Log Information Verification Method, Device, Equipment and Medium

By using a preset similarity algorithm to process the initial log information and target assertion information in log information verification, the candidate log information is determined and verified, the problems of low accuracy, high time-consuming and poor time-consuming log information verification in the prior art are solved, and more efficient and accurate log information verification is achieved.

CN115061874BActive Publication Date: 2025-06-10INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210672999.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-14
Publication Date
2025-06-10
Estimated Expiration
2042-06-14

AI Technical Summary

Technical Problem

The prior art has low accuracy when verifying log information, takes a lot of time, and has poor timeliness.

Method used

By collecting the initial log information on the server, using the preset similarity algorithm to process the initial log information and target assertion information, determine the candidate log information, and verify it based on the matching results of the candidate log information and target assertion information.

Benefits of technology

It improves the accuracy and efficiency of log information verification, reduces calculation overhead, and improves work effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115061874B_ABST
    Figure CN115061874B_ABST
Patent Text Reader

Abstract

The present disclosure provides a log information verification method, which can be applied to the fields of cloud computing and computers. The log information verification method includes: collecting initial log information from a server to obtain a log information set, where the initial log information includes structured log information composed of at least one log key-value pair; processing the initial log information and target assertion information by using a preset similarity algorithm to obtain target similarity information, where the target assertion information includes at least one assertion key-value pair; determining candidate log information from the initial log information in the log information set according to the target similarity information; and verifying the candidate log information as target log information according to the target matching result between the candidate log information and the target assertion information, where the target log information represents that the target program corresponding to the target log information in the server runs normally. The present disclosure also provides a log information verification device, device, storage medium, and program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the fields of cloud computing technology and computer technology, and particularly relates to a method, apparatus, device, medium, and program product for verifying log information. Background Art

[0002] Log information can be information generated during the operation of a program, such as alarm information, execution error information, etc. Log information generated during the operation of one or more servers can be collected by a log collection end, and by analyzing the log information, it can be determined whether there are problems in the log information, and by verifying the correctness of the log, it can be determined whether the program can execute smoothly.

[0003] In the process of implementing the inventive concept of the present disclosure, the inventors found that the accuracy rate of verifying log information is relatively low, and it takes a lot of time, and the verification timeliness is relatively poor. Summary of the Invention

[0004] In view of the above problems, the present disclosure provides a method, apparatus, device, medium, and program product for verifying log information.

[0005] According to a first aspect of the present disclosure, there is provided a method for verifying log information, including:

[0006] Collect initial log information from a server end to obtain a log information set, where the initial log information includes structured log information composed of at least one log key-value pair, and the log key-value pair includes a log information key representing log attribute information and a log information value corresponding to the log information key;

[0007] Process the initial log information and target assertion information using a preset similarity algorithm to obtain target similarity information, where the target assertion information includes at least one assertion key-value pair;

[0008] Determine candidate log information from the initial log information in the log information set according to the target similarity information; and

[0009] Verify the candidate log information as target log information according to a target matching result between the candidate log information and the target assertion information, where the target log information represents that a target program corresponding to the target log information in the server end runs normally.

[0010] According to an embodiment of the present disclosure, processing the initial log information and target assertion information using a preset similarity algorithm to obtain target similarity information includes:

[0011] Construct a target dictionary corresponding to a target bag-of-words model according to the initial log information in the log information set and the target assertion information;

[0012] The above initial log information and the above target assertion information are respectively compared using the above target dictionary to obtain an initial log vector and a target assertion vector;

[0013] The above initial log vector and the above target assertion vector are processed using the above preset similarity algorithm to obtain the above target similarity information.

[0014] According to an embodiment of the present disclosure, the above preset similarity algorithm includes at least one of the following:

[0015] Pearson algorithm, Spearman algorithm, Kendall algorithm, cosine similarity algorithm, Euclidean distance algorithm.

[0016] According to an embodiment of the present disclosure, according to the target matching result of the above candidate log information and the above target assertion information, verifying the above candidate log information as target log information includes:

[0017] The above candidate log information and the above target assertion information are processed using a preset matching algorithm to obtain the above target matching result;

[0018] When the above target matching result indicates that the above candidate log information matches the above target assertion information, the above candidate log is verified as the above target log;

[0019] Wherein, the above preset matching algorithm includes at least one of the following: naive algorithm, KMP algorithm, Rabin-Karp algorithm.

