Log analysis method, apparatus, device, and storage medium

By periodically or through event-triggered log data acquisition from the target server model, and by obtaining analysis dimensions and performing log analysis, the problem of low log analysis efficiency in existing technologies is solved, achieving efficient log analysis and multi-dimensional data understanding.

CN116185780BActive Publication Date: 2026-05-19INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INSPUR SUZHOU INTELLIGENT TECH CO LTD
Filing Date
2023-03-10
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In the prior art, log analysis methods, devices, equipment, and control units are applied in specific technical fields, usually in technical fields where log analysis efficiency needs to be improved, especially in the field of computer technology, particularly log analysis methods, devices, equipment, and storage media.

Method used

This paper provides a log analysis method that obtains log data from a target server model through periodic or event-triggered acquisition, acquires analysis dimensions, extracts test log data from the log data, performs log analysis based on the analysis dimensions, and outputs the results. It supports log management for multiple analysis dimensions and different server models.

Benefits of technology

It improves log analysis efficiency, making it easier to understand the overall data situation of product production, supports log management of multiple analysis dimensions and different server models, and achieves comprehensive and rapid data mastery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116185780B_ABST
    Figure CN116185780B_ABST
Patent Text Reader

Abstract

The application relates to a log analysis method, device, equipment and storage medium, the method comprising: periodically or triggeredly in response to an event, acquiring log data of a server of a target model; acquiring an analysis dimension of the server of the target model, wherein the analysis dimension comprises one or more of an overall pass rate, a test item pass rate, an overall abnormality rate and a specific abnormality rate; according to the analysis dimension of the server of the target model, acquiring test log data corresponding to the analysis dimension from the log data; and according to the test log data, analyzing the log data of the server of the target model and outputting a log analysis result. The application can improve the efficiency of log analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a log analysis method, apparatus, device, and storage medium. Background Technology

[0002] Currently, diagnostic testing is performed during server production, generating log data. Analyzing this log data helps identify areas for improvement in the production process. However, because different server models are involved, and the tests for servers vary, the log analysis process generates a large volume of data, resulting in a massive amount of log data.

[0003] In current technologies, log data analysis is typically performed on a single test item on a single server. This means that multiple manual log analyses are required to gain a comprehensive understanding of the overall data situation of product production, and the efficiency of log analysis needs to be improved. Summary of the Invention

[0004] Based on this, this application provides a log analysis method, apparatus, device, and storage medium to solve the problems existing in the prior art.

[0005] Firstly, a log analysis method is provided, which includes:

[0006] Periodically or in response to event triggers, retrieve log data from the target model of the server;

[0007] Obtain the analysis dimensions of the target model server, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate;

[0008] Based on the analysis dimensions of the target server model, obtain the test log data corresponding to the analysis dimensions from the log data;

[0009] Analyze the log data of the target server model based on the test log data, and output the log analysis results.

[0010] According to one achievable method in an embodiment of this application, the target model server includes: one server or multiple servers;

[0011] The periodic or event-triggered acquisition of log data from the target model server includes:

[0012] Receive periodically sent log analysis instructions or log analysis instructions triggered by events, wherein the log analysis instructions contain information about the target model of the server corresponding to the log analysis instructions;

[0013] According to the log analysis instructions, obtain the log data corresponding to each target server model.

[0014] According to one achievable method in an embodiment of this application, the step of analyzing the log data of the target model server based on the test log data and outputting the log analysis results includes:

[0015] The analysis dimensions of the log data of the target model server are analyzed based on the test log data, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate.

[0016] Output log analysis results, which include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate.

[0017] According to one possible implementation method in an embodiment of this application, the method further includes:

[0018] Obtain a pre-set log analysis threshold for the log analysis results, wherein the log analysis threshold includes one or more of the following: overall pass rate threshold, test item pass rate threshold, overall anomaly rate threshold, and specific anomaly rate threshold;

[0019] If the log analysis results exceed the log analysis threshold, an alarm email will be sent to a preset contact.

