Abnormal log information display method and device, electronic equipment and storage medium
By acquiring business transaction codes and log files, extracting valid log data, and using a log link tracing matrix to locate and categorize abnormal log information, the system solves the problems of high resource pressure and low tracing efficiency in the log collection system, achieving efficient log management and system availability.
Patent Information
- Application Number
- CN202211215597.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-30
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2042-09-30
AI Technical Summary
Log collection systems suffer from problems such as high system resource pressure, redundant log file storage leading to system failures, and low efficiency in tracing issues.
By acquiring business transaction codes and log files, valid log data is extracted, and abnormal log information is located using a log link tracing matrix. The information is then categorized and displayed, invalid log data is removed, redundant storage is reduced, and location efficiency is improved.
It enables accurate tracking and efficient display of abnormal log information, reduces system resource pressure, and improves log processing efficiency and system availability.
Smart Images

Figure CN115510005B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a method for displaying abnormal log information, a device for displaying abnormal log information, an electronic device, and a computer-readable storage medium. Background Technology
[0002] Log files are collections of files used to record system operation events or application runtime. They can be divided into event logs and message logs. They serve to process historical data, track problems, and understand system activities. In actual operation, a system may have a large number of log files. Therefore, a log collection system is introduced to facilitate system developers in collecting and managing a large number of log files.
[0003] However, as the number of applications connected to the log collection system and the number of users logging into the applications increase, the log collection system is prone to storing a large number of invalid log files. On the one hand, the log collection system is prone to failure or malfunction due to excessive system resource pressure. On the other hand, when system operators and system developers collect log data and track problems, they need to browse or process too much data in the log files, resulting in low efficiency in tracking problems. Summary of the Invention
[0004] This invention provides a method, apparatus, electronic device, and computer-readable storage medium for displaying abnormal log information, in order to solve or partially solve the problems of high system resource pressure in log collection systems and low efficiency in problem tracking caused by the large number of log files that relevant technicians need to browse or process when collecting log data and tracking problems.
[0005] This invention discloses a method for displaying abnormal log information, the method comprising:
[0006] Obtain the business transaction code corresponding to each business system and the log file corresponding to the business transaction code, wherein the business transaction code is an identifier used to identify the business system;
[0007] Extract the text content corresponding to the preset log content options from the log file, and use the text content as valid log data. The preset log content options are options generated based on the attribute information of the log file.
[0008] Obtain the log link tracing matrix corresponding to the valid log data, and use the log link tracing matrix to locate the abnormal log information of the valid log data;
[0009] The business flow code is used to classify the abnormal log information, at least one abnormal log information group corresponding to the abnormal log information is obtained, and the abnormal log information group is displayed.
[0010] Optionally, the obtaining of the business flow code corresponding to each business system comprises:
[0011] The parent code, the business identifier, and the terminal identifier of the terminal corresponding to each business system are obtained respectively;
[0012] The parent code, the business identifier, and the terminal identifier are subjected to binary conversion processing to obtain binary data;
[0013] The binary data is subjected to position division to obtain position information of the binary data, and the position information of the binary data is subjected to position deformation to generate deformation shift data;
[0014] The deformation shift data is subjected to induction processing to obtain a business flow code corresponding to the induction processing.
[0015] Optionally, the business system comprises a local cache bit, and the extracting of the text content corresponding to the preset log content option from the log file and the taking of the text content as the effective log data comprise:
[0016] The log data corresponding to the preset log content option is extracted from the log file;
[0017] According to the recording time sequence of the log data, the log data is grouped by using the index identifier of the business flow code to obtain a log data group corresponding to a business system;
[0018] The text content corresponding to a key chain is extracted from the log data group in a targeted manner, and the text content is stored to the local cache bit through global packet capture;
[0019] The text content stored to the local cache bit is taken as the effective log data.
[0020] Optionally, the log file comprises invalid log data, and the extracting of the text content corresponding to the preset log content option from the log file and the taking of the text content as the effective log data further comprise:
[0021] The log data in the log file outside the local cache bit is taken as the invalid log data, and the invalid log data is removed from the business system.
[0022] Optionally, obtaining the log tracing matrix corresponding to the valid log data, and using the log tracing matrix to locate the abnormal log information of the valid log data, includes:
[0023] Identify the business serial number of the valid log data, perform tracking processing on the business serial number, and generate a log link tracing matrix corresponding to the business serial number. The log link tracing matrix is a matrix used to locate the abnormal log information.
[0024] In response to a query operation on the valid log data, the log link tracing matrix is used to locate abnormal log information in the valid log data.
[0025] Optionally, the step of classifying the abnormal log information using the business serial number to obtain at least one abnormal log information group corresponding to the abnormal log information includes:
[0026] Based on preset classification information, the abnormal log information belonging to the same business serial number is classified into at least one abnormal log information group corresponding to the abnormal log information.
