A flow sampling control method, device, equipment and readable storage medium
By judging the optimal analysis of single disks in the switch or router and transferring stream sampling packet processing, the efficient completion problem of downstream sampling tasks of high-load CPU is solved, and the rational utilization of resources and improvement of equipment performance is achieved.
Patent Information
- Application Number
- CN202310780077.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-29
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2043-06-29
AI Technical Summary
When the CPU single disk utilization rate of a switch or router is very high, it is difficult for the existing technology to complete the stream sampling task efficiently, resulting in the task being unable to complete or affect the normal operation of the equipment.
By polling, obtain the CPU real-time utilization and sampling task status of each single disk, determine whether there is an optimal parsing single disk, and transfer the stream sampled message to the optimal parsing single disk for parsing, so as to reduce the consumption of CPU resources and memory space on this disk.
On the basis of rationally utilizing the existing CPU resources of the device, efficiently complete the flow sampling task, ensure the normal operation of the device, improve the smoothness and efficiency, and avoid port congestion.
Smart Images

Figure CN116708250B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication packet technology, and in particular to a flow sampling control method, apparatus, device, and readable storage medium. Background Art
[0002] NetFlow is a network monitoring feature that collects the number and information of IP packets entering and leaving a network interface. It is primarily used in products such as routers and switches. By analyzing the information collected by NetFlow, network administrators can understand the source and destination of packets, the types of network services, and the causes of network congestion.
[0003] Because sampling, extracting, and parsing network traffic consumes a significant amount of CPU resources, switches and routers with numerous ports and a high volume of internally exchanged data require extensive computation to sample and monitor network traffic, consuming significant CPU resources. Consequently, enabling flow sampling to monitor the network when CPU utilization is high on a switch or router will prevent the flow sampling task from completing, potentially impacting the device's normal operation. Therefore, efficiently completing flow sampling tasks when CPU utilization is high is a pressing issue. Summary of the Invention
[0004] The present application provides a flow sampling control method, apparatus, device and readable storage medium, so as to efficiently complete the flow sampling task when the CPU single disk occupancy rate is very high.
[0005] In a first aspect, a flow sampling control method is provided, comprising the following steps:
[0006] Poll to obtain the real-time CPU utilization and sampling task status of each single disk;
[0007] Determine whether there is an optimal parsing disk based on the CPU real-time utilization and the sampling task status, and obtain a determination result;
[0008] When a stream sampling task needs to be deployed on a target disk, the optimal parsing disk is determined to perform the parsing task based on the judgment result and the target disk's CPU real-time utilization.
[0009] If so, the flow sampling message obtained by the target disk is parsed based on the optimal parsing disk to complete the flow sampling task.
[0010] In some embodiments, determining whether an optimal parsing disk exists based on the real-time CPU utilization and the sampling task status, and obtaining a determination result, includes:
[0011] Determine whether the real-time CPU utilization of all single disks is greater than or equal to a preset first percentage threshold;
[0012] If so, it is determined that there is no optimal parsing single disk;
[0013] If not, an optimal parsing disk is determined from disks whose CPU real-time utilization is less than a first percentage threshold according to the CPU real-time utilization and the sampling task status.
[0014] In some embodiments, determining the optimal parsing disk from disks having a CPU real-time utilization less than a first percentage threshold according to the CPU real-time utilization and the sampling task status includes:
[0015] When there is at least one first single disk whose CPU real-time utilization is less than the first percentage threshold, determining whether the sampling task status of all first single disks is in the deployed state;
[0016] If so, the first disk with the lowest CPU real-time utilization is selected as the optimal resolution disk;
[0017] If not, the single disk with the lowest CPU real-time utilization is selected from the first single disk whose sampling task status is in the undeployed state as the optimal parsing single disk.
[0018] In some embodiments, determining whether to use the optimal parsing disk to perform the parsing task based on the judgment result and the real-time CPU utilization of the target disk includes:
[0019] When the result of the judgment is that the optimal resolution disk exists, it is determined whether the CPU real-time utilization rate of the target disk is less than a preset second percentage threshold;
[0020] If so, it is determined that the parsing task is not performed by the optimal parsing disk;
[0021] If not, it is determined that the parsing task is performed by the optimal parsing disk.
[0022] In some embodiments, before the step of determining whether the real-time CPU utilization of the target single disk is less than a preset second percentage threshold, the method further includes:
[0023] The CPU utilization correction value is calculated based on the standard utilization of the target single disk, the scalable utilization of the target single disk, and the total utilization of all threads corresponding to all single disks in the device;
[0024] The CPU real-time utilization of the target single disk is corrected based on the CPU availability correction value to obtain a corrected CPU real-time utilization, and the step of determining whether the CPU real-time utilization of the target single disk is less than a preset second percentage threshold is performed based on the corrected CPU real-time utilization.
