A method, system, device, equipment and medium for obtaining monitoring logs

By matching each virtual machine with a log monitoring module to obtain and process all traffic data accessing the virtual machine, the problem of inaccurate monitoring logs in the existing technology is solved, and efficient and accurate monitoring log generation is achieved.

CN116248559BActive Publication Date: 2025-05-30HANGZHOU XINGHAN NONGCHAO NETWORK TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310456533.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-25
Publication Date
2025-05-30
Estimated Expiration
2043-04-25

AI Technical Summary

Technical Problem

In the prior art, the formats of the business monitoring logs are diverse and the paths are not uniform, which leads to inaccurate monitoring logs, making it difficult to generate monitoring logs efficiently and accurately.

Method used

Each virtual machine is matched with a log monitoring module, through which all traffic data accessing the virtual machine is obtained and processed, thereby generating a complete monitoring log.

Benefits of technology

By matching each virtual machine with a log monitoring module, traffic bottlenecks can be effectively reduced, the accuracy and efficiency of monitoring logs can be ensured, and the operation efficiency of target equipment can be improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116248559B_ABST
    Figure CN116248559B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a method, system, device, equipment and medium for obtaining monitoring logs. The method includes: a log monitoring module obtains target traffic data and forwards the target traffic data to a first virtual machine so that the first virtual machine processes the target traffic data. Among them, the target device includes at least one virtual machine and at least one log monitoring module. The first virtual machine is any one of the at least one virtual machine, and one virtual machine is bound to one log monitoring module; the log monitoring module generates monitoring logs based on the target traffic data. Through some embodiments of the present application, a log monitoring module can be matched for each virtual machine, thereby reducing traffic bottlenecks, and at the same time, all traffic input into the virtual machine can be monitored, and then monitoring logs can be generated efficiently and accurately.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of network security, and particularly to a method, system, device, equipment and medium for obtaining monitoring logs. Background Art

[0002] Business monitoring logs are an important data source for business monitoring. Business monitoring includes, but is not limited to, interface GPS, interface latency, interface error rate, and some other composite business metrics, etc. Almost all businesses require business monitoring to ensure the stability of their own systems. In the related art, the operation of outputting business monitoring logs is decentralized to each business party, resulting in problems such as diverse log formats and inconsistent paths, and further leading to inaccurate generated monitoring logs.

[0003] Therefore, how to generate monitoring logs efficiently and accurately has become a problem to be solved. Summary of the Invention

[0004] The embodiments of the present application provide a method, system, device, equipment and medium for obtaining monitoring logs. Through some embodiments of the present application, at least one log monitoring module can be matched for each virtual machine, so as to reduce the traffic bottleneck, and at the same time, all traffic input into the virtual machine can be monitored, and then monitoring logs can be generated efficiently and accurately.

[0005] In a first aspect, the present application provides a method for obtaining monitoring logs, which is applied to a target device. The method includes: a log monitoring module obtains target traffic data and forwards the target traffic data to a first virtual machine, so that the first virtual machine processes the target traffic data. Wherein, the target device includes at least one virtual machine and at least one log monitoring module, the first virtual machine is any one of the at least one virtual machine, and one virtual machine is bound to one log monitoring module; the log monitoring module generates monitoring logs based on the target traffic data.

[0006] Therefore, different from the method of using one gateway corresponding to multiple virtual machines in the related art, the embodiments of the present application can obtain all traffic data accessing the virtual machine (including traffic data accessing the virtual machine from the client and traffic data accessed by other virtual machines) by matching one log monitoring module for each virtual machine, so as to generate complete monitoring logs. At the same time, since the log monitoring module in the present application is only responsible for the log processing of the virtual machine bound to it, the situation of IO bottleneck will not occur, the operation efficiency of the target device is improved, and thus monitoring logs can be generated efficiently and accurately.

[0007] In combination with the first aspect, in an implementation of the present application, before the log monitoring module acquires target traffic data, the method further includes: acquiring the request type of the target traffic data; looking up the listening port number corresponding to the request type in a listening port comparison table, where the listening port comparison table is used to store the correspondence between the request type and the listening port number; modifying the listening port number of the log monitoring module; the log monitoring module acquiring target traffic data includes: the log monitoring module acquiring the target traffic data through the listening port number.

