A log alarm filtering method, device, equipment and medium
By configuring the keyword index of the application name and the target filter word, log alarm filtering is performed by word-by-word matching, which solves the problem of unstable log system and realizes efficient log alarm filtering.
Patent Information
- Application Number
- CN202210264281.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-17
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2042-03-17
AI Technical Summary
In the existing technology, a large number of fuzzy queries in log alarm filtering cause the log system to be unstable or even crash. Fuzzy queries are inevitable. How to reduce the number of fuzzy queries to optimize log alarm filtering?
By configuring the application name as the first-level index, the target log data and filter words are determined, and the second-level index is constructed using the keywords of the target filter words. Fuzzy search and filtering are performed word by word, reducing the number of fuzzy queries.
It effectively avoids log system instability, improves the efficiency of log alarm filtering, and reduces the number and content of fuzzy queries.
Smart Images

Figure CN114610579B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of program control technology, and in particular to a log alarm filtering method, device, equipment and medium. Background Art
[0002] Currently, with the development of Internet technology, various application software are increasing. In order for them to operate normally, it is necessary to monitor the corresponding log data and issue timely alarms. Before performing log alarms, certain predictable alarms need to be filtered. In the prior art, alarm filtering can be performed by using a method of fuzzy query using a like function. However, log alarm filtering requires a large number of fuzzy queries under a relatively large log collection volume, which brings devastating disasters to the log system, causing instability or even collapse of the log system. However, fuzzy queries are indispensable in log alarm filtering. In summary, how to reduce the number of fuzzy queries when performing log alarm filtering to optimize log alarm filtering needs further solution. Summary of the Invention
[0003] In view of this, the purpose of the present invention is to provide a log alarm filtering method, apparatus, device, and medium that can reduce the number of fuzzy queries during log alarm filtering to optimize log alarm filtering. The specific solution is as follows:
[0004] In a first aspect, the present application discloses a log alarm filtering method, comprising:
[0005] Configure the first-level index based on the application name of the target application;
[0006] Determine target log data corresponding to the target application and target filter words related to the alarm based on the first layer index;
[0007] Traversing the target filter words and extracting a keyword as a search key for each target filter word according to a preset rule to construct a second-level index;
[0008] The target log data is traversed by utilizing the second-layer index and fuzzy query and filtering are performed on the target log data to complete alarm filtering of the target log data.
[0009] Optionally, configuring the first-level index according to the application name of the target application includes:
[0010] The application name of the target application input through the preset collection interface is obtained, and the first-level index is configured according to the application name.
[0011] Optionally, determining the target log data corresponding to the target application and the target filter words related to the alarm based on the first-layer index includes:
[0012] Searching the target log data corresponding to the target application from the application log data according to the first layer index;
[0013] The target filter word related to the alarm corresponding to the target application is searched from the local cache according to the first layer index; the application name of each application obtained from the background server and the corresponding filter word are stored in the local cache.
[0014] Optionally, the traversing the target log data using the second-layer index and performing fuzzy query and filtering on the target log data to complete alarm filtering of the target log data includes:
[0015] The target log data is traversed using the second-layer index. When a character in the target log data successfully matches a search key in the second-layer index, a fuzzy query and filtering is performed on the preset area corresponding to the character based on the target filter word in the filter word set corresponding to the search key to complete the alarm filtering of the target log data.
[0016] Optionally, traversing the target filter words and extracting a keyword as a search key for each target filter word according to a preset rule to construct a second-level index includes:
[0017] Traversing the target filter words and extracting the first character of each target filter word as the search key to construct a second-level index;
[0018] The target filter words with the same first character are placed in the same filter word set.
[0019] Optionally, also include:
[0020] The application name of the target application, the target filter word, the search key of the second-layer index, and the filter word set are stored in a mapping manner through local cache.
[0021] Optionally, before traversing the target log data using the second-layer index and performing fuzzy query and filtering on the target log data to complete alarm filtering on the target log data, the method further includes:
[0022] Filtering error log data from the target log data using the error log identifier to obtain corresponding filtered log data;
[0023] Accordingly, the use of the second-layer index to traverse the target log data and perform fuzzy query and filtering on the target log data to complete the alarm filtering of the target log data includes:
[0024] The filtered log data is traversed using the second-layer index and fuzzy query and filtering are performed on the filtered log data to complete the alarm filtering of the target log data.