[0027] The preset classification information includes at least the error frequency, abnormal time, and business type of the abnormal log information.
[0028] Optionally, displaying the abnormal log information group includes:
[0029] Obtain the abnormal data report corresponding to the abnormal log information;
[0030] The abnormal data report is displayed, which includes the system status of the target business system corresponding to the abnormal log information.
[0031] This invention also discloses a device for displaying abnormal log information, the device comprising:
[0032] The business transaction code acquisition module is used to acquire the business transaction code corresponding to each business system and the log file corresponding to the business transaction code. The business transaction code is an identifier used to identify the business system.
[0033] The effective log data extraction module is used to extract text content corresponding to preset log content options from the log file, and use the text content as effective log data. The preset log content options are options generated based on the attribute information of the log file.
[0034] An abnormal log information location module is used to obtain the log link tracing matrix corresponding to the valid log data, and use the log link tracing matrix to locate the abnormal log information of the valid log data.
[0035] The abnormal log information display module is used to classify the abnormal log information using the business serial number, obtain at least one abnormal log information group corresponding to the abnormal log information, and display the abnormal log information group.
[0036] Optionally, the business serial number acquisition module is specifically used for:
[0037] Obtain the parent code, business identifier, and terminal identifier of the terminal corresponding to each business system;
[0038] The parent code, the service identifier, and the terminal identifier are converted into binary data.
[0039] The binary data is divided into positions to obtain the position information of the binary data. The position information of the binary data is then deformed to generate deformed shift data.
[0040] The deformed and shifted data is processed to obtain the business serial number corresponding to the processing.
[0041] Optionally, the business system includes a local cache, and the effective log data extraction module is specifically used for:
[0042] Extract log data corresponding to the preset log content options from the log file;
[0043] Based on the recording sequence of the log data, the log data is grouped using the index identifier of the business serial number to obtain log data groups corresponding to the business system;
[0044] The text content corresponding to the key chain is extracted from the log data group, and the text content is stored in the local cache location by global packet capture;
[0045] The text content stored in the local cache is used as the valid log data.
[0046] Optionally, the log file includes invalid log data, and the apparatus further includes:
[0047] The invalid log data removal module is used to identify log data in log files outside the local cache as invalid log data and remove the invalid log data from the business system.
[0048] Optionally, the anomaly log information location module is specifically used for:
[0049] Identify the business serial number of the valid log data, perform tracking processing on the business serial number, and generate a log link tracing matrix corresponding to the business serial number. The log link tracing matrix is a matrix used to locate the abnormal log information.
[0050] In response to a query operation on the valid log data, the log link tracing matrix is used to locate abnormal log information in the valid log data.
[0051] Optionally, the exception log information display module is specifically used for:
[0052] Based on preset classification information, the abnormal log information belonging to the same business serial number is classified into at least one abnormal log information group corresponding to the abnormal log information.
[0053] The preset classification information includes at least the error frequency, abnormal time, and business type of the abnormal log information.
[0054] Optionally, the exception log information display module is specifically used for:
[0055] Obtain the abnormal data report corresponding to the abnormal log information;
[0056] The abnormal data report is displayed, which includes the system status of the target business system corresponding to the abnormal log information.
[0057] This invention also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0058] The memory is used to store computer programs;
[0059] When the processor executes a program stored in the memory, it implements the method described in the embodiments of the present invention.
[0060] This invention also discloses a computer-readable storage medium storing instructions that, when executed by one or more processors, cause the processors to perform the methods described in this invention.
[0061] The embodiments of the present invention have the following advantages:
[0062] In this embodiment of the invention, business transaction codes corresponding to each business system and log files corresponding to the business transaction codes are obtained. Text content corresponding to preset log content options is extracted from the log files and used as valid log data. A log link tracing matrix corresponding to the valid log data is obtained. The log link tracing matrix is used to locate abnormal log information in the valid log data. The abnormal log information is classified using business transaction codes to obtain at least one abnormal log information group corresponding to the abnormal log information. The abnormal log information group is then displayed. By obtaining business transaction codes for each business system, the accuracy of tracking abnormal business systems is ensured. The preset log content options can selectively extract the valid log data required by the user, reducing redundant storage of invalid log data and reducing the amount of log data processed. At the same time, the abnormal log information is quickly located based on the log link tracing matrix, improving the efficiency of locating abnormal log information. The logs are grouped and the abnormal log information groups are displayed in units of "groups," which is beneficial for users to obtain information intuitively. Attached Figure Description
[0063] Figure 1 This is a schematic diagram of the overall framework of the log management system provided in this embodiment of the invention;
[0064] Figure 2 This is a flowchart illustrating the steps of a method for displaying abnormal log information provided in an embodiment of the present invention;
[0065] Figure 3 This is a flowchart of the steps for generating a business serial number provided in an embodiment of the present invention;
[0066] Figure 4 This is a flowchart of the steps for cleaning up invalid log data provided in this embodiment of the invention;
[0067] Figure 5 This is a schematic diagram illustrating the data transmission between the abnormal data report, log tracking system, and display platform provided in this embodiment of the invention;
[0068] Figure 6 This is a schematic diagram illustrating the location of abnormal log information through a log management system provided in an embodiment of the present invention;
[0069] Figure 7 This is a structural block diagram of an abnormal log information display device provided in an embodiment of the present invention;
[0070] Figure 8 This is a structural block diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0071] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0072] With the updates and iterations of various open-source projects and frameworks, the technology of log collection systems is constantly being upgraded and improved. System operators and developers can quickly locate the location of abnormal situations through log collection systems, ensuring the high availability of the system. However, current log collection systems store a large amount of log information, resulting in high system redundancy and high system resource pressure, making it impossible for relevant technical personnel to quickly query or filter abnormal logs from a large amount of log information.