[0020] According to an embodiment of the present disclosure, before collecting the initial log information from the server to obtain a log information set, the above log information verification method further includes:

[0021] Bytecode information is sent to the above server, wherein the bytecode information is embedded in a program in the above server, and the bytecode information is suitable for recording the initial log information generated during the operation of the program.

[0022] According to an embodiment of the present disclosure, the above log attribute information includes at least one of the following:

[0023] The program identifier of the program in the above server, the call duration of the program in the above server, the alarm information of the program in the above server, the class information of the program call in the above server.

[0024] A second aspect of the present disclosure provides a log information verification device, including:

[0025] A collection module, configured to collect initial log information from a server to obtain a log information set, where the initial log information includes structured log information composed of at least one log key-value pair, and the log key-value pair includes a log information key representing log attribute information and a log information value corresponding to the log information key;

[0026] A similarity processing module, configured to process the initial log information and target assertion information by using a preset similarity algorithm to obtain target similarity information, where the target assertion information includes at least one assertion key-value pair;

[0027] A determination module, configured to determine candidate log information from the initial log information in the log information set according to the target similarity information; and

[0028] A matching module, configured to verify the candidate log information as target log information according to a target matching result between the candidate log information and the target assertion information, where the target log information represents that a target program corresponding to the target log information in the server runs normally.

[0029] A third aspect of the present disclosure provides an electronic device, including: one or more processors; a memory, configured to store one or more programs, where when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above-mentioned log information verification method.

[0030] A fourth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above-mentioned log information verification method.

[0031] A fifth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned log information verification method is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above-mentioned content and other objects, features and advantages of the present disclosure will become clearer. In the drawings:

[0033] Figure 1 Schematically shows an application scenario diagram of a log information verification method and device according to an embodiment of the present disclosure;

[0034] Figure 2 Schematically shows a flowchart of a log information verification method according to an embodiment of the present disclosure;

[0035] Figure 3ASchematically shows a flowchart of processing initial log information and target assertion information using a preset similarity algorithm to obtain target similarity information according to an embodiment of the present disclosure;

[0036] Figure 3B Schematically shows an application scenario diagram of a log information verification method according to an embodiment of the present disclosure;

[0037] Figure 4 Schematically shows a flowchart of a log information verification method according to an embodiment of the present disclosure;

[0038] Figure 5 Schematically shows a structural block diagram of a log information verification device according to an embodiment of the present disclosure; and

[0039] Figure 6 Schematically shows a block diagram of an electronic device suitable for implementing a log information verification method according to an embodiment of the present disclosure. Detailed implementation manners

[0040] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.

[0041] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0042] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0043] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C).

[0044] Embodiments of the present disclosure provide a log information verification method, including:

[0045] Collect initial log information from a server to obtain a log information set, where the initial log information includes structured log information composed of at least one log key-value pair, and the log key-value pair includes a log information key representing log attribute information and a log information value corresponding to the log information key; process the initial log information and target assertion information using a preset similarity algorithm to obtain target similarity information, where the target assertion information includes at least one assertion key-value pair; determine candidate log information from the initial log information in the log information set according to the target similarity information; and verify the candidate log information as target log information according to the target matching result between the candidate log information and the target assertion information, where the target log information represents that the target program corresponding to the target log information in the server runs normally.

[0046] According to the embodiments of the present disclosure, since the initial log information in the log information set includes log key-value pairs composed of a log information key and a log information value, and the target assertion information includes assertion key-value pairs with the same format as the log key-value pairs, the initial log information and the target assertion information can be processed using a preset similarity algorithm, and according to the obtained target similarity information, candidate log information can be determined from the initial log information in the log information set, so as to achieve fuzzy screening of the initial log information in the log information set, filter out other initial log information in the log information set except the candidate log information according to the fuzzy screening result, and further reduce the computational overhead of matching the candidate log information with the target assertion information. According to the target matching result between the candidate log information and the target assertion information, the candidate log information is verified as target log information, that is, the technical feature that the target assertion information can verify the normal operation of the program is utilized, and the target log information representing the normal operation of the target program is screened out according to this technical feature, thereby helping relevant personnel quickly verify the correctness of the log information, improving the verification accuracy while reducing the computational overhead, and enhancing the work effectiveness.

