A method, apparatus, computer device, and storage medium for generating an interface state

By using distributed search engines and hidden Markov models in API exception monitoring, the interface status is generated, and the problem of low monitoring accuracy and flexibility in the existing technology is solved, and more efficient system monitoring is achieved.

CN114185848BActive Publication Date: 2025-05-27CHINA MOBILE GROUP SHANDONG +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010964409.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-15
Publication Date
2025-05-27
Estimated Expiration
2040-09-15

AI Technical Summary

Technical Problem

The prior art relies on dictionary files in API exception monitoring, resulting in lower monitoring accuracy and flexibility and increased system load.

Method used

Generate interface data by getting interface logs in the message queue and adding them to a distributed search engine. Then, the built Hidden Markov model is used to generate the interface state within a specified time period.

Benefits of technology

Improves the monitoring accuracy and monitoring flexibility of interface status, and reduces system load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114185848B_ABST
    Figure CN114185848B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a method, device, computer device, and storage medium for generating an interface status. In the technical solution provided by the embodiment of the present invention, interface logs are obtained from a message queue at a preset time interval; the interface logs are added to a distributed search engine; interface data is generated according to the distributed search engine; and an interface status within a specified time period is generated according to the interface data and a constructed hidden Markov model, which can improve the monitoring accuracy and flexibility of the interface status and reduce the system load.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method, apparatus, computer device, and storage medium for generating an interface state.

Background Art

[0002] The capability open platform uniformly manages the open service capabilities. The service capabilities are docked with the cooperation channels in the form of application program interfaces (APIs) through the capability open platform. With the growth of the number of access channels to the platform, maintaining the efficiency and stability of the capability open docking has become a key support point for the high-quality development of the business. Monitoring the anomalies of the APIs from a technical level is the main operation and maintenance means. For the anomaly monitoring of the APIs, currently, mainly based on the API calls, dictionary-based behavior matching is performed to monitor the APIs. The monitoring accuracy and flexibility relying solely on the dictionary file are relatively low, increasing the system load.

Summary of the Invention

[0003] In view of this, embodiments of the present invention provide a method, apparatus, computer device, and storage medium for generating an interface state, which can improve the monitoring accuracy and flexibility of the interface state and reduce the system load.

[0004] On the one hand, an embodiment of the present invention provides a method for generating an interface state, the method comprising:

[0005] Obtaining interface logs from a message queue at a preset time interval;

[0006] Adding the interface logs to a distributed search engine;

[0007] Generating interface data according to the distributed search engine;

[0008] Generating an interface state within a specified time period according to the interface data and a constructed hidden Markov model.

[0009] Optionally, before obtaining the interface logs from the message queue at a preset time interval, it further includes:

[0010] Obtaining interface request logs, interface response logs, and alarm logs;

[0011] Regarding the interface request logs, interface response logs, and alarm logs as interface logs;

[0012] Asynchronously adding the interface logs to a set message queue.

[0013] Optionally, the distributed search engine includes a statistical index; generating interface data according to the distributed search engine includes:

[0014] Through a distributed search engine, interface data is retrieved according to a statistical index.

[0015] Optionally, it further includes:

[0016] A service serial number is set between the statistical index and the log index, and the service serial number is used to associate the statistical index with the log index.

[0017] Optionally, before generating the interface status within a specified time period based on the interface data and the constructed hidden Markov model, it further includes:

[0018] Judge whether the interface data meets the set abnormal trigger condition;

[0019] If it is determined that the interface data meets the abnormal trigger condition, obtain the historical interface log;

[0020] Input the historical interface log into a Markov chain for training to generate a hidden Markov model.

[0021] Optionally, the distributed search engine includes a log index; it further includes:

[0022] If it is determined that the interface data meets the abnormal trigger condition, through the distributed search engine, retrieve the log data according to the log index;

[0023] Generate an alarm log according to the log data.

[0024] Optionally, it further includes:

[0025] If it is determined that the interface data does not meet the abnormal trigger condition, continue to execute the step of obtaining the interface log from the message queue at a preset time interval.