[0073] One of the core inventive points of this invention is to obtain the business transaction codes corresponding to each business system and the log files corresponding to the business transaction codes, extract the text content corresponding to the preset log content options from the log files, use the text content as valid log data, obtain the log link tracing matrix corresponding to the valid log data, use the log link tracing matrix to locate the abnormal log information of the valid log data, classify the abnormal log information using the business transaction codes, obtain at least one abnormal log information group corresponding to the abnormal log information, and display the abnormal log information group. By obtaining the business transaction codes for each business system, the accuracy of tracking abnormal business systems is ensured. Using preset log content options allows for targeted extraction of the valid log data required by the user, reducing redundant storage of invalid log data and reducing the amount of log data processed. At the same time, the abnormal log information is quickly located based on the log link tracing matrix, improving the efficiency of locating abnormal log information. Furthermore, the logs are grouped, and the abnormal log information groups are displayed in units of "groups," which is beneficial for users to intuitively obtain information.
[0074] Reference Figure 1This diagram illustrates the overall framework of the log management system provided in this embodiment of the invention. The log management system includes a business system, a serial number generation system, a log collection system, a log filtering system, and a log tracking matrix system. The serial number system generates unified serial numbers for different business systems according to preset rules, ensuring the uniqueness and queryability of the serial numbers. It includes at least a rule center for storing rules, a serial number generation module for generating business serial numbers, and a serial number management module for managing different business serial numbers. The business system obtains the business serial numbers generated by the serial number system and transmits log information to the log collection system. The log collection system collects logs, participates in the log filtering system to process logs, and performs preliminary compliance processing, removing logs without business serial numbers. The log filtering system filters logs sent by the log collection system based on filtering options set by relevant technical personnel, identifying invalid and valid log content. It can remove invalid logs and retain valid ones. It can also extract unified rule logs based on preset rules and issue warnings for abnormal logs using pre-defined alert rules. The system includes a user center, rule processing module, storage management module, and alert center. The log tracing matrix system generates a tracing matrix based on the unified serial number sent by the log collection system and sends the matrix back to the system. This matrix categorizes and displays abnormal log information using the unified serial number. It generates a log chain tracing matrix from the data source to the problem's origin, and generates abnormal data reports based on the tracing matrix, which are then displayed on a platform. Thus, the log management system obtains a unique tracing stream through serial number generation, data exchange, and matrix generation with other systems. This stream connects all problem logs, allowing for cross-domain log tracing to pinpoint the source of the problem and resolve corresponding issues in the business system.
[0075] Reference Figure 2 The diagram illustrates a flowchart of a method for displaying abnormal log information according to an embodiment of the present invention, which may specifically include the following steps:
[0076] Step 201: Obtain the business transaction code corresponding to each business system and the log file corresponding to the business transaction code. The business transaction code is an identifier used to identify the business system.
[0077] In this embodiment of the invention, the business system can be a system that provides various functions to users. For example, the business system can be an order system, a logistics system, a user system, and other different types of systems. The serial number can be a commonly used code on the production line. Generally, operating system machinery comes with a serial number to distinguish and limit the output quantity of products, identify and inspect products. In this invention, the business serial number can be an identifier used to identify the business system. Each business system corresponds to the same business serial number. For example, the order system corresponds to business serial number A, and the logistics system corresponds to business serial number B. The log file can be a record file or collection of files used to record system operation events. It is divided into event logs and message logs, and it has the functions of processing historical data, diagnosing and tracking problems, and understanding system activities.
