Log Search Method and Device

By receiving log search requests, detecting pod information, determining application containers and target servers, and initializing log probes for log search, the problem of inefficient log file query in multi-application cluster environments is solved, and efficient log file search and resource saving is achieved.

CN112699219BActive Publication Date: 2025-07-22PING AN SECURITIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011621833.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-30
Publication Date
2025-07-22
Estimated Expiration
2040-12-30

AI Technical Summary

Technical Problem

In a multi-application cluster environment, log file query is inefficient, making it difficult for developers to quickly locate problems.

Method used

By receiving log search requests, detecting whether pod information is included, determining the application container and target server, initializing log probes for log search, and improving log file search efficiency.

Benefits of technology

Reduce resource loss in a multi-server environment, improve log search efficiency, save container work resources, and enhance the practicality of log file search.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112699219B_ABST
    Figure CN112699219B_ABST
Patent Text Reader

Abstract

An embodiment of the present application discloses a log search method and device, which are applied to a server. The method includes: receiving a log search request initiated by a user, where the log search request carries application information to be queried, and detecting whether the application information to be queried includes pod information; further, if the application information to be queried includes pod information, determining at least one application container corresponding to the pod information, and determining a target server corresponding to each application container in the at least one application container, so as to obtain at least one target server; finally, based on the at least one target server, initializing a first log probe corresponding to each target server in the at least one target server to obtain at least one second log probe, and performing log search based on the at least one second log probe to obtain at least one first log file. Using the embodiment of the present application is beneficial to improving the efficiency of log search. The present application also relates to blockchain technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and in particular, to a log search method and apparatus. Background Art

[0002] Log files are event records generated by network devices, systems, service programs, etc. during operation. Each line of the log records descriptions of related operations such as date, time, user, and actions. Different applications correspond to various log files, such as application program logs, system logs, etc. However, when the user's demand for the log file to be queried is large, and the number of cluster nodes corresponding to various applications in the server is increasing, if some unknown problems occur in the entire online system, developers need to find error logs in the log files of each device, resulting in low efficiency and being not conducive to problem-solving. Summary of the Invention

[0003] Embodiments of this application provide a log search method and apparatus, which are beneficial to improving the efficiency of log search.

[0004] In a first aspect of the embodiments of this application, a log search method is provided, which is applied to a server and includes:

[0005] Receiving a log search request initiated by a user, where the log search request carries information about the application to be queried;

[0006] Detecting whether the information about the application to be queried includes pod information;

[0007] If the information about the application to be queried includes the pod information, determining at least one application container corresponding to the pod information;

[0008] Determining a target server corresponding to each application container in the at least one application container to obtain at least one target server;

[0009] Based on the at least one target server, initializing a first log probe corresponding to each target server in the at least one target server to obtain at least one second log probe;

[0010] Based on the at least one second log probe, performing log search to obtain at least one first log file.

[0011] In a second aspect of the embodiments of this application, a log search apparatus is provided, which is applied to a server. The apparatus includes: a receiving unit, a detecting unit, a determining unit, an initializing unit, and a searching unit, where

[0012] The receiving unit is configured to receive a log search request initiated by a user, where the log search request carries information about the application to be queried;

[0013] The detection unit is configured to detect whether the application information to be queried includes pod information;

[0014] The determination unit is configured to, if the application information to be queried includes the pod information, determine at least one application container corresponding to the pod information;

[0015] The determination unit is further configured to determine a target server corresponding to each application container in the at least one application container, so as to obtain at least one target server;

[0016] The initialization unit is configured to initialize a first log probe corresponding to each target server in the at least one target server based on the at least one target server, so as to obtain at least one second log probe;

[0017] The search unit is configured to perform log search based on the at least one second log probe, so as to obtain at least one first log file.

[0018] A third aspect of the embodiments of the present application provides a server, which includes a processor, an input device, an output device, and a memory. The processor, the input device, the output device, and the memory are interconnected. Wherein, the memory is used to store a computer program, the computer program includes program instructions, and the processor is configured to call the program instructions to execute the method described in the first aspect of the embodiments of the present application.

[0019] A fourth aspect of the embodiments of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute some or all of the steps described in the first aspect of the embodiments of the present application.

[0020] A fifth aspect of the embodiments of the present application provides a computer program product, where the computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute some or all of the steps described in the first aspect of the embodiments of the present application. The computer program product may be a software installation package.