[0025] In some embodiments, the method further comprises:
[0026] When the judgment result is that there is no optimal parsing disk or the CPU real-time utilization rate of the target disk is less than the second percentage threshold, it is determined that the target disk will perform the parsing task.
[0027] In some embodiments, after the step of parsing the stream sampling message obtained by the target disk based on the optimal parsing disk, the method further includes:
[0028] The new flow sampling message obtained by parsing is sent to the traffic analysis server through the optimal parsing disk, so that the traffic analysis server can analyze and monitor the current network traffic based on the new flow sampling message.
[0029] In a second aspect, a flow sampling control device is provided, comprising a main control disk and a target single disk;
[0030] The master control disk is used to poll and obtain the CPU real-time utilization and sampling task status of each single disk; based on the CPU real-time utilization and the sampling task status, it is determined whether there is an optimal parsing single disk, and a judgment result is obtained;
[0031] The target disk is used to determine whether the optimal parsing disk will perform the parsing task when the target disk needs to deploy a flow sampling task, based on the judgment result and the real-time CPU utilization of the target disk; if so, the optimal parsing disk is used to parse the flow sampling message obtained by the target disk to complete the flow sampling task.
[0032] In a third aspect, a flow sampling control device is provided, comprising: a memory and a processor, wherein the memory stores at least one instruction, and the processor loads and executes the at least one instruction to implement the aforementioned flow sampling control method.
[0033] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions. When the computer instructions are executed by a computer, the computer is caused to execute the aforementioned flow sampling control method.
[0034] The present application provides a flow sampling control method, apparatus, device and readable storage medium, including polling to obtain the CPU real-time utilization and sampling task status of each single disk; judging whether there is an optimal parsing single disk based on the CPU real-time utilization and the sampling task status, and obtaining a judgment result; when the target single disk needs to deploy a flow sampling task, determining whether the optimal parsing single disk performs the parsing task based on the judgment result and the CPU real-time utilization of the target single disk; if so, parsing the flow sampling message obtained by the target single disk based on the optimal parsing single disk to complete the flow sampling task. Through the present application, when the target single disk needs to deploy a flow sampling task, the optimal parsing single disk will be selected according to the CPU real-time utilization of each single disk to parse and process the flow sampling message, that is, the flow sampling message obtained on the target single disk will be transferred to other disks for parsing, so as to reduce the consumption of the CPU resources of the disk and the consumption of the memory space of the disk, thereby ensuring the feasibility of NetFlow flow sampling deployment on the basis of rationally utilizing the existing CPU resources of the device, so that the flow sampling task can be completed efficiently. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0036] Figure 1 A flow chart of a flow sampling control method provided in an embodiment of the present application;
[0037] Figure 2 A schematic diagram of a process for determining the optimal parsing disk according to an embodiment of the present application;
[0038] Figure 3 A schematic diagram of a process for determining a target disk to perform a parsing task provided in an embodiment of the present application;
[0039] Figure 4 This is a structural diagram of a flow sampling control device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0040] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0041] The embodiments of the present application provide a flow sampling control method, apparatus, device, and readable storage medium, so as to efficiently complete the flow sampling task when the CPU single disk occupancy rate is very high.
[0042] Figure 1 A flow sampling control method provided in an embodiment of the present application includes the following steps:
[0043] Step S10: polling to obtain the real-time CPU utilization and sampling task status of each single disk;
[0044] For example, it's understandable that for devices like routers and switches, when the volume of data exchanged internally is very large, a significant amount of CPU resources is consumed to sample, extract, and parse network traffic, resulting in high CPU utilization per disk. When CPU utilization is high, it becomes impossible to deploy flow sampling tasks, or even guarantee the complete execution of tasks. New flow sampling tasks often have to be initiated to monitor the network. This not only prevents successful task completion but can also impact the normal operation of the device, reducing the overall device's performance and efficiency. Therefore, when CPU utilization is high and cannot accommodate flow sampling tasks, how to effectively utilize the entire device's CPU resources to efficiently complete flow sampling tasks is a pressing issue.