[0078] In its implementation, the serial number system can obtain basic parameters such as the parent code, business identifier, and terminal identifier of each business system. The parent code, business identifier, and terminal identifier are used as unique code input conditions. The parent code, business identifier, and terminal identifier are converted into binary data. Then, the binary data is divided into positions to obtain the position information of the binary data. The position information of the binary data is deformed to generate deformed shift data. The deformed shift data is summarized to obtain the business serial number corresponding to the summarized processing.
[0079] In one example of the present invention, the service identifier can be the service code ID of the service system, and the terminal identifier can be the machine ID, as shown below. Figure 3 The flowchart illustrating the steps for generating a business serial number according to an embodiment of the present invention is shown. After obtaining information such as the parent code, business code ID, and machine ID, the serial number system can call the unified serial number production rules set in the rule center according to user needs. Then, the unified serial number production rules are used to summarize the information such as the parent code, business code ID, and machine ID to obtain summarized information. The summarized information is then encapsulated, and the snowflake algorithm is used to perform uniqueness processing on the summarized information to produce a business serial number for the business system.
[0080] Specifically, the transformation and shifting of data is mainly implemented through the Snowflake algorithm. First, the original data (parent code, business code ID, and machine ID) is input into the Snowflake algorithm. Then, the original data is processed into binary data, converting the data type of the original data into binary data. Next, the position is distinguished by the binary data, and the location is divided. By dividing the overall binary data into positional content and specifying positional information, the positional information is prepared for subsequent positional transformation. The positional transformation of the binary data includes the following sub-steps:
[0081] S21, begin transformation one, shift the timestamp to the left to free up relevant data bits;
[0082] S22, start displacement two, calculate the data machine center value;
[0083] S23, begin displacement three, calculate generator ID value;
[0084] S24, Variation 4: Calculate and generate an auto-incrementing value ID;
[0085] S25, which combines the above-mentioned deformation and shift data values;
[0086] S26, Verify the value, generate and return the ID value.
[0087] Finally, the ID values are summarized to obtain the business serial number, and the business serial number is returned to the business system to generate a business serial number specific to the business system.
[0088] Step 202: Extract the text content corresponding to the preset log content options from the log file, and use the text content as valid log data. The preset log content options are options generated based on the attribute information of the log file.
[0089] In this embodiment of the invention, the preset log content options can be options generated based on the attribute information of the log file, such as the specific content of the log file, the recording or storage time of the log file, etc. The preset log content options can include problem keywords, specified dates, specified error levels, etc. The invention does not limit these options. Valid log data can be logs that match the preset log content options. For example, if the error levels include error level I, error level II, and error level III, and the preset log content option specifies error level II, then the text content corresponding to error level II will be used as valid log data. If the preset log content option is the keyword "order error", then the text content corresponding to "order error" will be used as valid log data. If the preset log content option is the specified date: September 2022, then the text content recorded by the business system in "September 2022" will be used as valid log data. In one embodiment of the present invention, the business system includes a local cache. The log filtering system can first extract log data corresponding to preset log content options from the log file, and then group the log data according to the recording time sequence of the log data using the index identifier of the business serial number to obtain several log data groups corresponding to the business system. The text content corresponding to the key chain can be extracted from the several log data groups through the index identifier, and the text content is stored in the local cache by performing a global packet capture operation on the file content. The text content stored in the local cache is used as valid log data.
[0090] The local cache can be used to store the grouped log data. The Critical Chain is a project management method based on the Theory of Constraints, which uses the log data stored in the local cache as valid log data and the log data outside the local cache as invalid log data.
[0091] In another embodiment of the present invention, the log file includes invalid log data. Log data in the log file outside the local cache bit within the current time period is regarded as invalid log data, and invalid log data is removed from the business system. By removing invalid log data, the function of cleaning up invalid and redundant data is realized, which greatly reduces the system pressure of the log management system and ensures high space utilization.
[0092] As an example, refer to Figure 4 The flowchart illustrating the steps for cleaning up invalid log data provided in this embodiment of the invention is shown. The log collection system processes log data according to the time dimension. First, it extracts the set rule conditions, such as keywords and time periods, and performs grouping and segmentation operations on the serial codes corresponding to the log data. After the grouping and segmentation operations, it extracts the valid log data corresponding to the key chains from each log group. Through global packet capture, the valid log data is stored in the local cache. Invalid log data outside the local cache within the current time period is cleaned up. By cleaning up invalid and redundant log data, the resource pressure on the log management system is reduced and the processing efficiency is improved.
[0093] Step 203: Obtain the log link tracing matrix corresponding to the valid log data, and use the log link tracing matrix to locate the abnormal log information of the valid log data;
[0094] In this embodiment of the invention, the log link tracing matrix is a matrix used to track abnormal log information. By using the log link tracing matrix corresponding to valid log data, abnormal log information of valid log data can be quickly located, thereby improving the processing efficiency of the log management system.