[0021] Implementing the embodiments of the present application has at least the following beneficial effects:

[0022] According to the embodiments of the present application, applied to a server, the above method includes: receiving a log search request initiated by a user, where the log search request carries information about the application to be queried, and detecting whether the information about the application to be queried includes pod information; further, if the information about the application to be queried includes pod information, determining at least one application container corresponding to the pod information, and determining the target server corresponding to each application container in the at least one application container, to obtain at least one target server; finally, based on the at least one target server, initializing the first log probe corresponding to each target server in the at least one target server, to obtain at least one second log probe, and based on the at least one second log probe, performing log search to obtain at least one first log file; thus, using multiple servers to store the above multiple log files is beneficial to reducing resource consumption; at the same time, after the user initiates a log search request, it is possible to search for log files outside the pod container based on the log probes respectively corresponding to the multiple servers, which is beneficial to improving the log search efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0024] Figure 1A FIG. [ID] provides a schematic diagram of the architecture of a log search system according to an embodiment of the present application;

[0025] Figure 1B FIG. [ID] provides a flowchart of a log search method according to an embodiment of the present application;

[0026] Figure 2A FIG. [ID] provides a flowchart of a log search method according to an embodiment of the present application;

[0027] Figure 2B FIG. [ID] provides a flowchart of a log search method according to an embodiment of the present application;

[0028] Figure 3 FIG. [ID] provides a schematic diagram of the structure of a server according to an embodiment of the present application;

[0029] Figure 4 FIG. [ID] provides a schematic diagram of the structure of a log search device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0030] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application.

[0031] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned accompanying drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.

[0032] Referring to "embodiment" in the present application means that a specific feature, structure or characteristic described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described in the present application may be combined with other embodiments.

[0033] In order to better understand the embodiments of the present application, the methods applying the embodiments of the present application will be introduced below.

[0034] The server mentioned in the embodiments of the present application may include, but is not limited to, a background server, a component server, a cloud server, a data distribution system server or a data distribution software server, etc. The above are only examples, not an exhaustive list, including but not limited to the above-mentioned devices.

[0035] Please refer to Figure 1A , Figure 1AIt is a schematic diagram of the architecture of a log search system provided by an embodiment of the present application. As shown in the figure, the system architecture diagram includes a conventional system architecture and a Kubernetes system architecture. Among them, the above-mentioned conventional system architecture may refer to a non-Kubernetes system architecture, which uses multiple physical servers to store log files. The system architecture of the embodiment of the present application is shown in the figure. On the basis of the conventional system architecture, a Kubernetes system architecture is added. The Kubernetes system architecture is composed of a distributed storage, service nodes, and control nodes. The cluster status in the Kubernetes system architecture is stored in the distributed storage, and the management control module of the cluster runs on the control node; the service node is the host node that actually runs the application containers. A proxy will run on each service node, and this proxy can be understood as a virtual server or a cloud server.

[0036] Among them, the above-mentioned log search system can be applied to a cloud computing network. Multiple pod containers can run in the above-mentioned service nodes. A pod is the smallest unit of the Kubernetes system architecture, which refers to one or more containers in a group of containers, and is equivalent to a combination of containers. The proxy corresponding to the above-mentioned service node can be used to control the pod containers. In the pod containers, there can be at least one application container. The application containers in the same pod container can share information. The log files corresponding to different applications can be stored in the above-mentioned multiple application containers. Each pod container or application container can correspond to a virtual server; the above-mentioned multiple pod containers can form a container network, and this container network is included in the above-mentioned cloud computing network; in addition, the above-mentioned system architecture can also be applied to a blockchain network. Blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. Blockchain, in essence, is a decentralized database, which is a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity (anti-counterfeiting) of the information and generate the next block. Blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer, etc.; specifically, the above-mentioned system architecture can be deployed in a blockchain network, and the distributed storage characteristics of the system architecture can be utilized to better manage the blockchain nodes in the blockchain network, further improve the high availability of the main chain nodes in the blockchain nodes, and is conducive to better monitoring and management of each node.

[0037] Among them, in the conventional system architecture, 3 server agents may be included. The specific number is not limited here. For example, Server 1, Server 2, and Server 3. Each server can be used to store log files corresponding to multiple applications. In the Kubernetes system architecture, 3 server agents may be included. The specific number is not limited here, and they respectively correspond to Server 4, Server 5, and Server 6. Any one of the above-mentioned Server 4, Server 5, or Server 6 can be the agent corresponding to the service node.

[0038] Among them, after the user initiates a log search request, based on the application information to be queried carried in the log search request, it can be determined which system the log file to be queried is stored in. If the application information to be queried does not include pod information, it is determined that the log file of the application to be queried is stored in the Kubernetes system architecture. Then, the target server corresponding to the application (which can be Server 4, Server 5, or Server 6) can be determined, and through the log probe corresponding to the target server, log search is performed to obtain multiple first log files. If the application information to be queried does not include pod information, it is determined that the log of the application to be queried is stored in the conventional system architecture. Then, the server corresponding to the query log request (which can be Server 1, Server 2, or Server 3) can be determined. Furthermore, multiple second log files are retrieved from the file corresponding to the server.

[0039] It can be seen that in the embodiment of the present application, the Kubernetes system architecture can be added on the basis of the conventional system architecture, which is beneficial to improving the practicability of the entire system. At the same time, in the Kubernetes system architecture, log file search can be implemented outside the pod container through the log probe, and there is no need to implement log file search inside the container, which is beneficial to saving the working resources of the container.

[0040] Please refer to Figure 1B , Figure 1B which is a schematic flowchart of a log search method provided by an embodiment of the present application and is applied to a server. The above method includes the following steps:

[0041] 101. Receive a log search request initiated by a user, where the log search request carries application information to be queried.

