to obtain a second alarm information set reported by the virtual network function VNF.
  • the second alarm information set includes at least one alarm information of the virtualized network function VNF.
  • the work order dispatching module 12 is configured to perform correlation analysis on the first alarm information set and the second alarm information set, and distribute the configured work order for the alarm information having the correlation relationship.
  • the work order dispatching module 12 includes: an extracting unit 121, a querying unit 122, and a dispatching unit 123.
  • the extracting unit 121 is configured to extract a management object identifier carried by the alarm information of the first alarm information set.
  • the querying unit 122 is configured to query, according to the association relationship of the management object identifier, the alarm information that has a correlation relationship between the first alarm set and the second alarm set.
  • the dispatching unit 123 is configured to distribute the configured work order for the alarm information having the correlation relationship.
  • the identifier of the VM is allocated by the NFVI or the MANO.
  • MANO includes VNF, VIM and NFVO.
  • the alarm information having the correlation relationship between the first alarm set and the second alarm set is divided into the same group, each group is assigned a group identifier, and root cause alarm information and derivatives in each group are selected.
  • the alarm information is assigned a corresponding alarm type identifier.
  • FIG. 6 is another schematic structural diagram of a network element management system according to an embodiment of the present invention.
  • the network element management system includes a processor 61, a memory 62, and a communication interface 63.
  • the processor 61, the memory 62, and the communication interface 63 may be connected by a bus or other means, and a bus connection is taken as an example in FIG.
  • the memory 62 is used to store program code.
  • the program may include program code, and the program code includes computer operation instructions.
  • the memory 62 may include a random access memory (RAM), and may also include a non-volatile memory such as at least one disk storage.
  • the processor 61 executes the program code stored in the memory 62, and is used to implement the alarm information processing method provided by the embodiment of the present invention, including:
  • the first alarm information set is alarm information of the VNFM to the at least one network function virtualization infrastructure NFVI and at least one virtualization infrastructure
  • the alarm information of the manager VIM is generated after correlation analysis.
  • Correlation analysis is performed on the first alarm information set and the second alarm information set, and the configured work order is distributed for the alarm information having the correlation relationship.
  • the processor 61 performs the correlation analysis on the first alarm information set and the second alarm information set, and distributes the configured work order for the alarm information having the correlation relationship, including:
  • a configured work order is dispatched for the alarm information with a correlation relationship.
  • the identifier of the VM is allocated by the NFVI or the MANO.
  • the alarm information having the correlation relationship between the first alarm set and the second alarm set is divided into the same group, each group is assigned a group identifier, and root cause alarm information and derivatives in each group are selected.
  • the alarm information is assigned a corresponding alarm type identifier.
  • FIG. 7 is a method for processing alarm information according to an embodiment of the present invention.
  • the method may be performed by an EMS, where the method includes:
  • the first alarm association information includes at least one of the following: an association relationship between the first object identifier and the preset object identifier.
  • the first object identifier includes at least one of the following: a VNF identifier, a virtual machine VM identifier, and a virtual transmission resource identifier of the VM.
  • the VM identifier is used to uniquely identify a VM.
  • the VM identifier may be a VM name (name) or a VM identifier (identifier, ID).
  • VNF identifier used to uniquely identify a VNF.
  • the VNF identifier may specifically be a VNF ID or a VNF name, which is not limited herein.
  • the VM's virtual transport resource identifier is used to uniquely identify a VM, for example, VNIC ID, VNIC name, VPORT ID or VPORT name, which is not limited here.
  • association relationship of the preset object identifiers is used to indicate an association relationship between different object identifiers, for example, a correspondence between a VNF ID and a VM ID, and, for example, a VNF ID, a VM ID, and a host (HOST) identifier.
  • object identifiers for example, a correspondence between a VNF ID and a VM ID, and, for example, a VNF ID, a VM ID, and a host (HOST) identifier.
  • HOST host
  • the HOST identifier is the host identifier in the infrastructure layer of the NFVI, and is used to uniquely identify a HOST of an NFVI, specifically a HOST ID or a HOST name; the VIM is responsible for managing the NFVI, including the infrastructure layer, the virtual layer, and the application of the NFVI. Floor.
  • the first alarm message further includes a first alarm information set.
  • the first alarm message may include an alarm message or an alarm information group. That is, the first alarm information set may include at least one of the following: NFVI alarm information (including the infrastructure layer and the virtualization layer). Alarm information), VM alarm information and VNFM alarm information.
  • the VNFM alarm information may be a correlation alarm information generated by the VNFM, for example, may be generated by correlation analysis between at least two alarm information reported by the VIMM by the VNFM, or may be generated by a virtual machine corresponding to the VNFM.
  • the NFVI alarm information may be alarm information generated by the NFVI.
  • the VM alarm information may be the alarm information generated by the VM managed by the VM or the VIM corresponding to the VIM, or may be the correlation alarm information generated by the VIM. For example, the alarm information generated by the correlation analysis between the two NFVI alarm information by the VIM. .
  • the above is merely illustrative and not limiting.
  • first alarm association information may be carried in the first alarm information set, and the first alarm association information may also be independent of the first alarm information set.
  • the first alarm association information may be carried in the alarm information included in the first alarm information set.
  • the first alarm information set includes at least two VM alarm information, and each VM alarm information includes a VM identifier, and the VM identifier is the first alarm association information.
  • the first alarm information set may include: an alarm information including a VM identifier, and at least one alarm information including a lower-level object identifier (for example, a HOST ID of the NFVI).
  • the first alarm association information may be located in the first alarm message in parallel with the first alarm information set.
  • the first alarm association information is a VM ID
  • the structure of the first alarm message may be ⁇ VM ID, alarm information 1, alarm information 2, and alarm information 3 ⁇ , wherein the alarm information 1, the alarm information 2, and the advertisement
  • the police information 3 constitutes a first set of alarm information.
  • the first alarm information may further include a fault mode, which is used to indicate the cause of the fault, for example, a high CPU usage, a hardware device fault, and the like, and details are not described herein.
  • a fault mode which is used to indicate the cause of the fault, for example, a high CPU usage, a hardware device fault, and the like, and details are not described herein.
  • the foregoing first alarm information set may further include a correlation identifier, configured to indicate alarm information that has a correlation association relationship.
  • the correlation identifier may be a group identifier, and the alarm information having the same correlation group identifier has a correlation, for example, a first alarm information set ⁇ alarm information 1, group1; alarm information 2, group1 ⁇ , wherein the alarm information 1 and the alarm
  • the information 2 has the same group identifier, indicating that there is a correlation between the two; the correlation identifier may also be a relationship between different alarms, for example, the first alarm information set ⁇ alarm information 1, 0; alarm information 2, 1 ⁇ , where 0 indicates that the alarm information 1 is a parent alarm, and 1 indicates that the alarm information 2 is a sub-alarm, that is, the two are parent-child alarm relationships.
  • Object identifier, and 0 indicates the parent alarm, and 1 indicates the sub-alarm.
  • ⁇ VM1, 0, VM2, 1 ⁇ indicates that the alarm information 1 and 2 are the parent-child alarm relationship.
  • the foregoing first alarm message may further include a root cause alarm, which is used to indicate a root cause of the generated alarm.
  • the second alarm message includes the second alarm association information, and the second alarm association information includes at least one of the following: an association relationship between the second object identifier and the preset object identifier;
  • the second alarm message may further include a second alarm information set, where the second alarm information set may include at least one VNF alarm information.
  • the second object identifier is used to uniquely identify the second object, and the first object and the second object may be the same or different.
  • the second alarm association information may be carried in the second alarm information set, and the second alarm association information may also be independent of the second alarm information set.
  • the second alarm association information may also be independent of the second alarm information set.
  • the related description of the first alarm association information is not described here.
  • the first alarm message and the second alarm message may be entered according to a preset correlation rule. Row correlation analysis. For example, if the first alarm association information is the same as the second alarm association information, the first alarm message and the second alarm message have a correlation.
  • step 703 may specifically adopt the following implementation manner.
  • Correlation analysis is performed on the acquired information with the same alarm correlation according to a preset correlation rule.
  • the first alarm information set includes: alarm information 1, alarm information 2, alarm information 3, and alarm information 4;
  • the second alarm information set includes alarm information 5, alarm information 6, alarm information 7, and alarm information 8;
  • the alarm information 1 and the alarm information 2 in the first alarm information set include the same alarm-related information VM1.
  • the alarm information 3 and the alarm information 4 respectively include alarm-related information VNF ID1 and VNF ID2, and the alarm information 5 carries the VM1.
  • the EMS obtains the alarm information carrying the management object identifier VM1: alarm information 1, 2, and 5; and performs correlation analysis on the alarm information 1, 2, and 5 according to the preset correlation rule, if the correlation rule is a parent-child alarm And the alarm information 1 and 5 are the parent-child alarm relationship, and the alarm information 1 and 5 having the parent-child alarm relationship are found in the alarm information 1, 2 and 5, and the alarm information 1 and 5 are determined to be the correlation alarm information.
  • first alarm association information and the second alarm association information in the foregoing manner 1 may all be association relationships of preset object identifiers.
  • the first object identifier in the first alarm association information and the second object identifier in the second alarm association information, in the first alarm information set and the second alarm information, according to the association relationship of the preset object identifiers Obtaining a third alarm information set in the set, where the third alarm information set is composed of alarm information having an association relationship between the object identifiers;
  • Correlation analysis is performed on the third alarm information set according to a preset correlation rule.
  • the alarm information that has an association relationship between the object identifiers may include alarm information having the same object identifier, and alarm information including an object identifier that has an association relationship with the same object identifier.
  • association relationship of the preset object identifier may be preset in the EMS or may be configured to the EMS through the communication interface, and is not limited.
  • the first object identifier in the first alarm association information and the second object identifier in the second alarm association information have different identifier types.
  • the identifier type may include: a VM identifier, a HOST identifier, and a virtual transmission resource identifier of the VM.
  • the first alarm information set includes: alarm information 1 and alarm information 2; the second alarm information set includes alarm information 3 and alarm information 4; and the object identifier included in the alarm information 1 in the first alarm information set is VM name1
  • the alarm information 2 includes an object identifier of Host name1, and the alarm information 3 and the alarm information 4 respectively include object identifiers VM name1 and VM name2.
  • the EMS obtains the third alarm information set: the alarm information 1, the alarm information 2, and the alarm information 3, and analyzes the relationship between the three alarms according to the preset correlation rule. For details, refer to the description in the first method. .
  • association relationship between the preset object identifiers may be specifically carried in the first alarm message or the second alarm message, and may be preset in the EMS, which is not limited herein.
  • Manner 3 When the first alarm message includes the correlation identifier, the first alarm association information and the second alarm association information perform correlation analysis on the first alarm information set and the second alarm information set according to the correlation identifier.
  • the first alarm information set ⁇ alarm information 1, group1; alarm information 2, group1 ⁇ , and the alarm information 1 includes VM1
  • the alarm information 2 includes VM2
  • the information 3 includes VM1
  • the alarm information 4 includes VM3, and the alarm information 1, 2, and 3 have a correlation relationship.
  • the preset correlation rules can be divided into time correlation rules and spatial correlation rules, such as: parent-child alarms and sibling alarms. Relevant rules can be used after being opened on site, eliminating the need for customers to summarize rules and tests on the spot. The default correlation rules are verified by experts and tested, and the accuracy is high. The correlation rule can be enabled or disabled according to requirements. The correlation rule consists of several sub-rules. You can also enable or disable one or more sub-rules as needed.
  • the VNF alarm information is compared with the alarm information reported by the VNFM.
  • the correlation analysis determines the alarm information of correlations in different layers to achieve the correlation of alarm information across layers, avoids the complexity of manual alarm analysis, reduces the time of alarm analysis, and reduces the operation and maintenance cost of the network. .
  • the method further includes:
  • the EMS distributes the configured work order for the alarm information with the correlation relationship.
  • step 703 the method further includes:
  • the alarm information having the correlation relationship between the first alarm information set and the second alarm information set is divided into the same group, and the group identifier is allocated to the divided group.
  • FIG. 8 is another method for processing alarm information according to an embodiment of the present invention.
  • the method is performed by a VNFM, and specifically includes:
  • the VM alarm information may include a third object identifier, where the third object identifier is uniquely identified, and the third object identifier may include at least one of the following: a VM identifier, a HOST identifier, and a virtual transmission resource identifier of the virtual machine.
  • the VM identifier is used to uniquely identify a VM
  • the HOST identifier is used to uniquely identify a HOST of the NFVI, which may be a HOST ID or a HOST name.
  • the virtual transport resource identifier of the virtual machine is used to uniquely identify a VM, for example, a VPORT ID or VPORT name, for example, vNIC ID or vNIC name.
  • the VM alarm information further includes a fault mode, which is used to indicate a cause of the fault, for example, a high CPU usage, a hardware device fault, and the like, and is not limited; and may include a correlation identifier, where the correlation identifier may be a group
  • the identifiers of the alarms having the same correlation group identifiers are related to each other.
  • the correlation identifiers may also be related to different alarms. For details, refer to the related description in step 701 in FIG.
  • the VM alarm information may be related to at least two pieces of alarm information (for example, one NFVI alarm information, one VM alarm information; and, for example, at least two NFVI alarm information or at least two VM alarm information) by the VIM.
  • the VM-related alarm information that is reported later, or the NFVI alarm information reported by the NFVI may also be the VM alarm information generated by the VM corresponding to the VIM, or may be the alarm information generated by the VM managed by the VIM.
  • the first alarm message further includes a first alarm information set.
  • the first alarm message is generated according to the VM alarm information, and the following two implementation manners may be used:
  • the first alarm message may include only the first object identifier.
  • the content of the VM alarm information may be used as the first alarm information set, and details are not described herein.
  • Manner 2 Perform correlation analysis on the VM alarm information to generate a first alarm message.
  • the VNFM performs correlation analysis on the VM alarm information according to the same type of identifier, and uses the identifier of the same type as the first alarm association information. .
  • identifier of the same type may be a VM identifier, a HOST identifier, or a vNIC identifier, and details are not described herein.
  • the VNFM alarms the VM according to a preset configuration relationship, when the type of the identifier included in the at least one alarm information is different from the identifier type included in the other alarm information in the VM alarm information.
  • the information is analyzed for correlation, and the first alarm related information is obtained.
  • the at least one alarm information includes an identifier type of the HOST identifier, that is, the at least one alarm information is reported by the NFVI underlying layer
  • the other alarm information includes the VM identifier, that is, the other alarm is performed by the NFVI virtual layer or
  • the VNFM obtains the configuration relationship between the VM and the HOST, and obtains the VM identifier corresponding to the HOST identifier according to the obtained configuration relationship, and then performs correlation analysis on the VM alarm information according to the VM identifier.
  • the HOST identifier corresponding to the VM identifier in the other alarm information in the VM alarm information is obtained according to the configuration relationship, and then the VM alarm information is analyzed according to the HOST identifier.
  • the VM alarm information is correlated and the first alarm message is generated according to the correlation identifier of the VM and the third object identifier carried in the VM alarm information.
  • the generated first alarm message may further include: assigning a correlation identifier to the VM alarm information having relevance.
  • the generated first alert message may further include an assigned correlation identifier.
  • NFVI alarm information 1, group1; NFVI alarm information 2, group1 ⁇ another VM alarm information is NFVI alarm information 3 and NFVI alarm information 1 contains VM1, NFVI alarm information 2 contains host1, NFVI The alarm information 3 contains VM1, and the NFVI alarm information 1, 2 and 3 have correlation.
  • the configuration relationship between the VM and the HOST may be a correspondence between the virtual machine and the host.
  • first alarm association information in the first alarm message in the second manner can also be obtained by using the method provided in the foregoing manner, and details are not described herein.
  • the VNFM reports the first alarm message to the EMS, so that the EMS performs correlation analysis with the VNF alarm information according to the first alarm message, and then determines alarm information with correlation relationship in different layers to implement cross-
  • the association of alarm information at the layer avoids the complexity of manual analysis of alarms and reduces the time for alarm analysis, thereby reducing the operation and maintenance costs of the network.
  • FIG. 9 is another method for processing alarm information according to an embodiment of the present invention.
  • the method is performed by a VIM, and specifically includes:
  • the at least two pieces of alarm information may include: at least one NFVI alarm information and at least one VM alarm information; or the at least two pieces of alarm information are both NFVI alarm information or VM alarm information, which are not limited.
  • the VM alarm information is the VM-related alarm information, and may include at least one of a VM identifier, a HOST identifier, and a virtual transmission resource identifier of the virtual machine.
  • a VM identifier identifier for the VM-related alarm information
  • HOST identifier identifier for the virtual machine
  • a virtual transmission resource identifier of the virtual machine identifier for the VM-related alarm information.
  • the VM correlation alarm information may be in the following three forms:
  • VM correlation alarm information only contains the VM identifier.
  • the NFVI identifier may include the VM identifier, the HOST identifier, and the VM identifier and the subordinate object identifier.
  • the RNVI identifier may include the VM identifier, the HOST identifier, and the NFVI identifier in the NFVI alarm associated with the VM correlation alarm information. At least one of virtual machine resource identifications of virtual machines.
  • the VIM performs a correlation analysis on the first NFVI alarm information reported by the first NFVI virtual layer and the second NFVI alarm information reported by the first NFVI infrastructure layer (for example, NFVI HOST), where the first NFVI alarm information includes the VM.
  • the ID, the second NFVI alarm information includes a HOST ID. If there is a correlation between the two alarms, the generated VM correlation alarm information includes a VM ID and a lower level identifier HOST ID.
  • the VM correlation alarm information includes at least two pieces of alarm information, and a correlation identifier of the at least two alarms.
  • the correlation identifier may be a group identifier, and the alarm information having the same correlation group identifier may have a correlation, and the correlation identifier may also be a relationship between different alarms. For details, refer to the related description in step 701 in FIG. 7. Further, the root cause alarm identifier may be further included to indicate a root cause of the VM relevance alarm information.
  • the VIM performs correlation analysis on at least two alarm information, which reduces the complexity of the manual alarm analysis and reduces the alarm analysis time.
  • the correlation analysis of the alarm information by the VIM greatly reduces the VNFM. load.
  • the foregoing method may further include:
  • the NFVI alarm information includes an NFVI identifier.
  • the NFVI identifier may include at least one of a VM identifier, a HOST identifier, and a virtual transmission resource identifier of the virtual machine.
  • the NFVI alarm information may be specifically reported by the virtual layer or the bottom layer of the NFVI.
  • FIG. 10 is another method for processing alarm information according to an embodiment of the present invention, where the method includes:
  • NFVI reports NFVI alarm information to VIM.
  • the VIM receives the NFVI alarm information, and generates VM alarm information according to the received NFVI alarm information.
  • the step 102 may specifically adopt the following two implementation manners:
  • Method 1 Perform correlation analysis on the reported NFVI alarm information to generate VM correlation alarm information
  • Mode 2 The VIM sends the NFVI alarm information directly to the VNFM.
  • the NFVI alarm information may be generated by the same NFVI or different NFVIs.
  • the VM alarm information may also be generated by the same VIM or different VIMs, which is not limited herein.
  • the NFVI reports the NFVI alarm message to the VIM.
  • the VIM reports the NFVI alarm information and the VIM alarm information to the VNFM.
  • the VNFM analyzes the correlation between the NFVI alarm information and the VIM alarm information to generate the first alarm information set.
  • the NFVI reports the NFVI alarm information to the VIM.
  • the VIM also fails and generates VIM alarm information.
  • the VIM correlates the NFVI alarm information with the VIM alarm information.
  • sexual analysis, and the VIM alarm information of the correlation analysis is sent to the VNFM; the VNFM performs correlation analysis on at least two VIM alarm information to generate the first alarm information set.
  • the NFVI alarm information and the VIM alarm information may carry parameters such as an object identifier, an alarm time, and an alarm level, which are not limited herein.
  • the NFVI alarm information includes an NFVI identifier, and the NFVI identifier may include at least one of a VM ID, a host ID, and a vNIC ID.
  • the VNFM performs correlation analysis on the VM alarm information reported by the VIM to generate a first alarm message.
  • the VM alarm information may include at least two of NFVI alarm information and VM alarm information.