[0008] Therefore, in the embodiment of the present application, by matching the corresponding listening port number according to the type of traffic data, the implementation difficulty and operation and maintenance difficulty can be controlled, and the traffic data can be monitored flexibly.

[0009] In combination with the first aspect, in an implementation of the present application, before the log monitoring module acquires target traffic data, the method further includes: configuring the format for the log monitoring module to generate monitoring logs, where the format includes the client IP, time, and response status code.

[0010] Therefore, in the embodiment of the present application, by configuring the format for generating logs, the logs can be output in a standardized manner, which is convenient for subsequent processing of the input monitoring logs.

[0011] In combination with the first aspect, in an implementation of the present application, after the log monitoring module generates monitoring logs based on the target traffic data, the method further includes: confirming that each virtual machine in the at least one virtual machine has generated a corresponding monitoring log, and summarizing each monitoring log to the log center for storage.

[0012] Therefore, in the embodiment of the present application, by confirming that each virtual machine has generated a corresponding monitoring log, the accuracy of the generated logs can be ensured.

[0013] In combination with the first aspect, in an implementation of the present application, before the log monitoring module acquires target traffic data, the method further includes: downloading a target log monitoring module in the system base image, where the target log monitoring module includes configuration parameters, and the configuration parameters include a listening port number; binding the target log monitoring module to the first virtual machine; the log monitoring module acquiring target traffic data includes: the target log monitoring module acquiring the target traffic data; the log monitoring module generating monitoring logs based on the target traffic data includes: the target log monitoring module generating monitoring logs based on the target traffic data.

[0014] Therefore, the embodiment of the present application can reduce the time for configuring the parameters of the target device and improve the operation efficiency of the target device by finding the target log monitoring module that has completed the matching parameters in the base image.

[0015] Combined with the first aspect, in an implementation manner of the present application, after the log monitoring module generates a monitoring log based on the target traffic data, the method further includes: after the first virtual machine is deleted, deleting the log monitoring module bound to the first virtual machine at the same time; or, after a new first virtual machine is added, binding the log monitoring module to the new first virtual machine at the same time.

[0016] Therefore, the embodiment of the present application can flexibly perform dynamic expansion by scaling the log monitoring module along with the virtual machine, thereby reducing the operation burden of the target device.

[0017] In a second aspect, the present application provides a device for obtaining a monitoring log. The log monitoring module includes a traffic acquisition module and a log generation module; the traffic acquisition module is configured to acquire target traffic data and forward the target traffic data to a first virtual machine so that the first virtual machine processes the target traffic data. Among them, the target device includes at least one virtual machine and at least one log monitoring module, the first virtual machine is any one of the at least one virtual machine, and one virtual machine is bound to one log monitoring module; the log generation module is configured to generate a monitoring log based on the target traffic data.

[0018] Combined with the second aspect, in an implementation manner of the present application, the traffic acquisition module is further configured to: acquire the request type of the target traffic data; look up the listening port number corresponding to the request type in the listening port comparison table, where the listening port comparison table is used to store the correspondence between the request type and the listening port number; modify the listening port number of the log monitoring module; the log monitoring module acquires the target traffic data through the listening port number.

[0019] Combined with the second aspect, in an implementation manner of the present application, the traffic acquisition module is further configured to: configure the format for the log monitoring module to generate a monitoring log, where the format includes the client IP, time, and response status code.

[0020] Combined with the second aspect, in an implementation manner of the present application, the log generation module is further configured to: confirm that each virtual machine in the at least one virtual machine has generated a corresponding monitoring log, and summarize each monitoring log to the log center for storage.

[0021] In combination with the second aspect, in an embodiment of the present application, the traffic acquisition module is further configured to: download a target log monitoring module in the system base image, where the target log monitoring module includes configuration parameters, and the configuration parameters include a listening port number; bind the target log monitoring module to the first virtual machine; the target log monitoring module acquires the target traffic data; the target log monitoring module generates a monitoring log based on the target traffic data.