[0042] Among them, the embodiment of the present application can be applied to a server, and the server can be a virtual server. The server may include a log search system as shown in Figure 1A . The application to be queried can be various business applications. For example, it may include at least one of the following: shopping applications, payment applications, voice applications, video applications, etc. The specific types are not limited here.

[0043] Among them, a preset Kubernetes architecture can be pre-set in the server. The preset Kubernetes architecture can be set by the user himself or be the system default, which is not limited here. Based on the preset Kubernetes architecture, a log search architecture as shown in Figure 1A can be constructed. The preset Kubernetes architecture can be used to manage containerized applications on multiple hosts in the cloud platform.

[0044] Among them, the application information to be queried can include at least one of the following: application identifier, query time period, log name, query range, etc., which is not limited here.

[0045] In specific implementation, the server can receive a log search request initiated by a client. The log search request can be used to query the log file corresponding to any application in the front end. The log search request can carry the application information to be queried.

[0046] 102. Detect whether the application information to be queried includes pod information.

[0047] Among them, the pod information can refer to the attribute information corresponding to a specific pod container. For example, pod name, component name, IP address, etc., which is not limited here.

[0048] Among them, the server can include multiple pod containers. Each pod container can correspond to a different server. In the preset Kubernetes architecture, the pod container is the basis for all business types and can be a combination of one or more application containers.

[0049] Among them, the log files corresponding to each application in the preset Kubernetes architecture can be assembled and stored in different containers (pod containers). Each pod container can correspond to a server. Each pod container can include at least one application container. Each application can also correspond to a pod container, or multiple applications can correspond to one pod container. Different application containers in the same pod container can share data.

[0050] In a possible example, step 102, detecting whether the application information to be queried includes pod information, can include the following steps:

[0051] 21. Determine the application identifier corresponding to the application information to be queried;

[0052] 22. Determine the target label corresponding to the application identifier;

[0053] 23. According to the mapping relationship between the preset label and the encapsulation rule, determine the target encapsulation rule corresponding to the target label;

[0054] 24. Encapsulate the application identifier based on the target encapsulation rule to obtain the component name corresponding to the application identifier;

[0055] 25. Query whether the component name exists in the database corresponding to the preset Kubernetes architecture;

[0056] 26. If so, determine that the pod information is included in the application information to be queried;

[0057] 27. If not, determine that the pod information is not included in the application information to be queried.

[0058] Among them, the above application identifier may include at least one of the following: application name, application signature information, unique identifier, application process ID, etc., which are not limited here.

[0059] Among them, the server can preset the corresponding labels for different applications in advance. The label can correspond one-to-one with the application identifier. The label can be a string or a number, etc. For example, it can be lablename:A, etc.; the label can be configured in the configuration file corresponding to the pod container of the preset Kubernetes architecture.

[0060] Among them, the server can preset the encapsulation rule for each label and establish the mapping relationship between the preset label and the encapsulation rule.

[0061] Among them, the server where the user's required log file is located corresponds one-to-one with the component name. The corresponding server can be searched through the component name to determine whether there is pod information in the server; in order to facilitate determining whether there is pod information in the above application information to be queried and whether the pod information exists in the database corresponding to the above preset Kubernetes architecture; since in the server, the component name can be recognized by the server, regardless of whether the above application migrates, its corresponding component name will not change. Therefore, in order to improve the query accuracy, the server can query the component name in the database corresponding to the preset Kubernetes architecture.

[0062] In specific implementation, the label can be preset for the identification information of each application, and the mapping relationship between the label and the encapsulation rule of the component name can be established. In this way, the above application identifier can be encapsulated through the mapping relationship between the label and the component name to obtain the component name; thus, the component name can be used to query in the database corresponding to the preset Kubernetes architecture. If the component name exists, it can be determined that the pod information is included in the above application information to be queried, otherwise, it is not included.

[0063] Among them, the above packaging rule may refer to the rule of obtaining the component name by packaging according to the application name of different applications in the preset Kubernetes architecture. For example, if the application identifier of application A is application name A, the target label corresponding to this application name can be determined as: lablename:A; for the convenience of subsequent searching, the packaging rule of the component name can be made consistent with the naming rule of the above target label. In this way, a mapping relationship between the preset label and the packaging rule is established. For example, if the target label of this application A is "SIS-OMM-JTC-APP-AMS", the application name of application A can be packaged in the form of: "SIS-OMM-JTC-APP-AMS", and "SIS-OMM-JTC-APP-AMS" is the component name corresponding to this application. This component name can be applied in the preset Kubernetes architecture so that the above preset Kubernetes architecture can identify this application through the component name; in this way, when determining the pod information, the setting method of the naming rule of the label and the packaging rule of the application identifier is the same, which is also conducive to directly searching through the target label. If there is a component name that is the same as the target label, it can be considered that there is pod information in the above preset Kubernetes to improve the search efficiency.

[0064] 103. If the pod information is included in the application information to be queried, determine at least one application container corresponding to the pod information.

[0065] Among them, the above pod information may refer to the attribute information corresponding to a specific pod container, such as the component name, IP address, etc., which is not limited here. In addition, only in the above preset Kubernetes architecture does there exist corresponding pod information. If the above log search request is stored in a conventional environment, there is no pod information.