[0045] In order to solve the above problems, this embodiment will coordinate the existing resources of the device to efficiently complete the flow sampling task, ensuring that the task is completed smoothly and that the normal operation of the device is not affected, thereby improving the fluency and efficiency of the entire device. Specifically, a timer is first set for each single disk in the device, and the main control disk polls each single disk based on the timer. It should be noted that the duration of the timer can be determined according to actual needs. For example, if it is set to 5 minutes, each single disk will report its own CPU real-time utilization and sampling task status to the main control disk every 5 minutes. The cpu_used flag can be used to identify the CPU real-time utilization, and the reserve_flag flag can be used to indicate the sampling task status. Specifically, the reserve_flag can be set to 1 to indicate that the sampling task status is a deployed sampling task, while the reserve_flag can be set to 0 to indicate that the sampling task status is a non-deployed sampling task.
[0046] When the master control disk receives the real-time CPU utilization and sampling task status reported by each single disk, it will collect statistics on them to determine the real-time CPU utilization and sampling task status of each single disk.
[0047] Step S20: determining whether there is an optimal parsing disk based on the CPU real-time utilization and the sampling task status, and obtaining a determination result;
[0048] For example, it should be understood that the size of the CPU real-time utilization rate indicates whether there are idle or large CPU resources in the single disk for processing other tasks, that is, the ability of the single disk to process other tasks can be known through the CPU real-time utilization rate; and the sampling task status indicates whether the single disk is currently executing a stream sampling task. If so, it means that part of the CPU resources of the single disk have been occupied by other stream sampling tasks, so its ability to process other tasks is relatively weak; if not, it means that the CPU resources of the single disk are not occupied by other stream sampling tasks, so its ability to process other tasks is relatively strong.
[0049] Therefore, in this embodiment, the main control disk will determine whether there is a single disk that can parse the flow sampling messages of other single disks based on the real-time CPU utilization and sampling task status of each single disk. If so, it will be used as the optimal parsing single disk to share the pressure of executing the flow sampling task with other single disks.
[0050] Furthermore, the determining whether there is an optimal parsing disk based on the CPU real-time utilization and the sampling task status, and obtaining a determination result, includes:
[0051] Determine whether the real-time CPU utilization of all single disks is greater than or equal to a preset first percentage threshold;
[0052] If so, it is determined that there is no optimal parsing single disk;
[0053] If not, an optimal parsing disk is determined from disks whose CPU real-time utilization is less than a first percentage threshold according to the CPU real-time utilization and the sampling task status.
[0054] For example, in this embodiment, the specific value of the first percentage threshold can be determined according to actual network requirements and is not limited here. For example, if the first percentage threshold is set to 60%, then for each single disk, see Figure 2 As shown, determine whether the real-time CPU utilization of each disk is greater than or equal to 60%. If so, this indicates that the disk's CPU utilization is already high, leaving no free CPU resources for other tasks. This indicates that the disk's ability to handle other tasks is limited and should be discarded as a backup disk for sampling. Therefore, it should not be considered when selecting the optimal resolution disk. If the real-time CPU utilization of all disks is greater than or equal to 60%, this indicates that no disk in the current device is available for other tasks. This indicates that the optimal resolution disk does not exist. In this case, the flag slot_idS indicating the presence of an optimal resolution disk can be set to a fixed value.
[0055] It should be noted that the fixed value can be any value as long as it can indicate that there is no optimal resolution disk and can be recognized by the computer. For example, if the fixed value is set to 0xff, then when there is no optimal resolution disk, slot_idS is set to 0xff, that is, the master disk will send slot_idS = 0xff to each single disk to inform each single disk that there is no optimal resolution disk.
[0056] If there is a single disk with a CPU real-time utilization rate of less than 60%, the optimal parsing disk is determined from these single disks based on the CPU real-time utilization rate and the sampling task status. The optimal parsing disk information is sent to each single disk that has reported the CPU real-time utilization rate, so that other single disks can choose whether to share the pressure of executing the flow sampling task through the optimal parsing disk.
[0057] Furthermore, determining the optimal parsing disk from the disks whose CPU real-time utilization is less than a first percentage threshold according to the CPU real-time utilization and the sampling task status includes:
[0058] When there is at least one first single disk whose CPU real-time utilization is less than the first percentage threshold, determining whether the sampling task status of all first single disks is in the deployed state;
[0059] If so, the first disk with the lowest CPU real-time utilization is selected as the optimal resolution disk;
[0060] If not, the single disk with the lowest CPU real-time utilization is selected from the first single disk whose sampling task status is in the undeployed state as the optimal parsing single disk.
[0061] For example, see Figure 2 As described above, when there is at least one first single disk whose CPU real-time utilization is less than 60%, it is necessary to determine whether each first single disk has deployed a stream sampling task based on the reserve_flag value of each first single disk, that is, if reserve_flag = 1, it means that the first single disk has deployed a stream sampling task, and if reserve_flag = 0, it means that the first single disk has not yet deployed a stream sampling task.