[0026] On the other hand, an embodiment of the present invention provides a device for generating an interface status, including:

[0027] A first acquisition unit for acquiring interface logs from the message queue at a preset time interval;

[0028] A first addition unit for adding the interface logs to the distributed search engine;

[0029] A first generation unit for generating interface data according to the distributed search engine;

[0030] A second generation unit for generating the interface status within a specified time period according to the interface data and the constructed hidden Markov model.

[0031] On the other hand, an embodiment of the present invention provides a storage medium, the storage medium includes a stored program, wherein when the program runs, it controls the device where the storage medium is located to execute the above method for generating the interface status.

[0032] On the other hand, an embodiment of the present invention provides a computer device, including a memory and a processor. The memory is used to store information including program instructions, and the processor is used to control the execution of the program instructions. It is characterized in that when the program instructions are loaded and executed by the processor, the above-mentioned method for generating an interface state is implemented.

[0033] In the solution of the embodiment of the present invention, interface logs are obtained from the message queue at a preset time interval; the interface logs are added to a distributed search engine; interface data is generated according to the distributed search engine; and an interface state within a specified time period is generated according to the interface data and the constructed hidden Markov model, which can improve the monitoring accuracy and flexibility of the interface state and reduce the system load.

Description of the Drawings

[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required to be used in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0035] Figure 1 It is a system architecture diagram for generating an interface state provided by an embodiment of the present invention

[0036] Figure 2 It is a flowchart of a method for generating an interface state provided by an embodiment of the present invention;

[0037] Figure 3 It is a flowchart of another method for generating an interface state provided by an embodiment of the present invention;

[0038] Figure 4 It is a schematic diagram of an HMM model provided by an embodiment of the present invention;

[0039] Figure 5 It is a schematic structural diagram of a device for generating an interface state provided by an embodiment of the present invention;

[0040] Figure 6 It is a schematic diagram of a computer device provided by an embodiment of the present invention.

Detailed Embodiments

[0041] In order to better understand the technical solutions of the present invention, the embodiments of the present invention will be described in detail below with reference to the drawings.

[0042] It should be clear that the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0043] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "the", and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0044] It should be understood that the term "and / or" used herein is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " herein generally represents an "or" relationship between the associated objects before and after.

[0045] It should be understood that although the terms first, second, etc. may be used in the embodiments of the present invention to describe the set thresholds, these set thresholds should not be limited to these terms. These terms are only used to distinguish the set thresholds from each other. For example, without departing from the scope of the embodiments of the present invention, the first set threshold may also be referred to as the second set threshold, and similarly, the second set threshold may also be referred to as the first set threshold.

[0046] Figure 1 The system architecture diagram for generating an interface state provided for the embodiments of the present invention is as Figure 1 shown. The system includes: a distributed search engine layer 100, an application program interface (API) location layer 200, and an anomaly recognition layer 300.

[0047] The distributed search engine layer 100 includes multiple distributed nodes, as Figure 1 shown. The distributed nodes include a Master node, a Client node, and a Data node. Among them, the Master node is used to maintain the source data and manage the status of the cluster nodes; the Client node is used for data task distribution and result aggregation, and can share the pressure for the Data nodes; the Data node is used to write data or query data to the upper layer. The distributed search engine layer 100 is used to transmit the source data to the API location layer 200.

[0048] The API location layer 200 includes multiple APIs, as Figure 1As shown, the API positioning layer 200 includes a first interface (API_1), a second interface (API_2), and a third interface (API_3). The API can locate a specified abnormal event based on the received source data and its own characteristics.

[0049] The abnormal event recognition layer 300 includes multiple abnormal events, such as Figure 1 As shown, the abnormal events include abnormal event A, abnormal event B, and abnormal event C. For example: API_1 and API_3 locate abnormal event B based on the received source data and their own characteristics; API_2 locates abnormal event A based on the received source data and its own characteristics; API_3 locates abnormal event C based on the received source data and its own characteristics.

[0050] In the embodiments of the present invention, Figure 1 the shown system architecture diagram is also used to execute the following Figure 2 or Figure 3 the method for generating the interface status shown, which will not be elaborated here.

[0051] In the technical solution provided by the embodiments of the present invention, interface logs are obtained from the message queue at a preset time interval; the interface logs are added to the distributed search engine; interface data is generated according to the distributed search engine; and the interface status within a specified time period is generated according to the interface data and the constructed hidden Markov model, which can improve the monitoring accuracy and flexibility of the interface status and reduce the system load.