[0025] In a second aspect, the present application discloses a log alarm filtering device, comprising:
[0026] A first-level index determination module, configured to configure a first-level index according to an application name of a target application;
[0027] a log and filter word determination module, configured to determine target log data corresponding to the target application and target filter words related to the alarm based on the first layer index;
[0028] A second-layer index determination module, configured to traverse the target filter words and extract a keyword as a search key for each target filter word according to a preset rule to construct a second-layer index;
[0029] The log alarm filtering module is used to traverse the target log data using the second-layer index and perform fuzzy query and filtering on the target log data to complete alarm filtering of the target log data.
[0030] In a third aspect, the present application discloses an electronic device, comprising:
[0031] Memory, used to store computer programs;
[0032] The processor is used to execute the computer program to implement the steps of the log alarm filtering method disclosed above.
[0033] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the log alarm filtering method disclosed above are implemented.
[0034] When performing log alarm filtering, the present application first configures the first-level index according to the application name of the target application, and determines the target log data corresponding to the target application and the target filter words related to the alarm based on the first-level index, and then traverses the target filter words and extracts a keyword as a search key for each target filter word according to the preset rules to construct a second-level index, and finally uses the second-level index to traverse the target log data for fuzzy query and filtering to complete the alarm filtering of the target log data. It can be seen that when performing log alarm filtering, the present application uses the first-level index configured by the application name, and uses the keywords in the corresponding target filter words as the second-level index to perform fuzzy query and filtering on the target log data. Therefore, when performing log alarm filtering, the present application first uses the first-level index configured by the application name to obtain the target log data and target filter words corresponding to the target application, and can select the target log data and target filter words corresponding to the target application for corresponding fuzzy queries, thereby avoiding the problem of log system instability or even crash caused by directly performing fuzzy queries on a large amount of log data through a large number of filter words, and reducing the number of fuzzy queries; on the other hand, by further configuring the keywords in the corresponding target filter words as the second-level index, the target log data can be quickly matched word by word directly through the search key of the second-level index, and the target log data can be fuzzy queried and filtered after matching the corresponding search key, thereby avoiding directly performing fuzzy queries on the target log data through the target filter words, and further reducing the number of fuzzy queries and the content of fuzzy queries, thereby improving the efficiency of log alarm filtering. In summary, the present application can reduce the number of fuzzy queries and optimize log alarm filtering when performing log alarm filtering. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0036] Figure 1 A flow chart of a log alarm filtering method provided by this application;
[0037] Figure 2 A flow chart of a specific log alarm filtering method provided by this application;
[0038] Figure 3 A flow chart of a specific log alarm filtering method provided by this application;
[0039] Figure 4 A structural diagram of a log alarm filtering device provided by this application;
[0040] Figure 5 This is a structural diagram of an electronic device provided in this application. DETAILED DESCRIPTION
[0041] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0042] In the prior art, alarm filtering can be performed by using a fuzzy query method using a "like" function. However, when collecting relatively large amounts of log data, log alarm filtering requires a large number of fuzzy queries, which can be devastating to the log system, causing instability or even crashing. However, fuzzy queries are essential for log alarm filtering. To this end, the present application provides a log alarm filtering method that can reduce the number of fuzzy queries during log alarm filtering and optimize log alarm filtering.
[0043] The embodiment of the present invention discloses a log alarm filtering method, see Figure 1 Said method comprises:
[0044] Step S11: configure the first-level index according to the application name of the target application.
[0045] In this embodiment, the target application refers to the application corresponding to the username entered by the user through the preset collection interface. Specifically, the application name of the target application entered through the preset collection interface is first obtained, and then the first-level index is configured based on the application name. The preset collection interface can configure different first-level indexes based on the application name entered.
[0046] It is understandable that due to the different log alarm filtering requirements of users, the user name of the target application corresponding to the user's requirements can be obtained through the preset collection interface, and the user name of the target application can be configured as the first-level index, so that all log data and filter words can be filtered for the first time through the first-level index to obtain the target log data corresponding to the target application and the target filter words related to the alarm.
[0047] Step S12: Determine target log data corresponding to the target application and target filter words related to the alarm based on the first-layer index.