[0047] In the technical solution of the present disclosure, the processing of collection, storage, use, processing, transmission, provision, disclosure and application of user personal information involved all comply with the provisions of relevant laws and regulations, necessary confidentiality measures are taken, and public order and good customs are not violated.

[0048] In the technical solution of the present disclosure, before obtaining or collecting user personal information, the authorization or consent of the user is obtained.

[0049] Figure 1 Schematically shows an application scenario diagram of the log information verification method and device according to an embodiment of the present disclosure.

[0050] As Figure 1As shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, network 104, server 105, and server side 106. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0051] Users can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).

[0052] The terminal devices 101, 102, 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.

[0053] The server 105 may be a server providing various services, such as a background management server that supports the websites browsed by users using the terminal devices 101, 102, 103 (for example only). The background management server may analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0054] The server side 106 may be one or more servers running a program, and the server 105 may collect initial log information from the server side 106 through the network 104.

[0055] It should be noted that the log information verification method provided by the embodiments of the present disclosure can generally be executed by the server 105. Correspondingly, the log information verification device provided by the embodiments of the present disclosure can generally be set in the server 105. The log information verification method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server 105. Correspondingly, the log information verification device provided by the embodiments of the present disclosure can also be set in a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server 105.

[0056] It should be understood that Figure 1 the numbers of terminal devices, network, server, and server side in

[0057] Based on the following Figure 1 described scenarios, the Figures 2 to 4 log information verification method for the disclosed embodiments will be described in detail.

[0058] Figure 2 The flowchart of the log information verification method according to an embodiment of the present disclosure is schematically shown.

[0059] As Figure 2 shown, the log information verification method of this embodiment may include operation S210 to operation S240.

[0060] In operation S210, initial log information from the server is collected to obtain a log information set. Among them, the initial log information includes structured log information composed of at least one log key-value pair. The log key-value pair includes a log information key representing log attribute information and a log information value corresponding to the log information key.

[0061] According to an embodiment of the present disclosure, the server may be a server or a server cluster capable of running relevant programs. During the running of the program, log information recording the running situation of the program will be generated. The log information may include log attribute information and log information values corresponding to the log attribute information. The initial log message may be structured log information storing the log attribute information and the log information value as the log information key and the log information value respectively. For example, the initial log information may be expressed as (key1, value1), where key1 may represent the execution duration and value1 may represent 300s.

[0062] In an embodiment of the present disclosure, the initial log information may be structured information in JSON format.

[0063] It should be understood that the number of servers may be one or more, and the number of programs running on each server may also be one or more. The log information key may represent the name of the program, the parameter name of the program running, etc. The same log key-value pair may have one log information key corresponding to one log information value, or multiple log information keys corresponding to the same log information value. The specific corresponding format of the log information key and the log information value in the log key-value pair in the embodiments of the present disclosure is not limited.

[0064] In operation S220, the initial log information and the target assertion information are processed using a preset similarity algorithm to obtain target similarity information, where the target assertion information includes at least one assertion key-value pair.

[0065] According to an embodiment of the present disclosure, the target assertion information may include assertion key-value pairs composed of assertion attribute information used to determine the normal execution of a program in the assertion information and assertion information values corresponding to the assertion attribute information. Such assertion information may be based on the assertion information used to test the running situation of a program in relevant program test cases.

[0066] It should be noted that the assertion information may be stored in a test case assertion database, for example. Corresponding configuration information may be formulated according to requirements, and the configuration information may be executed for the assertion information in the assertion database, so that the target assertion information can be obtained. Or the target assertion information may also be obtained based on other related technologies. The embodiments of the present disclosure do not limit the specific acquisition method of the target assertion information.

[0067] In operation S230, according to the target similarity information, candidate log information is determined from the initial log information in the log information set.

[0068] According to an embodiment of the present disclosure, the preset similarity algorithm may include any algorithm used to determine relevance or similarity in related technologies, such as the cosine similarity algorithm, the Pearson algorithm, etc. The embodiments of the present disclosure do not limit the specific algorithm type of the preset similarity algorithm.