[0066] Among them, since a pod container may include multiple application containers, and the log files of the above application to be queried may be stored in different application containers according to the time point or other allocation methods, at least one application container corresponding to the above pod information can be determined, and this application container can correspond to the above application to be queried.

[0067] 104. Determine the target server corresponding to each application container in the at least one application container to obtain at least one target server.

[0068] Among them, in the K8S (Kubernetes) architecture, each pod can correspond to a server, and the component name corresponding to this pod can be in one-to-one correspondence with this server. Specifically, a mapping relationship between the component name and the IP address can be established. Each pod can include at least one application container. After determining the at least one application container above, its corresponding target server can be determined.

[0069] In a possible example, step 104 above, determining the target server corresponding to each application container in the at least one application container, includes:

[0070] 41. Determine the target node corresponding to the pod information according to the component name;

[0071] 42. Obtain the component correspondence table corresponding to the target node;

[0072] 43. Based on the component correspondence table, determine the target server corresponding to each application container in the at least one application container.

[0073] Among them, in a preset Kubernetes architecture, multiple pod containers can run on multiple nodes in the architecture. The node can be a service node in the preset Kubernetes architecture. Each node can correspond to at least one pod container. The node can be a virtual machine or a physical machine, which is not limited here.

[0074] Among them, the above-mentioned multiple nodes can run in a cloud environment. When the above-mentioned multiple nodes run in a cloud environment, the running status of the nodes can be detected at intervals. If it is detected that a certain node is abnormal, it will ask the supplier whether the virtual machine of the node is available. If it is not available, the node can be deleted from the node list.

[0075] Among them, in order to clearly understand the pod containers running under the node, each node can correspond to a component correspondence table. The component correspondence table can include multiple pod containers, and at least one application container included in each pod container.

[0076] Among them, each application container can correspond to a server, and the server can also be a virtual machine or a physical machine, which is not limited here.

[0077] In a possible example, step 43 above, based on the component correspondence table, determining the target server corresponding to each application container in the at least one application container, may include the following steps:

[0078] Based on the component correspondence table, use the pod information as a query voucher to query in the component correspondence table to obtain the target server corresponding to each application container in the at least one application container.

[0079] Among them, the above component correspondence table may include pod information and application containers included in each pod container. Any information in the pod information, such as the IP address corresponding to the pod container, can be used as a query credential to query in the above component correspondence table to obtain at least one application container corresponding to the application to be queried in the pod information and the target server corresponding to each container; the log file required by the user exists in the above at least one target server.

[0080] 105. Based on the at least one target server, initialize the first log probe corresponding to each target server in the at least one target server to obtain at least one second log probe.

[0081] Among them, in the above preset Kubernetes architecture, each server may correspond to a log probe, and the log probe can be used to find log files.

[0082] In a specific implementation, a log probe can be preset for each server. The log probe may include information such as the specific location corresponding to the log file on its server and the log level. After determining the at least one target server, the corresponding at least one first log probe can be initialized respectively. The purpose of initialization is to find the log file related to the above log search request, and at least one second log probe can be obtained. In this way, the log file can be found outside the pod container through the log probe, and there is no need to find the log file inside the container, which is beneficial to saving the working resources inside the container.

[0083] 106. Based on the at least one second log probe, perform a log search to obtain at least one first log file.

[0084] Among them, according to the at least one second target probe after initialization, the log file corresponding to the above log search request can be directly found in the at least one target server to obtain at least one first log file. Finally, a return result can be constructed based on the at least one first log file found and returned to the corresponding front end of the user. The return result may include at least one IP address, log file, etc. corresponding to the above at least one target server. The user can also further search for specific log files according to the IP address.

[0085] It can be seen that the log search method described in the embodiments of the present application is applied to a server, which can receive a log search request initiated by a user. The log search request carries information about the application to be queried, and it is detected whether the information about the application to be queried includes pod information. Furthermore, if the information about the application to be queried includes pod information, at least one application container corresponding to the pod information is determined, and the target server corresponding to each application container in the at least one application container is determined to obtain at least one target server. Finally, based on the at least one target server, the first log probe corresponding to each target server in the at least one target server is initialized to obtain at least one second log probe, and based on the at least one second log probe, log search is performed to obtain at least one first log file. In this way, multiple servers are used to store the above-mentioned multiple log files, which is beneficial to reducing resource consumption. At the same time, after the user initiates a log search request, the log files outside the pod container can be found based on the log probes respectively corresponding to the multiple servers, which is beneficial to improving the log search efficiency.

[0086] Consistently with the above, please refer to Figure 2A , Figure 2A which is a flowchart example of a log search method disclosed in the embodiments of the present application and is applied to a server. The log search method may include the following steps:

[0087] 201. Receive a log search request initiated by a user, where the log search request carries information about the application to be queried.

[0088] 202. Detect whether the information about the application to be queried includes pod information.

[0089] 203. If the information about the application to be queried includes the pod information, determine at least one application container corresponding to the pod information.

[0090] 204. Determine the target server corresponding to each application container in the at least one application container to obtain at least one target server.