[0062] If the reserve_flag of all first disks is 1, it indicates that the stream sampling task has been deployed on all first disks. In this case, only the first disk A with the smallest cpu_used can be used as the optimal parsing disk, and slot_idS is assigned to the slot number of the first disk A. If there are multiple first disks A with the smallest cpu_used, the first disk B with the smallest slot number is selected from the multiple first disks A with the smallest cpu_used, and slot_idS is assigned to the slot number of the first disk B.
[0063] When there is at least one first single disk whose reserve_flag is equal to 0, it indicates that at least one first single disk has not yet deployed a flow sampling task. In this case, the first single disk that has not yet deployed a flow sampling task is selected to enter the sampling standby disk pool, and the first single disk D with the smallest cpu_used is selected from the first single disk C that has not yet deployed a flow sampling task as the optimal parsing single disk, and slot_idS is assigned to the slot number of the first single disk D; if there are multiple first single disks D with the smallest cpu_used, the first single disk E with the smallest slot number is selected from the multiple first single disks D with the smallest cpu_used, and slot_idS is assigned to the slot number of the first single disk E.
[0064] Step S30: When the target disk needs to deploy a stream sampling task, determine whether the optimal parsing disk will perform the parsing task based on the judgment result and the real-time CPU utilization of the target disk;
[0065] For example, in this embodiment, see Figure 3 As shown in the figure, when the target single disk needs to deploy a stream sampling task, that is, when the stream sampling task needs to be executed, it polls once based on a 5-minute timer, obtains the slot_idS value from the main control disk and stores it, and then determines whether other single disks will perform the parsing task based on the slot_idS value to share the stream sampling task.
[0066] Specifically, when the slot_idS value is equal to 0xff, it means that there is no optimal parsing disk at present, that is, the stream sampling task cannot be shared by other disks, and the parsing task can only be performed by the target disk itself. In this case, the parsing disk is set as the current disk and the setting is stored. When the slot_idS value is not equal to 0xff, that is, it is equal to a specific slot number, it means that there is an optimal parsing disk. At this time, the cpu_used of the target disk will be further used to judge whether it is capable of completing the entire stream sampling task alone. If it is capable, it means that it can complete the parsing task by itself. In this case, the parsing disk is set as the current disk and the setting is stored. If it is not capable, it is determined that the parsing task is completed by the optimal parsing disk. In this case, the parsing disk will be set as the ID of the optimal parsing disk corresponding to the slot number corresponding to slot_idS issued by the main control disk, and the setting will be stored.
[0067] It is understandable that after the target disk determines the object to perform the parsing task, it will still report its own cpu_used and reserve_flag to the main control disk regularly (for example, every 5 minutes) so that the main control disk can adjust and update the optimal parsing disk in the device in real time.
[0068] Furthermore, the determining whether to use the optimal parsing disk to perform the parsing task based on the judgment result and the real-time CPU utilization of the target disk includes:
[0069] When the result of the judgment is that the optimal resolution disk exists, it is determined whether the CPU real-time utilization rate of the target disk is less than a preset second percentage threshold;
[0070] If so, it is determined that the parsing task is not performed by the optimal parsing disk;
[0071] If not, it is determined that the parsing task is performed by the optimal parsing disk;
[0072] When the judgment result is that there is no optimal parsing disk or the CPU real-time utilization rate of the target disk is less than the second percentage threshold, it is determined that the target disk will perform the parsing task.
[0073] For example, it should be noted that the specific value of the second percentage threshold can be determined according to actual network requirements. It can be the same as or different from the first percentage threshold, and is not limited here. For example, the second percentage threshold can also be set to 60%. Figure 3 As shown in the figure, when the slot_idS value is equal to 0xff, that is, there is no optimal parsing disk at present, it will be determined that the target disk itself performs the parsing task; when the slot_idS value is equal to a specific slot number, it means that there is an optimal parsing disk at present. At this time, it will be determined whether the cpu_used of the target disk is less than 60%. If so, it means that the target disk is capable of completing the entire stream sampling task alone, that is, no other disks are needed to share the parsing task. Therefore, it is determined that the parsing task is not performed by the optimal parsing disk, but by the target disk itself, that is, the parsing disk is set as the local disk and the setting is stored.