[0069] According to an embodiment of the present disclosure, the target similarity information may be the calculation result of a preset similarity algorithm. In the case where the target similarity information indicates that the initial log information has similarity or relevance to the target assertion information, the initial log information may be determined as candidate log information, so as to screen out the initial log information with relatively low relevance or similarity to the target log information from the log information set, saving some computing power overhead for the subsequent exact matching of the candidate log information and the target assertion information.

[0070] In operation S240, according to the target matching result of the candidate log information and the target assertion information, the candidate log information is verified as the target log information, where the target log information indicates that the target program corresponding to the target log information in the server runs normally.

[0071] According to an embodiment of the present disclosure, the candidate log information and the target assertion information may be matched according to a relevant matching algorithm, such as the full matching algorithm, etc., to obtain the target matching result, and the correctness of the target log information is verified through the accurate target matching result. That is, in the case where the target matching result indicates that the target log information matches the target assertion information, it can be determined that the target log information records that the corresponding target program can run normally, thereby improving the accuracy of verifying the log information.

[0072] According to an embodiment of the present disclosure, since the initial log information in the log information set includes log key-value pairs composed of a log information key and a log information value, and the target assertion information includes assertion key-value pairs having the same format as the log key-value pairs, the initial log information and the target assertion information can be processed using a preset similarity algorithm. According to the obtained target similarity information, candidate log information can be determined from the initial log information in the log information set, thereby realizing fuzzy screening of the initial log information in the log information set. According to the fuzzy screening result, other initial log information in the log information set except the candidate log information is filtered out, thereby reducing the computational overhead of matching the candidate log information with the target assertion information. According to the target matching result between the candidate log information and the target assertion information, the candidate log information is verified as the target log information, that is, the technical characteristic that the program runs normally can be verified using the target assertion information, and the target log information representing the normal operation of the target program is screened out according to this technical feature, thereby helping relevant personnel quickly verify the correctness of the log information, improving the verification accuracy while reducing the computational overhead, and enhancing the work effectiveness.

[0073] According to an embodiment of the present disclosure, the log attribute information may include at least one of the following:

[0074] The program identifier of the program in the server, the call duration of the program in the server, the alarm information of the program in the server, the class information called by the server program.

[0075] According to an embodiment of the present disclosure, the class information called by the server program may include category information such as hierarchical categories and execution categories for characterizing the program.

[0076] According to an embodiment of the present disclosure, the alarm information of the program in the server may include multiple alarm types, such as WARNING, INFO, etc.

[0077] It should be noted that the log attribute information may include any information for recording the program running situation, and those skilled in the art can select according to actual needs.

[0078] According to an embodiment of the present disclosure, before operating S210 to collect the initial log information from the server and obtain the log information set, the log information verification method may further include the following operations.

[0079] Send bytecode information to the server, where the bytecode information is embedded in the program in the server, and the bytecode information is suitable for recording the initial log information generated during the program running.

[0080] According to an embodiment of the present disclosure, the bytecode information may include pseudocode generated based on bytecode enhancement technology for monitoring the program running process. The bytecode information can achieve code embedding of the program through a virtual server mounted on the server side, and combine with a sandbox virtual machine to intercept log information, so as to collect the log information of the program without intruding into the program code and generate structured initial log information, making the initial log information compatible with multiple log frameworks.

[0081] In an embodiment of the present disclosure, the initial log information collected from one or more server sides can be transmitted to the Kafka message queue. By collecting the initial log information through the Kafka message queue to obtain the program call situation, the collected initial log information can be stored in a non-relational database.

[0082] According to an embodiment of the present disclosure, since the log frameworks of different server sides or different application programs can be different, for example, it can include Log4j, Logback, SLF4J, etc., the log information generated based on different log frameworks can have different formats, which results in that the log information directly generated by the server side does not have a unified format specification, with poor readability, usability and standardization, leading to low analysis efficiency for the log information. At the same time, there will be mutual calls between different programs, which may cause missing information printing in the log information, greatly disturbing the troubleshooting of problems, reducing the timeliness of finding log problems, and unable to accurately and timely verify the correctness of the log. However, the bytecode information generated according to the bytecode enhancement technology can convert log information in different formats into unified format initial log information without intruding into the program code, and avoid the loss of key information, laying a foundation for the subsequent accurate matching with the target assertion information.