[0091] 205. Based on the at least one target server, initialize the first log probe corresponding to each target server in the at least one target server to obtain at least one second log probe.

[0092] 206. Based on the at least one second log probe, perform log search to obtain at least one first log file.

[0093] Among them, the log search method described in the above steps 201 - 206 can refer to Figure 1B the corresponding steps of the log search method described therein.

[0094] Optionally, after the above step 206, the following steps may further be included:

[0095] A1. Start a preset timing task, poll the target interface corresponding to the preset Kubernetes architecture within a preset period, determine the nodes corresponding to each component in the database, and obtain the node information corresponding to each component;

[0096] A2. Update the component correspondence table based on the node information corresponding to each component.

[0097] Among them, the above preset period can be set by the user or be the system default, which is not limited herein. The preset period can be 50ms, 60ms, 100ms, 10 minutes, 1 hour, one day, etc., which is not limited herein; within each preset period, the target interface corresponding to the preset Kubernetes architecture can be polled to determine the component relationships in the interface, the node information where the pod containers run, etc.

[0098] Among them, after it is determined that the application information to be queried includes pod information, it indicates that the corresponding log file is stored in the preset Kubernetes architecture. In addition, if the log document is correspondingly stored in the blockchain network, and the blockchain network is deployed in the preset Kubernetes architecture, it can also be considered that the log file is stored in the preset Kubernetes architecture. In the embodiments of the present application, the business application corresponding to the above log file can be deployed in the environment of the preset Kubernetes architecture. For example, it can be mapped to the NodePort of the cluster working node through SLB (Server Load Balance). Among them, the NodePort service is a way to direct external traffic to the preset Kubernetes architecture to access various services in the blockchain network. In this way, the cluster technology and its own characteristics of the preset Kubernetes architecture can be used to provide the ability of standardized software packaging and distribution for the business applications in the blockchain network; and provide support for the scheduling ability of the underlying resources required by the blockchain network, such as computing, storage, network, etc.

[0099] Further, since in the above-mentioned preset Kubernetes architecture, due to the characteristics of container orchestration in the preset Kubernetes architecture, the pod containers corresponding to the applications may drift on each node, which also causes the log files contained in the pod containers to drift. For example, at different time nodes, the application may exist on different application nodes. Therefore, the server can preset a timing task. Based on this timing task, it can poll the target interface corresponding to the preset Kubernetes architecture within a preset period, and update the component correspondence table corresponding to each component's node in the database in real time to achieve real-time update of the container orchestration situation in the preset Kubernetes architecture. The above-mentioned preset component correspondence table may include information such as the pod corresponding to each application and the node or server corresponding to the pod, etc. Thus, when the pod node drifts, the search for log files can still be realized, and the trend of container orchestration can be understood at any time, which is beneficial to the extraction of log files.

[0100] 207. If the pod information is not included in the to-be-query application information, then perform log search based on the to-be-query application information to obtain at least one second log file.

[0101] Among them, the to-be-query application information may include at least one of the following: application name, query time period, log name, query range, etc. If the information about the application container bound to the server cannot be queried in the database corresponding to the server, then it is determined as a non-Kubernetes cluster architecture application service. Then, in the specific implementation, if the pod information is not included in the to-be-query application information, that is, the configuration information related to the pod container is not included, or the component name does not exist in the database corresponding to the above-mentioned preset Kubernetes architecture, it is determined that the pod information is not included in the to-be-query application information, and then directly perform log search based on the to-be-query application information. At this time, it can be determined that the to-be-query application does not depend on the above-mentioned preset Kubernetes architecture, and the target database corresponding to the to-be-query application can be directly obtained, and in this target database, perform log search according to the query range included in the to-be-query application information.

[0102] 208. Construct a first log search result based on the at least one first log file.

[0103] Among them, the server can construct a first log search result based on the at least one first log file that has been searched. For example, it can construct the data of the tree structure of the above-mentioned log search request based on information such as the server corresponding to the pod container where the first log file is located and its corresponding IP address to generate a first log search result and return it to the corresponding front end of the user.

[0104] 209. Construct a second log search result based on the at least one second log file.

[0105] Among them, the target database corresponding to the application to be queried can be obtained, and in this target database, log search is performed according to the query range included in the application information to be queried, and the search paths of at least one second log file can be obtained. The search paths may include target server information, port information, file paths, etc. In this way, a second log search result can be constructed and returned to the corresponding front end of the user.

[0106] 210. Assemble the first log search result and the second log search result to obtain the return result corresponding to the log search request, and send the return result to the user.

[0107] Among them, in practical applications, if there is a situation where an application in a conventional environment migrates to a Kubernetes environment, most of such migrations are gray-scale migrations. There will be a situation where part of the log files in the query range in the application information to be queried exist in the above-mentioned preset Kubernetes architecture, and part exist in a conventional server. The conventional server can correspond to a non-Kubernetes architecture and can be a traditional physical server. Then, after log search, there can be a corresponding search result for each; finally, the results (log files) corresponding to the above two searches can be summarized and assembled, and the return result (the log file after assembly) corresponding to the above log search request can be sent to the corresponding front end of the user.