[0020] According to one achievable method in an embodiment of this application, the analysis dimensions for obtaining the target model of the server include:

[0021] Obtain the analysis dimensions corresponding to each target server model;

[0022] The step of retrieving test log data corresponding to the analysis dimension from the log data based on the analysis dimension of the target server model includes:

[0023] Based on the analysis dimension corresponding to each target server model, test log data corresponding to the analysis dimension of each target server model is obtained from the log data of each target server model.

[0024] The step of analyzing the log data of the target server model based on the test log data and outputting the log analysis results includes:

[0025] Based on the test log data corresponding to each target server model, analyze the log data of each target server model and output the log analysis results for each target server model.

[0026] According to one achievable method in an embodiment of this application, the step of sending an alert email to a preset contact if the log analysis result exceeds the log analysis threshold includes:

[0027] If the overall pass rate result exceeds the overall pass rate threshold, an alarm email is sent to the preset first contact person;

[0028] If the pass rate of the test item exceeds the pass rate threshold of the test item, an alarm email will be sent to a preset second contact person;

[0029] If the overall anomaly rate exceeds the overall anomaly rate threshold, an alarm email will be sent to a preset third contact.

[0030] If the specific anomaly rate result exceeds the specific anomaly rate threshold, an alarm email is sent to a preset fourth contact.

[0031] According to one achievable method in an embodiment of this application, the step of analyzing the log data of the target model server based on the test log data and outputting the log analysis results includes:

[0032] Analyze the log data of the target server model based on the test log data, and generate log analysis results;

[0033] The log analysis results are sent to the server backend of the target model.

[0034] Secondly, a log analysis apparatus is provided, the apparatus comprising:

[0035] First acquisition module: used to periodically or in response to event triggers to acquire log data of the target model of server;

[0036] The second acquisition module is used to acquire the analysis dimensions of the target model server, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate.

[0037] Data selection module: used to obtain test log data corresponding to the analysis dimension of the target server model from the log data;

[0038] Data analysis module: used to analyze the log data of the target model server based on the test log data, and output the log analysis results.

[0039] Thirdly, a computer device is provided, comprising:

[0040] At least one processor; and

[0041] A memory communicatively connected to the at least one processor; wherein,

[0042] The memory stores computer instructions that can be executed by the at least one processor to enable the at least one processor to perform the method involved in the first aspect above.

[0043] Fourthly, a computer-readable storage medium is provided, having stored thereon computer instructions, wherein the computer instructions are used to cause a computer to perform the methods involved in the first aspect above.

[0044] According to the technical content provided in the embodiments of this application, this application periodically or in response to event triggering acquires log data of a target model server and obtains the analysis dimensions of the target model server. Further, based on the analysis dimensions of the target model server, test log data corresponding to the analysis dimensions is obtained from the log data. Then, the log data of the target model server is analyzed based on the test log data, and the log analysis results are output. This application embodiment can automatically analyze log data according to user-selected or pre-set analysis dimensions, and can analyze log data for multiple analysis dimensions simultaneously, resulting in high log analysis efficiency and a more convenient understanding of the overall data situation of product production. Attached Figure Description

[0045] Figure 1 This is a flowchart illustrating a log analysis method in one embodiment;

[0046] Figure 2 This is a structural block diagram of a log analysis device in one embodiment;

[0047] Figure 3 This is a schematic structural diagram of a computer device in one embodiment. Detailed Implementation

[0048] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the present application and are not intended to limit the scope of the present application.

[0049] This application provides a log analysis method applicable to servers. It automatically analyzes log data using a pre-created log analysis model to derive analysis results for a specific server model over a certain period. The method provided in this application is applied to a self-developed log analysis model.

[0050] Figure 1 A flowchart of a log analysis method provided in this application embodiment is shown below. Figure 1 As shown, the method may include the following steps:

[0051] Step 101: Periodically or in response to event triggers, obtain log data from the target model of the server.

[0052] Specifically, periodically acquiring log data from the target server model means automatically acquiring log data from the target server model periodically according to a pre-set frequency, such as once a day, once a week, once a month, once a quarter, or once a year. Acquiring log data from the target server model in response to event triggers includes acquiring log data from the target server model according to user instructions. The log analysis model of this application can analyze log data from one or more server models. In this step, the log analysis model acquires log data from the target server model corresponding to the user's selection.