[0095] Optionally, the log tracing matrix system can obtain the business transaction code corresponding to the valid log data, then identify and judge the business transaction code to trace the data flow link of the valid log data, and generate a log link tracing matrix based on the data flow link. The log link tracing matrix has corresponding data processing rules, which makes it easy for relevant technical personnel to obtain the complete data flow for the valid log data based on the log link tracing matrix. When relevant technical personnel need to trace the problem of the log, they can quickly locate the source of the problem.
[0096] In practice, after the log tracing matrix system generates a log link tracing matrix for valid log data, the log management system can respond to user queries for valid log data and use the log link tracing matrix to locate abnormal log information from the valid log data.
[0097] Step 204: Use the business serial number to classify the abnormal log information to obtain at least one abnormal log information group corresponding to the abnormal log information, and display the abnormal log information group.
[0098] In this embodiment of the invention, the log management system can use business serial numbers to classify abnormal log information, obtain at least one abnormal log information group corresponding to the abnormal log information, and display the abnormal log information group. In this way, by grouping the abnormal log information, the system can perform overall and dynamic statistical analysis on the logs that have problems.
[0099] Optionally, abnormal log information belonging to the same business serial number can be categorized according to preset classification information to obtain at least one abnormal log information group corresponding to the abnormal log information. The preset classification information can be the classification information set by relevant technical personnel according to actual needs, which at least includes the error frequency, abnormal time and business type of the abnormal log information.
[0100] Specifically, if the preset classification information is error frequency, the abnormal log information can be classified according to error frequency and business serial number, resulting in abnormal log information groups based on "error frequency". For example, abnormal log information groups with error frequencies of 5, 10, and 20 can be obtained, and abnormal log information group ① corresponding to error frequency of 5, abnormal log information group ② corresponding to error frequency of 10, and abnormal log information group ③ corresponding to error frequency of 20 can be displayed. If the preset classification information is business type, the abnormal log information can be classified according to business type and business serial number, resulting in abnormal log information groups based on "business type". For example, abnormal log information group ④ corresponding to order business and abnormal log information group ⑤ corresponding to order cancellation business can be obtained, and abnormal log information groups ④ and ⑤ can be displayed. If the preset classification information is abnormal time, the abnormal log information can be classified according to abnormal time and business serial number, resulting in abnormal log information groups based on "abnormal time point or abnormal time period". For example, abnormal log information group ⑥ with an abnormal time within 2 days can be displayed.
[0101] As an example, refer to Figure 5This diagram illustrates the data transmission between the abnormal data report, log tracking system, and display platform provided in an embodiment of the present invention. The log tracking system generates a log chain tracking matrix based on the business serial number, and forms a data processing logic layer and a report display layer around the unique business serial number. The main sub-steps include:
[0102] S41, identify and judge the serial number, track and process the serial number to form a complete log link tracing matrix, so as to quickly locate the source of the anomaly;
[0103] S42, the data synchronization logic layer forms its own data processing rules based on the matrix content, and processes and displays the data externally through a filtering rule generator.
[0104] S43. After improving the data processing of the above two layers and sorting out the data, customize the responsibility items in the report display layer, and filter out the report information that meets the user's needs based on the responsibility items.
[0105] Among them, the responsibility item refers to the query content entered by relevant technical personnel in the log management system according to actual needs. Based on the responsibility item selected by the user, classification information can be obtained, and abnormal data reports can be displayed based on classification information, so as to facilitate relevant technical personnel to further understand the system status of the business system.
[0106] In one example of the present invention, an abnormal data report corresponding to the abnormal log information is obtained and displayed. The abnormal data report includes the system status of the target business system corresponding to the abnormal log information. The system status can include the normal working status and abnormal working status of the business system. The abnormal log information and the data flow corresponding to the abnormal log information are displayed intuitively by using the abnormal data report, thereby improving the accuracy of system problem location, determining the cause of the problem across systems, breaking down communication barriers, and reducing the disk occupation time of system logs.
[0107] As an example, refer to Figure 6This illustration shows a schematic diagram of locating abnormal log information through a log management system provided by an embodiment of the present invention. If operators discover faults or anomalies in the business system, they can report the problem to the developers or have the developers discover the problem themselves. Maintenance personnel can maintain the entire log management system to ensure normal operation between various systems. Before developers enable the log collection system, a unified serial number system can generate a unique serial number for each business system and send it to the corresponding business system. Developers can pre-set rules and alert methods on the log monitoring and summarization platform. When it is necessary to find problematic logs in a business system, the log collection system can collect the log information and business serial number of the business system, and then send the log information and business serial number to the log monitoring and summarization platform. After receiving the log information and business serial number, the log monitoring and summarization platform can process the log information. Developers can then trigger the generation of a log chain tracking matrix based on the log monitoring and summarization platform to quickly locate the corresponding abnormal log information and obtain trajectory data and reports for the problematic logs, which are then displayed on a display platform.