[0022] In combination with the second aspect, in an embodiment of the present application, the log generation module is further configured to: after the first virtual machine is deleted, delete the log monitoring module bound to the first virtual machine at the same time; or, after a new first virtual machine is added, bind the log monitoring module to the new first virtual machine at the same time.

[0023] In a third aspect, the present application provides a system for acquiring monitoring logs, where the system includes: a client for sending target traffic data; a target device for acquiring the target traffic data and performing the method described in any embodiment of the first aspect according to the target traffic data to obtain a monitoring log.

[0024] In a fourth aspect, the present application provides an electronic device, including: a processor, a memory, and a bus; the processor is connected to the memory through the bus, and the memory stores a computer program, and when the computer program is executed by the processor, the method described in any embodiment of the first aspect can be implemented.

[0025] In a fifth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed, the method described in any embodiment of the first aspect can be implemented. Description of the Drawings

[0026] Figure 1 It is a schematic diagram of the composition of the system for acquiring monitoring logs shown in the embodiments of the present application;

[0027] Figure 2 It is a flowchart of the method for acquiring monitoring logs shown in the embodiments of the present application;

[0028] Figure 3 It is a schematic diagram of the composition of the device for acquiring monitoring logs shown in the embodiments of the present application;

[0029] Figure 4 It is a schematic diagram of the composition of an electronic device shown in the embodiments of the present application. Detailed Embodiments

[0030] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Usually, the components of the embodiments of this application described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of this application provided in the accompanying drawings below is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative efforts fall within the protection scope of this application.

[0031] The embodiments of this application can be applied to scenarios for generating monitoring logs. To address the problems in the background art, in some embodiments of this application, a log monitoring module is matched to each virtual machine, and the log monitoring module generates corresponding monitoring logs. For example: In some embodiments of this application, first, the log monitoring module obtains target traffic data and forwards the target traffic data to the first virtual machine so that the first virtual machine processes the target traffic data. Then, the log monitoring module generates a monitoring log based on the target traffic data.

[0032] The method steps in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0033] Figure 1 The structural diagram of the system for obtaining monitoring logs in some embodiments of this application is provided. The system includes a client 110 and a target device 120. Specifically, the client 110 sends target traffic data to the target device 120. After the log monitoring module in the target device 120 obtains the target traffic data, it forwards the target traffic data to the virtual machine corresponding to the current log monitoring module, and then generates a monitoring log based on the target traffic data.

[0034] In the related art, there are the following two methods for generating monitoring logs:

[0035] One solution is to output monitoring logs at the gateway layer. Whether it is traditional virtual machine services or microservices, the traffic sources received by business instances mainly have two: one is the distribution from the upstream gateway, and the other is the mutual call between peer instances. Outputting monitoring logs at the gateway layer is the most common practice. This solution has two defects. One is that the relationship between gateway instances and business instances is basically one-to-many. In large-traffic scenarios, the huge amount of business logs generated are concentrated on a small number of gateway instances, which is likely to form an IO bottleneck. The other is that this solution can only monitor north-south traffic (i.e., the traffic transmitted from the outside to the business instance), and cannot monitor the east-west traffic between business instances (i.e., the traffic between business instances).

[0036] Another solution is the ServiceMesh approach in the microservice scenario. The Side-Car process is deployed in the business POD / container to host the inbound and outbound traffic of the business, and the log format and output business monitoring logs are customized in the Side-Car process. This solution is a de facto standard solution in the microservice system (including logging, speed limiting, high availability, circuit breaking, access control, etc.), but the implementation threshold of this solution is high, and the transformation and maintenance are relatively complex, which is difficult for small and medium-sized teams and enterprises to control. In addition, this solution is mainly suitable for microservice scenarios and is not friendly to traditional virtual machine service architectures.