[0052] Figure 2 is a flowchart of a method for generating an interface status provided by an embodiment of the present invention. As Figure 2 shown, the method includes:

[0053] Step 101: Obtain interface logs from the message queue at a preset time interval.

[0054] Step 102: Add the interface logs to the distributed search engine.

[0055] Step 103: Generate interface data according to the distributed search engine.

[0056] Step 104: Generate the interface status within a specified time period according to the interface data and the constructed hidden Markov model.

[0057] In the technical solution provided by the embodiments of the present invention, interface logs are obtained from the message queue at a preset time interval; the interface logs are added to the distributed search engine; interface data is generated according to the distributed search engine; and the interface status within a specified time period is generated according to the interface data and the constructed hidden Markov model, which can improve the monitoring accuracy and flexibility of the interface status and reduce the system load.

[0058] Figure 3 A flowchart of another method for generating an interface state provided by an embodiment of the present invention is as follows Figure 3 As shown, the method includes:

[0059] Step 201, obtain interface request logs, interface response logs, and alarm logs.

[0060] In the embodiments of the present invention, each step is executed by a server.

[0061] In the embodiments of the present invention, interface request logs and interface response logs are obtained from platform server logs; alarm logs are obtained from device fault alarm information. Among them, platform server logs belong to business-side source data, and alarm logs belong to hardware-side source data.

[0062] In the embodiments of the present invention, considering the foreground business-side call factors and hardware device fault privacy that affect the API call status in actual production applications, both business-side source data and hardware-side source data are used as source data for API exception monitoring, which can take into account the business characteristics and the impact of hardware devices on the API, making the source data more reliable.

[0063] Step 202, use the interface request logs, interface response logs, and alarm logs as interface logs.

[0064] In the embodiments of the present invention, interface logs include interface request logs, interface response logs, and alarm logs.

[0065] In the embodiments of the present invention, interface logs are source data for API exception monitoring.

[0066] Step 203, asynchronously add the interface logs to a set message queue.

[0067] In the embodiments of the present invention, the interface logs are asynchronously added to the message queue through a message system. As an alternative solution, the message system is an open-source stream processing platform (Kafka) message system.

[0068] In the embodiments of the present invention, asynchronously adding multi-source data to the message queue can reduce the system load and relieve the system pressure.

[0069] Step 204, obtain the interface logs from the message queue at a preset time interval.

[0070] In the embodiments of the present invention, the preset time interval can be set according to the actual situation.

[0071] In the embodiments of the present invention, an open-source log management platform (Logstash) obtains the interface logs from the message queue at a preset time interval.

[0072] In an embodiment of the present invention, interface logs are transmitted from an API service gateway to Logstash via a message queue. Logstash divides the data in the interface logs into two parts: API call statistics data and API call message log data, and stores the API call statistics data and API call message log data in an in-memory database, which can achieve the archival collection of multi-source data. As an alternative solution, the in-memory database is Redis.

[0073] Step 205: Add the interface logs to a distributed search engine.

[0074] As an alternative solution, the distributed search engine is an Elastic Search search engine.

[0075] In an embodiment of the present invention, an Elastic Search search engine is built through distributed node deployment, and the interface logs are added to the distributed search engine.

[0076] In an embodiment of the present invention, the distributed search engine can provide underlying architecture support for the mechanism construction and algorithm design of API exception monitoring and analysis.

[0077] Step 206: Query the interface data according to the statistical index through the distributed search engine.

[0078] In an embodiment of the present invention, the distributed search engine includes distributed nodes, and multiple indexes can be set in the distributed nodes for data management. As an alternative solution, two indexes are set in the distributed nodes of the distributed search engine for data management, namely a statistical index and a log index.

[0079] In an embodiment of the present invention, the API has an API code (API ID), and the statistical index can perform real-time search on the interface data with the API ID as the dimension.

[0080] In an embodiment of the present invention, the log data and interface data are displayed on a visual user interface. The user can manage the log data and interface data through the visual user interface. If it is detected that the user operation causes the API status to change, the status is associated with the API gateway at the second level for status synchronization. As an alternative solution, the visual user interface is Kibana.