  • the first alarm message may include the first alarm association information, and may further include the first alarm information.
  • the first alarm information set may be generated after the VNFM performs correlation analysis on the at least one NFVI alarm information and the at least one VIM alarm information, or may be at least two VIM alarm information by the VNFM. Generated after correlation analysis.
  • the first alarm association information includes at least one of the following: an association relationship between the first object identifier and the preset object identifier, where the first object identifier is used to uniquely identify an object, and may be a VNF identifier or a VM identifier.
  • the first object identifier may be a VNF ID or a VM ID or a vNIC ID, or may be a VNF name or a VM name or a vNIC name;
  • an association relationship of a preset object identifier may be used to indicate an association relationship between different object identifiers, for example, a VNF ID.
  • the correspondence between the VM ID and the VM ID for example, the correspondence between the VNF ID, the VM ID, and the HOST ID, will not be enumerated here.
  • the VNFM may perform correlation analysis on the at least one NFVI alarm information and the at least one VIM alarm information according to the correlation rule, determine related alarm information, and compose the related alarm information into a group.
  • the VNFM can block at least one NFVI alarm information or at least one VIM alarm information to reduce the number of alarm information.
  • the first alarm information set is generated, and the VNFM reports the first alarm information set to the EMS, where the first alarm information set can be expressed in the form of a fault tree.
  • the VNFM sends a first alarm message to the EMS.
  • the EMS receives the first alarm message reported by the VNFM.
  • the VNF reports the second alarm message.
  • the second alarm message may include the second alarm association information, and may also include the second alarm information set.
  • the second alarm information set may include the second alarm association information, and may also include the second alarm information set.
  • the second alarm association information may be used by the EMS to perform correlation analysis on the second alarm information set, where the second alarm association information includes at least one of the following: an association relationship between the second object identifier and the preset object identifier;
  • the second object identifier is used to uniquely identify a management object, and may be a VNF identifier or a VM identifier or a vNIC identifier, for example, may be a VNF ID or a VM ID, or may be a VNF name or a VM name; a preset object identifier.
  • the association relationship may be used to indicate the association relationship between the respective management object identifiers, for example, the correspondence between the VNF ID and the VM ID, and for example, the correspondence between the VNF ID, the VM ID, and the HOST, where the relationship is no longer List one by one.
  • the second alarm association information may be carried in the second alarm information set, for example, the alarm information included in the second alarm information set carries the second alarm association information;
  • the second alarm information set may be independent of the second alarm information set. For example, when all the alarm information in the second alarm information set is from the same management object, the second alarm association information and the second alarm information set may be juxtaposed to the first alarm. In the news, there is no limit here.
  • the second alarm information set may include at least one VNF alarm information, and the at least one VNF alarm information may be generated by the same VNF or a different VNF.
  • the VNF when the VNF detects its own fault, the VNF generates at least one VNF alarm information, and the at least one VNF alarm information forms a second alarm information set, and the VNF reports the second alarm information set to the EMS.
  • the VNF identifier of the VNF that generates the alarm and the correspondence between the VNF identifier and the VM identifier or the correspondence between the VNF identifier and the vNIC identifier may be obtained with the VNF identifier.
  • the EMS receives the second alarm message reported by the VNF.
  • steps 1006-1007 and steps 1001-1005 are in no particular order and is not limited.
  • the EMS performs correlation analysis on the first alarm message and the second alarm message according to the first alarm association information and the second alarm association information.
  • the step 1008 can be implemented by using the specific implementation of the step 703 in the embodiment shown in FIG. 7, and details are not described herein.
  • the alarm information in the first alarm information set may include alarm information generated by the infrastructure layer and the virtualization layer
  • the alarm information in the second alarm information set may include alarm information of the service layer
  • the EMS may be related according to a preset.
  • the sex rule analyzes the correlation between the first alarm information set and the second alarm information set, and integrates the alarm information with the correlation relationship, thereby avoiding the manual analysis process, greatly saving the alarm analysis time and improving the time. Work efficiency.
  • the preset correlation rules may be specifically classified into a temporal correlation rule and a spatial correlation rule, for example, a parent-child alarm and a sibling alarm; the EMS finds the associated alarm information from the two alarm sets according to the correlation rule. For example, the root source alarm information and the derived alarm information are determined.
  • the EMS pairs the first alarm information set and the second alarm information set Correlation analysis is performed on the alarm information in the middle, which realizes the analysis and integration of cross-layer alarms, avoids the manual analysis process, greatly saves the alarm analysis time and improves the work efficiency.
  • the EMS before receiving the first alarm message reported by the VNFM, the EMS further includes:
  • the VNFM configures an association relationship of the object identifiers for the VNF.
  • the MANO configures the association relationship of the object identifiers for the VNF, and the alarm information of the second alarm information set reported by the VNF to the EMS carries the association relationship of the object identifier, and the alarm information of the second alarm information set also carries the information.
  • the object identifier of the object of the fault, the alarm information of the first alarm information set also carries the object identifier of the object that is faulty, and the EMS can query the first alarm information set according to the association relationship of the object identifier carried in the alarm information in the second alarm information set.
  • the alarm information having a correlation relationship with the second alarm information set.
  • the identifier of the object carried in the alarm information in the first alarm information set includes, for example, the association relationship of the object identifier carried in the alarm information in the second alarm information set is: VNF ID-VM ID-vNIC ID, association of the object identifier A relationship represents an identifier of an object having a corresponding relationship in a business layer, a virtualization layer, and an infrastructure layer.
  • the service layer is the upper layer
  • the virtualization layer is the intermediate layer
  • the infrastructure layer is the lower layer.
  • the objects of each layer have a certain correspondence. If the object in the infrastructure layer fails, the corresponding object in the virtualization layer and the service layer will also be faulty. When the object in each layer fails, the alarm information carries the association relationship between the object identifier or the object identifier.
  • the alarm information of different layers of the same virtual device is obtained, so as to further confirm whether the alarm information of each layer in the same virtual device is caused by the same fault, that is, the correlation of the alarm information is confirmed.
  • an apparatus for processing an alarm information may be an EMS.
  • the apparatus may be used to perform the operation steps of the EMS in FIG. 7 or FIG. 10, and the apparatus may specifically include a first receiving unit. 1101. A second receiving unit 1102 and a processing unit 1103.
  • the first receiving unit 1101 is configured to receive a first alarm message that is reported by the VNFM, where the first alarm message includes first alarm association information, where the first alarm association information includes at least one of the following: a first object identifier and The association relationship of the preset object identifiers;
  • the second receiving unit 1102 is configured to receive a second alarm message that is reported by the VNF, where the second alarm message includes second alarm association information, where the second alarm association information includes at least one of the following: a second object identifier and The association relationship of the preset object identifiers;
  • the processing unit 1103 is configured to: according to the first alarm association information and the second alarm association information, the first alarm message received by the first receiving unit 1101 and the second alarm received by the second receiving unit 1102 The message is analyzed for relevance.
  • the first object identifier includes at least one of the following: a VNF identifier, a virtual machine VM identifier, and a virtual transmission resource identifier of the VM.
  • the second object identifier includes at least one of the following: a VNF identifier, a VM identifier, and a virtual transmission resource identifier of the VM.
  • the association relationship between the preset object identifiers is used to indicate an association relationship between different object identifiers;
  • the VNF identifier includes a VNF identifier ID or a VNF name name;
  • the VM identifier includes a VM ID or a VM name;
  • the virtual transmission resource identifier includes a virtual transmission resource ID or a virtual transmission resource name.
  • the first alarm message further includes a first alarm information set; the first alarm information set includes at least one of the following: NFVI alarm information, VM alarm information, and VNFM alarm information.
  • NFVI alarm information the VM alarm information, and the VNFM alarm information, refer to the related description in the method embodiments of FIG. 7-10, and details are not described herein.
  • the second alarm message further includes a second alarm information set, where the second alarm information set includes at least one VNF alarm information.
  • VNF alarm information For a description of the VNF alarm information, refer to the embodiments shown in FIG. 7 or FIG.
  • the processing unit 1103 is specifically configured to:
  • the third alarm information set is composed of alarm information having an association relationship between the object identifiers; and performing correlation analysis on the third alarm information set according to the preset correlation rule.
  • the EMS provided by the embodiment of the present invention performs correlation analysis on the VNF alarm information and the alarm information reported by the VNFM to determine the alarm information of the correlation in different layers, thereby realizing the association of the alarm information across layers and avoiding the manual.
  • the complexity of the alarm analysis reduces the time for alarm analysis, thereby reducing the operation and maintenance costs of the network.
  • an apparatus for processing an alarm information is a VNFM, and the apparatus may be specifically configured to perform a method for performing VNFM in the embodiment shown in FIG. 8 or FIG. 10, where the apparatus may specifically include :
  • the receiving unit 1201 is configured to receive virtual machine VM alarm information reported by the virtualization infrastructure management VIM, where the VM alarm information includes a third object identifier.
  • the processing unit 1202 is configured to generate, according to the VM alarm information received by the receiving unit 1201, a first alarm message, where the first alarm message includes first alarm association information, where the first alarm association information includes at least one of the following: An association relationship between the first object identifier and the preset object identifier;
  • the sending unit 1203 is configured to send the first alarm message generated by the processing unit 1202 to the network element management system (EMS), so that the EMS performs correlation analysis on the first alarm message and the second alarm information reported by the VNF.
  • EMS network element management system
  • the third object identifier may include at least one of the following: a VM identifier, a host HOST identifier of the NFVI infrastructure layer, and a virtual transmission resource identifier of the VM;
  • the VM identifier may include a VM identifier ID or a VM name name; the HOST identifier may include a HOST ID or a HOST name; and the virtual transmission resource identifier of the VM may include a virtual transmission resource ID or a virtual transmission resource name.
  • the virtual transmission resource identifier of the VM is used to uniquely identify a VM, for example, a VPORT ID or a VPORT name, and for example, a vNIC ID or a vNIC name.
  • the first object identifier may be used to uniquely identify the first object; the first object identifier may include at least one of the following: a VNF identifier, a VM identifier, and a virtual transmission resource identifier of the VM;
  • the association relationship of the preset object identifiers may be used to indicate an association relationship between different object identifiers.
  • the first alarm message further includes first alarm set information, where the first alarm information set includes at least one of the following: NFVI alarm information, VM alarm information, and VNFM alarm information.
  • processing unit 1202 is specifically configured to:
  • Correlation analysis is performed on the VM alarm information to generate the first alarm message.
  • step 803 For details, refer to the two embodiments of step 803 in the embodiment shown in the figure, and details are not described herein.
  • the VNFM provided by the embodiment of the present invention sends a first alarm message to the EMS, so that the EMS performs correlation analysis with the VNF alarm information according to the first alarm message, thereby determining alarm information having a correlation relationship in different layers.
  • the association of alarm information across layers is implemented, which avoids the complexity of manual analysis of alarms and reduces the time for alarm analysis, thereby reducing the operation and maintenance costs of the network.
  • an apparatus for processing an alarm information is a VIM, and the apparatus may be used to perform the operation steps of the VIM in the embodiment shown in FIG. 9 or FIG. 1301 and a transmitting unit 1302.
  • the processing unit 1301 is configured to perform correlation analysis on at least two pieces of alarm information to generate virtual machine VM alarm information.
  • the sending unit 1302 is configured to report the VM alarm information generated by the processing unit 1301 to the virtualized network function manager VNFM, so that the VNFM reports the first alarm message to the network element management system EMS according to the VM alarm information,
  • the EMS performs correlation analysis on the first alarm message and the second alarm information reported by the VNF.
  • the at least two pieces of alarm information may include:
  • At least one network function virtualized infrastructure NFVI alarm information and at least one VM alarm information At least one network function virtualized infrastructure NFVI alarm information and at least one VM alarm information;
  • At least two NFVI alarms At least two NFVI alarms; or,
  • At least two VM alarms At least two VM alarms.
  • the foregoing apparatus further includes:
  • the receiving unit 1303 is configured to receive the NFVI alarm information reported by the NFVI, where the NFVI alarm information includes an NFVI identifier;
  • the processing unit 1301 is configured to perform correlation analysis on the NFVI alarm information received by the receiving unit 1303, and generate the VM alarm information.
  • the NFVI identifier includes at least one of a VM identifier, a host HOST identifier, and a virtual transmission resource identifier of the virtual machine; the VM identifier includes a VM identifier ID or a VM name; the HOST identifier includes a HOST ID or a HOST The virtual transmission resource identifier of the VM includes a virtual transmission resource ID or a virtual transmission resource name.
  • the VIM provided by the embodiment of the present invention reduces the complexity of the manual alarm analysis and reduces the alarm analysis time by performing correlation analysis on at least two alarm information.
  • the correlation analysis of the alarm information by the VIM greatly reduces the VNFM. The load.
  • An embodiment of the present invention provides an alarm information processing system, including at least one of the following: an alarm information processing apparatus shown in FIG. 11 to FIG.
  • an embodiment of the present invention further provides another alarm information processing apparatus, which is an EMS, including a processor 1401, a first communication interface 1402, and a second communication interface 1403.
  • an EMS including a processor 1401, a first communication interface 1402, and a second communication interface 1403.
  • the first communication interface 1402 is configured to receive the first alarm message reported by the VNFM, where the first alarm message includes first alarm association information, where the first alarm association information includes at least one of the following: a first object identifier and The association relationship of the preset object identifiers;
  • the second communication interface 1403 is configured to receive a second alarm message that is reported by the VNF, where the second alarm message includes second alarm association information, where the second alarm association information includes at least one of the following: a second object identifier and The association relationship of the preset object identifiers;
  • the processor 1401 is configured to: according to the first alarm association information and the second alarm association information, the first alarm message received by the first communication interface 1402 and the second alarm received by the second communication interface 1403 The message is analyzed for relevance.
  • the first object identifier includes at least one of the following: a VNF identifier, a virtual machine VM identifier, and a virtual transmission resource identifier of the VM.
  • the second object identifier includes at least one of the following: a VNF identifier, a VM identifier, and a virtual transmission resource identifier of the VM.
  • the association relationship between the preset object identifiers is used to indicate an association relationship between different object identifiers;
  • the VNF identifier includes a VNF identifier ID or a VNF name name;
  • the VM identifier includes a VM ID or a VM name;
  • the virtual transmission resource identifier includes a virtual transmission resource ID Or virtual transfer resource name.
  • the first alarm message further includes a first alarm information set; the first alarm information set includes at least one of the following: NFVI alarm information, VM alarm information, and VNFM alarm information.
  • NFVI alarm information the VM alarm information, and the VNFM alarm information, refer to the related description in the method embodiments of FIG. 7-10, and details are not described herein.
  • the second alarm message further includes a second alarm information set, where the second alarm information set includes at least one VNF alarm information.
  • VNF alarm information For a description of the VNF alarm information, refer to the embodiments shown in FIG. 7 or FIG.
  • the processor 1401 is specifically configured to:
  • the third alarm information set is composed of alarm information having an association relationship between the object identifiers; and performing correlation analysis on the third alarm information set according to the preset correlation rule.
  • step 703 the alarm information that has an association relationship between the object identifiers, and the related description of the association relationship of the preset object identifiers may be referred to step 703 in the embodiment shown in FIG. I won't go into details here.
  • an apparatus for processing an alarm information is a VNFM, and the apparatus may be specifically configured to perform the method of performing VNFM in the embodiment shown in FIG. 8 or FIG. 10 , and the apparatus may specifically include :
  • a first communication interface 1501 configured to receive virtual machine VM alarm information reported by the virtualization infrastructure management VIM, where the VM alarm information includes a third object identifier;
  • the processor 1502 is configured to generate a first alarm message according to the VM alarm information received by the first communication interface 1501, where the first alarm message includes first alarm association information, where the first alarm association information includes at least one of the following Kind: the relationship between the first object identifier and the preset object identifier;
  • a second communication interface 1503 configured to send the first alarm message generated by the processor 1502 to The network element management system EMS, so that the EMS performs correlation analysis on the first alarm message and the second alarm information reported by the VNF.
  • the third object identifier may include at least one of the following: a VM identifier, a host HOST identifier of the NFVI infrastructure layer, and a virtual transmission resource identifier of the VM;
  • the VM identifier may include a VM identifier ID or a VM name name; the HOST identifier may include a HOST ID or a HOST name; and the virtual transmission resource identifier of the VM may include a virtual transmission resource ID or a virtual transmission resource name.
  • the virtual transmission resource identifier of the VM is used to uniquely identify a VM, for example, a VPORT ID or a VPORT name, and for example, a vNIC ID or a vNIC name.
  • the first object identifier may be used to uniquely identify the first object; the first object identifier may include at least one of the following: a VNF identifier, a VM identifier, and a virtual transmission resource identifier of the VM;
  • the association relationship of the preset object identifiers may be used to indicate an association relationship between different object identifiers.
  • the first alarm message further includes first alarm set information, where the first alarm information set includes at least one of the following: NFVI alarm information, VM alarm information, and VNFM alarm information.
  • the processor 1502 is specifically configured to:
  • Correlation analysis is performed on the VM alarm information to generate the first alarm message.
  • step 803 For details, refer to the two embodiments of step 803 in the embodiment shown in the figure, and details are not described herein.
  • the VNFM provided by the embodiment of the present invention sends a first alarm message to the EMS, so that the EMS performs correlation analysis with the VNF alarm information according to the first alarm message, thereby determining alarm information having a correlation relationship in different layers.
  • the association of alarm information across layers is implemented, which avoids the complexity of manual analysis of alarms and reduces the time for alarm analysis, thereby reducing the operation and maintenance costs of the network.
  • an apparatus for processing an alarm information is a VIM, and the apparatus may be used to perform the operation steps of the VIM in the embodiment shown in FIG. 9 or FIG.
  • the processor 1601 and the first communication interface 1602 can be included.
  • the processor 1601 is configured to perform correlation analysis on at least two pieces of alarm information to generate virtual machine VM alarm information.
  • the first communication interface 1602 is configured to report the VM alarm information generated by the processor 1601 to the virtualized network function manager VNFM, so that the VNFM reports the first alarm message to the network element management system EMS according to the VM alarm information,
  • the EMS performs correlation analysis on the first alarm message and the second alarm information reported by the VNF.
  • the at least two pieces of alarm information may include:
  • At least one network function virtualized infrastructure NFVI alarm information and at least one VM alarm information At least one network function virtualized infrastructure NFVI alarm information and at least one VM alarm information;
  • At least two NFVI alarms At least two NFVI alarms; or,
  • At least two VM alarms At least two VM alarms.
  • the foregoing apparatus further includes:
  • the second communication interface 1603 is configured to receive the NFVI alarm information reported by the NFVI, where the NFVI alarm information includes an NFVI identifier;
  • the processor 1601 is configured to perform correlation analysis on the NFVI alarm information received by the second communication interface 1603, and generate the VM alarm information.
  • the NFVI identifier includes at least one of a VM identifier, a host HOST identifier, and a virtual transmission resource identifier of the virtual machine; the VM identifier includes a VM identifier ID or a VM name; the HOST identifier includes a HOST ID or a HOST The virtual transmission resource identifier of the VM includes a virtual transmission resource ID or a virtual transmission resource name.
  • the VIM provided by the embodiment of the present invention reduces the complexity of the manual alarm analysis and reduces the alarm analysis time by performing correlation analysis on at least two alarm information.
  • the correlation analysis of the alarm information by the VIM greatly reduces the VNFM. The load.
  • the storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明实施例公开了一种告警信息处理方法,包括:EMS获取VNFM上报的第一告警信息集合;其中,所述第一告警信息集合是由所述VNFM对至少一个NFVI的告警信息和至少一个虚拟化基础设施管理器VIM的告警信息进行相关性分析后生成的;所述EMS获取VNF上报的第二告警信息集合;其中,所述第二告警信息集合包括至少一个所述虚拟化网络功能VNF的告警信息;所述EMS对所述第一告警信息集合和所述第二告警信息集合进行相关性分析,为具有相关性关系的告警信息派发配置的工单。本发明实施例还公开了一种网元管理系统和告警信息处理系统。采用本发明,能实现跨层的告警信息关联,减少工单的数量。