[0037] Based on the defects of the above two solutions, this application proposes a new standardized output method for business monitoring logs, which installs an nginx instance (i.e., log monitoring module) in the POD / virtual machine where each business instance is located, takes over the inbound and outbound traffic of the business instance, and uses the access_log that comes with nginx as the standard monitoring log. This solution can make full use of the distributed instance resources of the business in a large traffic scenario, is not easy to reach the IO bottleneck, and traffic forwarding is a stateless operation, so it can be horizontally expanded and reduced with the business instance. For example, when a POD (i.e., a space for processing data, similar to a virtual machine) is horizontally expanded, an nginx instance is synchronously deployed in the newly started POD to receive upstream traffic and forward it to the business instance (process). Similarly, when a virtual machine is horizontally expanded, an nginx instance is synchronously deployed in the virtual machine to receive upstream traffic and forward it to the business instance. The deployment process based on nginx is simple and the maintenance threshold is low, the implementation complexity and maintenance cost are low, and it is compatible with the virtual machine architecture and microservice architecture.

[0038] The following uses the target device as an example to illustrate a method for obtaining monitoring logs executed by the target device in some embodiments of the present application. It can be understood that the technical solution of the method for obtaining monitoring logs in the embodiment of the present application can be applied to any target device, such as a server.

[0039] At least to solve the problems in the background technology, such as Figure 2 As shown, some embodiments of the present application provide a method for obtaining a monitoring log, the method comprising:

[0040] S210, the log monitoring module obtains target traffic data and forwards the target traffic data to the first virtual machine; S220, the log monitoring module generates a monitoring log based on the target traffic data.

[0041] It is understandable that the first virtual machine includes at least one process, and after the first virtual machine receives the target traffic data, one of the at least one processes processes the target traffic data, for example, the process obtains a file corresponding to the target traffic data.

[0042] It should be noted that the target device includes at least one virtual machine and at least one log monitoring module. The first virtual machine is any one of the at least one virtual machine, and one virtual machine is bound to one log monitoring module.

[0043] That is to say, each virtual machine in the target device corresponds to a log monitoring module. The log monitoring module first intercepts the target traffic data sent to the virtual machine bound to it, and then forwards it to the virtual machine bound to it, and generates a monitoring log based on the target traffic data. For example, virtual machine A is bound to a log monitoring module A. After the log monitoring module A monitors that the client sends target traffic data to virtual machine A, the log monitoring module A forwards the target traffic data to virtual machine A, and the process in virtual machine A processes the target traffic data, and the log monitoring module A generates a monitoring log based on the target traffic data.

[0044] In an implementation manner of the present application, before S210, it is also necessary to set the listening port of the log monitoring module.

[0045] Specifically, first, obtain the request type of the target traffic data. Then, look up the listening port number corresponding to the request type in the listening port comparison table, where the listening port comparison table is used to store the corresponding relationship between the request type and the listening port number. Finally, modify the listening port number of the log monitoring module.

[0046] That is to say, before the log monitoring module obtains the target traffic data, it is necessary to clarify the listening port, and the listening port number is related to the request type of the target traffic data. The target device pre-clarifies the request type of the target traffic data, then looks up the listening port number according to the request type, and configures the listening port number of the log monitoring module. Then the log monitoring module obtains the target traffic data through the listening port number.

[0047] For example, if the request type is http, the corresponding listening port number is http80. If the request type is grpc, the corresponding listening port number is 80http2.

[0048] It should be noted that when setting the listening port number, the forwarding port corresponding to the request type can also be set.

[0049] In an implementation manner of the present application, before S210, it is also necessary to configure the format of the monitoring log generated by the log monitoring module.

[0050] It can be understood that the format of the monitoring log includes the client IP, local time, response status code, original request line, request processing duration, etc.

[0051] That is to say, in order to generate standard monitoring logs, before obtaining the target traffic data, the present application needs to uniformly configure the format of the monitoring logs. It can be understood that the format of the monitoring logs can be adjusted according to production requirements, and the present application does not limit the format of the monitoring logs.

[0052] In an implementation manner of the present application, the configured log monitoring module can be downloaded before S210. Specifically, first, the target log monitoring module is downloaded in the system base image, where the target log monitoring module includes configuration parameters, and the configuration parameters include the listening port number. Then, the target log monitoring module is bound to the first virtual machine. Next, the target log monitoring module obtains the target traffic data. Finally, the target log monitoring module generates monitoring logs based on the target traffic data.

[0053] That is to say, for further optimization to reduce the operation duration, the target log monitoring module with the configured log format and / or listening port number can be directly packaged into the system base image to save the download time. Using this image in the virtual machine and directly executing it can complete the traffic forwarding configuration.