[0048] Specifically, determining the target log data corresponding to the target application and the target filter words related to the alarm based on the first-layer index includes: searching the target log data corresponding to the target application from the application log data according to the first-layer index; searching the target filter words related to the alarm corresponding to the target application from the local cache according to the first-layer index; the local cache storing the application name of each application and its corresponding filter words obtained from the background server. It should be noted that the target log data is filtered out from all log data by reading the first-layer index configured by the application name of the target application collected from the preset interface, wherein the application name is used as a distinguishing key to isolate data between different logs in the entire log data, separating the log data of different applications, so that the target log data can be filtered out from all log data through the first-layer index. Furthermore, the application filter words are stored in the remote dictionary server. When the first-layer index configured by the application name of the target application collected from the preset interface is obtained, the target filter words corresponding to the target application are filtered out from the application filter words using the first-layer index and stored in the local cache. Through the above technical solution, the target log data and target filter words corresponding to the target application can be obtained through the configured first-level index, thereby selecting the target log data and target filter words corresponding to the target application for corresponding fuzzy query, thereby avoiding the problem of log system instability or even crash caused by directly performing fuzzy query on a large amount of log data through a large number of filter words, and reducing the number of fuzzy queries.
[0049] Step S13: traverse the target filtering words and extract a keyword as a search key for each target filtering word according to a preset rule to construct a second-level index.
[0050] It is understandable that even when the first-level index is well configured, extreme cases may occur. For example, if the target application is configured with too many target filter terms, in this case, even if the number of fuzzy queries is reduced by filtering through the first-level index, a large number of fuzzy queries may still occur, which will place a heavy burden on the system and seriously consume resources. To this end, this embodiment introduces a second-level index, namely a nested index, which further reduces the number of fuzzy queries. In this embodiment, a second index is constructed by extracting a keyword for each target filter term and using the keyword as a search key, so that the target log data can be subsequently filtered through the second-level index.
[0051] Step S14: traverse the target log data using the second-layer index and perform fuzzy query and filtering on the target log data to complete alarm filtering of the target log data.
[0052] In this embodiment, the target log data is first traversed using the second-level index, and then fuzzy query and filtering are performed on the target log. When traversing the target log data using the second-level index, only one quick match is required for each word in the target log data. Once the corresponding search key is matched, the target log data is fuzzy searched and filtered. This avoids directly searching the target log data using the target filter word, further reduces the number of fuzzy queries and the content of the fuzzy queries, and improves the efficiency of log alarm filtering.
[0053] It should be pointed out that the application name is the unique key for distinguishing the target filter words corresponding to different target applications, so it is indispensable as the first-level index, and selecting a keyword in the target filter word as the second-level index is also the key to improving the retrieval speed. In this embodiment, only selecting the second-level index is an optimal choice after balancing the complexity and performance. Among them, the target filter word must be a character string with a length greater than 0, and a keyword in the target filter word is selected as the retrieval key for the second-level retrieval. Therefore, the design of the two-level index structure is more universal, and when the filter word volume is not too large, there is not much difference in performance between using the second-level index and the second-level or higher index, but the design complexity will increase exponentially, which is not conducive to later maintenance. Therefore, in this embodiment, the two-level index method is selected for log alarm filtering.
[0054] It can be seen that this embodiment uses the first-level index configured by the application name when performing log alarm filtering, and uses the keywords in the corresponding target filter words as the second-level index to perform fuzzy query and filtering on the target log data. Therefore, when performing log alarm filtering, the present application first uses the first-level index configured by the application name to obtain the target log data and target filter words corresponding to the target application, and can select the target log data and target filter words corresponding to the target application for corresponding fuzzy query, thereby avoiding the problem of instability or even crash of the log system caused by directly performing fuzzy query on a large amount of log data through a large number of filter words, and reducing the number of fuzzy queries; on the other hand, by further configuring the keywords in the corresponding target filter words as the second-level index, the target log data can be quickly matched word by word directly through the search key of the second-level index. After matching the corresponding search key, the target log data is fuzzy queried and filtered, thereby avoiding directly performing fuzzy query on the target log data through the target filter words, further reducing the number of fuzzy queries and the content of fuzzy queries, and improving the efficiency of log alarm filtering. In summary, the present application can reduce the number of fuzzy queries and optimize log alarm filtering when performing log alarm filtering.
[0055] See also Figure 2As shown, the embodiment of the present invention discloses a specific log alarm filtering method. Compared with the previous embodiment, this embodiment further illustrates and optimizes the technical solution.
[0056] Step S21: configure the first-level index according to the application name of the target application.
[0057] Step S22: Determine target log data corresponding to the target application and target filter words related to the alarm based on the first-layer index.
[0058] Step S23: traverse the target filter words and extract the first character of each target filter word as the search key to construct a second-level index, and place the target filter words with the same first character in the same filter word set.