[0083] Figure 3A A flowchart is schematically shown for processing the initial log information and the target assertion information according to a preset similarity algorithm to obtain the target similarity information according to an embodiment of the present disclosure.

[0084] As Figure 3A shown, in operation S220, processing the initial log information and the target assertion information according to a preset similarity algorithm to obtain the target similarity information may include operations S310 to S330.

[0085] In operation S310, according to the initial log information and the target assertion information in the log information set, a target dictionary corresponding to the target bag-of-words model is constructed.

[0086] According to an embodiment of the present disclosure, each key-value pair in the initial log information and the target assertion information can be used as a target word, and a target dictionary corresponding to the target word bag model can be constructed based on these target words. The target dictionary stores the target words formed by the initial log information and the target assertion information.

[0087] In operation S320, the initial log information and the target assertion information are respectively compared using the target dictionary to obtain an initial log vector and a target assertion vector.

[0088] In operation S330, the initial log vector and the target assertion vector are processed using a preset similarity algorithm to obtain target similarity information.

[0089] According to an embodiment of the present disclosure, each key-value pair in the initial log information and the target assertion information can be used as a target word, and a target dictionary (i.e., word bag) corresponding to the target word bag model can be constructed based on these target words. The target dictionary stores the target words formed by the initial log information and the target assertion information.

[0090] According to an embodiment of the present disclosure, using the target words in the target dictionary, the target words corresponding to each initial log information can be compared. In the case where the initial log information has the target words in the target dictionary, a vector element 1 can be generated. Correspondingly, in the case where the initial log information does not contain the target words in the target dictionary, a vector element 0 can be generated. Thus, the structured initial log information can be converted into a serialized initial log vector. According to the same or similar method, the target assertion information can also be converted into a target assertion vector.

[0091] According to an embodiment of the present disclosure, the initial log vector and the target assertion vector are processed using a preset similarity algorithm, that is, by a similarity algorithm or a correlation algorithm, the similarity of the two vectors is calculated to obtain target similarity information. The similarity between the initial log information and the target assertion information is measured according to the target similarity information to achieve fuzzy matching of the initial log information and the target assertion information. Since the word bag model does not consider word order and can generate vector information convenient for calculating using the similarity algorithm, the calculation process can be simplified and the timeliness of log verification can be improved.

[0092] Figure 3B Schematically shows an application scenario diagram of the log information verification method according to an embodiment of the present disclosure.

[0093] As Figure 3B shown, the initial log target word set 310 can be expressed as:

[0094] {A123.B123, A124.B0, A234.B234, A345.B345, A456.B0};

[0095] The initial log target word set 310 may include log key-value pairs of each initial log information. Among them, "A123.B123" may represent the log key-value pair of the initial log information, "A123" represents the log information key, and "B123" represents the log information value corresponding to the log information key. Correspondingly, the log key-value pair "A1.B1" can be used as a target word of the initial log information.

[0096] The target assertion target word set 320 can be expressed as:

[0097] {A123.B123, A124.B124, A234.B234};

[0098] The target assertion target word set 320 may include assertion key-value pairs of each target assertion information. Among them, "A6.B6" may represent the assertion key-value pair of the target assertion information, "A6" represents the assertion information key, and "B6" represents the assertion information value corresponding to the assertion information key. Correspondingly, the assertion key-value pair "A6.B6" can be used as a target word of the target assertion information.

[0099] According to the initial log target word set 310 and the target assertion target word set 320, the target dictionary 330 corresponding to the bag-of-words model can be constructed. The target dictionary 330 can store the target words of the initial log information and the target words corresponding to the target assertion information in a preset order.

[0100] By comparing the initial log information 341 {A123.B123, A234.B234, A456.B0} with the target dictionary 330, the initial log vector 342 {1, 0, 1, 0, 1, 1, 0, 0} can be obtained.

[0101] It should be noted that, in order to further simplify the calculation process, duplicate target words are ignored in the target dictionary 330. Those skilled in the art can construct a target dictionary with duplicate target words according to actual needs, and generate the initial log vector and the target assertion vector accordingly.

[0102] It should be understood that, by using the same or similar method, the target assertion information can also be compared with the target dictionary 330 to obtain the target assertion vector.