[0054] In an implementation manner of the present application, after S220, it is confirmed that each virtual machine in at least one virtual machine has generated the corresponding monitoring logs, and the monitoring logs are aggregated to the log center for storage.

[0055] In an implementation manner of the present application, after S220, the first virtual machine can be scaled down or scaled up. Specifically, after the first virtual machine is deleted, the log monitoring module bound to the first virtual machine is deleted at the same time. Or, after a new first virtual machine is added, a log monitoring module is bound to the new first virtual machine at the same time.

[0056] That is to say, the log monitoring module can be scaled down and scaled up following the virtual machine to which it is bound. After the first virtual machine is scaled down, the corresponding log monitoring module will also be deleted. After the first virtual machine is scaled up, the corresponding log monitoring module will also be increased accordingly. That is, when capacity expansion is required in a traffic peak scenario, the above steps can be executed on the new virtual host to achieve the business-level capacity expansion of standard monitoring logs. When scaling down, the virtual machine can be removed from the SLB (Server Load Balancing) or the registration center according to the original business process.

[0057] The above describes the method for the target device in the present application to obtain monitoring logs. The following will describe the specific embodiments for obtaining monitoring logs in the present application.

[0058] The solution of the present application is applicable to both virtual machine services and microservice architectures. While realizing the standardized output of business monitoring logs, it effectively controls the implementation difficulty and operation and maintenance difficulty.

[0059] As a specific embodiment of the present application, the implementation process of the virtual machine service architecture is as follows:

[0060] The first step: Assume that the listening port of the business application is X, and the listening port of nginx (i.e., the log monitoring module) is Y (it can be understood that X and Y are not the same port). Before the application starts, initialize the running environment of the virtual machine first. Download nginx from the intranet.

[0061] The second step: Modify the log_format parameter configuration of nginx (the default is / etc / nginx / nginx.conf). The log_format parameter of nginx determines the content included in the nginx log according to the log format. It can be customized according to your own needs. Usually, the fields included are $remote_addr (client IP), $time_local (local time), $request (original request line), $status (response status code), $request_time (request processing duration), etc.

[0062] The third step: Modify the configuration of the Server module in the HTTP module of nginx. Configure the port that nginx needs to listen on through the listen parameter. For the http requests sent by the upstream, by modifying the location configuration, use the proxy_pass parameter to forward the requests received by the listen interface to the specified new port, so as to achieve the port traffic forwarding of http, and assist with modifying the forwarding request header configuration. If the request sent by the upstream is a grpc request, the listen parameter in the Server module needs to be configured in the format of "port number http2", such as "80http2". Just change proxy_pass to grpc_pass.

[0063] The fourth step: Observe the nginx log. After the above steps are configured, normal access to the business will generate nginx logs (the default path is / var / log / nginx / access.log). Each POD / virtual machine where the business instance is located will output independent nginx logs. Combining with the log collection system, the logs of different instances can be aggregated to the log center.

[0064] As another specific embodiment of the present application, the implementation process of the microservice architecture is as follows:

[0065] Step 1: Create the configurations required for the nginx service. The namespace where the configurations are located (biz-nginx-test in the configuration example) should be the same as the namespace where the business instance service is located. The content defined in the default configuration represents the configuration of the nginx instance, which is used to forward the requests on the ports listened by nginx to the IP and port specified by proxy_pass. This realizes proxying the http traffic of the business instance entry with the nginx instance. If the entry is grpc traffic, refer to the third step of the virtual machine service architecture.

[0066] Step 2: Create / modify the deployment script of the business, and add the configuration of the nginx container to the original deployment script. Among them, namespace represents the namespace where the business is located, images.galaxy-future.com / galaxy-future / nginx:latest represents the image address of the nginx instance, and volumeMounts represents replacing the files specified by the internal parameters of the nginx instance with the default configuration content defined in the configuration in the first step.

[0067] Step 3: Create a k8s service to enable the business to provide services externally. The port parameter specifies the interface exposed by the service (for example: 8080). The externally exposed interface should be the same as the port listened by nginx in the first step to ensure that the traffic is distributed to nginx and then forwarded by nginx to the business instance.