[0108] Please refer to Figure 2B, is a schematic flowchart of a log search method provided by an embodiment of this application. After the server receives a log search request initiated by a user, the log search request may carry information about the application to be queried. The information about the application to be queried may include at least one of the following: application identifier, query time period, log name, query scope, etc., which are not limited here; furthermore, it can be determined whether there is pod information in the information about the application to be queried carried therein. The pod information may refer to the container name, IP address, etc. corresponding to the pod container, which are not limited here; if there is pod information, it indicates that the log file of the application that the user needs to query is stored in the Kubernetes architecture corresponding to the Kubernetes system, and then at least one first log file corresponding to the application can be searched in the Kubernetes architecture based on the probe corresponding to the target server corresponding to the pod information, and a first log search result can be constructed; if there is no pod information, it indicates that the log file of the application that the user needs to query is stored in the system architecture of the conventional system, and then at least one second log file can be searched in its corresponding server, and a second log search result can be constructed; finally, the first log search result and the second log search result are assembled to obtain the log search result corresponding to the log search request. In this way, considering different solutions corresponding to different environments (conventional environment and Kubernetes environment), it is beneficial to improve the efficiency of log search and, at the same time, is also beneficial to improving the user experience.

[0109] It can be seen that the log search method described in the embodiments of the present application is applied to a server, which can receive a log search request initiated by a user. The log search request carries application information to be queried, and it is detected whether the application information to be queried includes pod information. Furthermore, if the application information to be queried includes pod information, at least one application container corresponding to the pod information is determined, and for each application container among the at least one application container, the target server corresponding to it is determined to obtain at least one target server. Finally, based on the at least one target server, a first log probe corresponding to each target server among the at least one target server is initialized to obtain at least one second log probe, and based on the at least one second log probe, log search is performed to obtain at least one first log file. Further, if the application information to be queried does not include pod information, log search is performed based on the application information to be queried to obtain at least one second log file. Finally, a first log search result can be constructed based on the at least one first log file, a second log search result can be constructed based on the at least one second log file, the first log search result and the second log search result are assembled to obtain a return result corresponding to the log search request, and the return result is sent to the user. In this way, considering different solutions corresponding to different environments (conventional environment and Kubernetes environment), the corresponding environment can be determined according to the pod information, which is beneficial to enhancing the practicability of log search. In addition, in the Kubernetes environment, the log file can be found outside the pod container through the log probe, and there is no need to implement the search for the log file outside the pod container inside the container, which is beneficial to saving the working resources of the container.

[0110] Consistently with the above, please refer to Figure 3 , Figure 3 which is a schematic structural diagram of a server provided by an embodiment of the present application. As Figure 3 shown, it includes a processor, a communication interface, a memory, and one or more programs. The processor, the communication interface, and the memory are interconnected. Among them, the memory is used to store computer programs, and the computer programs include program instructions. The processor is configured to call the program instructions. The above one or more programs include instructions for performing the following steps:

[0111] Receive a log search request initiated by a user, where the log search request carries application information to be queried;

[0112] Detect whether the application information to be queried includes pod information;

[0113] If the application information to be queried includes the pod information, determine at least one application container corresponding to the pod information;

[0114] Determine the target server corresponding to each application container in the at least one application container, and obtain at least one target server;

[0115] Based on the at least one target server, initialize the first log probe corresponding to each target server in the at least one target server, and obtain at least one second log probe;

[0116] Based on the at least one second log probe, perform a log search to obtain at least one first log file.

[0117] It can be seen that the server described in the embodiments of the present application can receive a log search request initiated by a user. The log search request carries the application information to be queried, and detects whether the application information to be queried includes pod information. Furthermore, if the application information to be queried includes pod information, determine at least one application container corresponding to the pod information, and determine the target server corresponding to each application container in the at least one application container to obtain at least one target server. Finally, based on the at least one target server, initialize the first log probe corresponding to each target server in the at least one target server to obtain at least one second log probe, and based on the at least one second log probe, perform a log search to obtain at least one first log file. In this way, using multiple servers to store the above multiple log files is beneficial to reducing resource consumption. At the same time, after the user initiates a log search request, the log files outside the pod container can be found based on the log probes respectively corresponding to the multiple servers, which is beneficial to improving the log search efficiency.

[0118] In a possible example, in terms of detecting whether the application information to be queried includes pod information, the program is used to execute the instructions for the following steps:

[0119] Determine the application identifier corresponding to the application information to be queried;

[0120] Determine the target label corresponding to the application identifier;

[0121] According to the preset mapping relationship between the label and the encapsulation rule, determine the target encapsulation rule corresponding to the target label;

[0122] Based on the target encapsulation rule, encapsulate the application identifier to obtain the component name corresponding to the application identifier;

[0123] Query whether the component name exists in the database corresponding to the preset Kubernetes architecture;

[0124] If so, determine that the application information to be queried contains the pod information;

[0125] Otherwise, it is determined that the to-be-query application information does not include the pod information.

[0126] In a possible example, in terms of determining a target server corresponding to each application container in the at least one application container, the program is used to execute instructions for the following steps:

[0127] Determine a target node corresponding to the pod information according to the component name;

[0128] Obtain a component correspondence table corresponding to the target node;

[0129] Based on the component correspondence table, determine a target server corresponding to each application container in the at least one application container.