[0053] Step 102: Obtain the analysis dimensions of the target server model, which include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate.

[0054] Specifically, users can select one or more analysis dimensions for the target server model. The log analysis model can obtain one or more analysis dimensions for the target server model. The analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate.

[0055] The overall pass rate is the percentage of servers of the target model that passed the zero-anomaly test within a certain time period, out of the total number of servers of that model. The test item pass rate is the percentage of servers of the target model that passed each test item without anomalies within a certain time period, out of the total number of servers of that model. Test items include configuration checks and hard drive stress tests. The overall anomaly rate is the percentage of servers of the target model that passed the anomaly test within a certain time period, out of the total number of servers of that model. The specific anomaly rate is the percentage of servers of the target model that experienced specific anomalies during production testing within a certain time period, out of the total number of servers of that model. When selecting "Test Item Pass Rate," one or more test items can be selected; when selecting "Specific Anomaly Rate," one or more error codes can be selected.

[0056] Step 103: Based on the analysis dimensions of the target server model, obtain the test log data corresponding to the analysis dimensions from the log data.

[0057] Specifically, based on the analysis dimensions of the target server model, test log data corresponding to those dimensions is retrieved from the log data. For example, the test log data corresponding to the overall pass rate includes the number of servers that passed the zero-anomaly test for the target server model. The test log data corresponding to the test item pass rate includes the number of servers that passed the zero-anomaly test for each test item during the testing process for the target server model. The test log data corresponding to the overall anomaly rate includes the number of servers that passed the anomaly test for the target server model. The test log data corresponding to the specific anomaly rate includes the number of specific anomalies that occurred during the production testing of the target server model.

[0058] Step 104: Analyze the log data of the target server model based on the test log data and output the log analysis results.

[0059] Specifically, based on the pre-acquired test log data corresponding to the analysis dimensions of the target model server, the log data of the target model server is analyzed, and the log analysis results corresponding to the analysis dimensions of the target model server are output.

[0060] In one embodiment of this application, step 104 involves analyzing the log data of the target model server based on the test log data and outputting the log analysis results. This includes: analyzing the analysis dimensions of the log data of the target model server based on the test log data, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate; and outputting the log analysis results, which include one or more of the following: overall pass rate result, test item pass rate result, overall anomaly rate result, and specific anomaly rate result.

[0061] Specifically, based on pre-acquired test log data corresponding to the analysis dimensions of the target server model, the log data of the target server model is analyzed, including one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate. Then, the log analysis results corresponding to the analysis dimensions of the target server model are output, including one or more of the following: overall pass rate result, test item pass rate result, overall anomaly rate result, and specific anomaly rate result.

[0062] As can be seen, this embodiment of the application periodically or in response to event triggering acquires log data of the target model server and obtains the analysis dimensions of the target model server. Furthermore, based on the analysis dimensions of the target model server, it retrieves test log data corresponding to the analysis dimensions from the log data, analyzes the log data of the target model server based on the test log data, and outputs the log analysis results. This embodiment of the application can automatically analyze log data according to user-selected or pre-set analysis dimensions, and can analyze log data for multiple analysis dimensions simultaneously, resulting in high log analysis efficiency and a more convenient understanding of the overall data situation of product production.

[0063] In one embodiment of this application, the target model server includes: one or more servers; the step 101 of periodically or in response to an event to obtain log data of the target model server includes: receiving a periodically sent log analysis instruction or a log analysis instruction in response to an event, wherein the log analysis instruction contains information of the target model server corresponding to the log analysis instruction; and obtaining log data corresponding to each target model server according to the log analysis instruction.

[0064] Specifically, in this embodiment, the target server model includes one or more servers. The multiple servers may include multiple servers of the same model or multiple servers of different models. The log analysis model receives periodically sent log analysis instructions or log analysis instructions triggered by events, wherein the log analysis instructions contain information about one or more target server models. The log analysis model obtains the log data corresponding to each target server model according to the log analysis instructions.