[0081] Furthermore, a service serial number is set between the statistical index and the log index. The service serial number is used to associate the statistical index and the log index, realizing the association ability between the interface data and the log data.

[0082] In the embodiments of the present invention, the platform can use the service serial number to match the interface data and the log data. The message processing flow with successful matching can be recorded in the call log, realizing an operation and maintenance approach of using the service serial number to track the background call log to locate business failures, reducing the frequency of interactive access to the log data, improving security, and making the access and management of the platform log data traceable.

[0083] Step 207: Determine whether the interface data meets the set exception trigger condition; if so, execute Step 208; if not, execute Step 204.

[0084] In the embodiments of the present invention, the exception trigger condition can be set according to the actual situation. As an optional solution, when the interface data includes the API call delay, the exception trigger condition includes that the API call delay is greater than or equal to the delay threshold; when the interface data includes the response duration, the exception trigger condition includes that the response duration is greater than or equal to the response duration threshold; when the interface data includes whether the API call has a response, the exception trigger condition includes but is not limited to one or any combination of and the API call has no response.

[0085] In the embodiments of the present invention, if it is determined that the interface data meets the exception trigger condition, it indicates that the API has an exception, and continue to execute Step 208; if it is determined that the interface data does not meet the exception trigger condition, it indicates that the API has no exception, and continue to monitor and execute Step 204.

[0086] Further, if the API has an exception, then through the distributed search engine, query the log data according to the log index; according to the log data, generate an alarm log, and add the alarm log to the device fault alarm information. Among them, the log data includes the API call log, the request message, and the response message.

[0087] Step 208: Obtain the historical interface log.

[0088] In the embodiments of the present invention, the historical interface log includes historical log data and historical interface data.

[0089] Step 209: Input the historical interface log into the Markov chain (CTCM) for training to generate a hidden Markov (HMM) model.

[0090] In the embodiments of the present invention, input the historical log data and historical interface data into the CTCM to model and train the API state change, and construct an HMM model. Among them, the API state includes normal, abnormal event occurrence, abnormal event detection, operation and maintenance adjustment, and recovery, and the API state change is recorded in the historical log data.

[0091] Step 210: Generate the interface state within a specified time period according to the interface data and the constructed HMM model.

[0092] In an embodiment of the present invention, the specified time period includes a time period from the current moment to a future moment.

[0093] In an embodiment of the present invention, interface data is input into the HMM model, and the interface status within the specified time period is output. The interface status includes normal status or abnormal status.

[0094] Figure 4 It is a schematic diagram of an HMM model provided by an embodiment of the present invention, as Figure 4 shown. The model represents a time series from top to bottom, that is: the time period. The time series includes multiple moments, which are respectively moment 1 to τ. The eigenvalue f of the feature γ of the API call status at each moment τ γ,τ is used as the visible state, and the corresponding instantaneous state label t γ,τ is used as the hidden state, t γ,τ The state transition of is described by CTMT. The HMM model is as Figure 4 shown, and the API call status label set T = {T1, T2,..., Tτ} is obtained. Among them, T represents the set of API call status label sequences, that is: the interface status. The label value "0" indicates normal status, and the label value "1" indicates abnormal status.

[0095] In an embodiment of the present invention, since the interface status within the specified time period can be generated, the API call status at a future moment can be predicted.

[0096] Furthermore, the HMM model algorithm is written in a Python script, and the web request call script program is implemented in the workbench of Kibana. The interface status is output through the HMM model, and the API status data visualization is realized on the Kibana platform, so that the operation and maintenance personnel can more conveniently locate the root cause of anomalies, observe the repair effect, and at the same time, the visualization page encapsulation of API anomaly detection events can be realized, and the API status is detected and monitored from both aspects of operation and maintenance and operation.

[0097] In the technical solution of the interface status generation method provided by the embodiment of the present invention, interface logs are obtained from the message queue at a preset time interval; the interface logs are added to the distributed search engine; interface data is generated according to the distributed search engine; and the interface status within the specified time period is generated according to the interface data and the constructed hidden Markov model, which can improve the monitoring accuracy and flexibility of the interface status and reduce the system load.