[0130] The above mainly introduces the solution of the embodiment of the present application from the perspective of the execution process on the method side. It can be understood that in order for the server to implement the above functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, combined with the units and algorithm steps of each example described in the embodiments provided in this article, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0131] Embodiments of the present application can divide the server into functional units according to the above method examples. For example, each functional unit can be divided corresponding to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. It should be noted that the division of units in the embodiments of the present application is illustrative, only a logical function division, and there can be other division methods in actual implementation.

[0132] Consistently with the above, please refer to Figure 4 , Figure 4 is a schematic structural diagram of a log search device disclosed in an embodiment of the present application, which is applied to a server. The device includes: a receiving unit 401, a detecting unit 402, a determining unit 403, an initializing unit 404, and a searching unit 405, where

[0133] The receiving unit 401 is configured to receive a log search request initiated by a user, and the log search request carries to-be-query application information;

[0134] The detection unit 402 is configured to detect whether the application information to be queried includes pod information;

[0135] The determination unit 403 is configured to, if the application information to be queried includes the pod information, determine at least one application container corresponding to the pod information;

[0136] The determination unit 403 is further configured to determine a target server corresponding to each application container in the at least one application container, and obtain at least one target server;

[0137] The initialization unit 404 is configured to initialize a first log probe corresponding to each target server in the at least one target server based on the at least one target server, and obtain at least one second log probe;

[0138] The search unit 405 is configured to perform log search based on the at least one second log probe, and obtain at least one first log file.

[0139] It can be seen that the log search device described in the embodiments of the present application is applied to a server, and can receive a log search request initiated by a user. The log search request carries application information to be queried, and detects whether the application information to be queried includes pod information; furthermore, if the application information to be queried includes pod information, at least one application container corresponding to the pod information is determined, and a target server corresponding to each application container in the at least one application container is determined, and at least one target server is obtained; finally, based on the at least one target server, a first log probe corresponding to each target server in the at least one target server is initialized to obtain at least one second log probe, and log search is performed based on the at least one second log probe to obtain at least one first log file; in this way, multiple servers are used to store the above multiple log files, which is beneficial to reducing resource consumption; at the same time, after the user initiates a log search request, the log files outside the pod container can be found based on the log probes respectively corresponding to the multiple servers, which is beneficial to improving the log search efficiency.

[0140] In a possible example, in terms of detecting whether the application information to be queried includes pod information, the determination unit 403 may specifically be configured to:

[0141] Determine an application identifier corresponding to the application information to be queried;

[0142] Determine a target label corresponding to the application identifier;

[0143] Determine a target encapsulation rule corresponding to the target label according to a preset mapping relationship between the label and the encapsulation rule;

[0144] Encapsulate the application identifier based on the target encapsulation rule to obtain the component name corresponding to the application identifier;

[0145] Query whether the component name exists in the database corresponding to the preset Kubernetes architecture;

[0146] If so, determine that the pod information is included in the application information to be queried;

[0147] If not, determine that the pod information is not included in the application information to be queried.

[0148] In a possible example, in terms of determining the target server corresponding to each application container in the at least one application container, the determining unit 403 may specifically be used for:

[0149] Determine the target node corresponding to the pod information according to the component name;

[0150] Obtain the component correspondence table corresponding to the target node;

[0151] Based on the component correspondence table, determine the target server corresponding to each application container in the at least one application container.

[0152] The embodiment of the present application further provides a computer-readable storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program enables the computer to execute some or all of the steps of any one of the log search methods described in the above method embodiments.

[0153] The embodiment of the present application further provides a computer program product, where the computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable the computer to execute some or all of the steps of any one of the log search methods described in the above method embodiments.

[0154] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.

[0155] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0156] In several embodiments provided by this application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in electrical or other forms.

[0157] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0158] In addition, in each embodiment of this application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software program modules.

[0159] If the above-mentioned integrated unit is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. And the aforementioned memory includes: USB flash drives, read-only memory (ROM), random access memory (RAM), mobile hard disks, magnetic disks, or optical discs and other media that can store program codes.

[0160] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable memory. The memory can include: flash drives, ROM, RAM, magnetic disks, or optical discs, etc.

[0161] The above has introduced the embodiments of the present application in detail. Specific examples are used herein to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation on the present application.