[0108] It should be noted that the embodiments of the present invention include, but are not limited to, the examples described above. It is understood that, under the guidance of the ideas in the embodiments of the present invention, those skilled in the art can make settings according to actual circumstances, and the present invention does not limit such settings.
[0109] In this embodiment of the invention, business transaction codes corresponding to each business system and log files corresponding to the business transaction codes are obtained. Text content corresponding to preset log content options is extracted from the log files and used as valid log data. A log link tracing matrix corresponding to the valid log data is obtained. The log link tracing matrix is used to locate abnormal log information in the valid log data. The abnormal log information is classified using business transaction codes to obtain at least one abnormal log information group corresponding to the abnormal log information. The abnormal log information group is then displayed. By obtaining business transaction codes for each business system, the accuracy of tracking abnormal business systems is ensured. The preset log content options can selectively extract the valid log data required by the user, reducing redundant storage of invalid log data and reducing the amount of log data processed. At the same time, the abnormal log information is quickly located based on the log link tracing matrix, improving the efficiency of locating abnormal log information. The logs are grouped and the abnormal log information groups are displayed in units of "groups," which is beneficial for users to obtain information intuitively.
[0110] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0111] Reference Figure 7 The diagram illustrates a structural block diagram of an abnormal log information display device provided in an embodiment of the present invention, which may specifically include the following modules:
[0112] The business transaction code acquisition module 701 is used to acquire the business transaction code corresponding to each business system and the log file corresponding to the business transaction code, wherein the business transaction code is an identifier used to identify the business system.
[0113] The valid log data extraction module 702 is used to extract text content corresponding to preset log content options from the log file, and use the text content as valid log data. The preset log content options are options generated based on the attribute information of the log file.
[0114] The abnormal log information location module 703 is used to obtain the log link tracing matrix corresponding to the valid log data, and use the log link tracing matrix to locate the abnormal log information of the valid log data.
[0115] The abnormal log information display module 704 is used to classify the abnormal log information using the business serial number, obtain at least one abnormal log information group corresponding to the abnormal log information, and display the abnormal log information group.
[0116] In one optional embodiment, the business serial number acquisition module 701 is specifically used for:
[0117] Obtain the parent code, business identifier, and terminal identifier of the terminal corresponding to each business system;
[0118] The parent code, the service identifier, and the terminal identifier are converted into binary data.
[0119] The binary data is divided into positions to obtain the position information of the binary data. The position information of the binary data is then deformed to generate deformed shift data.
[0120] The deformed and shifted data is processed to obtain the business serial number corresponding to the processing.
[0121] In one optional embodiment, the business system includes a local cache, and the effective log data extraction module 702 is specifically used for:
[0122] Extract log data corresponding to the preset log content options from the log file;
[0123] Based on the recording sequence of the log data, the log data is grouped using the index identifier of the business serial number to obtain log data groups corresponding to the business system;
[0124] The text content corresponding to the key chain is extracted from the log data group, and the text content is stored in the local cache location by global packet capture;
[0125] The text content stored in the local cache is used as the valid log data.
[0126] In one alternative embodiment, the log file includes invalid log data, and the apparatus further includes:
[0127] The invalid log data removal module is used to identify log data in log files outside the local cache as invalid log data and remove the invalid log data from the business system.
[0128] In one optional embodiment, the anomaly log information location module 703 is specifically used for:
[0129] Identify the business serial number of the valid log data, perform tracking processing on the business serial number, and generate a log link tracing matrix corresponding to the business serial number. The log link tracing matrix is a matrix used to locate the abnormal log information.
[0130] In response to a query operation on the valid log data, the log link tracing matrix is used to locate abnormal log information in the valid log data.
[0131] In one optional embodiment, the exception log information display module 704 is specifically used for:
[0132] Based on preset classification information, the abnormal log information belonging to the same business serial number is classified into at least one abnormal log information group corresponding to the abnormal log information.
[0133] The preset classification information includes at least the error frequency, abnormal time, and business type of the abnormal log information.
[0134] In one optional embodiment, the exception log information display module 704 is specifically used for:
[0135] Obtain the abnormal data report corresponding to the abnormal log information;
[0136] The abnormal data report is displayed, which includes the system status of the target business system corresponding to the abnormal log information.
[0137] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0138] In addition, this invention also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described method for displaying abnormal log information and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0139] This invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described method for displaying abnormal log information and achieves the same technical effect. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0140] Figure 8 A schematic diagram of the structure of an electronic device for implementing various embodiments of the present invention.