[0103] According to the embodiments of the present disclosure, the preset similarity algorithm may include at least one of the following:

[0104] Pearson algorithm, Spearman algorithm, Kendall algorithm, cosine similarity algorithm, Euclidean distance algorithm.

[0105] According to an embodiment of the present disclosure, when the preset similarity algorithm is the Pearson algorithm, the Pearson algorithm can be used to process the initial log vector and the target assertion vector, and the obtained target similarity information can be the Pearson correlation coefficient, which reflects the similarity degree between the initial log information and the target assertion information through the Pearson correlation coefficient.

[0106] The calculation process of the target similarity information can be represented by formula (1).

[0107]

[0108] In formula (1), X represents the initial log vector, Y represents the target assertion vector, and ρ x,Y represents the target similarity information.

[0109] It should be understood that by setting a preset similarity threshold, when the target similarity information is greater than or equal to the preset similarity threshold, it can be determined that the similarity degree between the initial log information and the target assertion information is relatively high, and thus the initial log information can be determined as candidate log information.

[0110] It should be noted that the log information verification method provided by the embodiments of the present disclosure can also obtain the target similarity information based on other preset similarity algorithms, such as the Spearman algorithm, the Kendall algorithm, the cosine similarity algorithm, and the Euclidean distance algorithm. Embodiments are not listed one by one here.

[0111] Figure 4 Schematically shows a flowchart of the log information verification method according to an embodiment of the present disclosure.

[0112] As Figure 4 shown, in operation S240, verifying the candidate log information as the target log information according to the target matching result between the candidate log information and the target assertion information may include operations S410 to S420.

[0113] In operation S410, process the candidate log information and the target assertion information using a preset matching algorithm to obtain a target matching result;

[0114] In operation S420, when the target matching result indicates that the candidate log information matches the target assertion information, verify the candidate log as the target log; where the preset matching algorithm includes at least one of the following: the naive algorithm, the KMP algorithm, and the Rabin-Karp algorithm.

[0115] According to an embodiment of the present disclosure, the preset matching algorithm may include a string pattern matching algorithm in the related art. Using the preset matching algorithm to match the candidate log information with the target log information according to the string, the obtained target matching result can not only reflect the character matching, but also reflect the order matching between characters. Therefore, the accuracy of the obtained target matching result is relatively high.

[0116] According to an embodiment of the present disclosure, when the preset matching algorithm is the naive algorithm, the candidate log information can be set as the substring P, and the target assertion information can be set as the main string T. Starting from the first character of the main string T, compare it with the substring P from the beginning respectively. When a mismatch is found, the main string T returns to the next character at the start of this round, and the substring P starts comparing from the beginning. Until all characters of the substring P are matched, return the subscript in the main string T where it is located.

[0117] Using the naive algorithm to process the candidate log information and the target assertion information, the time complexity of obtaining the target matching result can be expressed as o(m*n), where m represents the length of the substring P and n represents the length of the main string T.

[0118] According to an embodiment of the present disclosure, when the preset matching algorithm is the KMP algorithm, the candidate log information can also be set as the substring P, and the target assertion information can be set as the main string T. The specific processing process is as shown in the following content.

[0119] Step (1), set the initial value j = -1, representing the last position currently matched by the substring P.

[0120] Step (2), traverse the main string T with i, where i < n, and n represents the length of the main string T. For each i, execute Step (3) and Step (4) to determine whether T[i] and P[j + 1] match successfully;

[0121] Step (3), let j = next[j] (next[j] represents the last position of the prefix in the longest equal prefix and suffix of the substring P), until j rolls back to the initial value -1, or T[i] == P[j + 1] holds;

[0122] Step (4), if T[i] == P[j + 1] holds, then execute j++. When j reaches the position of m - 1 (m represents the length of the substring P), it indicates that the substring P matches the main string T successfully, and the substring P is a substring of the main string T.

[0123] According to an embodiment of the present disclosure, when the preset matching algorithm is the KMP algorithm, the time complexity of obtaining the target matching result can be o(m + n). Thus, compared with using the naive algorithm as the preset matching algorithm, the time complexity can be further reduced and the matching efficiency can be improved.

[0124] Based on the above log information verification method, the present disclosure also provides a log information verification device. The following will be combined with Figure 5 to describe this device in detail.