Description

一种告警信息处理方法、相关设备和系统 技术领域
本发明实施例涉及通信领域,尤其涉及一种告警信息处理方法、相关设备和系统。
背景技术
在NFV(Network Function Virtualization,网络功能虚拟化)系统的应用场景中,传统网络及网络节点的架构发生较大变化,传统的物理电信节点在新的网络架构下,物理节点演变为虚拟节点,在NFV系统标准定义的网络架构中增加了NFVI(Network Function Virtualization Infrastructure,网络功能虚拟化基础设施)、VIM(Virtualized Infrastructure Manager,虚拟化基础设施管理)、VNFM(Virtualized Network Function Manager,虚拟网络功能管理器)和NFVO(NFV Management and Orchestration,网络功能虚拟化管理与编排)等功能节点。
NFV系统中引入了虚拟化层和业务层,各个应用VNF运行在NFVI上。按照分层设计,EMS(Element Management System,网元管理系统)会分别对业务层和虚拟化层中的网元的告警信息进行监控。其中网元可以是虚拟化层中物理对象或业务层中的虚拟对象的统称,例如,物理对象包括:内存、硬盘、链路、单板、CPU、网卡,虚拟对象包括:虚拟机、虚拟网卡、应用程序等。
在目前的故障处理中,EMS对单一层面的告警信息进行监控,无法对整个网络的故障进行判断,EMS会针对同一根因告警信息派发的多个工单给维护人员。这样监控人员需要花费大量的时间分析故障、派发工单和跟踪工单,同时,维护人员也需要处理大量的工单,运维成本大幅度增加。
发明内容
本发明实施例所要解决的技术问题在于,提供一种告警信息处理方法、相关设备和系统,可解决现有技术中运维成本高问题。
为了解决上述技术问题,本发明实施例第一方面提供了一种告警信息处理 方法,包括:
网元管理系统EMS接收虚拟化网络功能管理器VNFM上报的第一告警消息;其中,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
所述EMS接收虚拟网络功能VNF上报的第二告警消息;其中,所述第二告警消息包括第二告警关联信息,所述第二告警关联信息包括以下至少一种:第二对象标识和所述预设的对象标识的关联关系;
所述EMS根据所述第一告警关联信息和所述第二告警关联信息,对所述第一告警消息和所述第二告警消息进行相关性分析。
结合第一方面,在第一方面的第一种实施方式中,所述第一对象标识包括以下至少一种:VNF标识,虚拟机VM标识和VM的虚拟传输资源标识;
所述第二对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系;
其中,所述VNF标识包括VNF标识符ID或者VNF名字name;所述VM标识包括VM ID或者VM name;所述虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
结合第一方面或第一方面的第一种实施方式,在第一方面的第二种实施方式中,所述第一告警消息还包括第一告警信息集合;所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
结合第一方面或第一方面的第一种或第二种实施方式,在第一方面的第三种实施方式中,所述第二告警消息还包括第二告警信息集合,所述第二告警信息集合包含至少一条VNF告警信息。
结合第一方面或第一方面的第一至三任一种实施方式,在第一方面的第四种实施方式中,当所述第一告警消息包括第一告警信息集合,且所述第二告警信息包括第二告警信息集合时,所述EMS根据所述第一告警关联信息和所述第二告警关联信息,对所述第一告警消息和所述第二告警消息进行相关性分析,包括:
根据所述第一告警关联信息和所述第二告警关联信息,在所述第一告警信息集合和所述第二告警信息集合中获取具有相同告警关联信息的告警信息;根 据预设的相关性规则,对所述获取的具有相同告警关联信息进行相关性分析;或者,
根据所述预设的对象标识的关联关系,所述第一对象标识,以及所述第二对象标识,在所述第一告警信息集合和所述第二告警信息集合中获取第三告警信息集合,所述第三告警信息集合是由对象标识之间具有关联关系的告警信息组成;根据预设的相关性规则,对所述第三告警信息集合进行相关性分析。
本发明第二方面提供了一种告警信息处理方法,包括:
虚拟化网络功能管理器VNFM接收虚拟化基础设施管理VIM上报的虚拟机VM告警信息,所述VM告警信息包含第三对象标识;
所述VNFM根据所述VM告警信息,生成第一告警消息,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
所述VNFM将所述第一告警消息发送给网元管理系统EMS,以便所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
结合第二方面,在第二方面的第一种实现方式中,所述第三对象标识包括以下至少一种:VM标识,NFVI基础设施层的主机HOST标识和VM的虚拟传输资源标识;
其中,所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
结合第二方面或第二方面的第一种实现方式,在第二方面的第二种实现方式中,所述第一对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系。
结合第二方面或第二方面的第一种或第二种实现方式,在第二方面的第三种实现方式中,所述第一告警消息还包括第一告警集合信息,所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
结合第二方面或第二方面的上述任一种实现方式,在第二方面的第四种实现方式中,所述VNFM根据所述VM告警信息,生成第一告警消息包括:
根据预设的所述第三对象标识与VNF标识之间的对应关系以及所述VM 告警信息中的所述第三对象标识,获得与所述第三对象标识相对应的VNF标识,并将所述获得的VNF标识作为所述第一对象标识,生成所述第一告警消息;或者,
对所述VM告警信息进行相关性分析,生成所述第一告警消息。
本发明的第三方面提供了一种告警信息处理方法,包括:
虚拟化基础设施管理VIM对至少两条告警信息进行相关性分析,生成虚拟机VM告警信息;
将所述生成的VM告警信息上报给虚拟化网络功能管理器VNFM,以使得所述VNFM根据所述VM告警信息上报第一告警消息给网元管理系统EMS,所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
结合第三方面,在第三方面的第一种实现方式中,所述至少两条告警信息包括:
至少一条网络功能虚拟化基础设施NFVI告警信息和至少一条VM告警信息;或者,
至少两条NFVI告警信息;或者,
至少两条VM告警信息。
结合第三方面或第三方面的第一种实现方式,在第三方面的第二种实现方式中,所述方法还包括:
接收NFVI上报的NFVI告警信息,所述NFVI告警信息包括NFVI标识;
所述VIM对至少两条告警信息进行相关性分析,生成虚拟机VM告警信息,包括:
对所述NFVI告警信息进行相关性分析,生成所述VM告警信息;
其中,所述NFVI标识包括VM标识,主机HOST标识和虚拟机的虚拟传输资源标识中的至少一种;所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
本发明的第四方面提供了一种告警信息处理装置,所述装置为网元管理系统EMS,包括:
第一接收单元,用于接收虚拟化网络功能管理器VNFM上报的第一告警消息;其中,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
第二接收单元,用于接收虚拟网络功能VNF上报的第二告警消息;其中,所述第二告警消息包括第二告警关联信息,所述第二告警关联信息包括以下至少一种:第二对象标识和所述预设的对象标识的关联关系;
处理单元,用于根据所述第一告警关联信息和所述第二告警关联信息,对所述第一接收单元接收的所述第一告警消息和所述第二接收单元接收的所述第二告警消息进行相关性分析。
结合第四方面,在第四方面的第一种实现方式中,所述第一对象标识包括以下至少一种:VNF标识,虚拟机VM标识和VM的虚拟传输资源标识;
所述第二对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系;
其中,所述VNF标识包括VNF标识符ID或者VNF名字name;所述VM标识包括VM ID或者VM name;所述虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
结合第四方面或第四方面的第一种实现方式,在第四方面的第二种实现方式中,所述第一告警消息还包括第一告警信息集合;所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
结合第四方面或第四方面的第一种或第二种实现方式,在第四方面的第三种实现方式中,所述第二告警消息还包括第二告警信息集合,所述第二告警信息集合包含至少一条VNF告警信息。
结合第四方面或第四方面的上述任一种实现方式,在第四方面的第四种实现方式中,当所述第一告警消息包括第一告警信息集合,且所述第二告警信息包括第二告警信息集合时,所述处理单元具体用于:
根据所述第一告警关联信息和所述第二告警关联信息,在所述第一告警信息集合和所述第二告警信息集合中获取具有相同告警关联信息的告警信息;根据预设的相关性规则,对所述获取的具有相同告警关联信息进行相关性分析;或者,
根据所述预设的对象标识的关联关系,所述第一对象标识,以及所述第二对象标识,在所述第一告警信息集合和所述第二告警信息集合中获取第三告警信息集合,所述第三告警信息集合是由对象标识之间具有关联关系的告警信息组成;根据预设的相关性规则,对所述第三告警信息集合进行相关性分析。
本发明的第五方面提供了一种告警信息处理装置,所述装置为虚拟化网络功能管理器VNFM,包括:
接收单元,用于接收虚拟化基础设施管理VIM上报的虚拟机VM告警信息,所述VM告警信息包含第三对象标识;
处理单元,用于根据所述接收单元接收的所述VM告警信息,生成第一告警消息,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
发送单元,用于将所述处理单元生成的所述第一告警消息发送给网元管理系统EMS,以便所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
结合第五方面,在第五方面的第一种实现方式中,所述第三对象标识包括以下至少一种:VM标识,NFVI基础设施层的主机HOST标识和VM的虚拟传输资源标识;
其中,所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
结合第五方面或第五方面的第一种实现方式,在第五方面的第二种实现方式中,所述第一对象标识用于唯一标识第一对象,其中,所述第一对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系。
结合第五方面或第五方面的第一种或第二种实现方式,在第五方面的第三种实现方式中,所述第一告警消息还包括第一告警集合信息,所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
结合第五方面或第五方面的上述任一种实现方式,在第五方面的第四种实现方式中,所述处理单元具体用于:
根据预设的所述第三对象标识与VNF标识之间的对应关系以及所述VM 告警信息中的所述第三对象标识,获得与所述第三对象标识相对应的VNF标识,并将所述获得的VNF标识作为所述第一对象标识,并根据所述第一对象标识生成所述第一告警消息;或者,
对所述VM告警信息进行相关性分析,生成所述第一告警消息。
本发明的第六方面提供了一种告警信息处理装置,所述装置为虚拟化基础设施管理VIM,包括:
处理单元,用于对至少两条告警信息进行相关性分析,生成虚拟机VM告警信息;
发送单元,用于将所述处理单元生成的VM告警信息上报给虚拟化网络功能管理器VNFM,以使得所述VNFM根据所述VM告警信息上报第一告警消息给网元管理系统EMS,所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
结合第六方面,在第六方面的第一种实现方式中,所述至少两条告警信息包括:
至少一条网络功能虚拟化基础设施NFVI告警信息和至少一条VM告警信息;或者,
至少两条NFVI告警信息;或者,
至少两条VM告警信息。
结合第六方面或第六方面的第一种实现方式,在第六方面的第二种实现方式中,还包括:
接收单元,用于接收NFVI上报的NFVI告警信息,所述NFVI告警信息包括NFVI标识;
所述处理单元,用于对所述接收单元接收的所述NFVI告警信息进行相关性分析,生成所述VM告警信息;
其中,所述NFVI标识包括VM标识,主机HOST标识和虚拟机的虚拟传输资源标识中的至少一种;所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
实施本发明,具有如下有益效果:
基于关联关系,可以将不同层的告警信息进行相关性分析,确定不同层中具有相关性关系的告警信息,实现跨层的告警信息的关联,为同一根因的告警信息派发相同的工单,从而能减少工单的派发数量,由此降低网络的运行维护成本。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本发明实施例提供的NFV系统的结构示意图;
图2是本发明实施例提供的一种告警信息处理方法的流程示意图;
图3是本发明实施例提供的一种告警信息处理系统的交互示意图;
图4是本发明实施例提供的一种网元管理系统的结构示意图;
图5是图4中工单派发模块的结构示意图。
图6是本发明实施例提供的一种网元管理系统的另一结构示意图;
图7是本发明实施例提供的一种告警信息处理方法的流程示意图;
图8是本发明实施例提供的另一种告警信息处理方法的流程示意图;
图9是本发明实施例提供的再一种告警信息处理方法的流程示意图;
图10是本发明实施例提供的另一种告警信息处理系统的交互示意图;
图11是本发明实施例提供的一种告警信息处理装置的结构示意图;
图12是本发明实施例提供的另一种告警信息处理装置的结构示意图;
图13是本发明实施例提供的再一种告警信息处理装置的结构示意图;
图14是本发明实施例提供的一种告警信息处理装置的结构示意图;
图15是本发明实施例提供的另一种告警信息处理装置的结构示意图;
图16是本发明实施例提供的再一种告警信息处理装置的结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清 楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
参见图1,为本发明实施例的网络架构图,本发明实施例的技术方案应用于NFV系统中,本发明实施例的NFV系统包括网络功能虚拟化基础设施(Network Function Virtualization Infrastructure,简称NFVI)、VIM、VNF、、EMS、VNFM和NFVO等功能节点。
其中,VNF对应于传统的非虚拟化网络中的物理网络功能实体(Physical Network Function,PNF),网络功能的功能性行为和状态与虚拟化与否无关,本发明实施例中,VNF和PNF拥有相同的功能性行为和外部接口。
EMS用于对NFV系统中的业务层和虚拟化层中的多个网元的告警信息进行监控。
VIM是包括用来控制和管理计算、存储和网络资源的虚拟化实体;
NFVO是负责对NFV资源进行网络侧的编排和管理,以及在NFV基础设施上实现NFV业务拓扑的虚拟化实体;
NFVI由硬件资源和虚拟资源以及虚拟化层组成,从VNF的角度来说,虚拟化层和硬件资源看起来是一个能够提供所需虚拟资源的实体。NFVI的管理控制单元负责NFVI内虚拟机VM的管理和控制。
VNFM负责VNF的生命周期的管理。
本实施例中所述的NFV系统中应用的接口包括:
1、虚拟层和硬件资源之间的VI-Ha接口,通过VI-Ha接口可以请求硬件资源并收集相关的硬件资源状态信息。
2、VNF和NFVI之间的Vn-Nf接口:描述NFVI提供给VNF的执行环境。
3、NFVO和VNFM之间的Or-Vnfm接口,是MANO的内部接口,其中,NFVO、VNFM和VIM共同组成MANO,具体用于:
VNFM发送资源相关的请求:例如资源的授权、验证、预留、分配等,用作VNF的生命周期管理;
NFVO发送配置信息给VNFM,使VNF能够根据VNF转发图(forwarding gragh)被合理的配置;
收集VNF的状态信息(例如故障信息)用作VNF的生命周期管理。
4、VIM和VNFM之间的Vi-Vnfm接口,是MANO的内部接口,具体用于:VNFM发送资源配置请求;
虚拟硬件资源配置以及状态信息交换。
5、NFVO和VIM之间的Or-Vi接口,是NFVO的内部接口,具体用于:NFVO发送资源预留请求;NFVO资源分配请求;虚拟硬件资源配置以及状态信息交换。
6、NFVI和VIM之间的Nf-Vi接口,具体用于:
根据资源分配请求进行特定的资源分配;转发虚拟资源状态信息;虚拟硬件资源配置以及状态信息交换。
7、OSS/BSS和NFVO之间的Os-Ma接口,具体用于:
请求对service gragh的生命周期管理;请求VNF生命周期管理;转发NFV相关的状态信息;交换策略管理信息;交换数据分析信息;转发NFV相关的计费和使用记录;交换容量和存货信息。
8、VNF/EMS和VNFM之间的Ve-Vnfm接口,具体用于:
请求VNF生命周期管理;交换配置信息;交换进行生命周期管理所必须的状态信息;
9、Service,VNF and Infrastructure Description和NFVO之间的Se-Ma接口:用来检索与VNF转发图相关的信息、与业务相关的信息,与VNF相关的信息,以及与NFVI信息模型相关的信息,该信息提供给NFVO使用。
本发明实施例将业务层的告警信息和基础设施层及虚拟化层的告警信息进行关联性分析,减少告警信息的数量,实现跨层的告警信息分析,为同一根因的告警信息派发同一工单,减少工单派发的数量,由此降低网络运行维护的成本。