[0065] In one embodiment of this application, the target model server includes one or more servers. Step 102, obtaining the analysis dimensions of the target model server, includes obtaining the analysis dimensions corresponding to each target model server. Step 103, obtaining test log data corresponding to the analysis dimensions from the log data according to the analysis dimensions of the target model server, includes obtaining the test log data corresponding to the analysis dimensions of each target model server from the log data corresponding to each target model server. Step 104, analyzing the log data of the target model server based on the test log data and outputting the log analysis results, includes analyzing the log data of each target model server based on the test log data corresponding to each target model server and outputting the log analysis results for each target model server.

[0066] Specifically, in this embodiment, the target server model includes one or more servers. The multiple servers include multiple servers of the same model or multiple servers of different models. The log analysis model receives periodically sent log analysis instructions or log analysis instructions triggered by events, wherein the log analysis instructions contain information about one or more target server models. The log analysis model obtains the log data corresponding to each target server model according to the log analysis instructions, and obtains the analysis dimension corresponding to each target server model. Based on the analysis dimension corresponding to each target server model, the model obtains test log data corresponding to the analysis dimension of each target server model from the log data corresponding to each target server model. Based on the test log data corresponding to each target server model, the model analyzes the log data of each target server model and outputs the log analysis result for each target server model.

[0067] The target server model in the embodiments of this application includes one or more servers. The embodiments of this application can analyze the log data of multiple servers, analyzing the log data of each server separately for each analysis dimension, and outputting the results. The embodiments of this application can not only manage log data across multiple analysis dimensions, but also manage logs from various different server models, resulting in high log analysis efficiency and a more convenient understanding of the overall data situation of product production.

[0068] In one embodiment of this application, the log analysis method provided by this application further includes: Step 105: Obtaining a pre-set log analysis threshold for the log analysis results, wherein the log analysis threshold includes one or more of the following: overall pass rate threshold, test item pass rate threshold, overall anomaly rate threshold, and specific anomaly rate threshold. Step 106: If the log analysis results exceed the log analysis threshold, an alarm email is sent to a preset contact.

[0069] Specifically, thresholds are set for each analysis dimension. When the log data analysis results exceed the set thresholds, an email alert is triggered, allowing for comprehensive and rapid understanding of product-generated data for management decision-making. The log analysis model obtains pre-set log analysis thresholds for the log analysis results. These thresholds include one or more of the following: overall pass rate threshold, test item pass rate threshold, overall anomaly rate threshold, and specific anomaly rate threshold. If the log analysis results exceed the log analysis thresholds, an alert email is sent to pre-defined contacts.

[0070] In one embodiment of this application, step 106 involves sending an alarm email to preset contacts if the log analysis result exceeds a log analysis threshold. This includes: sending an alarm email to a preset first contact if the overall pass rate result exceeds an overall pass rate threshold; sending an alarm email to a preset second contact if the test item pass rate result exceeds a test item pass rate threshold; sending an alarm email to a preset third contact if the overall anomaly rate result exceeds an overall anomaly rate threshold; and sending an alarm email to a preset fourth contact if the specific anomaly rate result exceeds a specific anomaly rate threshold.

[0071] Specifically, different analysis dimensions can have separate thresholds and email groups set. If the overall first-pass rate exceeds the overall first-pass rate threshold, an alert email is sent to the first preset contact person. If the test item pass rate exceeds the test item pass rate threshold, an alert email is sent to the second preset contact person. If the overall anomaly rate exceeds the overall anomaly rate threshold, an alert email is sent to the third preset contact person. If a specific anomaly rate exceeds the specific anomaly rate threshold, an alert email is sent to the fourth preset contact person. The log analysis model also includes a configuration management module for configuring product models and error codes, and includes a management email group that supports creating, deleting, modifying, and copying email group contacts.

[0072] In one embodiment of this application, step 104, which involves analyzing the log data of the target model server based on the test log data and outputting the log analysis results, includes: analyzing the log data of the target model server based on the test log data and generating log analysis results; and sending the log analysis results to the backend of the target model server.

[0073] Specifically, the log analysis model analyzes the log data of the target model server based on the test log data, generates log analysis results, and sends the log analysis results to the backend of the target model server for querying.

