The application relates to a real-time flow retention and
batch extraction method, which adopts a brand-new design logic and is designed in a unified logic scheduling relationship for the retention and extraction of
network data flow. For the retention, a cache
relay and a
file system writing are introduced to obtain the storage of each to-be-analyzed
network data flow in each file in the
file system, and each aggregation key corresponding to each
time mark information corresponding to each to-be-analyzed
network data flow divided according to a preset network data flow aggregation rule is combined to form each to-be-analyzed key, and each to-be-analyzed value formed by the storage address of each to-be-analyzed network data flow in the
file system corresponding to each to-be-analyzed key. Based on this, for a target extraction request, the target aggregation key and the target time period are compared with each to-be-analyzed key and the corresponding to-be-analyzed value, so that the target extraction request is responded, the storage speed of real-time flow is improved, and the efficiency of
batch extraction during subsequent use is improved. The application has important significance for the rapid extraction and analysis of retained flow.