[0141] The electronic device 800 includes, but is not limited to, components such as: a radio frequency unit 801, a network module 802, an audio output unit 803, an input unit 804, a sensor 805, a display unit 806, a user input unit 807, an interface unit 808, a memory 809, a processor 810, and a power supply 811. Those skilled in the art will understand that... Figure 8 The electronic device structures shown are not intended to limit the electronic device. An electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements. In embodiments of the present invention, the electronic device includes, but is not limited to, mobile phones, tablet computers, laptops, PDAs, in-vehicle terminals, wearable devices, and pedometers.
[0142] It should be understood that, in this embodiment of the invention, the radio frequency unit 801 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink data from the base station and processes it with the processor 810; additionally, it transmits uplink data to the base station. Typically, the radio frequency unit 801 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, etc. Furthermore, the radio frequency unit 801 can also communicate with networks and other devices through a wireless communication system.
[0143] Electronic devices provide users with wireless broadband internet access through network module 802, such as helping users send and receive emails, browse web pages, and access streaming media.
[0144] The audio output unit 803 can convert audio data received by the radio frequency unit 801 or the network module 802 or stored in the memory 809 into audio signals and output them as sound. Furthermore, the audio output unit 803 can also provide audio output related to specific functions performed by the electronic device 800 (e.g., call signal reception sound, message reception sound, etc.). The audio output unit 803 includes a speaker, a buzzer, and a receiver, etc.
[0145] Input unit 804 is used to receive audio or video signals. Input unit 804 may include a graphics processing unit (GPU) 8041 and a microphone 8042. The GPU 8041 processes image data of still images or videos acquired by an image capture device (such as a camera) in video capture mode or image capture mode. The processed image frames can be displayed on display unit 806. The image frames processed by GPU 8041 can be stored in memory 809 (or other storage medium) or transmitted via radio frequency unit 801 or network module 802. Microphone 8042 can receive sound and process such sound into audio data. The processed audio data can be converted into a format that can be transmitted to a mobile communication base station via radio frequency unit 801 in telephone call mode.
[0146] The electronic device 800 also includes at least one sensor 805, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor includes an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of the display panel 8061 according to the ambient light level, and the proximity sensor can turn off the display panel 8061 and / or backlight when the electronic device 800 is moved to the ear. As a type of motion sensor, an accelerometer sensor can detect the magnitude of acceleration in various directions (generally three axes). When stationary, it can detect the magnitude and direction of gravity and can be used to identify the posture of the electronic device (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc. The sensor 805 may also include a fingerprint sensor, pressure sensor, iris sensor, molecular sensor, gyroscope, barometer, hygrometer, thermometer, infrared sensor, etc., which will not be described in detail here.
[0147] The display unit 806 is used to display information input by the user or information provided to the user. The display unit 806 may include a display panel 8061, which may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.
[0148] User input unit 807 can be used to receive input numerical or character information, and to generate key signal inputs related to user settings and function control of electronic devices. Specifically, user input unit 807 includes a touch panel 8071 and other input devices 8072. Touch panel 8071, also known as a touch screen, can collect touch operations performed by the user on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near touch panel 8071). Touch panel 8071 may include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch position and the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives touch information from the touch detection device, converts it into touch point coordinates, and sends it to the processor 810, which receives and executes commands from the processor 810. In addition, touch panel 8071 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. Besides touch panel 8071, user input unit 807 may also include other input devices 8072. Specifically, other input devices 8072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, joysticks, etc., which will not be described in detail here.
[0149] Furthermore, the touch panel 8071 can cover the display panel 8061. When the touch panel 8071 detects a touch operation on or near it, it transmits the information to the processor 810 to determine the type of touch event. Subsequently, the processor 810 provides corresponding visual output on the display panel 8061 based on the type of touch event. Although in Figure 8 In this embodiment, the touch panel 8071 and the display panel 8061 are two independent components to realize the input and output functions of the electronic device. However, in some embodiments, the touch panel 8071 and the display panel 8061 can be integrated to realize the input and output functions of the electronic device. The specific implementation is not limited here.
[0150] Interface unit 808 serves as an interface for connecting external devices to electronic device 800. For example, external devices may include a wired or wireless headphone port, an external power supply (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting a device with an identification module, an audio input / output (I / O) port, a video I / O port, a headphone port, and so on. Interface unit 808 can be used to receive input from external devices (e.g., data, power, etc.) and transmit the received input to one or more components within electronic device 800, or it can be used to transmit data between electronic device 800 and external devices.