[0074] Meanwhile, when users view the log analysis model, a multi-tab page is opened. The first tab displays the basic attribute information of the model being viewed, and the second tab displays the list of log analysis results automatically generated by the model. An analysis result link is automatically generated for each period, and each link opens the analysis result page, which displays the data analysis results for each analysis dimension.

[0075] In the embodiments of this application, after creating the log analysis model, a log analysis process is generated simultaneously. This process periodically analyzes the target log data according to the machine type, frequency, and analysis dimension configured in the log analysis module, and transmits the analyzed log data to the server backend for querying. At the same time, it determines whether the data value in the analysis result exceeds the set threshold. If the threshold is exceeded, a warning email is sent to the recipients in the pre-configured email group.

[0076] The embodiments of this application can analyze log data from multiple servers, analyzing the log data of each server separately for each analysis dimension and outputting the results. The embodiments of this application can not only manage log data across multiple analysis dimensions, but also manage logs from various server models, resulting in high log analysis efficiency and a more convenient understanding of the overall data situation of product production.

[0077] It should be understood that, although Figure 1 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated in this application, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Furthermore, Figure 1 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0078] Figure 2 This is a schematic diagram of the structure of a log analysis device provided in an embodiment of this application, as shown below. Figure 2 As shown, the device may include:

[0079] First acquisition module 201: used to periodically or in response to event triggering to acquire log data of the target model of server;

[0080] The second acquisition module 202 is used to acquire the analysis dimensions of the target model server, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate.

[0081] Data selection module 203: used to obtain test log data corresponding to the analysis dimension from the log data according to the analysis dimension of the target model server;

[0082] Data analysis module 204: used to analyze the log data of the target model server based on the test log data, and output the log analysis results.

[0083] In one embodiment, the target model server includes: one or more servers; the first acquisition module 201 is further configured to: receive periodically sent log analysis instructions or log analysis instructions triggered by events, wherein the log analysis instructions contain information about the target model server corresponding to the log analysis instructions; and acquire log data corresponding to each target model server according to the log analysis instructions.

[0084] In one embodiment, the second acquisition module 202 is further configured to: analyze the analysis dimensions of the log data of the target model server based on the test log data, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate; and output log analysis results, wherein the log analysis results include one or more of the following: overall pass rate result, test item pass rate result, overall anomaly rate result, and specific anomaly rate result.

[0085] In one embodiment, the system further includes an alarm module 205: configured to obtain a pre-set log analysis threshold for the log analysis results, wherein the log analysis threshold includes one or more of the following: overall pass rate threshold, test item pass rate threshold, overall anomaly rate threshold, and specific anomaly rate threshold; if the log analysis results exceed the log analysis threshold, an alarm email is sent to a preset contact.

[0086] In one embodiment, the second acquisition module 202 is further configured to: acquire the analysis dimension corresponding to each target server model; the data selection module 203 is further configured to: acquire test log data corresponding to the analysis dimension of each target server model from the log data corresponding to each target server model. The data analysis module 204 is further configured to: analyze the log data of each target server model based on the test log data of each target server model, and output the log analysis results of each target server model.

[0087] In one embodiment, the alarm module 205 is further configured to: send an alarm email to a preset first contact if the overall pass rate result exceeds the overall pass rate threshold; send an alarm email to a preset second contact if the test item pass rate result exceeds the test item pass rate threshold; send an alarm email to a preset third contact if the overall anomaly rate result exceeds the overall anomaly rate threshold; and send an alarm email to a preset fourth contact if the specific anomaly rate result exceeds the specific anomaly rate threshold.

[0088] In one embodiment, the data analysis module 204 is further configured to: analyze the log data of the target model server based on the test log data, generate log analysis results, and send the log analysis results to the backend of the target model server.

[0089] According to the specific embodiments provided in this application, the technical solution provided in this application can have the following advantages:

[0090] In the embodiments of this application, after creating the log analysis model, a log analysis process is generated simultaneously. This process periodically analyzes the target log data according to the machine type, frequency, and analysis dimension configured in the log analysis module, and transmits the analyzed log data to the server backend for querying. At the same time, it determines whether the data value in the analysis result exceeds the set threshold. If the threshold is exceeded, a warning email is sent to the recipients in the pre-configured email group.