参见图2,为本发明实施例提供的一种告警信息处理方法,在本发明实施例中,所述方法包括:
S101、网元管理系统EMS获取虚拟化网络功能管理器VNFM上报的第一告警信息集合;其中,所述第一告警信息集合是由所述VNFM对至少一个网络功能虚拟化基础设施NFVI的告警信息和至少一个虚拟化基础设施管理器 VIM的告警信息进行相关性分析后生成的。
具体的,NFVI分为基础设施层和虚拟化层,基础设施层和虚拟化层中包含不同的管理对象,例如,基础设施层包括物理主机、存储器、交换机、物理网卡、物理端口等管理对象,虚拟化层包括虚拟机、虚拟网卡、虚拟端口等管理对象。NFVI中的管理对象发生故障时,NFVI向VIM上报至少一个NFVI的告警信息,告警信息中携带管理对象标识、告警时间、告警级别等参数。VIM负责对NFVI进行管理,当NFVI发生故障时,VIM也会发生故障产生VIM的告警信息,VIM将至少一个NFVI的告警信息和至少一个VIM的告警信息上报至VNFM,VNFM对至少一个NFVI的告警信息和至少一个VIM的告警信息进行相关性分析。
VNFM可根据相关性规则对至少一个NFVI的告警信息和至少一个VIM的告警信息进行相关性分析,确定出具有相关性的告警信息,将具有相关性的告警信息编为一组,同时VNFM可以对至少一个NFVI的告警信息和至少一个VIM的告警信息进行屏蔽,以减少告警信息的数量,经过上述处理后,生成第一告警信息集合,VNFM向EMS上报第一告警信息集合,其中,第一告警信息集合可以是故障树的形式来表现。
S102、所述EMS获取虚拟网络功能VNF上报的第二告警信息集合;其中,所述第二告警信息集合包括至少一个所述虚拟化网络功能VNF的告警信息。
具体的,VNF检测到自身的故障时,生成多个VNF的告警信息,多个告警信息组成第二告警集合,VNF向EMS上报第二告警集合。
S103、所述EMS对所述第一告警信息集合和所述第二告警信息集合进行相关性分析,为具有相关性关系的告警信息派发配置的工单。
具体的,EMS对第一告警集合和第二告警集合中的告警信息进行相关性分析,第一告警集合中的告警信息包含基础设施层和虚拟化层产生的告警信息,第二告警集合中的告警信息为包含业务层的告警信息,EMS根据可根据预设的相关性规则对第一告警集合和第二告警集合中的告警信息进行相关性分析,为具有相关性关系的告警信息派发配置的工单,这样将多个层的告警信息进行相关性分析,为具有相关性关系的告警信息派发工单,减少了工单的数量。
可选的,所述EMS对所述第一告警信息集合和所述第二告警信息集合进 行相关性分析,为具有相关性关系的告警信息派发配置的工单包括:
提取第一告警信息集合的告警信息携带的管理对象标识;
基于管理对象标识的关联关系,查询所述第一告警集合和所述第二告警集合中具有相关性关系的告警信息;
为具有相关性关系的告警信息派发配置的工单。
具体的,基础设施层、虚拟化层和业务层中分布有不同的管理对象,业务层作为最上层,虚拟化层作为中间层,基础设施层作为最下层。各个层的管理对象具有一定的对应关系。基础设施层中的管理对象发生故障,在虚拟化层和业务层中对应的管理对象也会发生故障,各个层中的管理对象发生故障时,在告警信息中携带管理对象标识。预先将具有这种对应关系的管理对象的管理对象标识进行绑定形成关联关系,例如,业务层中的Application1、虚拟化层中的VM1和基础设施层中的Host1具有关联关系,将Application1的标识、VM1的标识和Host1的标识进行绑定形成关联关系。
EMS提取第一告警集合中的告警信息携带的管理对象标识,基于关联关系,查询第一告警信息集合和第二告警信息集合具有相关性关系的告警信息,为具有相关性关系的告警信息派发配置的工单。例如,第一告警集合中包含:告警信息1、告警信息2、告警信息3、告警信息4;第二告警集合中包含告警信息5、告警信息6、告警信息7、告警信息8;第一告警集合中告警信息1和告警信息2具有相关性关系,告警信息3和告警信息4具有相关性关系,EMS提取告警信息1携带的管理对象标识为VM1的标识,根据关联关系:Application1-VM1-Host1,查询第二告警集合中告警信息5携带的管理对象的标识为Host1的标识,则EMS确定告警信息1、告警信息2、告警信息4和告警信息5具有相关性关系,EMS依据上述4个告警信息分析故障原因,并派发配置的工单。
可选的,所述网元管理系统EMS获取虚拟化网络功能管理器VNFM上报的第一告警信息集合之前,还包括:
MANO为所述VNF配置所述管理对象标识的关联关系;其中,所述所述第一告警信息集合中的告警信息携带的管理对象标识包括:VM的标识或vNIC的标识,所述第二告警信息集合的告警信息携带的管理对象标识包括所述 VNF的标识。
具体的,MANO为VNF配置所述管理对象标识的关联关系,VNF向EMS上报的第二告警信息集合的告警信息携带所述管理对象标识的关联关系,同时,第二告警信息集合的告警信息还携带发生故障的管理对象的管理对象标识,第一告警信息集合的告警信息也携带发生故障的管理对象的管理对象标识,EMS可以根据第二告警集合中的告警信息携带的管理对象标识的关联关系查询第一告警集合和第二告警集合中具有相关性关系的告警信息。其中,第一告警信息集合中的告警信息携带的管理对象的标识包括例如,第二告警信息集合中的告警信息携带的管理对象标识的关联关系为:VNF ID-VM ID-vNIC ID,管理对象标识的关联关系表示业务层、虚拟化层和基础设施层中具有对应关系的管理对象的标识。
可选的,所述VM的标识包括所述NFVI分配的标识或所述MANO分配的标识。
可选的,所述第一告警集合和所述第二告警集合中具有相关性关系的告警信息划分为相同的组,每个组分配有组标识,以及每个组内的根源告警信息和衍生告警信息分配有对应的告警类型标识。
具体的,VNFM可根据预设的相关性规则将第一告警集合中具有相关性关系的告警信息划分为相同的组,每个组分配由组标识,相关性规则分为时间相关性规则和空间相关性规则,VNFM根据空闲相关性规则确定相关性关系的类型,例如:父子告警和兄弟告警,从具有相关性关系的告警信息中确定根源告警信息和衍生告警信息,并分别分配不同的告警类型标识。同理,VNF也可以对第一告警集合中的告警信息进行上述的处理,此处不再赘述。
需要说明的是,相关性规则经现场开通即可使用,免去了客户在现场总结规则、测试的工作,缺省的相关性规则是经过专家的分析和测试验证的,准确性高。相关性规则可以根据需要使能或去使能,相关性规则由若干条子规则组成,也可以根据需要使能或去使能其中的一条或多条子规则。
实施本发明的实施例,基于关联关系,可以将不同层的告警信息进行相关性分析,确定不同层中具有相关性关系的告警信息,实现跨层的告警信息的关联,为同一根因的告警信息派发相同的工单,从而能减少工单的派发数量,由 此降低网络的运行维护成本。
参见图3,为本发明实施例提供的一种告警信息处理系统的交互示意图,在本发明实施例中,涉及的功能实体包括:EMS、VNF、VNFM、VIM和NFVI,上述功能实体之间的交互流程如下:
S201、NFVI发生故障时,生成至少一个NFVI的告警信息。具体的,NFVI分为基础设施层和虚拟化层,基础设施层由物理管理对象组成,虚拟化层中由虚拟管理对象组成,例如,基础设施层包括物理主机、存储器、交换机、物理网卡、物理端口等管理对象,虚拟化层包括虚拟机、虚拟网卡、虚拟端口等管理对象。NFVI中的管理对象发生故障时,NFVI生成至少一个NFVI的告警信息,告警信息中携带管理对象标识、告警时间、告警级别等参数。
S202、NFVI向VIM上报至少一个NFVI的告警信息。S203、VIM发生故障,生成至少一个VIM的告警信息。
具体的,当NFVI发生故障时,VIM也根据自身的状态信息和故障信息会生成告警信息,告警信息携带管理对象标识、告警时间、告警级别等参数。S204、VIM向VNFM上报至少一个NFVI的告警信息和至少一个VIM的告警信息。
S205、VNFM对至少一个NFVI的告警信息和至少一个VIM的告警信息进行相关性分析,生成第一告警信息集合。
具体的,VNFM可根据相关性规则对至少一个NFVI的告警信息和至少一个VIM的告警信息进行相关性分析,确定出具有相关性的告警信息,将具有相关性的告警信息编为一组,同时VNFM可以对至少一个NFVI的告警信息和至少一个VIM的告警信息进行屏蔽,以减少告警信息的数量,经过上述处理后,生成第一告警信息集合,VNFM向EMS上报第一告警信息集合,其中,第一告警信息集合可以是故障树的形式来表现。
S206、VNFM向EMS上报第一告警信息集合。
S207、VNF发生故障,生成至少一个VNF的告警信息。
具体的,NFVI中的管理对象和VNF中的管理对象具有对应关系,当NFVI中的管理对象发生故障,VNF中的管理对象也会相应发生故障。VNF发生故障时,生成至少一个VNF的告警信息。
S208、VNF对至少一个VNF的告警信息进行相关性分析,生成第二告警 信息集合。具体的,VNF可根据预设的相关性规则将第二告警集合中具有相关性关系的告警信息划分为相同的组,每个组分配由组标识,相关性规则分为时间相关性规则和空间相关性规则,VNF根据空闲相关性规则确定相关性关系的类型,例如:父子告警和兄弟告警,从具有相关性关系的告警信息中确定根源告警信息和衍生告警信息,并分别分配不同的告警类型标识。
S209、VNF向EMS上报第二告警信息集合。
S210、EMS对第一告警信息集合和第二告警信息结合中的告警信息进行相关性分析,派发工单。
具体的,EMS对第一告警集合和第二告警集合中的告警信息进行相关性分析,第一告警集合中的告警信息包含基础设施层和虚拟化层产生的告警信息,第二告警集合中的告警信息为包含业务层的告警信息,EMS根据可根据预设的相关性规则对第一告警集合和第二告警集合中的告警信息进行相关性分析,为具有相关性关系的告警信息派发配置的工单,这样将多个层的告警信息进行相关性分析,为具有相关性关系的告警信息派发工单,减少了工单的数量。
进一步,所述EMS对所述第一告警信息集合和所述第二告警信息集合进行相关性分析,为具有相关性关系的告警信息派发配置的工单包括:
提取第一告警信息集合的告警信息携带的管理对象标识;
基于管理对象标识的关联关系,查询所述第一告警集合和所述第二告警集合中具有相关性关系的告警信息;
为具有相关性关系的告警信息派发配置的工单。
具体的,基础设施层、虚拟化层和业务层中分布有不同的管理对象,业务层作为最上层,虚拟化层作为中间层,基础设施层作为最下层。各个层的管理对象具有一定的对应关系。基础设施层中的管理对象发生故障,在虚拟化层和业务层中对应的管理对象也会发生故障,各个层中的管理对象发生故障时,在告警信息中携带管理对象标识。预先将具有这种对应关系的管理对象的管理对象标识进行绑定形成关联关系,例如,业务层中的Application1、虚拟化层中的VM1和基础设施层中的Host1具有关联关系,将Application1的标识、VM1的标识和Host1的标识进行绑定形成关联关系。
EMS提取第一告警集合中的告警信息携带的管理对象标识,基于关联关系,查询第一告警信息集合和第二告警信息集合具有相关性关系的告警信息,为具有相关性关系的告警信息派发配置的工单。例如,第一告警集合中包含:告警信息1、告警信息2、告警信息3、告警信息4;第二告警集合中包含告警信息5、告警信息6、告警信息7、告警信息8;第一告警集合中告警信息1和告警信息2具有相关性关系,告警信息3和告警信息4具有相关性关系,EMS提取告警信息1携带的管理对象标识为VM1的标识,根据关联关系:Application1-VM1-Host1,查询第二告警集合中告警信息5携带的管理对象的标识为Host1的标识,则EMS确定告警信息1、告警信息2、告警信息4和告警信息5具有相关性关系,EMS依据上述4个告警信息分析故障原因,并派发配置的工单。
实施本发明的实施例,基于关联关系,可以将不同层的告警信息进行相关性分析,确定不同层中具有相关性关系的告警信息,实现跨层的告警信息的关联,为同一根因的告警信息派发相同的工单,从而能减少工单的派发数量,由此降低网络的运行维护成本。
参见图4,为本发明实施例提供的一种网元管理系统的结构示意图,在本发明实施例中,所述网元管理系统包括:第一获取模块10、第二获取模块11和工单派发模块12。
第一获取模块10,用于获取虚拟化网络功能管理器VNFM上报的第一告警信息集合;其中,所述第一告警信息集合是由所述VNFM对至少一个网络功能虚拟化基础设施NFVI的告警信息和至少一个虚拟化基础设施管理器VIM的告警信息进行相关性分析后生成的。
第二获取模块11,用于获取虚拟网络功能VNF上报的第二告警信息集合;其中,所述第二告警信息集合包括至少一个所述虚拟化网络功能VNF的告警信息。
工单派发模块12,用于对所述第一告警信息集合和所述第二告警信息集合进行相关性分析,为具有相关性关系的告警信息派发配置的工单。
可选的,参见图5,工单派发模块12包括:提取单元121、查询单元122和派发单元123。
提取单元121,用于提取第一告警信息集合的告警信息携带的管理对象标识。
查询单元122,用于基于管理对象标识的关联关系,查询所述第一告警集合和所述第二告警集合中具有相关性关系的告警信息。
派发单元123,用于为具有相关性关系的告警信息派发配置的工单。
可选的,所述第二告警信息集合的告警信息携带的所述管理对象标识的关联关系,所述第一告警信息集合中的告警信息携带虚拟机VM的标识或虚拟网卡vNIC的标识。
可选的,所述VM的标识由所述NFVI分配或所述MANO分配。其中,MANO包括VNF、VIM和NFVO。
可选的,所述第一告警集合和所述第二告警集合中具有相关性关系的告警信息划分为相同的组,每个组分配有组标识,以及每个组内的根源告警信息和衍生告警信息分配有对应的告警类型标识。
本发明实施例和方法实施例一基于同一构思,其带来的技术效果也相同,具体原理请参照方法实施例一的描述,此处不再赘述。
参见图6,为本发明实施例提供的一种网元管理系统的另一结构示意图,在本发明实施例中,所述网元管理系统包括处理器61、存储器62和通信接口63。处理器61、存储器62和通信接口63可通过总线或其他方式连接,图6中以总线连接为例。
其中,存储器62用于存储程序代码,具体地,程序可以包括程序代码,所述程序代码包括计算机操作指令。存储器62可能包含随机存取存储器(Random Access Memory,简称RAM),也可能还包括非易失性存储器(non-volatile memory),例如至少一个磁盘存储器。
处理器61执行所述存储器62中存储的程序代码,用于实现本发明实施例提供的告警信息处理方法,包括:
获取虚拟化网络功能管理器VNFM上报的第一告警信息集合;其中,所述第一告警信息集合是由所述VNFM对至少一个网络功能虚拟化基础设施NFVI的告警信息和至少一个虚拟化基础设施管理器VIM的告警信息进行相关性分析后生成的;
获取虚拟网络功能VNF上报的第二告警信息集合;其中,所述第二告警信息集合包括至少一个所述虚拟化网络功能VNF的告警信息;
对所述第一告警信息集合和所述第二告警信息集合进行相关性分析,为具有相关性关系的告警信息派发配置的工单。
可选的,处理器61执行所述对所述第一告警信息集合和所述第二告警信息集合进行相关性分析,为具有相关性关系的告警信息派发配置的工单包括:
提取第一告警信息集合的告警信息携带的管理对象标识;
基于管理对象标识的关联关系,查询所述第一告警集合和所述第二告警集合中具有相关性关系的告警信息;
为具有相关性关系的告警信息派发配置的工单。
可选的,所述第二告警信息集合的告警信息携带的所述管理对象标识的关联关系,所述第一告警信息集合中的告警信息携带虚拟机VM的标识或虚拟网卡vNIC的标识。
可选的,所述VM的标识由所述NFVI分配或所述MANO分配。
可选的,所述第一告警集合和所述第二告警集合中具有相关性关系的告警信息划分为相同的组,每个组分配有组标识,以及每个组内的根源告警信息和衍生告警信息分配有对应的告警类型标识。
参见图7,为本发明实施例提供的一种告警信息处理方法,该方法可以由EMS执行,所述方法包括:
701、接收VNFM上报的第一告警消息;其中,所述第一告警消息包含第一告警关联信息。
其中,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系。
进一步地,所述第一对象标识包括以下至少一种:VNF标识,虚拟机VM标识和VM的虚拟传输资源标识。
其中,VM标识,用于唯一标识一个VM。具体地,VM标识可以是VM名字(name),也可以是VM标识符(identifier,ID)。VNF标识,用于唯一标识一个VNF。VNF标识具体可以是VNF ID或VNF name,此处不予限制。VM的虚拟传输资源标识用于唯一标识一个VM,例如,VNIC ID,VNIC name, VPORT ID或者VPORT name,此处不予限制。
此外,上述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系,例如,VNF ID与VM ID之间的对应关系,再例如,VNF ID、VM ID以及主机(HOST)标识之间的对应关系,或者,VNF ID与VNIC ID之间的关系,此处不再一一列举。
其中,HOST标识为NFVI的基础设施层中主机标识,用于唯一标识一个NFVI的HOST,具体可以是HOST ID或者HOST name;VIM负责对NFVI进行管理,包括NFVI的基础设施层、虚拟层和应用层。
可选地,所述第一告警消息还包括第一告警信息集合。
其中,所述第一告警消息可以包括一条告警消息或者告警信息组,也就是说,所述第一告警信息集合可以包括以下至少一种:NFVI告警信息(包含基础设施层和虚拟化层产生的告警信息),VM告警信息和VNFM告警信息。其中,该VNFM告警信息可以是一条由VNFM生成的相关性告警信息,例如,可以是由VNFM对VIM上报的至少两条告警信息进行相关性分析生成的;还可以是VNFM对应的虚拟机产生的告警信息。NFVI告警信息可以是由NFVI生成的告警信息。VM告警信息可以是由VIM对应的VM或者VIM负责管理的VM生成的告警信息,也可以是该VIM生成的相关性告警信息,例如,VIM对两条NFVI告警信息进行相关性分析生成的告警信息。上述仅仅是举例说明,并不进行限定。
进一步地,所述第一告警关联信息可以携带在所述第一告警信息集合中,所述第一告警关联信息也可以独立于所述第一告警信息集合。
具体地,可以在第一告警信息集合中包含的告警信息中携带该第一告警关联信息。例如,第一告警信息集合中包含至少两条VM告警信息,每条VM告警信息中均包含VM标识,该VM标识即为上述第一告警关联信息。再例如,第一告警信息集合可以包括:一条包含有VM标识的告警信息,以及至少一条包含有下级对象标识(例如,NFVI的HOST ID)的告警信息。