[0098] Figure 5 It is a schematic structural diagram of an interface status generation device provided by an embodiment of the present invention. The device is used to execute the above interface status generation method, as Figure 5As shown in the figure, the device includes: a first acquisition unit 11, a first addition unit 12, a first generation unit 13, and a second generation unit 14.

[0099] The first acquisition unit 11 is used to acquire interface logs from the message queue at preset time intervals.

[0100] The first addition unit 12 is used to add the interface logs to the distributed search engine.

[0101] The first generation unit 13 is used to generate interface data according to the distributed search engine.

[0102] The second generation unit 14 is used to generate the interface status within a specified time period according to the interface data and the constructed hidden Markov model.

[0103] In an embodiment of the present invention, the device further includes: a second acquisition unit 15, a determination unit 16, and a second addition unit 17.

[0104] The second acquisition unit 15 is used to acquire interface request logs, interface response logs, and alarm logs.

[0105] The determination unit 16 is used to use the interface request logs, interface response logs, and alarm logs as interface logs.

[0106] The second addition unit 17 is used to asynchronously add the interface logs to the set message queue.

[0107] In an embodiment of the present invention, the first generation unit 13 is specifically used to query the interface data through the distributed search engine according to the statistical index.

[0108] In an embodiment of the present invention, the device further includes: a setting unit 18.

[0109] The setting unit 18 is used to set a service serial number between the statistical index and the log index, and the service serial number is used to associate the statistical index with the log index.

[0110] In an embodiment of the present invention, the device further includes: a judgment unit 19, a third acquisition unit 20, and a third generation unit 21.

[0111] The judgment unit 19 judges whether the interface data meets the set abnormal trigger condition; if it is judged that the interface data does not meet the abnormal trigger condition, the first acquisition unit 11 is triggered to continue to execute the step of acquiring interface logs from the message queue at preset time intervals.

[0112] The third acquisition unit 20 is used to acquire historical interface logs if the judgment unit 19 judges that the interface data meets the abnormal trigger condition.

[0113] The third generation unit 21 is used to input historical interface logs into a Markov chain for training to generate a hidden Markov model.

[0114] In an embodiment of the present invention, the device further includes: a query unit 22 and a fourth generation unit 23.

[0115] The query unit 22 is used to, if the judgment unit 19 determines that the interface data meets the abnormal trigger condition, query the log data according to the log index through a distributed search engine.

[0116] The fourth generation unit 23 is used to generate an alarm log according to the log data.

[0117] In the solution of the embodiment of the present invention, the interface logs are obtained from the message queue at a preset time interval; the interface logs are added to the distributed search engine; the interface data is generated according to the distributed search engine; and the interface status within a specified time period is generated according to the interface data and the constructed hidden Markov model, which can improve the monitoring accuracy and flexibility of the interface status and reduce the system load.

[0118] An embodiment of the present invention provides a storage medium, which includes a stored program. When the program runs, it controls the device where the storage medium is located to execute the steps of the embodiment of the above method for generating the interface status. For specific descriptions, reference can be made to the embodiment of the above method for generating the interface status.

[0119] An embodiment of the present invention provides a computer device, which includes a memory and a processor. The memory is used to store information including program instructions, and the processor is used to control the execution of the program instructions. When the program instructions are loaded and executed by the processor, the steps of the embodiment of the above method for generating the interface status are implemented. For specific descriptions, reference can be made to the embodiment of the above method for generating the interface status.

[0120] Figure 6 It is a schematic diagram of a computer device provided by an embodiment of the present invention. As Figure 6 shown, the computer device 30 of this embodiment includes: a processor 31, a memory 32, and a computer program 33 stored in the memory 32 and operable on the processor 31. When the computer program 33 is executed by the processor 31, it implements the method for generating the interface status in the embodiment. To avoid repetition, details are not described here one by one. Alternatively, when the computer program is executed by the processor 31, it implements the functions of each model / unit in the device for generating the interface status in the embodiment. To avoid repetition, details are not described here one by one.

[0121] The computer device 30 includes, but is not limited to, a processor 31 and a memory 32. Those skilled in the art can understand that Figure 6This is only an example of the computer device 30, which does not constitute a limitation on the computer device 30. It may include more or fewer components than those shown in the figure, or combine certain components, or different components. For example, the computer device may also include input / output devices, network access devices, buses, etc.