[0091] The embodiments of this application can analyze log data from multiple servers, analyzing the log data of each server separately for each analysis dimension and outputting the results. The embodiments of this application can not only manage log data across multiple analysis dimensions, but also manage logs from various server models, resulting in high log analysis efficiency and a more convenient understanding of the overall data situation of product production.

[0092] The same or similar parts among the above embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the device embodiments are basically similar to the method embodiments, so the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments.

[0093] It should be noted that the embodiments of this application may involve the use of user data. In practical applications, user-specific personal data may be used in the scheme described herein within the scope permitted by applicable laws and regulations, provided that it complies with the applicable laws and regulations of the country (e.g., explicit consent from the user, actual notification to the user, explicit authorization from the user, etc.).

[0094] According to embodiments of this application, this application also provides a computer device and a computer-readable storage medium. This application further provides a computer device including at least one processor and a memory communicatively connected to the at least one processor; wherein the memory stores computer instructions executable by the at least one processor, the computer instructions being executed by the at least one processor to enable the at least one processor to perform the log analysis method described in any of the above embodiments.

[0095] like Figure 3The diagram shown is a block diagram of a computer device according to an embodiment of this application. The term "computer device" is intended to represent various forms of digital computers or mobile devices. The digital computer may include a desktop computer, a portable computer, a workbench, a personal digital assistant, a server, a mainframe computer, and other suitable computers. The mobile device may include a tablet computer, a smartphone, a wearable device, etc.

[0096] like Figure 3 As shown, the computer device 300 includes a computing unit 301, a ROM 302, a RAM 303, a bus 304, and an input / output (I / O) interface 305. The computing unit 301, ROM 302, and RAM 303 are interconnected via the bus 304. The input / output (I / O) interface 305 is also connected to the bus 304.

[0097] The computing unit 301 can execute various processes in the method embodiments of this application according to computer instructions stored in the read-only memory (ROM) 302 or computer instructions loaded from the storage unit 308 into the random access memory (RAM) 303. The computing unit 301 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. The computing unit 301 can include, but is not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. In some embodiments, the methods provided in the embodiments of this application can be implemented as computer software programs, which are tangibly contained in a computer-readable storage medium, such as the storage unit 308.

[0098] RAM 303 can also store various programs and data required for the operation of device 300. Part or all of the computer program can be loaded and / or installed on device 300 via ROM 302 and / or communication unit 309.

[0099] The input unit 306, output unit 307, storage unit 308, and communication unit 309 in computer device 300 can be connected to I / O interface 305. The input unit 306 can be, for example, a keyboard, mouse, touchscreen, or microphone; the output unit 307 can be, for example, a monitor, speaker, or indicator light. Device 300 can exchange information and data with other devices through the communication unit 309.

[0100] It should be noted that the device may also include other components necessary for normal operation. It may also include only the components necessary for implementing the solution of this application, without necessarily including all the components shown in the figures.

[0101] Various implementations of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), payload programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof.

[0102] The computer instructions used to implement the methods of this application may be written in any combination of one or more programming languages. These computer instructions may be provided to the computing unit 301 such that when executed by the computing unit 301, such as a processor, the computer instructions cause the execution of the steps involved in the embodiments of the methods of this application.

[0103] This application also provides a computer-readable storage medium having computer instructions stored thereon for causing a computer to execute the log analysis method described in any of the above embodiments.

[0104] The computer-readable storage medium provided in this application can be a tangible medium that can contain or store computer instructions for performing the steps involved in the method embodiments of this application. The computer-readable storage medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, and other forms of storage media.