具体地,当第一告警信息集合中的所有告警信息来自同一个对象时,该第一告警关联信息可以与第一告警信息集合并列位于上述第一告警消息中。例如,假设第一告警关联信息为VM ID,则第一告警消息的结构可以为{VM ID,告警信息1,告警信息2,告警信息3},其中,告警信息1,告警信息2和告 警信息3构成了第一告警信息集合。
其中,上述第一告警信息还可以包含故障模式,用于指示产生故障的原因,例如,CPU占用率高,硬件设备故障等,不再赘述。
可选地,上述第一告警信息集合中还可以包含相关性标识,用于指示具有相关性关联关系的告警信息。该相关性标识可以为组标识,具有相同相关性组标识的告警信息具有相关性,例如,第一告警信息集合{告警信息1,group1;告警信息2,group1},其中,告警信息1和告警信息2具有相同的组标识,表明两者之间具有相关性;该相关性标识还可以为不同告警之间的关系,例如,第一告警信息集合{告警信息1,0;告警信息2,1},其中,0表示告警信息1是父告警,1表示告警信息2为子告警,即两者为父子告警关系。显然,还可以为第一告警信息集合{告警信息1,VM1,0,VM2,1;告警信息2,VM1,0,VM2,1},其中,VM1和VM2分别是告警信息1和2中的对象标识,且0表示父告警,1表示子告警,则{VM1,0,VM2,1}表示告警信息1和2是父子告警关系。
可选地,上述第一告警消息中还可以包括根因告警,用于指示产生告警的根本原因。
702、接收VNF上报的第二告警消息。
其中,所述第二告警消息包括第二告警关联信息;所述第二告警关联信息包括以下至少一种:第二对象标识和所述预设的对象标识的关联关系;
可选地,所述第二告警消息还可以包括第二告警信息集合,所述第二告警信息集合可以包含至少一条VNF告警信息。
具体地,第二对象标识用于唯一标识第二对象,所述第一对象与所述第二对象可以相同,也可以不同。
需要说明的是,所述第二告警关联信息可以携带在所述第二告警信息集合中,所述第二告警关联信息也可以独立于所述第二告警信息集合,具体可以参见步骤701中关于第一告警关联信息的相关描述,此处不再赘述。
703、根据所述第一告警关联信息和所述第二告警关联信息,对所述第一告警消息和所述第二告警消息进行相关性分析。
具体地,可以根据预设的相关性规则,对第一告警消息和第二告警消息进 行相关性分析。例如,若第一告警关联信息与第二告警关联信息相同,则第一告警消息和第二告警消息具有相关性。
可选的,当第一告警消息包含第一告警集合,且所述第二告警消息包含第二告警消息集合时,步骤703具体可以可以采用如下实施方式。
方式一:
根据所述第一告警关联信息和第二告警关联信息,在所述第一告警信息集合和所述第二告警信息集合中获取具有相同告警关联信息的告警信息;
根据预设的相关性规则,对所述获取的具有相同告警关联信息进行相关性分析。
例如,第一告警信息集合中包含:告警信息1、告警信息2、告警信息3、告警信息4;第二告警信息集合中包含告警信息5、告警信息6、告警信息7、告警信息8;且第一告警信息集合中告警信息1和告警信息2包含有相同的告警关联信息VM1,告警信息3和告警信息4分别包含有告警关联信息VNF ID1和VNF ID2,告警信息5携带VM1。EMS获取携带有管理对象标识为VM1的告警信息:告警信息1,2和5;并根据预设的相关性规则对告警信息1,2和5进行相关性分析,若该相关性规则为父子告警,且告警信息1和5为父子告警关系,则在告警信息1,2和5中找出具有父子告警关系的告警信息1和5,并确定告警信息1和5为具有相关性的告警信息。
需要说明的是,上述方式一中的第一告警关联信息和第二告警关联信息可以均为预设的对象标识的关联关系。
方式二:
根据预设的对象标识的关联关系,第一告警关联信息中的第一对象标识,以及第二告警关联信息中的第二对象标识,在所述第一告警信息集合和所述第二告警信息集合中获取第三告警信息集合,第三告警信息集合是由对象标识之间具有关联关系的告警信息组成;
根据预设的相关性规则,对所述第三告警信息集合进行相关性分析。
其中,对象标识之间具有关联关系的告警信息可以包括有具有相同对象标识的告警信息,以及包含有与所述相同对象标识之间存在关联关系的对象标识的告警信息。
需要说明的是,该预设的对象标识的关联关系可以预先设置在EMS内部,也可以通过通信接口配置给该EMS,不予限制。
其中,第一告警关联信息中的第一对象标识和第二告警关联信息中的第二对象标识存在不同的标识类型。其中,标识类型可以包括:VM标识,HOST标识,VM的虚拟传输资源标识。
例如,第一告警信息集合中包含:告警信息1、告警信息2;第二告警信息集合中包含告警信息3、告警信息4;且第一告警信息集合中告警信息1包含的对象标识为VM name1,告警信息2包含有对象标识为Host name1,告警信息3和告警信息4分别包含对象标识VM name1和VM name2。若预设的对象标识的关联关系为Application name1-VM name1-Host name1,即业务层中的应用名称Application name1、虚拟层中的VM name1和基础设施层中的Host name1之间的关联关系,则EMS获取第三告警信息集合:告警信息1、告警信息2和告警信息3,并依据预设的相关性规则对上述3个告警进行相关系分析,具体可以参见方式一中的描述,不再赘述。
需要说明的是,预设的对象标识的关联关系具体可以携带在第一告警消息或者第二告警消息中,还可以预先设置在EMS中,此处不予限制。
方式三:当第一告警消息中包含相关性标识时,根据相关性标识,第一告警关联信息,以及第二告警关联信息对第一告警信息集合和第二告警信息集合进行相关性分析。
例如,第一告警信息集合{告警信息1,group1;告警信息2,group1},且告警信息1包含VM1,告警信息2包含VM2,第二告警信息集合{告警信息3,告警信息4},告警信息3包含VM1,告警信息4包含VM3,则告警信息1,2和3之间具有相关性关系。
需要指出的是,预设的相关性规则可以分为时间相关性规则和空间相关性规则,例如:父子告警和兄弟告警。相关性规则经现场开通即可使用,免去了客户在现场总结规则、测试的工作,缺省的相关性规则是经过专家的分析和测试验证的,准确性高。相关性规则可以根据需要使能或去使能,相关性规则由若干条子规则组成,也可以根据需要使能或去使能其中的一条或多条子规则。
在本发明的实施例中,将VNF告警信息和VNFM上报的告警信息进行相 关性分析,确定不同层中具有相关性关系的告警信息,实现跨层的告警信息的关联,避免了人工对告警分析的复杂性,减少了告警分析的时间,由此降低网络的运行维护成本。
可选地,在本发明实施例的一种实施场景下,步骤703之后上述方法还包括:
EMS为具有相关性关系的告警信息派发配置的工单。
可选的,在本发明实施例的另一种实施场景下,步骤703之后还包括:
将所述第一告警信息集合和所述第二告警信息集合中具有相关性关系的告警信息划分为相同的组,并为所述划分的组分配组标识。
参见图8,为本发明实施例提供的另一种告警信息处理方法,该方法由VNFM执行,具体包括:
801、接收VIM上报的VM告警信息。
其中,VM告警信息可以包括第三对象标识,用于唯一标识第三对象,该第三对象标识可以包括以下至少一种:VM标识,HOST标识和虚拟机的虚拟传输资源标识。其中,VM标识用于唯一标识一个VM,HOST标识用于唯一标识一个NFVI的HOST,具体可以是HOST ID或者HOST name;虚拟机的虚拟传输资源标识用于唯一标识一个VM,例如,VPORT ID或者VPORT name,再例如,vNIC ID或者vNIC name。
可选地,VM告警信息还包括故障模式,用于指示产生故障的原因,例如,CPU占用率高,硬件设备故障等,不予限制;还可以包括相关性标识,该相关性标识可以为组标识,具有相同相关性组标识的告警信息具有相关性,该相关性标识还可以为不同告警之间的关系,具体可以参见图7中步骤701中的相关描述。
具体地,VM告警信息可以是由VIM对至少两条告警信息(例如,一条NFVI告警信息,一条VM告警信息;再例如,至少两条NFVI告警信息或至少两条VM告警信息)进行相关性分析后上报的VM相关性告警信息,或者是NFVI上报的NFVI告警信息,还可以是VIM自身对应的VM产生的VM告警信息,还可以是VIM负责管理的VM产生的告警信息。
802、根据所述VM告警信息,生成第一告警消息,所述第一告警消息包 含第一告警关联信息。
可选地,第一告警消息还包括第一告警信息集合。
其中,第一告警关联信息以及第一告警信息集合的相关描述可以参见步骤701。
803、将所述第一告警消息发送给EMS,以便EMS对所述第一告警消息进行与VNF上报的第二告警信息的相关性分析。
具体地,在步骤802中,根据所述VM告警信息,生成第一告警消息,具体可以采用如下两种实施方式:
方式一:
根据预设的预设的第三对象标识与VNF标识之间的对应关系,以及所述VM告警信息中的第三告警标识,获得与所述第三告警标识相对应的VNF标识,并将获得的VNF标识作为所述第一对象标识,生成所述第一告警消息。
例如,该第一告警消息中可以仅包含该第一对象标识,此外,还可以将所述VM告警信息的内容作为所述第一告警信息集合,不再赘述。
方式二:对所述VM告警信息进行相关性分析,生成第一告警消息。
其中,当所述VM告警信息中所有告警信息包含的标识类型相同时,则VNFM根据该相同类型的标识对所述VM告警信息进行相关性分析,将该相同类型的标识作为第一告警关联信息。
需要说明的是,该相同类型的标识可以是VM标识,也可以是HOST标识,还可以是vNIC标识,不再赘述。
其中,当所述VM告警信息中存在至少一个告警信息包含的标识类型与所述VM告警信息中的其它告警信息中包含的标识类型不同时,则VNFM根据预设的配置关系对所述VM告警信息进行相关性分析,获得第一告警关联信息。
例如,若上述至少一个告警信息包含的标识类型为HOST标识,即该至少一个告警信息是由NFVI底层上报的,而其他告警信息中包含的是VM标识,即该其他告警是由NFVI虚拟层或VM上报的,则VNFM获取VM与HOST之间的配置关系,并根据获取的配置关系,获得与HOST标识对应的VM标识,然后再根据VM标识对所述VM告警信息进行相关性分析。显然,也可 以根据配置关系,获得与所述VM告警信息中其他告警信息中的VM标识对应的HOST标识,然后根据HOST标识对所述VM告警信息进行相关性分析。
其中,当VM告警信息包含相关性标识时,根据VM包含的相关性标识和VM告警信息中携带的第三对象标识,对VM告警信息进行相关性分析,生成第一告警消息。
可选地,生成的第一告警消息之前还可以包括,对具有相关性的VM告警信息分配相关性标识。
进一步地,生成的第一告警消息还可以包含分配的相关性标识。
例如,若一个VM告警信息{NFVI告警信息1,group1;NFVI告警信息2,group1},另一VM告警信息为NFVI告警信息3,且NFVI告警信息1包含VM1,NFVI告警信息2包含host1,NFVI告警信息3包含VM1,则NFVI告警信息1,2和3具有相关性。
其中,VM与HOST之间的配置关系可以为虚拟机与host之间的对应关系。
需要指出的是,在方式二中第一告警消息中的第一告警关联信息同样可以采用上述方式一提供的方法获取,不再赘述。
在本发明的实施例中,VNFM上报第一告警消息给EMS,以便EMS根据该第一告警消息进行与VNF告警信息的相关性分析,进而确定不同层中具有相关性关系的告警信息,实现跨层的告警信息的关联,避免了人工对告警分析的复杂性,减少了告警分析的时间,由此降低网络的运行维护成本。
参见图9,为本发明实施例提供的另一种告警信息处理方法,该方法由VIM执行,具体包括:
901、对至少两条告警信息进行相关性分析,生成VM告警信息。
其中,所述至少两条告警信息可以包含:至少一条NFVI告警信息和至少一条VM告警信息;或者,所述至少两条告警信息均为NFVI告警信息或者均为VM告警信息,不予限制。
其中,VM告警信息为VM相关性告警信息,可以包括VM标识,HOST标识和虚拟机的虚拟传输资源标识中的至少一种,相关描述可以参见步骤801,不再赘述。
具体地,VM相关性告警信息可以采用如下三种形式:
形式一、VM相关性告警信息仅包含VM标识。
形式二、VM相关性告警信息包含VM标识和下级对象标识,该下级对象标识可以包括VM相关性告警信息中所关联的NFVI告警中的NFVI标识;其中,NFVI标识可以包括VM标识,HOST标识和虚拟机的虚拟传输资源标识中的至少一种。
例如,VIM对第一NFVI虚拟层上报的第一NFVI告警信息和第一NFVI基础设施层(例如,NFVI HOST)上报的第二NFVI告警信息进行相关性分析,其中,第一NFVI告警信息包含VM ID,第二NFVI告警信息包含HOST ID,若两个告警之间存在相关性,则生成的VM相关性告警信息包括VM ID和下级标识HOST ID。
形式三、VM相关性告警信息包含至少两条告警信息,及所述至少两条告警的相关性标识。
该相关性标识可以为组标识,具有相同相关性组标识的告警信息具有相关性,该相关性标识还可以为不同告警之间的关系,具体可以参见图7中步骤701中的相关描述。进一步地,还可以包括根因告警标识,用于指示该VM相关性告警信息产生的根本原因。
902、将生成的VM告警信息上报给VNFM。
在本发明实施例中,VIM对至少两个告警信息进行相关性分析,降低了人工告警分析的复杂度,减少了告警分析时间;此外,由VIM进行告警信息的相关性分析大大降低了VNFM的负荷。
可选地,在步骤901之前上述方法还可以包括:
接收NFVI上报的NFVI告警信息,所述NFVI告警信息包含NFVI标识。
其中,NFVI标识可以包括VM标识,HOST标识和虚拟机的虚拟传输资源标识中的至少一种。
其中,该NFVI告警信息具体可以是由NFVI的虚拟层或底层上报的。
参见图10,为本发明实施例提供的另一种告警信息处理方法,所述方法包括:
1001、NFVI上报NFVI告警信息给VIM。
其中,NFVI告警信息的相关描述参见图9所述实施例。
1002、VIM接收NFVI告警信息,并根据接收的NFVI告警信息生成VM告警信息。
其中,步骤102具体可以采用如下两种实施方式:
方式一、对上报的NFVI告警信息进行相关性分析,生成VM相关性告警信息;
方式二、VIM将接收的NFVI告警信息直接上报给VNFM。
其中,NFVI告警信息可以由同一NFVI或者不同的NFVI生成的,VM告警信息也可以由同一VIM或者不同的VIM生成,此处不予限制。
例如,当NFVI中的对象发生故障时,NFVI向VIM上报NFVI告警信息。当NFVI发生故障时,并导致VIM发生故障时,VIM将NFVI告警信息和VIM告警信息上报至VNFM;VNFM对NFVI告警信息和VIM告警信息进行相关性分析,生成上述第一告警信息集合。
再例如,当NFVI中的管理对象发生故障时,NFVI向VIM上报NFVI告警信息,当NFVI发生故障时,VIM也会发生故障,并产生VIM告警信息;VIM将NFVI告警信息和VIM告警信息进行相关性分析,并将相关性分析后的VIM告警信息发送给VNFM;VNFM对至少两个VIM告警信息进行相关性分析,生成上述第一告警信息集合。
需要说明的是,上述NFVI告警信息以及VIM告警信息中均可以携带对象标识、告警时间、告警级别等参数,此处不予限制。上述NFVI告警信息包括NFVI标识,该NFVI标识可以包括VM ID,host ID和vNIC ID中的至少一种。
其中,VM告警信息以及VIM进行相关性分析的相关描述可以参见图8或9所示的实施例。
1003、VNFM对VIM上报的VM告警信息进行相关性分析,生成第一告警消息。
其中,所述VM告警信息可以包括NFVI告警信息、VM告警信息中的至少两个。
其中,第一告警消息可以包含第一告警关联信息,还可以包含第一告警信 息集合,具体描述可以参见图7或8所述实施例中的相关描述,此处不再赘述。
具体地,所述第一告警信息集合可以是由所述VNFM对至少一个NFVI告警信息和至少一个VIM告警信息进行相关性分析后生成的,也可以是由所述VNFM对至少两个VIM告警信息进行相关性分析后生成的。
具体地,该第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;其中,第一对象标识用于唯一标识一个对象,可以为VNF标识或者VM标识,例如,可以为VNF ID或者VM ID或者vNIC ID,也可以为VNF name或者VM name或者vNIC name;预设的对象标识的关联关系可以用于表示不同对象标识之间的关联关系,例如,VNF ID与VM ID之间的对应关系,再例如,VNF ID、VM ID以及HOST ID之间的对应关系,此处不再一一列举。
具体地,步骤1003中,VNFM可根据相关性规则对至少一个NFVI告警信息和至少一个VIM告警信息进行相关性分析,确定出具有相关性的告警信息,将具有相关性的告警信息编为一组,使得VNFM可以对至少一个NFVI的告警信息或者至少一个VIM的告警信息进行屏蔽,以减少告警信息的数量。经过上述处理后,生成第一告警信息集合,VNFM向EMS上报第一告警信息集合,其中,第一告警信息集合可以采用故障树的形式来表现。
1004、VNFM发送第一告警消息给EMS。
1005、EMS接收VNFM上报的第一告警消息。
1006、VNF上报第二告警消息。
其中,所述第二告警消息可以包含第二告警关联信息,还可以包括第二告警信息集合,具体可以参见图7所示实施例中的相关描述。
具体地,该第二告警关联信息可以用于EMS对第二告警信息集合进行相关性分析,该第二告警关联信息包括以下至少一种:第二对象标识和预设的对象标识的关联关系;其中,第二对象标识用于唯一标识一个管理对象,可以为VNF标识或者VM标识或者和vNIC标识,例如,可以为VNF ID或者VM ID,也可以为VNF name或者VM name;预设的对象标识的关联关系可以用于指示各个管理对象标识之间的关联关系,例如,VNF ID与VM ID之间的对应关系,再例如,VNF ID、VM ID以及HOST之间的对应关系,此处不再一一列举。
可选地,该第二告警关联信息可以携带在所述第二告警信息集合中,例如,第二告警信息集合中包含的告警信息中携带该第二告警关联信息;该第二告警关联信息也可以独立于所述第二告警信息集合,例如,当第二告警信息集合中所有告警信息来自同一个管理对象时,可以将该第二告警关联信息与第二告警信息集合并列位于上述第一告警消息中,此处不予限制。