[0151] The memory 809 can be used to store software programs and various data. The memory 809 may primarily include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function (such as sound playback, image playback, etc.), etc.; the data storage area may store data created based on the use of the mobile phone (such as audio data, phonebook, etc.). Furthermore, the memory 809 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0152] The processor 810 is the control center of the electronic device. It connects various parts of the electronic device via various interfaces and lines. By running or executing software programs and / or modules stored in the memory 809, and by calling data stored in the memory 809, it performs various functions and processes data, thereby providing overall monitoring of the electronic device. The processor 810 may include one or more processing units; preferably, the processor 810 may integrate an application processor and a modem processor. The application processor mainly handles the operating system, user interface, and applications, while the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 810.
[0153] The electronic device 800 may also include a power supply 811 (such as a battery) for supplying power to various components. Preferably, the power supply 811 is logically connected to the processor 810 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system.
[0154] In addition, the electronic device 800 includes some functional modules not shown, which will not be described in detail here.
[0155] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0156] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0157] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of the present invention.
[0158] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0159] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0160] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0161] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0162] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0163] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0164] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for displaying abnormal log information, characterized in that, The method includes: Obtain the business transaction code corresponding to each business system and the log file corresponding to the business transaction code, wherein the business transaction code is an identifier used to identify the business system; Extract the text content corresponding to the preset log content options from the log file, and use the text content as valid log data. The preset log content options are options generated based on the attribute information of the log file. Obtain the log link tracing matrix corresponding to the valid log data, and use the log link tracing matrix to locate the abnormal log information of the valid log data; The abnormal log information is classified using the business serial number to obtain at least one abnormal log information group corresponding to the abnormal log information, and the abnormal log information group is displayed.
2. The method according to claim 1, characterized in that, The step of obtaining the business transaction code corresponding to each business system includes: Obtain the parent code, business identifier, and terminal identifier of the terminal corresponding to each business system; The parent code, the service identifier, and the terminal identifier are converted into binary data. The binary data is divided into positions to obtain the position information of the binary data, and the position information of the binary data is deformed to generate deformed shift data; The deformed and shifted data is processed to obtain the business serial number corresponding to the processing.
3. The method according to claim 1, characterized in that, The business system includes a local cache, the business serial number includes an index identifier, and the step of extracting text content corresponding to preset log content options from the log file and using the text content as valid log data includes: Extract log data corresponding to the preset log content options from the log file; Based on the recording sequence of the log data, the log data is grouped using the index identifier of the business serial number to obtain log data groups corresponding to the business system; The text content corresponding to the key chain is extracted from the log data group, and the text content is stored in the local cache location by global packet capture; The text content stored in the local cache is used as the valid log data.
4. The method according to claim 3, characterized in that, The log file includes invalid log data. Extracting text content corresponding to preset log content options from the log file and using that text content as valid log data further includes: Log data in log files outside the local cache will be treated as invalid log data and removed from the business system.
5. The method according to claim 2, characterized in that, The step of obtaining the log tracing matrix corresponding to the valid log data and using the log tracing matrix to locate the abnormal log information of the valid log data includes: Identify the business serial number of the valid log data, perform tracking processing on the business serial number, and generate a log link tracing matrix corresponding to the business serial number. The log link tracing matrix is a matrix used to locate the abnormal log information. In response to a query operation on the valid log data, the log link tracing matrix is used to locate abnormal log information in the valid log data.
6. The method according to claim 1, characterized in that, The step of classifying the abnormal log information using the business serial number to obtain at least one abnormal log information group corresponding to the abnormal log information includes: Based on preset classification information, the abnormal log information belonging to the same business serial number is classified into at least one abnormal log information group corresponding to the abnormal log information. The preset classification information includes at least the error frequency, abnormal time, and business type of the abnormal log information.
7. The method according to claim 1, characterized in that, The display of the abnormal log information group includes: Obtain the abnormal data report corresponding to the abnormal log information; The abnormal data report is displayed, which includes the system status of the target business system corresponding to the abnormal log information.
8. A device for displaying abnormal log information, characterized in that, The device includes: The business transaction code acquisition module is used to acquire the business transaction code corresponding to each business system and the log file corresponding to the business transaction code. The business transaction code is an identifier used to identify the business system. The effective log data extraction module is used to extract text content corresponding to preset log content options from the log file, and use the text content as effective log data. The preset log content options are options generated based on the attribute information of the log file. An abnormal log information location module is used to obtain the log link tracing matrix corresponding to the valid log data, and use the log link tracing matrix to locate the abnormal log information of the valid log data. The abnormal log information display module is used to classify the abnormal log information using the business serial number, obtain at least one abnormal log information group corresponding to the abnormal log information, and display the abnormal log information group.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store computer programs; When the processor executes a program stored in the memory, it implements the method as described in any one of claims 1-7.
10. A computer-readable storage medium having instructions stored thereon that, when executed by one or more processors, cause the processors to perform the method as described in any one of claims 1-7.
Citation Information
Patent Citations
Log acquisition device and log acquisition method
CN101969386A
Business system monitoring method, system and apparatus
CN107766208A