[0068] To solve the problems in the related technologies, a method that is insensitive to processes and has little impact on processes in daily use is needed to achieve standardized output of monitoring logs. Therefore, this application configures a separate nginx for each virtual machine as the traffic proxy of the virtual machine, and uses the standard output log of nginx as the monitoring log of the virtual machine, which solves the problem that the sudden traffic in the gateway log mode squeezes the computing power resources of the gateway and is prone to generate an IO bottleneck. At the same time, it solves and realizes the access monitoring of the east-west traffic between virtual machines. This application uses the computing power resources of the virtual machine application instance, and can achieve the output of standard monitoring logs on the basis of basically not changing the original technical architecture and not affecting the daily online and operation and maintenance of the virtual machine, and can be dynamically expanded with the virtual machine. It achieves no perception of the virtual machine and has little transformation resistance. This application also solves the complex deployment and operation and maintenance problems of the control plane and the data plane in the microservice architecture mode. This application focuses on solving the problem of outputting standard business monitoring logs, does not involve functions such as high availability, speed limiting, and circuit breaking, and does not require complex control rule configurations and k8s configurations. Only one nginx image needs to be configured to complete the deployment, which greatly reduces the deployment threshold. The function is single and simple, and basically no daily operation and maintenance management is required.

[0069] The specific embodiments of obtaining monitoring logs are described above, and the device for obtaining monitoring logs will be described below.

[0070] As Figure 3 shown, some embodiments of the present application provide a device 300 for obtaining monitoring logs, and the device includes: a traffic acquisition module 310 and a log generation module 320.

[0071] The traffic acquisition module 310 is configured to obtain target traffic data and forward the target traffic data to the first virtual machine, so that the first virtual machine processes the target traffic data. Among them, the target device includes at least one virtual machine and at least one log monitoring module, the first virtual machine is any one of the at least one virtual machine, and one virtual machine is bound to one log monitoring module; the log generation module 320 is configured to generate monitoring logs based on the target traffic data.

[0072] In an implementation manner of the present application, the traffic acquisition module 310 is further configured to: obtain the request type of the target traffic data; look up the listening port number corresponding to the request type in the listening port comparison table, where the listening port comparison table is used to store the correspondence between the request type and the listening port number; modify the listening port number of the log monitoring module; the log monitoring module obtains the target traffic data through the listening port number.

[0073] In an implementation manner of the present application, the traffic acquisition module 310 is further configured to: configure the format for the log monitoring module to generate monitoring logs, where the format includes the client IP, time, and response status code.

[0074] In an implementation manner of the present application, the log generation module 320 is further configured to: confirm that each virtual machine in the at least one virtual machine has generated a corresponding monitoring log, and summarize each monitoring log to the log center for storage.

[0075] In an implementation manner of the present application, the traffic acquisition module 310 is further configured to: download a target log monitoring module in the system base image, where the target log monitoring module includes configuration parameters, and the configuration parameters include a listening port number; bind the target log monitoring module to the first virtual machine; the target log monitoring module obtains the target traffic data; the target log monitoring module generates monitoring logs based on the target traffic data.

[0076] In an implementation manner of the present application, the log generation module 320 is further configured to: after the first virtual machine is deleted, delete the log monitoring module bound to the first virtual machine at the same time; or, after a new first virtual machine is added, bind the log monitoring module to the new first virtual machine at the same time.

[0077] In an embodiment of the present application, Figure 3 the modules shown can implement Figure 1 and Figure 2 each process in the method embodiment. Figure 3 The operations and / or functions of each module in Figure 1 are respectively for implementing Figure 2 the corresponding processes in the method embodiments in

[0078] As Figure 4 shown, an embodiment of the present application provides an electronic device 400, including: a processor 410, a memory 420, and a bus 430. The processor is connected to the memory through the bus. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, they are used to implement the method described in any one of the above embodiments. For details, reference can be made to the description in the above method embodiments. To avoid repetition, the detailed description is appropriately omitted here.

[0079] Among them, the bus is used to realize the direct connection and communication of these components. Among them, in an embodiment of the present application, the processor may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0080] The memory can be, but is not limited to, Random Access Memory (RAM), Read Only Memory (ROM), Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electric Erasable Programmable Read-Only Memory (EEPROM), etc. Computer-readable instructions are stored in the memory, and when the computer-readable instructions are executed by the processor, the methods described in the above embodiments can be executed.