[0125] Figure 5 A structural block diagram of a log information verification device according to an embodiment of the present disclosure is schematically shown.

[0126] As Figure 5 shown, the log information verification device 500 of this embodiment includes an acquisition module 510, a similarity processing module 520, a determination module 530, and a matching module 540.

[0127] The acquisition module 510 is configured to acquire initial log information from a server to obtain a log information set. Among them, the initial log information includes structured log information composed of at least one log key-value pair. The log key-value pair includes a log information key representing log attribute information and a log information value corresponding to the log information key.

[0128] The similarity processing module 520 is configured to process the initial log information and the target assertion information by using a preset similarity algorithm to obtain target similarity information. Among them, the target assertion information includes at least one assertion key-value pair.

[0129] The determination module 530 is configured to determine candidate log information from the initial log information in the log information set according to the target similarity information.

[0130] The matching module 540 is configured to verify the candidate log information as target log information according to the target matching result between the candidate log information and the target assertion information. Among them, the target log information represents that the target program corresponding to the target log information in the server is running normally.

[0131] According to an embodiment of the present disclosure, the similarity processing module may include: a construction unit, a comparison unit, and a processing unit.

[0132] The construction unit is configured to construct a target dictionary corresponding to the target bag-of-words model according to the initial log information and the target assertion information in the log information set.

[0133] The comparison unit is configured to perform comparison processing on the initial log information and the target assertion information respectively by using the target dictionary to obtain an initial log vector and a target assertion vector.

[0134] The processing unit is configured to process the initial log vector and the target assertion vector by using a preset similarity algorithm to obtain target similarity information.

[0135] According to an embodiment of the present disclosure, the preset similarity algorithm includes at least one of the following:

[0136] Pearson algorithm, Spearman algorithm, Kendall algorithm, cosine similarity algorithm, Euclidean distance algorithm.

[0137] According to an embodiment of the present disclosure, the matching module may include: a matching unit and a verification unit.

[0138] The matching unit is configured to process candidate log information and target assertion information by using a preset matching algorithm to obtain a target matching result;

[0139] The verification unit is configured to verify the candidate log as a target log when the target matching result indicates that the candidate log information matches the target assertion information;

[0140] Wherein, the preset matching algorithm includes at least one of the following: naive algorithm, KMP algorithm, Rabin-Karp algorithm.

[0141] According to an embodiment of the present disclosure, the log information verification device may further include a sending module.

[0142] The sending module is configured to send bytecode information to the server, wherein the bytecode information is embedded in a program in the server, and the bytecode information is applicable to record initial log information generated during program operation.

[0143] According to an embodiment of the present disclosure, the log attribute information may include at least one of the following: program identifier of the program in the server, call duration of the program in the server, alarm information of the program in the server, class information to which the server program belongs.

[0144] According to an embodiment of the present disclosure, any plurality of modules among the acquisition module 510, the similarity processing module 520, the determination module 530, and the matching module 540 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the acquisition module 510, the similarity processing module 520, the determination module 530, and the matching module 540 may be at least partially implemented as a hardware circuit, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system in a package, an application-specific integrated circuit (ASIC), or may be implemented by any other reasonable means such as hardware or firmware through circuit integration or packaging, or may be implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the acquisition module 510, the similarity processing module 520, the determination module 530, and the matching module 540 may be at least partially implemented as a computer program module, and when the computer program module is run, corresponding functions may be executed.

[0145] Figure 6 Schematically shows a block diagram of an electronic device suitable for implementing the log information verification method according to an embodiment of the present disclosure.

[0146] As Figure 6 shown, the electronic device 600 according to an embodiment of the present disclosure includes a processor 601, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603. The processor 601 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application-specific integrated circuit (ASIC)), etc. The processor 601 may also include on-board memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0147] In the RAM 603, various programs and data required for the operation of the electronic device 600 are stored. The processor 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. The processor 601 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 602 and / or the RAM 603. It should be noted that the programs may also be stored in one or more memories other than the ROM 602 and the RAM 603. The processor 601 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0148] According to an embodiment of the present disclosure, the electronic device 600 may further include an input / output (I / O) interface 605, and the input / output (I / O) interface 605 is also connected to the bus 604. The electronic device 600 may further include one or more of the following components connected to the I / O interface 605: an input portion 606 including a keyboard, a mouse, etc.; an output portion 607 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 608 including a hard disk, etc.; and a communication portion 609 including a network interface card such as a LAN card, a modem, etc. The communication portion 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read from thereon is installed into the storage portion 608 as needed.