Claims

1. A log search method, characterized in that, Applied to a server, the server is deployed in a target system architecture, and the target system architecture includes a conventional system architecture and a Kubernetes system architecture, including: Receiving a log search request initiated by a user, where the log search request carries application information to be queried; the application information to be queried includes an application identifier and a query time period; Detecting whether the application information to be queried includes pod information; the detection method is: determining the application identifier corresponding to the application information to be queried; determining the target label corresponding to the application identifier; according to the mapping relationship between the preset label and the encapsulation rule, determining the target encapsulation rule corresponding to the target label; based on the target encapsulation rule, encapsulating the application identifier to obtain the component name corresponding to the application identifier; querying whether the component name exists in the database corresponding to the preset Kubernetes architecture; if so, determining that the application information to be queried includes the pod information; if not, determining that the application information to be queried does not include the pod information; the encapsulation rule of the component name matches the naming rule of the target label; If the application information to be queried includes the pod information, determining at least one application container corresponding to the pod information; if the application information to be queried includes the pod information, it indicates that the corresponding log file is stored in the preset Kubernetes architecture; Determining the target server corresponding to each application container in the at least one application container to obtain at least one target server; the pod information is the attribute information corresponding to the pod container, and the attribute information includes a component name and an IP address; the determination method of the target server is: according to the component name and the mapping relationship between the component name and the IP address, determining the target node corresponding to the pod information; obtaining the component correspondence table corresponding to the target node; based on the component correspondence table, using the pod information as a query voucher to query in the component correspondence table to obtain the target server corresponding to each application container in the at least one application container; Based on the at least one target server, initializing the first log probe corresponding to each target server in the at least one target server to obtain at least one second log probe; Based on the at least one second log probe, performing log search to obtain at least one first log file; Starting a preset timing task, polling the target interface corresponding to the preset Kubernetes architecture within a preset period to determine the node corresponding to each component in the database, and obtaining the node information corresponding to each component; Updating the component correspondence table based on the node information corresponding to each component; If the application information to be queried does not include the pod information, performing log search based on the application information to be queried to obtain at least one second log file; if the application information to be queried does not include the pod information, it indicates that the corresponding log file is stored in the conventional system architecture; If there is a situation where the application in the conventional environment is migrated to the Kubernetes environment, the first log search result corresponding to the first log file and the second log search result corresponding to the second log file are assembled to obtain the return result corresponding to the log search request, and the return result is sent to the user. The return result is used to indicate the IP addresses, the first log file, and the second log file corresponding to the at least one target server.

2. A log search device, characterized in that, Applied to a server, the server is deployed in a target system architecture, and the target system architecture includes a conventional system architecture and a Kubernetes system architecture. The device includes: a receiving unit, a detecting unit, a determining unit, an initializing unit, and a searching unit, where The receiving unit is configured to receive a log search request initiated by a user, and the log search request carries application information to be queried; the application information to be queried includes an application identifier and a query time period; The detecting unit is configured to detect whether the application information to be queried includes pod information; the detection method is: determining the application identifier corresponding to the application information to be queried; determining the target label corresponding to the application identifier; according to the mapping relationship between the preset label and the encapsulation rule, determining the target encapsulation rule corresponding to the target label; based on the target encapsulation rule, encapsulating the application identifier to obtain the component name corresponding to the application identifier; querying whether the component name exists in the database corresponding to the preset Kubernetes architecture; if so, determining that the application information to be queried includes the pod information; if not, determining that the application information to be queried does not include the pod information; the encapsulation rule of the component name matches the naming rule of the target label; The determining unit is configured to, if the application information to be queried includes the pod information, determine at least one application container corresponding to the pod information; if the application information to be queried includes the pod information, it indicates that the corresponding log file is stored in the preset Kubernetes architecture; The determining unit is further configured to determine the target server corresponding to each application container in the at least one application container to obtain at least one target server; the pod information is the attribute information corresponding to the pod container, and the attribute information includes a component name and an IP address; the determining method of the target server is: according to the component name and the mapping relationship between the component name and the IP address, determining the target node corresponding to the pod information; obtaining the component correspondence table corresponding to the target node; based on the component correspondence table, using the pod information as a query credential to query in the component correspondence table to obtain the target server corresponding to each application container in the at least one application container; The initializing unit is configured to initialize the first log probe corresponding to each target server in the at least one target server based on the at least one target server to obtain at least one second log probe; The search unit is configured to perform log search based on the at least one second log probe to obtain at least one first log file; The determination unit is further configured to start a preset timing task, poll a target interface corresponding to a preset Kubernetes architecture within a preset period, determine nodes corresponding to each component in the database, and obtain node information corresponding to each component; update the component correspondence table based on the node information corresponding to each component; The search unit is further configured to, if the pod information is not included in the application information to be queried, perform log search based on the application information to be queried to obtain at least one second log file; if the pod information is not included in the application information to be queried, it indicates that the corresponding log file is stored in the conventional system architecture; The determination unit is further configured to, if there is a situation where an application in a conventional environment migrates to a Kubernetes environment, assemble a first log search result corresponding to the first log file and a second log search result corresponding to the second log file to obtain a return result corresponding to the log search request, and send the return result to the user, where the return result is used to indicate the IP addresses, the first log file, and the second log file corresponding to the at least one target server.

3. A server, characterized in that, It includes a processor, an input device, an output device, and a memory. The processor, the input device, the output device, and the memory are interconnected. Among them, the memory is used to store a computer program, and the computer program includes program instructions. The processor is configured to call the program instructions to execute the method according to claim 1.

4. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and the computer program includes program instructions. When the program instructions are executed by a processor, the processor is caused to execute the method according to claim 1.

Citation Information

Patent Citations

  • Log file storage method and device

    CN110704376A

  • Business log query method and system of distributed system, medium and equipment

    CN111078657A