[0122] The so-called processor 31 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0123] The memory 32 may be an internal storage unit of the computer device 30, such as the hard disk or memory of the computer device 30. The memory 32 may also be an external storage device of the computer device 30, such as a plug-in hard disk, a smart media (SM) card, a secure digital (SD) card, a flash card, etc. equipped on the computer device 30. Further, the memory 32 may also include both the internal storage unit and the external storage device of the computer device 30. The memory 32 is used to store computer programs and other programs and data required by the computer device. The memory 32 may also be used to temporarily store data that has been output or is to be output.

[0124] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods may be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other may be through some interfaces, and the indirect couplings or communication connections of the devices or units may be in electrical, mechanical, or other forms.

[0125] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0126] In addition, each functional unit in various embodiments of the present invention may be integrated in a processing unit, may also exist separately as individual physical units, or two or more units may be integrated in one unit. The above-mentioned integrated unit may be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.

[0127] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.

Claims

1. A method for generating an interface status, characterized in that, the method includes: Obtaining interface logs from a message queue at a preset time interval, where the interface logs include interface request logs, interface response logs, and alarm logs; Adding the interface logs to a distributed search engine; Generating interface data according to the distributed search engine; Generating the interface status within a specified time period according to the interface data and a constructed hidden Markov model; The distributed search engine includes a statistical index and a log index. The statistical index is used to query interface data, and the log index is used to query log data; A service serial number is set between the statistical index and the log index, and the service serial number is used to associate the statistical index with the log index; Before generating the interface status within a specified time period according to the interface data and a constructed hidden Markov model, it further includes: Judging whether the interface data meets the set abnormal trigger condition; If it is judged that the interface data meets the abnormal trigger condition, query the log data according to the log index through the distributed search engine; Generating the alarm log according to the log data.

2. The method according to claim 1, characterized in that, Before obtaining the interface logs from the message queue at a preset time interval, it further includes: Obtaining the interface request log, the interface response log, and the alarm log; Regarding the interface request log, the interface response log, and the alarm log as the interface logs; Asynchronously adding the interface logs to a set message queue.

3. The method according to claim 1, characterized in that, Generating the interface data according to the distributed search engine includes: Querying the interface data according to the statistical index through the distributed search engine.

4. The method according to claim 1, characterized in that, It further includes: If it is judged that the interface data meets the abnormal trigger condition, obtaining historical interface logs; Inputting the historical interface logs into a Markov chain for training to generate a hidden Markov model.

5. The method according to claim 4, characterized in that, It further includes: If it is judged that the interface data does not meet the abnormal trigger condition, continue to execute the step of obtaining the interface logs from the message queue at a preset time interval.

6. An apparatus for generating an interface status, characterized in that, the apparatus includes: A first obtaining unit for obtaining interface logs from a message queue at a preset time interval, where the interface logs include interface request logs, interface response logs, and alarm logs; A first adding unit for adding the interface logs to a distributed search engine; A first generating unit for generating interface data according to the distributed search engine; A second generating unit for generating the interface status within a specified time period according to the interface data and a constructed hidden Markov model; The distributed search engine includes a statistical index and a log index. The statistical index is used to query interface data, and the log index is used to query log data; A setting unit, configured to set a service serial number between the statistical index and the log index, where the service serial number is used to associate the statistical index with the log index; The apparatus further includes: A judging unit, configured to judge whether the interface data meets an abnormal trigger condition set; A querying unit, configured to, if it is judged that the interface data meets the abnormal trigger condition, query log data according to the log index through the distributed search engine; A fourth generating unit, configured to generate the alarm log according to the log data.

7. A storage medium, characterized in that the storage medium includes a stored program, wherein, when the program runs, it controls the device where the storage medium is located to execute the method for generating the interface state according to any one of claims 1 to 5.

8. A computer device, including a memory and a processor, the memory is used to store information including program instructions, and the processor is used to control the execution of the program instructions, characterized in that when the program instructions are loaded and executed by the processor, the method for generating the interface state according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Log analysis method based on elastic component

    CN107273267A

  • Abnormal interface detection method, abnormal interface detection device, computer equipment, and storage medium

    CN108377240A