[0059] In this embodiment, the target filter terms are traversed and the first character of each target filter term is extracted as the search key to construct a second-level index. It is understandable that the target filter term must be a string with a length greater than 0, so the first character must exist. Furthermore, the target filter terms with the same first character are placed in the same filter term set, and the application name of the target application, the target filter term, the search key of the second-level index, and the filter term set are stored in a local cache in a mapped manner. The data structure of the local cache is:
[0060] Map<application name,Map<filter word.charAt(0),Set<filter word>>>;
[0061] It should be pointed out that compared with the prior art that uses a dictionary tree to implement filtering, the present invention uses a Map, which is more efficient in addition and deletion operations. In small-volume business scenarios, especially when the first characters are basically different, the efficiency of Map in filtering words is not lower than that of the dictionary tree, and the structure is simpler, so the performance is more stable.
[0062] Step S24: Use the second-layer index to traverse the target log data. When the characters in the target log data successfully match the search key in the second-layer index, fuzzy query and filtering are performed on the preset area corresponding to the characters based on the target filter words in the filter word set corresponding to the search key to complete the alarm filtering of the target log data.
[0063] In this embodiment, the target log data is quickly matched word by word using the second-level index constructed by using the first character of the target filter word as the search key. When the match is successful, the target filter word in the filter word set corresponding to the search key is used to perform fuzzy query and filtering on the preset area corresponding to the character to complete the alarm filtering of the target log data. The preset area is the preset character length corresponding to the target filter word. In a specific embodiment, the character length of the longest target filter word among all target filter words can be used as the preset character length. That is, when performing word-by-word matching of the target log data, when the character in the target log data successfully matches the second-level index, a fuzzy query and filtering is performed on the preset character length after the above-mentioned successfully matched character. It can be understood that the use of nested indexes in the second-level index can further reduce the number of fuzzy queries and the content of fuzzy queries, thereby improving the efficiency of log alarm filtering.
[0064] It can be seen that in this embodiment, the first character in the target filter word is used as the search key to construct the second-level index, and the target filter words with the same first character are put into the same set. When the match is successful, fuzzy query and filtering are performed on the preset area corresponding to the character based on the target filter word in the filter word set corresponding to the search key, which can further reduce the number of fuzzy queries and the content of fuzzy queries, and improve the efficiency of log alarm filtering.
[0065] See also Figure 3 As shown, the embodiment of the present invention discloses a specific log alarm filtering method. Compared with the previous embodiment, this embodiment further illustrates and optimizes the technical solution.
[0066] Step S31: Configure the first-level index according to the application name of the target application.
[0067] Step S32: Determine target log data corresponding to the target application and target filter words related to the alarm based on the first-layer index.
[0068] Step S33: traverse the target filtering words and extract a keyword as a search key for each target filtering word according to a preset rule to construct a second-level index.
[0069] Step S34: filtering out error log data from the target log data using the error log identifier to obtain corresponding filtered log data.
[0070] It is understandable that in the collection and monitoring of logs, error logs are set to be alerted by default, and error logs generally occupy a large number of characters. Therefore, before performing alarm filtering, the content of the error log can be filtered out to further reduce the content of the target log data that needs to be fuzzy queried.
[0071] java.lang.IllegalStateException: The process corresponding to the port does not exist: Port
[8888]
[0072] at com.project.requesthandler.ApplicationShellRequestHandler.handleRequest(ApplicationShellRequestHandler.java:30)
[0073] at com.project.ShellScriptServiceImpl.sendShellScript(ShellScriptServiceImpl.java:130)
[0074] As described above, for an error log, developers will only make a judgment based on the first line [The process corresponding to the port does not exist], and will not filter the specific stack trace information printed by the following threads. In this case, in this embodiment, the error log content below the first line can be reduced or completely removed to reduce the fuzzy query content. The error log identifier is a pre-set error log flag. As described in the error log above, the stack trace information begins with "at". Therefore, the first "java'\tat'" is used as the end match mark to reduce the content required for fuzzy query.
[0075] It should be pointed out that in the Java log, the information printed in the exception stack is specified. When it goes to the next line, it is prefixed with \t. The prefix is at, and \t is a transfer character. It is printed as four spaces on the console. In the above error log, the space before at is \t. \t is a line break format for the log.
[0076] Step S35: traverse the filtered log data using the second-layer index and perform fuzzy query and filtering on the filtered log data to complete the alarm filtering of the target log data.
