Web log processing method and device
A processing method and technology of network management equipment, applied in the field of communication, can solve the problem of long upgrade cycle of log processing software version, and achieve the effect of avoiding long upgrade cycle and saving user costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- Publication Date
- 2010-12-29
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to the communication field, in particular to a method and equipment for processing network logs. Background technique
[0002] In the network management system, the network management device obtains the network logs of each managed device, and monitors the network behavior of each managed device. For network devices produced by different manufacturers, the types of network logs may be different. Many equipment manufacturers have defined one or more log formats for the statistics of the network logs of their network equipment.
[0003] For network management equipment, various types of network logs may be obtained for analysis. Existing network management equipment usually encodes, parses and processes different logs from different manufacturers. When a new log format or log template appears on a managed device, new log processing software must be configured on the network management device to adapt. Such as figure 1 As shown,...
Examples
Embodiment Construction
[0046] In order to clearly illustrate the web log processing method provided by the present invention, the types of existing web logs are firstly introduced below.
[0047] Although there are many formats of weblogs, they are basically divided into two categories:
[0048] The first type of network logs are fixed-format logs, including NetFlow V1, V5, V7, and V8, NetStream V5, V8, NAT, FLOW, and ACCESS logs, and these log formats are relatively fixed. For example, the log format of NetFlow V5 includes the format of the log header shown in Table 1 and the format of each log shown in Table 2. The size and meaning of each field are fixed and will not change.
[0049] Table 1
[0050] Table B-3 Version 5 Header Format
[0051]
[0052] Table 2
[0053] Table B-4 Version 5 Flow Record Format
[0054]
[0055] The second type is template-based logs, such as NetFlow V9, NetStream V9, IPFIX, etc. This type of log is more flexible and can carry different network logs. Before...