Looking for breakthrough ideas for innovation challenges? Try Patsnap Eureka!

Automatic extraction and analysis for formwork based on heterogenerous logbook

An automatic extraction and analysis method technology, applied in the information field, can solve problems such as unable to meet the log analysis function

Inactive Publication Date: 2005-07-27
上海光华如新信息科技股份有限公司
View PDF0 Cites 65 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Although AWStats has certain characteristics in the analysis of web logs, there are still great defects in the processing mechanism: AWStats solidifies the analysis function of each log file in the tool according to the characteristics of each log file, so This tool can only realize the automatic analysis of several specific web log files. For other types of log files, the functional expansion can only be realized by changing the original program. This mechanism makes AWStats unable to meet the requirements at all. The log analysis function of various types of systems, servers or security devices has great limitations in its application range

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Automatic extraction and analysis for formwork based on heterogenerous logbook
  • Automatic extraction and analysis for formwork based on heterogenerous logbook

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0122] Embodiment 1: Information automatic extraction and analysis process of Skynet Firewall log files.

[0123] Skynet firewall log files are of text type, and the logs to be analyzed are as follows:

[0124] [1:59:58] Port 1294 of 192.168.0.107 stops sending data to this machine,

[0125] TCP flag: FA

[0126] continue to next rule

[0127] [1:59:58] The machine answers port 1294 of 192.168.0.107,

[0128] TCP flag: A

[0129] continue to next rule

[0130] [1:59:58] The Http[80] port of this machine stops sending data to 192.168.0.107,

[0131] TCP flag: FA

[0132] continue to next rule

[0133] The automatic extraction and analysis process of the Skynet Firewall log file information is as follows:

[0134] (1) Define the log analysis template

[0135] From the above information, it can be seen that the log file includes three types of records, from the first line to the third line is the record that the remote host port stops sending data to the local machine, and...

Embodiment 2

[0317] Embodiment two: the information automatic extraction and analysis process of wtmp log file is as follows:

[0318] (1) Define the log analysis template

[0319] field name

position (byte)

field length (byte)

username

0-31

32

The initial ID of the record

32-35

4

device name

36-67

32

process id

68-71

4

record type

72-73

2

process abort status

74-75

2

process exit status

76-77

2

record generation time

78-85

8

[0320] According to the structural characteristics of the log file, the defined binary log analysis template is as follows:

[0321]

[0322] < binary log template

[0323] Template_Id="15"

[0324] Record_type_num="1"

[0325] Record_Interval_Method="fixed_len">

[0326]

[0327] < record type

[0328] Type_Name="wtmp_log"

[0329] ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

A method for picking up and analysing information automatically includes using XML daily record analysing module to enter automatic picking up procedure, compairing packed up daily record with safety rule to judge whether system operation is abnormal or not, recording biased byte value of each analysis, detecting variation of each target device or daily record file at fixed time to realize automatic analysis to increased part of daily record according to recorded state information of dialy record.

Description

technical field [0001] The invention relates to a method for automatic extraction and analysis of log information, in particular to a method for automatic extraction and analysis of heterogeneous log information based on a template, which belongs to the field of information technology. Background technique [0002] At present, various hosts, servers, network devices, security devices, operating systems, and application systems all have logging functions to record the operating status and usage of the devices and systems themselves. It is a common practice to establish a network-wide audit and monitoring system to collect, manage and analyze all kinds of log information. Although log files contain a wealth of valuable information, the information is only useful if you dig deeper. Judging from the current implementation situation, most systems focus on the collection of log information, and the ability to analyze logs is relatively weak. Usually, in the case of serious securi...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): G06F11/14G06F17/27G06F17/30
Inventor 张世永廖健吴承荣杨暄
Owner 上海光华如新信息科技股份有限公司
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products