[0081] It can be understood that Figure 4 The structure shown is only schematic, and it may also include more or fewer components than those shown in Figure 4 or have a different configuration from that shown in Figure 4 The components shown in Figure 4 can be implemented using hardware, software, or a combination thereof.

[0082] An embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a server, the method described in any one of the above all embodiments is implemented. For details, reference can be made to the description in the above method embodiments. To avoid repetition, the detailed description is appropriately omitted here.

[0083] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0084] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for obtaining monitoring logs, characterized in that, applied to a target device, the method includes: A log monitoring module obtains target traffic data and forwards the target traffic data to a first virtual machine so that the first virtual machine processes the target traffic data. Wherein, the target device includes at least one virtual machine and at least one log monitoring module, the first virtual machine is any one of the at least one virtual machine, and one virtual machine is bound to one log monitoring module; The log monitoring module generates monitoring logs based on the target traffic data; Wherein, before the log monitoring module obtains the target traffic data, the method further includes: Obtaining the request type of the target traffic data; looking up the listening port number corresponding to the request type in a listening port comparison table, where the listening port comparison table is used to store the correspondence between the request type and the listening port number; modifying the listening port number of the log monitoring module; The log monitoring module obtaining the target traffic data includes: The log monitoring module obtains the target traffic data through the listening port number.

2. The method according to claim 1, characterized in that, before the log monitoring module obtains the target traffic data, the method further includes: Configuring the format for the log monitoring module to generate monitoring logs, where the format includes the client IP, time, and response status code.

3. The method according to claim 1, characterized in that, after the log monitoring module generates monitoring logs based on the target traffic data, the method further includes: Confirming that each virtual machine in the at least one virtual machine has generated corresponding monitoring logs, and summarizing the monitoring logs to a log center for storage.

4. The method according to claim 1, characterized in that, before the log monitoring module obtains the target traffic data, the method further includes: Downloading a target log monitoring module in a system base image, where the target log monitoring module includes configuration parameters, and the configuration parameters include a listening port number; Binding the target log monitoring module to the first virtual machine; The log monitoring module obtaining the target traffic data includes: The target log monitoring module obtains the target traffic data; The log monitoring module generating monitoring logs based on the target traffic data includes: The target log monitoring module generates monitoring logs based on the target traffic data.

5. The method according to claim 1, characterized in that, after the log monitoring module generates monitoring logs based on the target traffic data, the method further includes: After the first virtual machine is deleted, deleting the log monitoring module bound to the first virtual machine at the same time; or, After adding a new first virtual machine, binding the log monitoring module to the new first virtual machine at the same time.

6. A device for obtaining monitoring logs, characterized in that, applied to a target device, the log monitoring module includes a traffic acquisition module and a log generation module, and the device is used to implement the method for obtaining monitoring logs as described in claim 1; The traffic acquisition module is configured to acquire target traffic data and forward the target traffic data to a first virtual machine so that the first virtual machine processes the target traffic data. Among them, the target device includes at least one virtual machine and at least one log monitoring module. The first virtual machine is any one of the at least one virtual machine, and one virtual machine is bound to one log monitoring module; The log generation module is configured to generate a monitoring log based on the target traffic data.

7. A system for obtaining monitoring logs, characterized in that, the system includes: A client for sending target traffic data; A target device for acquiring the target traffic data and executing the method according to any one of claims 1-5 based on the target traffic data to obtain a monitoring log.

8. An electronic device, characterized in that, it includes: A processor, a memory and a bus; The processor is connected to the memory through the bus. The memory stores a computer program, and when the computer program is executed by the processor, the method according to any one of claims 1-5 can be implemented.

9. A computer-readable storage medium, characterized in that, a computer program is stored on the computer-readable storage medium, and when the computer program is executed, the method according to any one of claims 1-5 can be implemented.

Citation Information

Patent Citations

  • Traffic statistical method under cloud computing environment

    CN103036721A

  • Data analysis method and device, server and readable storage medium

    CN111783094A