其中,所述第二告警信息集合可以包括至少一个VNF告警信息,该至少一个VNF告警信息可以由同一个VNF或不同的VNF生成。
具体的,VNF检测到自身的故障时,生成至少一个VNF告警信息,该至少一个VNF告警信息组成第二告警信息集合,VNF向EMS上报第二告警信息集合。
需要说明的是,VNF上报告警之前,可以根据产生告警的VNF的VNF标识,以及VNF标识与VM标识之间的对应关系或者VNF标识与vNIC标识之间的对应关系,获得与所述VNF标识对应的VM标识或者vNIC标识。
1007、EMS接收VNF上报的第二告警消息。
需要指出的是,步骤1006-1007与步骤1001-1005之间的执行顺序不分先后,不予限制。
1008、EMS根据第一告警关联信息和第二告警关联信息,对第一告警消息和所述第二告警消息进行相关性分析。
其中,步骤1008可以采用图7所示实施例中步骤703的的具体实施方式来实现,不再赘述。
具体的,第一告警信息集合中的告警信息可以包含基础设施层和虚拟化层产生的告警信息,第二告警信息集合中的告警信息可以包含业务层的告警信息,EMS可根据预设的相关性规则对第一告警信息集合和第二告警信息集合中的告警信息进行相关性分析,将具有相关性关系的告警信息进行整合,避免了人工分析的过程,大大节省了告警分析时间,提高了工作效率。
其中,预设的相关性规则具体可以分为时间相关性规则和空间相关性规则,例如:父子告警和兄弟告警;EMS根据相关性规则从上述两个告警集合中找出具有关联性的告警信息,例如,确定根源告警信息和衍生告警信息。
采用本实施例提供的方法,EMS对第一告警信息集合和第二告警信息集 合中的告警信息进行相关性分析,实现了跨层告警的分析整合,避免了人工分析的过程,大大节省了告警分析时间,提高了工作效率。
可选的,EMS接收VNFM上报的第一告警消息之前,还包括:
VNFM为所述VNF配置所述对象标识的关联关系。
具体的,MANO为VNF配置所述对象标识的关联关系,VNF向EMS上报的第二告警信息集合的告警信息携带所述对象标识的关联关系,同时,第二告警信息集合的告警信息还携带发生故障的对象的对象标识,第一告警信息集合的告警信息也携带发生故障的对象的对象标识,EMS可以根据第二告警信息集合中的告警信息携带的对象标识的关联关系查询第一告警信息集合和第二告警信息集合中具有相关性关系的告警信息。其中,第一告警信息集合中的告警信息携带的对象的标识包括例如,第二告警信息集合中的告警信息携带的对象标识的关联关系为:VNF ID-VM ID-vNIC ID,对象标识的关联关系表示业务层、虚拟化层和基础设施层中具有对应关系的对象的标识。
需要说明的是,上述各实施例中,基础设施层、虚拟化层和业务层中分布有不同的对象,业务层作为最上层,虚拟化层作为中间层,基础设施层作为最下层。各个层的对象具有一定的对应关系。基础设施层中的对象发生故障,在虚拟化层和业务层中对应的对象也会发生故障,各个层中的对象发生故障时,在告警信息中携带对象标识或者对象标识的关联关系,就可以获得同一虚拟装置的不同层的告警信息,以此来进一步确认同一虚拟装置中各层告警信息是否由相同的故障引起的,即确认告警信息的相关性。
参见图11,本发明实施例提供的一种告警信息处理装置,所述装置可以为EMS,该装置可以用于执行图7或图10中EMS的操作步骤,该装置具体可以包括第一接收单元1101,第二接收单元1102以及处理单元1103。
第一接收单元1101,用于接收VNFM上报的第一告警消息;其中,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
第二接收单元1102,用于接收VNF上报的第二告警消息;其中,所述第二告警消息包括第二告警关联信息,所述第二告警关联信息包括以下至少一种:第二对象标识和所述预设的对象标识的关联关系;
处理单元1103,用于根据所述第一告警关联信息和所述第二告警关联信息,对第一接收单元1101接收的所述第一告警消息和第二接收单元1102接收的所述第二告警消息进行相关性分析。
可选地,所述第一对象标识包括以下至少一种:VNF标识,虚拟机VM标识和VM的虚拟传输资源标识。
可选地,所述第二对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识。
其中,所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系;所述VNF标识包括VNF标识符ID或者VNF名字name;所述VM标识包括VM ID或者VM name;所述虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
可选地,所述第一告警消息还包括第一告警信息集合;所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
其中,NFVI告警信息,VM告警信息以及VNFM告警信息可以参见图7-10各方法实施例中的相关描述,不再赘述。
可选地,所述第二告警消息还包括第二告警信息集合,所述第二告警信息集合包含至少一条VNF告警信息。
其中,VNF告警信息的相关描述可以参见图7或图10所示各实施例。
可选地,当所述第一告警消息包括第一告警信息集合,且所述第二告警信息包括第二告警信息集合时,处理单元1103具体用于:
根据所述第一告警关联信息和所述第二告警关联信息,在所述第一告警信息集合和所述第二告警信息集合中获取具有相同告警关联信息的告警信息;根据预设的相关性规则,对所述获取的具有相同告警关联信息进行相关性分析;或者,
根据所述预设的对象标识的关联关系,所述第一对象标识,以及所述第二对象标识,在所述第一告警信息集合和所述第二告警信息集合中获取第三告警信息集合,所述第三告警信息集合是由对象标识之间具有关联关系的告警信息组成;根据预设的相关性规则,对所述第三告警信息集合进行相关性分析。
需要说明的是,上述预设的相关性规则,对象标识之间具有关联关系的告警信息,以及预设的对象标识的关联关系的相关描述可以参见图7所示实施例 中的步骤703,此处不再赘述。
在本发明的实施例提供的EMS,通过将VNF告警信息和VNFM上报的告警信息进行相关性分析,确定不同层中具有相关性关系的告警信息,实现跨层的告警信息的关联,避免了人工对告警分析的复杂性,减少了告警分析的时间,由此降低网络的运行维护成本。
参见图12,本发明实施例提供的一种告警信息处理装置,所述装置为VNFM,该装置具体可以用于执行图8或图10所示实施例中VNFM执行的方法,该装置具体可以包括:
接收单元1201,用于接收虚拟化基础设施管理VIM上报的虚拟机VM告警信息,所述VM告警信息包含第三对象标识;
处理单元1202,用于根据接收单元1201接收的所述VM告警信息,生成第一告警消息,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
发送单元1203,用于将处理单元1202生成的所述第一告警消息发送给网元管理系统EMS,以便所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
其中,所述第三对象标识可以包括以下至少一种:VM标识,NFVI基础设施层的主机HOST标识和VM的虚拟传输资源标识;
其中,所述VM标识可以包括VM标识符ID或者VM名字name;所述HOST标识可以包括HOST ID或者HOST name;所述VM的虚拟传输资源标识可以包括虚拟传输资源ID或者虚拟传输资源name。
具体地,VM的虚拟传输资源标识用于唯一标识一个VM,,例如,VPORT ID或者VPORT name,再例如,vNIC ID或者vNIC name。
其中,所述第一对象标识可以用于唯一标识第一对象;所述第一对象标识可以包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
其中,所述预设的对象标识的关联关系可以用于表示不同对象标识之间的关联关系。
可选地,所述第一告警消息还包括第一告警集合信息,所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
其中,上述各告警信息的相关描述可以参见图7或图8所示实施例,不再 赘述。
可选地,处理单元1202具体用于:
根据预设的所述第三对象标识与VNF标识之间的对应关系以及所述VM告警信息中的所述第三对象标识,获得与所述第三对象标识相对应的VNF标识,并将所述获得的VNF标识作为所述第一对象标识,生成所述第一告警消息;或者,
对所述VM告警信息进行相关性分析,生成所述第一告警消息。
具体地,可以参见图所示实施例中步骤803的两种实施例方式,不再赘述。
在本发明的实施例提供的VNFM,通过上报第一告警消息给EMS,以便EMS根据该第一告警消息进行与VNF告警信息的相关性分析,进而确定不同层中具有相关性关系的告警信息,实现跨层的告警信息的关联,避免了人工对告警分析的复杂性,减少了告警分析的时间,由此降低网络的运行维护成本。
参见图13,本发明实施例提供的一种告警信息处理装置,所述装置为VIM,该装置可以用于执行图9或图10所示实施例中VIM的操作步骤,具体可以包括:处理单元1301和发送单元1302。
处理单元1301,用于对至少两条告警信息进行相关性分析,生成虚拟机VM告警信息;
发送单元1302,用于将处理单元1301生成的VM告警信息上报给虚拟化网络功能管理器VNFM,以使得所述VNFM根据所述VM告警信息上报第一告警消息给网元管理系统EMS,所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
其中,所述至少两条告警信息可以包括:
至少一条网络功能虚拟化基础设施NFVI告警信息和至少一条VM告警信息;或者,
至少两条NFVI告警信息;或者,
至少两条VM告警信息。
可选地,上述装置还包括:
接收单元1303,用于接收NFVI上报的NFVI告警信息,所述NFVI告警信息包括NFVI标识;
处理单元1301,用于对接收单元1303接收的所述NFVI告警信息进行相关性分析,生成所述VM告警信息;
其中,所述NFVI标识包括VM标识,主机HOST标识和虚拟机的虚拟传输资源标识中的至少一种;所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
本发明实施例提供的VIM,通过对至少两个告警信息进行相关性分析,降低了人工告警分析的复杂度,减少了告警分析时间;此外,由VIM进行告警信息的相关性分析大大降低了VNFM的负荷。
本发明实施例提供一种告警信息处理系统,包括以下至少一个装置:图11至图13所示的告警信息处理装置。
参见图14,本发明实施例还提供了另一种告警信息处理装置,该装置为EMS,包括处理器1401,第一通信接口1402和第二通信接口1403。
第一通信接口1402,用于接收VNFM上报的第一告警消息;其中,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
第二通信接口1403,用于接收VNF上报的第二告警消息;其中,所述第二告警消息包括第二告警关联信息,所述第二告警关联信息包括以下至少一种:第二对象标识和所述预设的对象标识的关联关系;
处理器1401,用于根据所述第一告警关联信息和所述第二告警关联信息,对第一通信接口1402接收的所述第一告警消息和第二通信接口1403接收的所述第二告警消息进行相关性分析。
可选地,所述第一对象标识包括以下至少一种:VNF标识,虚拟机VM标识和VM的虚拟传输资源标识。
可选地,所述第二对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识。
其中,所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系;所述VNF标识包括VNF标识符ID或者VNF名字name;所述VM标识包括VM ID或者VM name;所述虚拟传输资源标识包括虚拟传输资源ID 或者虚拟传输资源name。
可选地,所述第一告警消息还包括第一告警信息集合;所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
其中,NFVI告警信息,VM告警信息以及VNFM告警信息可以参见图7-10各方法实施例中的相关描述,不再赘述。
可选地,所述第二告警消息还包括第二告警信息集合,所述第二告警信息集合包含至少一条VNF告警信息。
其中,VNF告警信息的相关描述可以参见图7或图10所示各实施例。
可选地,当所述第一告警消息包括第一告警信息集合,且所述第二告警信息包括第二告警信息集合时,处理器1401具体用于:
根据所述第一告警关联信息和所述第二告警关联信息,在所述第一告警信息集合和所述第二告警信息集合中获取具有相同告警关联信息的告警信息;根据预设的相关性规则,对所述获取的具有相同告警关联信息进行相关性分析;或者,
根据所述预设的对象标识的关联关系,所述第一对象标识,以及所述第二对象标识,在所述第一告警信息集合和所述第二告警信息集合中获取第三告警信息集合,所述第三告警信息集合是由对象标识之间具有关联关系的告警信息组成;根据预设的相关性规则,对所述第三告警信息集合进行相关性分析。
需要说明的是,上述预设的相关性规则,对象标识之间具有关联关系的告警信息,以及预设的对象标识的关联关系的相关描述可以参见图7所示实施例中的步骤703,此处不再赘述。
参见图15,本发明实施例提供的一种告警信息处理装置,所述装置为VNFM,该装置具体可以用于执行图8或图10所示实施例中VNFM执行的方法,该装置具体可以包括:
第一通信接口1501,用于接收虚拟化基础设施管理VIM上报的虚拟机VM告警信息,所述VM告警信息包含第三对象标识;
处理器1502,用于根据第一通信接口1501接收的所述VM告警信息,生成第一告警消息,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
第二通信接口1503,用于将处理器1502生成的所述第一告警消息发送给 网元管理系统EMS,以便所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
其中,所述第三对象标识可以包括以下至少一种:VM标识,NFVI基础设施层的主机HOST标识和VM的虚拟传输资源标识;
其中,所述VM标识可以包括VM标识符ID或者VM名字name;所述HOST标识可以包括HOST ID或者HOST name;所述VM的虚拟传输资源标识可以包括虚拟传输资源ID或者虚拟传输资源name。
具体地,VM的虚拟传输资源标识用于唯一标识一个VM,,例如,VPORT ID或者VPORT name,再例如,vNIC ID或者vNIC name。
其中,所述第一对象标识可以用于唯一标识第一对象;所述第一对象标识可以包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
其中,所述预设的对象标识的关联关系可以用于表示不同对象标识之间的关联关系。
可选地,所述第一告警消息还包括第一告警集合信息,所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
其中,上述各告警信息的相关描述可以参见图7或图8所示实施例,不再赘述。
可选地,处理器1502具体用于:
根据预设的所述第三对象标识与VNF标识之间的对应关系以及所述VM告警信息中的所述第三对象标识,获得与所述第三对象标识相对应的VNF标识,并将所述获得的VNF标识作为所述第一对象标识,生成所述第一告警消息;或者,
对所述VM告警信息进行相关性分析,生成所述第一告警消息。
具体地,可以参见图所示实施例中步骤803的两种实施例方式,不再赘述。
在本发明的实施例提供的VNFM,通过上报第一告警消息给EMS,以便EMS根据该第一告警消息进行与VNF告警信息的相关性分析,进而确定不同层中具有相关性关系的告警信息,实现跨层的告警信息的关联,避免了人工对告警分析的复杂性,减少了告警分析的时间,由此降低网络的运行维护成本。
参见图16,本发明实施例提供的一种告警信息处理装置,所述装置为VIM,该装置可以用于执行图9或图10所示实施例中VIM的操作步骤,具体 可以包括:处理器1601和第一通信接口1602。
处理器1601用于对至少两条告警信息进行相关性分析,生成虚拟机VM告警信息;
第一通信接口1602,用于将处理器1601生成的VM告警信息上报给虚拟化网络功能管理器VNFM,以使得所述VNFM根据所述VM告警信息上报第一告警消息给网元管理系统EMS,所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
其中,所述至少两条告警信息可以包括:
至少一条网络功能虚拟化基础设施NFVI告警信息和至少一条VM告警信息;或者,
至少两条NFVI告警信息;或者,
至少两条VM告警信息。
可选地,上述装置还包括:
第二通信接口1603,用于接收NFVI上报的NFVI告警信息,所述NFVI告警信息包括NFVI标识;
处理器1601,用于对第二通信接口1603接收的所述NFVI告警信息进行相关性分析,生成所述VM告警信息;
其中,所述NFVI标识包括VM标识,主机HOST标识和虚拟机的虚拟传输资源标识中的至少一种;所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
本发明实施例提供的VIM,通过对至少两个告警信息进行相关性分析,降低了人工告警分析的复杂度,减少了告警分析时间;此外,由VIM进行告警信息的相关性分析大大降低了VNFM的负荷。
本发明实施例和方法实施例一基于同一构思,其带来的技术效果也相同,具体原理请参照方法实施例的描述,此处不再赘述。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成,所述的程序可存储于一计算机可读取存储介质中,该程序在执行时,可包括如上述各方法的实施例的流程。 其中,所述的存储介质可为磁碟、光盘、只读存储记忆体(Read-Only Memory,ROM)或随机存储记忆体(Random Access Memory,RAM)等。
以上所揭露的仅为本发明一种较佳实施例而已,当然不能以此来限定本发明之权利范围,本领域普通技术人员可以理解实现上述实施例的全部或部分流程,并依本发明权利要求所作的等同变化,仍属于发明所涵盖的范围。