[0077] In this embodiment, fuzzy querying and filtering the filtered log data through the second-level index is performed, compared to directly performing fuzzy querying and filtering operations on the target log data. The filtered log data is the target log data that does not contain error logs. It can be understood that by filtering the error logs, the content that needs to be fuzzy searched is reduced, thereby reducing the number of fuzzy queries and improving the efficiency of log alarm filtering.
[0078] It can be seen that in this embodiment, by filtering the error logs with longer characters that will trigger alarms by default in the target log, the amount of filtered log data that needs to be matched during the subsequent second indexing is greatly reduced, thereby achieving the effect of reducing the number of fuzzy queries and improving the efficiency of log alarm filtering.
[0079] See also Figure 4 As shown, the embodiment of the present application discloses a log alarm filtering device, comprising:
[0080] A first-level index determination module 11 is configured to configure a first-level index according to an application name of a target application;
[0081] a log and filter word determination module 12, configured to determine target log data corresponding to the target application and target filter words related to the alarm based on the first layer index;
[0082] A second-level index determination module 13 is configured to traverse the target filtering words and extract a keyword as a search key for each target filtering word according to a preset rule to construct a second-level index;
[0083] The log alarm filtering module 14 is configured to traverse the target log data using the second-layer index and perform fuzzy query and filtering on the target log data to complete alarm filtering on the target log data.
[0084] It can be seen that this embodiment uses the first-level index configured by the application name when performing log alarm filtering, and uses the keywords in the corresponding target filter words as the second-level index to perform fuzzy query and filtering on the target log data. Therefore, when performing log alarm filtering, the present application first uses the first-level index configured by the application name to obtain the target log data and target filter words corresponding to the target application, and can select the target log data and target filter words corresponding to the target application for corresponding fuzzy query, thereby avoiding the problem of instability or even crash of the log system caused by directly performing fuzzy query on a large amount of log data through a large number of filter words, and reducing the number of fuzzy queries; on the other hand, by further configuring the keywords in the corresponding target filter words as the second-level index, the target log data can be quickly matched word by word directly through the search key of the second-level index. After matching the corresponding search key, the target log data is fuzzy queried and filtered, thereby avoiding directly performing fuzzy query on the target log data through the target filter words, further reducing the number of fuzzy queries and the content of fuzzy queries, and improving the efficiency of log alarm filtering. In summary, the present application can reduce the number of fuzzy queries and optimize log alarm filtering when performing log alarm filtering.
[0085] In some specific embodiments, the first-layer index determination module 11 is specifically configured to: obtain an application name of a target application input through a preset acquisition interface, and configure a first-layer index according to the application name.
[0086] In some specific embodiments, the log and filter word determination module 12 specifically includes:
[0087] a target log data determining unit, configured to search the application log data for target log data corresponding to the target application according to the first layer index;
[0088] The target filter word determination unit is used to search the local cache for the target filter word related to the alarm corresponding to the target application according to the first layer index; the local cache stores the application name of each application obtained from the background server and its corresponding filter word.
[0089] In some specific embodiments, the log alarm filtering module 14 is specifically used to: use the second-layer index to traverse the target log data, and when the characters in the target log data successfully match the search key in the second-layer index, fuzzy query and filtering are performed on the preset area corresponding to the characters based on the target filter word in the filter word set corresponding to the search key to complete the alarm filtering of the target log data.
[0090] In some specific embodiments, the second-layer index determination module 13 is specifically used to: traverse the target filter words and extract the first character of each target filter word as the search key to construct the second-layer index; and place the target filter words with the same first character in the same filter word set.
[0091] In some specific embodiments, the log alarm filtering device further includes:
[0092] The local storage module is used to store the application name of the target application, the target filter word, the search key of the second-level index and the filter word set in a mapping manner through local cache.
[0093] In some specific embodiments, the log alarm filtering device further includes:
[0094] A log filtering module, configured to filter out error log data from the target log data using an error log identifier to obtain corresponding filtered log data;
[0095] Correspondingly, the log alarm filtering module 14 is specifically configured to use the second-layer index to traverse the filtered log data and perform fuzzy query and filtering on the filtered log data to complete alarm filtering of the target log data.
[0096] Figure 5 The electronic device 20 provided in an embodiment of the present application is shown. The electronic device 20 may further include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the log alarm filtering method disclosed in any of the aforementioned embodiments. Furthermore, the electronic device 20 in this embodiment may be a computer.