[0149] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.

[0150] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the above-described ROM 602 and / or RAM 603 and / or one or more memories other than ROM 602 and RAM 603.

[0151] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiment of the present disclosure.

[0152] When the computer program is executed by the processor 601, it executes the above functions defined in the system / apparatus of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0153] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and is downloaded and installed through the communication part 609, and / or installed from the removable medium 611. The program code included in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0154] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 609, and / or installed from the removable medium 611. When the computer program is executed by the processor 601, it executes the above functions defined in the system of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0155] In accordance with embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0156] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0157] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or / and combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0158] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and these substitutions and modifications should fall within the scope of the present disclosure.

Claims

1. A method for verifying log information, including: Collecting initial log information from a server to obtain a log information set, where the initial log information includes structured log information composed of at least one log key-value pair, and the log key-value pair includes a log information key representing log attribute information and a log information value corresponding to the log information key; Processing the initial log information and target assertion information using a preset similarity algorithm to obtain target similarity information, where the target assertion information includes at least one assertion key-value pair; Determining candidate log information from the initial log information in the log information set according to the target similarity information; and Verifying the candidate log information as target log information according to the target matching result between the candidate log information and the target assertion information, where the target log information represents that the target program corresponding to the target log information in the server runs normally.

2. The log information verification method according to claim 1, wherein, Processing the initial log information and target assertion information using a preset similarity algorithm to obtain target similarity information includes: Constructing a target dictionary corresponding to a target bag-of-words model according to the initial log information in the log information set and the target assertion information; Performing comparison processing on the initial log information and the target assertion information respectively using the target dictionary to obtain an initial log vector and a target assertion vector; Processing the initial log vector and the target assertion vector using the preset similarity algorithm to obtain the target similarity information.

3. The log information verification method according to claim 1 or 2, wherein, The preset similarity algorithm includes at least one of the following: Pearson algorithm, Spearman algorithm, Kendall algorithm, cosine similarity algorithm, Euclidean distance algorithm.

4. The log information verification method according to claim 1, wherein, Verifying the candidate log information as target log information according to the target matching result between the candidate log information and the target assertion information includes: Processing the candidate log information and the target assertion information using a preset matching algorithm to obtain the target matching result; When the target matching result indicates that the candidate log information matches the target assertion information, verifying the candidate log as the target log; where the preset matching algorithm includes at least one of the following: naive algorithm, KMP algorithm, Rabin-Karp algorithm.

5. The log information verification method according to claim 1, wherein, Before collecting the initial log information from the server to obtain the log information set, the log information verification method further includes: Sending bytecode information to the server, where the bytecode information is embedded in the program in the server, and the bytecode information is suitable for recording the initial log information generated during the running of the program.

6. The log information verification method according to claim 1, wherein, The log attribute information includes at least one of the following: The program identifier of the program in the server, the call duration of the program in the server, the alarm information of the program in the server, and the class information called by the server program.

7. A log information verification device, comprising: A collection module for collecting initial log information from a server to obtain a log information set, wherein the initial log information includes structured log information composed of at least one log key-value pair, and the log key-value pair includes a log information key representing log attribute information and a log information value corresponding to the log information key; A similarity processing module for processing the initial log information and target assertion information using a preset similarity algorithm to obtain target similarity information, wherein the target assertion information includes at least one assertion key-value pair; A determination module for determining candidate log information from the initial log information in the log information set according to the target similarity information; and A matching module for verifying the candidate log information as target log information according to the target matching result of the candidate log information and the target assertion information, wherein the target log information represents that the target program corresponding to the target log information in the server is running normally.

8. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having executable instructions stored thereon, which when executed by a processor cause the processor to execute the method according to any one of claims 1 to 6.

10. A computer program product comprising a computer program, which when executed by a processor implements the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Structured logging and instrumentation framework

    US20160041894A1

  • Data mining through property checks based upon string pattern determinations

    US8838559B1