Claims (26)

  1. 一种告警信息处理方法,其特征在于,包括:
    网元管理系统EMS接收虚拟化网络功能管理器VNFM上报的第一告警消息;其中,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
    所述EMS接收虚拟网络功能VNF上报的第二告警消息;其中,所述第二告警消息包括第二告警关联信息,所述第二告警关联信息包括以下至少一种:第二对象标识和所述预设的对象标识的关联关系;
    所述EMS根据所述第一告警关联信息和所述第二告警关联信息,对所述第一告警消息和所述第二告警消息进行相关性分析。
  2. 如权利要求1所述的方法,其特征在于,所述第一对象标识包括以下至少一种:VNF标识,虚拟机VM标识和VM的虚拟传输资源标识;
    所述第二对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
    所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系;
    其中,所述VNF标识包括VNF标识符ID或者VNF名字name;所述VM标识包括VM ID或者VM name;所述虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
  3. 如权利要求1或2所述的方法,其特征在于,所述第一告警消息还包括第一告警信息集合;所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
  4. 如权利要求1-3任一项所述的方法,其特征在于,所述第二告警消息还包括第二告警信息集合,所述第二告警信息集合包含至少一条VNF告警信息。
  5. 如权利要求1-4任一项所述的方法,其特征在于,当所述第一告警消息包括第一告警信息集合,且所述第二告警信息包括第二告警信息集合时,所述EMS根据所述第一告警关联信息和所述第二告警关联信息,对所述第一告警消息和所述第二告警消息进行相关性分析,包括:
    根据所述第一告警关联信息和所述第二告警关联信息,在所述第一告警信息集合和所述第二告警信息集合中获取具有相同告警关联信息的告警信息;根 据预设的相关性规则,对所述获取的具有相同告警关联信息进行相关性分析;或者,
    根据所述预设的对象标识的关联关系,所述第一对象标识,以及所述第二对象标识,在所述第一告警信息集合和所述第二告警信息集合中获取第三告警信息集合,所述第三告警信息集合是由对象标识之间具有关联关系的告警信息组成;根据预设的相关性规则,对所述第三告警信息集合进行相关性分析。
  6. 一种告警信息处理方法,其特征在于,包括:
    虚拟化网络功能管理器VNFM接收虚拟化基础设施管理VIM上报的虚拟机VM告警信息,所述VM告警信息包含第三对象标识;
    所述VNFM根据所述VM告警信息,生成第一告警消息,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
    所述VNFM将所述第一告警消息发送给网元管理系统EMS,以便所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
  7. 如权利要求6所述的方法,其特征在于,所述第三对象标识包括以下至少一种:VM标识,NFVI基础设施层的主机HOST标识和VM的虚拟传输资源标识;
    其中,所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
  8. 如权利要求6或7所述的方法,其特征在于,所述第一对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
    所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系。
  9. 如权利要求6-8任一项所述的方法,其特征在于,所述第一告警消息还包括第一告警集合信息,所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
  10. 如权利要求6-9任一项所述的方法,其特征在于,所述VNFM根据所述VM告警信息,生成第一告警消息包括:
    根据预设的所述第三对象标识与VNF标识之间的对应关系以及所述VM告警信息中的所述第三对象标识,获得与所述第三对象标识相对应的VNF标 识,并将所述获得的VNF标识作为所述第一对象标识,生成所述第一告警消息;或者,
    对所述VM告警信息进行相关性分析,生成所述第一告警消息。
  11. 一种告警信息处理方法,其特征在于,包括:
    虚拟化基础设施管理VIM对至少两条告警信息进行相关性分析,生成虚拟机VM告警信息;
    将所述生成的VM告警信息上报给虚拟化网络功能管理器VNFM,以使得所述VNFM根据所述VM告警信息上报第一告警消息给网元管理系统EMS,所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
  12. 如权利要求11所述的方法,其特征在于,所述至少两条告警信息包括:
    至少一条网络功能虚拟化基础设施NFVI告警信息和至少一条VM告警信息;或者,
    至少两条NFVI告警信息;或者,
    至少两条VM告警信息。
  13. 如权利要求11或12所述的方法,其特征在于,所述方法还包括:
    接收NFVI上报的NFVI告警信息,所述NFVI告警信息包括NFVI标识;
    所述VIM对至少两条告警信息进行相关性分析,生成虚拟机VM告警信息,包括:
    对所述NFVI告警信息进行相关性分析,生成所述VM告警信息;
    其中,所述NFVI标识包括VM标识,主机HOST标识和虚拟机的虚拟传输资源标识中的至少一种;所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
  14. 一种告警信息处理装置,其特征在于,所述装置为网元管理系统EMS,包括:
    第一接收单元,用于接收虚拟化网络功能管理器VNFM上报的第一告警消息;其中,所述第一告警消息包含第一告警关联信息,所述第一告警关联信 息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
    第二接收单元,用于接收虚拟网络功能VNF上报的第二告警消息;其中,所述第二告警消息包括第二告警关联信息,所述第二告警关联信息包括以下至少一种:第二对象标识和所述预设的对象标识的关联关系;
    处理单元,用于根据所述第一告警关联信息和所述第二告警关联信息,对所述第一接收单元接收的所述第一告警消息和所述第二接收单元接收的所述第二告警消息进行相关性分析。
  15. 如权利要求14所述的装置,其特征在于,所述第一对象标识包括以下至少一种:VNF标识,虚拟机VM标识和VM的虚拟传输资源标识;
    所述第二对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
    所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系;
    其中,所述VNF标识包括VNF标识符ID或者VNF名字name;所述VM标识包括VM ID或者VM name;所述虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
  16. 如权利要求14或15所述的装置,其特征在于,所述第一告警消息还包括第一告警信息集合;所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
  17. 如权利要求14-16任一项所述的装置,其特征在于,所述第二告警消息还包括第二告警信息集合,所述第二告警信息集合包含至少一条VNF告警信息。
  18. 如权利要求14-17任一项所述的装置,其特征在于,当所述第一告警消息包括第一告警信息集合,且所述第二告警信息包括第二告警信息集合时,所述处理单元具体用于:
    根据所述第一告警关联信息和所述第二告警关联信息,在所述第一告警信息集合和所述第二告警信息集合中获取具有相同告警关联信息的告警信息;根据预设的相关性规则,对所述获取的具有相同告警关联信息进行相关性分析;或者,
    根据所述预设的对象标识的关联关系,所述第一对象标识,以及所述第二对象标识,在所述第一告警信息集合和所述第二告警信息集合中获取第三告警 信息集合,所述第三告警信息集合是由对象标识之间具有关联关系的告警信息组成;根据预设的相关性规则,对所述第三告警信息集合进行相关性分析。
  19. 一种告警信息处理装置,其特征在于,所述装置为虚拟化网络功能管理器VNFM,包括:
    接收单元,用于接收虚拟化基础设施管理VIM上报的虚拟机VM告警信息,所述VM告警信息包含第三对象标识;
    处理单元,用于根据所述接收单元接收的所述VM告警信息,生成第一告警消息,所述第一告警消息包含第一告警关联信息,所述第一告警关联信息包括以下至少一种:第一对象标识和预设的对象标识的关联关系;
    发送单元,用于将所述处理单元生成的所述第一告警消息发送给网元管理系统EMS,以便所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
  20. 如权利要求19所述的装置,其特征在于,所述第三对象标识包括以下至少一种:VM标识,NFVI基础设施层的主机HOST标识和VM的虚拟传输资源标识;
    其中,所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
  21. 如权利要求19或20所述的装置,其特征在于,所述第一对象标识用于唯一标识第一对象,其中,所述第一对象标识包括以下至少一种:VNF标识,VM标识和VM的虚拟传输资源标识;
    所述预设的对象标识的关联关系用于表示不同对象标识之间的关联关系。
  22. 如权利要求19-21任一项所述的装置,其特征在于,所述第一告警消息还包括第一告警集合信息,所述第一告警信息集合包含以下至少一种:NFVI告警信息,VM告警信息和VNFM告警信息。
  23. 如权利要求19-22任一项所述的装置,其特征在于,所述处理单元具体用于:
    根据预设的所述第三对象标识与VNF标识之间的对应关系以及所述VM告警信息中的所述第三对象标识,获得与所述第三对象标识相对应的VNF标识,并将所述获得的VNF标识作为所述第一对象标识,并根据所述第一对象 标识生成所述第一告警消息;或者,
    对所述VM告警信息进行相关性分析,生成所述第一告警消息。
  24. 一种告警信息处理装置,其特征在于,所述装置为虚拟化基础设施管理VIM,包括:
    处理单元,用于对至少两条告警信息进行相关性分析,生成虚拟机VM告警信息;
    发送单元,用于将所述处理单元生成的VM告警信息上报给虚拟化网络功能管理器VNFM,以使得所述VNFM根据所述VM告警信息上报第一告警消息给网元管理系统EMS,所述EMS对所述第一告警消息与VNF上报的第二告警信息进行相关性分析。
  25. 如权利要求24所述的装置,其特征在于,所述至少两条告警信息包括:
    至少一条网络功能虚拟化基础设施NFVI告警信息和至少一条VM告警信息;或者,
    至少两条NFVI告警信息;或者,
    至少两条VM告警信息。
  26. 如权利要求24或25所述的装置法,其特征在于,还包括:
    接收单元,用于接收NFVI上报的NFVI告警信息,所述NFVI告警信息包括NFVI标识;
    所述处理单元,用于对所述接收单元接收的所述NFVI告警信息进行相关性分析,生成所述VM告警信息;
    其中,所述NFVI标识包括VM标识,主机HOST标识和虚拟机的虚拟传输资源标识中的至少一种;所述VM标识包括VM标识符ID或者VM名字name;所述HOST标识包括HOST ID或者HOST name;所述VM的虚拟传输资源标识包括虚拟传输资源ID或者虚拟传输资源name。
PCT/CN2015/075796 2015-02-12 2015-04-02 一种告警信息处理方法、相关设备和系统 Ceased WO2016127482A1 (zh)

