Log analysis method and device based on feature matching
An analysis method and feature matching technology, applied in the field of computer information, can solve problems such as difficult to grasp, cumbersome process of field analysis and processing, etc., to achieve the effect of increasing efficiency and lowering the threshold
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0042] It mainly includes the following steps:
[0043] Step S1: Set the data source, such as figure 1 As shown, wherein the input unit 11 is used for the user to set the name for the new log source, the protocol or mode of the user inputting the collection log in the input unit 12 can be syslog, http, IMAP, etc., the source IP of the user input log in the input unit 13 , the input unit 14 responds to the completion of the setting by the user, and after completion, step S2 can be entered.
[0044] Step S2: Set a log parsing template.
[0045] Step S21: if figure 2 As shown, the data samples are first obtained from the data source and displayed on the display unit 21 .
[0046] Step S22: Take out the template T from the built-in template library one by one i (feature_set, regex), record the feature set of the current template as T i [feature_set], one by one from the feature set T i Extract the feature feature from [feature_set] i , to determine whether the sample log c...
Embodiment 2
[0052] When setting the log parsing template, if no parsing template matching the current data source is found (or not satisfied with the found parsing template), pass figure 2 The trigger unit 25 enters the human-computer interaction module and generates a new parsing template semi-automatically.
[0053] Step S31: If image 3 As shown, the data sample obtained from the data source is displayed in the display unit 31;
[0054] Step S32: The user selects the field content to be extracted in the display unit 31, and an input unit 32 is triggered, and the user inputs a field name in the input unit. This operation can get a field, which is composed of three parts, field name (name), field value (value) and position (position), recorded as field (name, value, position), where position is determined by the starting position (start ) and the end position (end), recorded as position (start, end). Furthermore, the start position start represents the first character of the field cont...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