[0105] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A log analysis method, characterized in that, The method includes: Periodically or in response to event triggers, retrieve log data from the target model of the server; Obtain the analysis dimensions of the target model server, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate; Wherein, the overall pass rate is the proportion of the number of servers of the target model that passed the zero-anomaly test within a specified time range to the total number of servers of that model; the test item pass rate is the proportion of the number of servers of the target model that passed the zero-anomaly test for each test item during the testing process within a specified time range to the total number of servers of that model; the overall anomaly rate is the proportion of the number of servers of the target model that passed the anomaly test within a specified time range to the total number of servers of that model; and the specific anomaly rate is the proportion of the number of servers of the target model that experienced specific anomalies during production testing within a specified time range to the total number of servers of that model. Based on the analysis dimensions of the target server model, obtain the test log data corresponding to the analysis dimensions from the log data; The analysis dimensions of the log data of the target model server are analyzed based on the test log data, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate. Output log analysis results, which include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate. Obtain a pre-set log analysis threshold for the log analysis results, wherein the log analysis threshold includes one or more of the following: overall pass rate threshold, test item pass rate threshold, overall anomaly rate threshold, and specific anomaly rate threshold; If the log analysis results exceed the log analysis threshold, an alarm email will be sent to a preset contact.

2. The log analysis method according to claim 1, characterized in that, The target model of the server includes: one server or multiple servers; The periodic or event-triggered acquisition of log data from the target model server includes: Receive periodically sent log analysis instructions or log analysis instructions triggered by events, wherein the log analysis instructions contain information about the target model of the server corresponding to the log analysis instructions; According to the log analysis instructions, obtain the log data corresponding to each target server model.

3. The log analysis method according to claim 2, characterized in that, The analytical dimensions for obtaining the target server model include: Obtain the analysis dimensions corresponding to each target server model; The step of retrieving test log data corresponding to the analysis dimension from the log data based on the analysis dimension of the target server model includes: Based on the analysis dimension corresponding to each target server model, test log data corresponding to the analysis dimension of each target server model is obtained from the log data corresponding to each target server model. The step of analyzing the log data of the target server model based on the test log data and outputting the log analysis results includes: Based on the test log data corresponding to each target server model, analyze the log data of each target server model and output the log analysis results for each target server model.

4. The log analysis method according to claim 1, characterized in that, If the log analysis result exceeds the log analysis threshold, an alert email is sent to a preset contact, including: If the overall pass rate result exceeds the overall pass rate threshold, an alarm email is sent to the preset first contact person; If the pass rate of the test item exceeds the pass rate threshold of the test item, an alarm email will be sent to a preset second contact person; If the overall anomaly rate exceeds the overall anomaly rate threshold, an alarm email will be sent to a preset third contact. If the specific anomaly rate result exceeds the specific anomaly rate threshold, an alarm email is sent to a preset fourth contact.

5. The log analysis method according to claim 1, characterized in that, The step of analyzing the log data of the target server model based on the test log data and outputting the log analysis results includes: Analyze the log data of the target server model based on the test log data, and generate log analysis results; The log analysis results are sent to the server backend of the target model.

6. A log analysis device, characterized in that, The device includes: First acquisition module: used to periodically or in response to event triggers to acquire log data of the target model of server; The second acquisition module is used to acquire the analysis dimensions of the target server model, wherein the analysis dimensions include one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate; wherein, the overall pass rate is the proportion of the number of servers of the target model that pass the test with zero anomalies within a specified time range to the total number of servers of that model; the test item pass rate is the proportion of the number of servers of the target model that pass the test with zero anomalies during the testing process within a specified time range to the total number of servers of that model; the overall anomaly rate is the proportion of the number of servers of the target model that pass the test with anomalies within a specified time range to the total number of servers of that model; and the specific anomaly rate is the proportion of the number of servers of the target model that generate specific anomalies during production testing within a specified time range to the total number of servers of that model. Data selection module: used to obtain test log data corresponding to the analysis dimension of the target server model from the log data; Data Analysis Module: Used to analyze the log data of the target server model based on the test log data, including one or more of the following: overall pass rate, test item pass rate, overall anomaly rate, and specific anomaly rate; output log analysis results, including one or more of the following: overall pass rate result, test item pass rate result, overall anomaly rate result, and specific anomaly rate result; obtain a pre-set log analysis threshold for the log analysis results, including one or more of the following: overall pass rate threshold, test item pass rate threshold, overall anomaly rate threshold, and specific anomaly rate threshold; if the log analysis result exceeds the log analysis threshold, send an alarm email to a preset contact.

7. A computer device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores computer instructions executable by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the method of any one of claims 1-5.

8. A computer-readable storage medium storing computer instructions thereon, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1 to 5.