Priority Applications (10)

Application Number Priority Date Filing Date Title
EP15881643.9A EP3255833B1 (en) 2015-02-12 2015-04-02 Alarm information processing method, relevant device and system
CN201580000952.6A CN106170947B (zh) 2015-02-12 2015-04-02 一种告警信息处理方法、相关设备和系统
EP19192023.0A EP3633922B1 (en) 2015-02-12 2015-04-02 Alarm information processing method and system
AU2015382846A AU2015382846B2 (en) 2015-02-12 2015-04-02 Alarm information processing method, related device and system
RU2017131583A RU2679344C1 (ru) 2015-02-12 2015-04-02 Способ обработки информации об аварийных сигналах, соответствующее устройство и система
JP2017542440A JP6742327B2 (ja) 2015-02-12 2015-04-02 アラーム情報を処理する方法、関連デバイス、およびシステム
KR1020177025614A KR102001898B1 (ko) 2015-02-12 2015-04-02 알람 정보 처리 방법, 관련 디바이스 및 시스템
BR112017017330-1A BR112017017330B1 (pt) 2015-02-12 2015-04-02 Método e aparelho de processamento de informações de alarme
US15/675,105 US10771323B2 (en) 2015-02-12 2017-08-11 Alarm information processing method, related device, and system
US16/997,609 US20200382362A1 (en) 2015-02-12 2020-08-19 Alarm information processing method, related device, and system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CNPCT/CN2015/072910 2015-02-12
CN2015072910 2015-02-12

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/675,105 Continuation US10771323B2 (en) 2015-02-12 2017-08-11 Alarm information processing method, related device, and system

Publications (1)

Publication Number Publication Date
WO2016127482A1 true WO2016127482A1 (zh) 2016-08-18

Family

ID=56614083

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/075796 Ceased WO2016127482A1 (zh) 2015-02-12 2015-04-02 一种告警信息处理方法、相关设备和系统

Country Status (9)

Country Link
US (2) US10771323B2 (zh)
EP (2) EP3255833B1 (zh)
JP (1) JP6742327B2 (zh)
KR (1) KR102001898B1 (zh)
CN (1) CN106170947B (zh)
AU (1) AU2015382846B2 (zh)
BR (1) BR112017017330B1 (zh)
RU (2) RU2712438C2 (zh)
WO (1) WO2016127482A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109150572A (zh) * 2017-06-28 2019-01-04 华为技术有限公司 实现告警关联的方法、装置以及计算机可读存储介质
CN109995569A (zh) * 2018-01-02 2019-07-09 中国移动通信有限公司研究院 故障联动处理方法、网元及存储介质
CN116170281A (zh) * 2021-11-25 2023-05-26 中兴通讯股份有限公司 告警关联规则生成方法、装置、电子设备和存储介质

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3593495B1 (en) 2017-03-10 2024-06-12 Nokia Solutions and Networks Oy Method for fault escalation in nfv environment
CN107608767A (zh) * 2017-10-30 2018-01-19 中国联合网络通信集团有限公司 一种节点管理的方法及设备
US10270644B1 (en) * 2018-05-17 2019-04-23 Accenture Global Solutions Limited Framework for intelligent automated operations for network, service and customer experience management
CN111404716B (zh) * 2019-01-02 2022-12-13 中国移动通信有限公司研究院 一种协同告警处理的方法及系统
US12236357B2 (en) * 2019-01-08 2025-02-25 International Business Machines Corporation Generating a sequence rule
CN112073208B (zh) 2019-05-25 2022-01-14 成都华为技术有限公司 一种告警分析方法、装置、芯片系统、存储介质
US11177998B2 (en) * 2019-09-25 2021-11-16 International Business Machines Corporation Cross domain topology from machine learning
CN111431736B (zh) * 2020-02-27 2022-05-13 华为技术有限公司 告警关联规则生成方法和装置
CN113448809B (zh) * 2020-03-24 2024-12-13 伊姆西Ip控股有限责任公司 管理应用系统中的消息的方法、设备和计算机程序产品
US11533216B2 (en) * 2020-08-28 2022-12-20 Ciena Corporation Aggregating alarms into clusters to display service-affecting events on a graphical user interface
US11329863B1 (en) * 2021-10-18 2022-05-10 Amdocs Development Limited System, method, and computer program for dynamic prioritization of monitoring system related alerts

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040193943A1 (en) * 2003-02-13 2004-09-30 Robert Angelino Multiparameter network fault detection system using probabilistic and aggregation analysis
CN103718512A (zh) * 2013-09-11 2014-04-09 华为技术有限公司 一种告警上报方法及相关设备、系统
CN104170323A (zh) * 2014-04-09 2014-11-26 华为技术有限公司 基于网络功能虚拟化的故障处理方法及装置、系统
CN104243232A (zh) * 2014-07-02 2014-12-24 中国人民解放军信息工程大学 虚拟网故障探测和定位方法

Family Cites Families (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR100429512B1 (ko) * 2001-12-06 2004-05-03 삼성전자주식회사 망관리시스템에서 프로파일프로비젼에 의한 가입자등록고속처리방법
EP1573613A4 (en) * 2002-03-01 2009-11-18 Fisher Rosemount Systems Inc INTEGRATED ALARM GENERATION IN ONE PROCESSING SYSTEM
US20040210623A1 (en) * 2003-03-06 2004-10-21 Aamer Hydrie Virtual network topology generation
US7257744B2 (en) * 2003-03-17 2007-08-14 Tyco Telecommunications (Us) Inc. System and method for fault diagnosis using distributed alarm correlation
US7203881B1 (en) * 2004-06-29 2007-04-10 Sun Microsystems, Inc. System and method for simulating system operation
US20060031473A1 (en) * 2004-07-07 2006-02-09 Wood John A System and method for high capacity fault correlation
CN1992636B (zh) * 2005-12-29 2010-04-21 华为技术有限公司 一种处理告警信息的系统及方法
CN101128001B (zh) * 2006-08-18 2010-12-01 中兴通讯股份有限公司 网元管理系统对振荡告警的处理方法
CN101316187B (zh) * 2007-06-01 2010-08-25 杭州华三通信技术有限公司 网络管理方法和网络管理系统
CN101202676B (zh) * 2007-09-28 2010-05-19 中国移动通信集团福建有限公司 无线故障管理系统装置
CN101414933B (zh) * 2007-10-15 2011-08-10 中兴通讯股份有限公司 一种告警相关性信息的处理方法及装置
US8175863B1 (en) * 2008-02-13 2012-05-08 Quest Software, Inc. Systems and methods for analyzing performance of virtual environments
CN101582807B (zh) * 2009-07-02 2011-10-05 北京讯风光通信技术开发有限责任公司 一种基于北向接口实现网络管理的方法及系统
US9300548B2 (en) * 2011-10-14 2016-03-29 Alcatel Lucent Providing dynamic reliability and security in communications environments
EP2672668B1 (en) * 2012-06-06 2018-09-26 Juniper Networks, Inc. Facilitating the operation of a virtual network by predicting a failure
CN104125087B (zh) * 2013-04-28 2017-10-24 中国移动通信集团设计院有限公司 一种告警信息处理方法及装置
CN105282765A (zh) * 2014-06-30 2016-01-27 中兴通讯股份有限公司 一种管理配置信息的方法、设备及网元管理系统
US9594649B2 (en) * 2014-10-13 2017-03-14 At&T Intellectual Property I, L.P. Network virtualization policy management system
CN105591784A (zh) * 2014-10-24 2016-05-18 中兴通讯股份有限公司 告警处理方法及装置
CN105634785B (zh) * 2014-11-07 2019-01-01 中国移动通信集团公司 一种故障上报方法、系统及相关装置
WO2016093861A1 (en) * 2014-12-12 2016-06-16 Nokia Solutions And Networks Oy Alarm correlation in network function virtualization environment
US9946614B2 (en) * 2014-12-16 2018-04-17 At&T Intellectual Property I, L.P. Methods, systems, and computer readable storage devices for managing faults in a virtual machine network

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040193943A1 (en) * 2003-02-13 2004-09-30 Robert Angelino Multiparameter network fault detection system using probabilistic and aggregation analysis
CN103718512A (zh) * 2013-09-11 2014-04-09 华为技术有限公司 一种告警上报方法及相关设备、系统
CN104170323A (zh) * 2014-04-09 2014-11-26 华为技术有限公司 基于网络功能虚拟化的故障处理方法及装置、系统
CN104243232A (zh) * 2014-07-02 2014-12-24 中国人民解放军信息工程大学 虚拟网故障探测和定位方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3255833A4 *

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109150572A (zh) * 2017-06-28 2019-01-04 华为技术有限公司 实现告警关联的方法、装置以及计算机可读存储介质
CN109995569A (zh) * 2018-01-02 2019-07-09 中国移动通信有限公司研究院 故障联动处理方法、网元及存储介质
CN109995569B (zh) * 2018-01-02 2022-06-03 中国移动通信有限公司研究院 故障联动处理方法、网元及存储介质
CN116170281A (zh) * 2021-11-25 2023-05-26 中兴通讯股份有限公司 告警关联规则生成方法、装置、电子设备和存储介质

Also Published As

Publication number Publication date
EP3255833A4 (en) 2018-02-21
EP3255833B1 (en) 2019-09-11
BR112017017330A2 (zh) 2018-04-03
RU2019102417A (ru) 2019-02-22
KR20170117169A (ko) 2017-10-20
EP3633922A1 (en) 2020-04-08
JP2018509086A (ja) 2018-03-29
CN106170947B (zh) 2019-09-27
BR112017017330B1 (pt) 2023-12-12
CN106170947A (zh) 2016-11-30
RU2712438C2 (ru) 2020-01-28
EP3633922B1 (en) 2024-09-18
RU2679344C1 (ru) 2019-02-07
EP3255833A1 (en) 2017-12-13
AU2015382846B2 (en) 2018-10-04
US10771323B2 (en) 2020-09-08
KR102001898B1 (ko) 2019-07-24
US20170339007A1 (en) 2017-11-23
US20200382362A1 (en) 2020-12-03
RU2019102417A3 (zh) 2019-09-09
AU2015382846A1 (en) 2017-10-05
JP6742327B2 (ja) 2020-08-19

Similar Documents

Publication Publication Date Title
WO2016127482A1 (zh) 一种告警信息处理方法、相关设备和系统
CN108039964B (zh) 基于网络功能虚拟化的故障处理方法及装置、系统
US9733973B2 (en) Automatically determining sensor location in a virtualized computing environment
CN103368768B (zh) 混合云环境中自动缩放网络覆盖的方法、装置及设备
EP3285439B1 (en) Network service lifecycle management method and device
CN102857363B (zh) 一种虚拟网络的自主管理系统和方法
US8443078B2 (en) Method of determining equivalent subsets of agents to gather information for a fabric
US20180024866A1 (en) System, virtualization control apparatus, method for controlling a virtualization control apparatus, and program
US10360614B1 (en) Assessing and rating deployments of resources
US10892947B2 (en) Managing cross-cloud distributed application
US11848833B1 (en) System and method for operational intelligence based on network traffic
US10305764B1 (en) Methods, systems, and computer readable mediums for monitoring and managing a computing system using resource chains
TW201427336A (zh) 動態關聯實體與虛擬資源相依關係並自動生成多維度異質性資源網路拓樸之方法與系統
CN107566136A (zh) 虚拟网元管理em建立连接的方法、装置及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15881643

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2017542440

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112017017330

Country of ref document: BR

REEP Request for entry into the european phase

Ref document number: 2015881643

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2017131583

Country of ref document: RU

Kind code of ref document: A

Ref document number: 20177025614

Country of ref document: KR

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 2015382846

Country of ref document: AU

Date of ref document: 20150402

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 112017017330

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20170811