[0097] In this embodiment, the power supply 23 is used to provide voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0098] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0099] The operating system 221 is used to manage and control the hardware devices on the electronic device 20, and the computer program 222 can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of implementing the log alarm filtering method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program capable of implementing other specific tasks.
[0100] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when executed by a processor, the computer program implements the aforementioned disclosed log alarm filtering method. The specific steps of this method can be referred to the corresponding contents disclosed in the aforementioned embodiments and will not be repeated here.
[0101] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0102] The above is a detailed introduction to the log alarm filtering method, device, equipment and medium provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A log alarm filtering method, characterized in that: include: Configure the first-level index based on the application name of the target application; The configuring the first-level index according to the application name of the target application includes: obtaining the application name of the target application input through a preset acquisition interface, and configuring the first-level index according to the application name; Determine target log data corresponding to the target application and target filter words related to the alarm based on the first layer index; The determining of the target log data corresponding to the target application and the target filter words related to the alarm based on the first-layer index includes: searching the target log data corresponding to the target application from the application log data according to the first-layer index; searching the target filter words related to the alarm corresponding to the target application from the local cache according to the first-layer index; the local cache storing the application name of each application obtained from the background server and its corresponding filter words, the application name serving as a unique key to distinguish target filter words corresponding to different target applications; Traversing the target filter words and extracting a keyword as a search key for each target filter word according to a preset rule to construct a second-level index, where the second-level index is a nested index; The target log data is traversed by utilizing the second-layer index and fuzzy query and filtering are performed on the target log data to complete alarm filtering of the target log data.
2. The log alarm filtering method according to claim 1, characterized in that: The traversing the target log data by using the second-layer index and performing fuzzy query and filtering on the target log data to complete the alarm filtering of the target log data includes: The target log data is traversed using the second-layer index. When a character in the target log data successfully matches a search key in the second-layer index, a fuzzy query and filtering is performed on the preset area corresponding to the character based on the target filter word in the filter word set corresponding to the search key to complete the alarm filtering of the target log data.
3. The log alarm filtering method according to claim 1, characterized in that: The step of traversing the target filter words and extracting a keyword as a search key for each target filter word according to a preset rule to construct a second-level index includes: Traversing the target filter words and extracting the first character of each target filter word as the search key to construct a second-level index; The target filter words with the same first character are placed in the same filter word set.
4. The log alarm filtering method according to claim 3, characterized in that: Also includes: The application name of the target application, the target filter word, the search key of the second-layer index, and the filter word set are stored in a mapping manner through local cache.
5. The log alarm filtering method according to any one of claims 1 to 4, characterized in that: Before traversing the target log data using the second-layer index and performing fuzzy query and filtering on the target log data to complete the alarm filtering of the target log data, the method further includes: Filtering error log data from the target log data using the error log identifier to obtain corresponding filtered log data; Accordingly, the use of the second-layer index to traverse the target log data and perform fuzzy query and filtering on the target log data to complete the alarm filtering of the target log data includes: The filtered log data is traversed using the second-layer index and fuzzy query and filtering are performed on the filtered log data to complete the alarm filtering of the target log data.
6. A log alarm filtering device, characterized in that: include: A first-level index determination module, configured to configure a first-level index according to an application name of a target application; The first-layer index determination module is specifically configured to: obtain an application name of a target application input through a preset acquisition interface, and configure a first-layer index according to the application name; a log and filter word determination module, configured to determine target log data corresponding to the target application and target filter words related to the alarm based on the first layer index; The log and filter word determination module is specifically configured to: search the target log data corresponding to the target application from the application log data according to the first-layer index; search the target filter word associated with the alarm corresponding to the target application from the local cache according to the first-layer index; the local cache stores the application name of each application obtained from the backend server and its corresponding filter word, the application name serving as a unique key to distinguish target filter words corresponding to different target applications; A second-layer index determination module is used to traverse the target filtering words and extract a keyword as a search key for each target filtering word according to a preset rule to construct a second-layer index, wherein the second-layer index is a nested index; The log alarm filtering module is used to traverse the target log data using the second-layer index and perform fuzzy query and filtering on the target log data to complete alarm filtering of the target log data.
7. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is used to execute the computer program to implement the steps of the log alarm filtering method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the steps of the log alarm filtering method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Log retrieval method and device
CN106055621A
Log query method and device, electronic device and storage medium
CN111522714A
Transaction data exception monitoring method, system, equipment and medium
CN113886343A