[0074] If the cpu_used of the target disk is greater than or equal to 60%, it indicates that the target disk is unable to complete the entire stream sampling task alone. That is, other disks are needed to share the parsing task. Therefore, the optimal parsing disk is determined to perform the parsing task. The parsing disk is set as the ID of the optimal parsing disk issued by the master disk and the setting is stored.
[0075] Furthermore, before the step of determining whether the real-time CPU utilization of the target single disk is less than a preset second percentage threshold, the method further includes:
[0076] The CPU utilization correction value is calculated based on the standard utilization of the target single disk, the scalable utilization of the target single disk, and the total utilization of all threads corresponding to all single disks in the device;
[0077] The CPU real-time utilization of the target single disk is corrected based on the CPU availability correction value to obtain a corrected CPU real-time utilization, and the step of determining whether the CPU real-time utilization of the target single disk is less than a preset second percentage threshold is performed based on the corrected CPU real-time utilization.
[0078] For example, in this embodiment, since the cpu_used of each single disk changes in real time during the operation of the device, that is, when the target single disk needs to deploy a stream sampling task, its cpu_used may be different from the cpu_used reported to the main control disk. At this time, in order to more accurately determine the cpu_used of the target single disk, the cpu_used will be corrected and updated. Specifically, the real-time CPU utilization correction value p of the target single disk is first calculated, that is, the standard utilization of the target single disk, the scalable utilization of the target single disk, and the total utilization of all threads corresponding to all single disks in the device are substituted into the following calculation formula to obtain the CPU utilization correction value p:
[0079]
[0080] Where M a Indicates the standard utilization of the target single disk, M k Indicates the scalable utilization rate of the target single disk. Indicates the total utilization of all threads corresponding to all disks in the device.
[0081] After calculating the CPU utilization correction value p, the result of 1-p is used as the latest cpu_used of the target disk. The latest cpu_used is then used to determine whether the target disk has the ability to process the stream sampling task. If the latest cpu_used is less than 60%, it means that the target disk can accept and run the stream sampling task. If the latest cpu_used is greater than or equal to 60%, the target disk will not accept the stream sampling task.
[0082] Step S40: If yes, the flow sampling message obtained by the target disk is parsed based on the optimal parsing disk to complete the flow sampling task.
[0083] Exemplarily, in this embodiment, when the target single disk is driven to perform the stream sampling task and obtains the stream sampling message, its underlying chip module will determine whether to parse the stream sampling message on this disk based on the stored settings. If so, the stream sampling message will be parsed directly on this disk; if not, the stream sampling message will be forwarded to the optimal parsing single disk based on the ID number stored in the settings, and the stream sampling message will be parsed by the optimal parsing single disk.
[0084] Among them, the specific process of parsing is as follows: encapsulating the flow sampling message and marking it as an NFS (Netflow Sample Select, Netflow flow sampling message extraction) message; then based on the NFS component in the optimal parsing disk, the message callback is performed to trigger the message unpacking process, and the flow sampling message is matched and extracted through the ACL (Access Control List, Access Control List) message to obtain the parsed flow sampling message; the processed flow sampling message is stored in the buffer of the NFS component, and when the aging condition is met, the processed flow sampling message is output to the NFE (Netflow Sample Export, Netflow flow sampling message output) component in the optimal parsing disk for aging and output; the NFE component assembles the parsed flow sampling message according to the format of Netflow v5 or NetflowV9, and sends it to the driver chip through the protocol processing interface. The chip sends the message to the corresponding server through routing lookup according to the DIP (i.e., destination IP) in the message, thus completing the parsing of the flow sampling message.
[0085] It can be seen that in this embodiment, when the amount of data exchanged internally by devices such as routers is too large, that is, when the current disk is unable to bear the flow sampling task, the flow sampling message will be transferred to other disks for parsing, aging storage and other processing to reduce the consumption of the CPU resources of the current disk; at the same time, it can be understood that the flow sampling message needs to be stored in the buffer and aged and output only when the aging condition is met. In this embodiment, the above-mentioned processing of the flow sampling message is also transferred to other disks for processing, thereby reducing the consumption of the memory space of the current disk.
[0086] Furthermore, after the step of parsing the stream sampling message obtained by the target disk based on the optimal parsing disk, the method further includes:
[0087] The new flow sampling message obtained by parsing is sent to the traffic analysis server through the optimal parsing disk, so that the traffic analysis server can analyze and monitor the current network traffic based on the new flow sampling message.
[0088] For example, in this embodiment, after the optimal parsing disk performs standardization processing on the flow sampling message and completes assembly, it will encapsulate the routing header and call the NIO (network host protocol packet processing module) interface to send it to the corresponding line port. That is, after the optimal parsing disk completes the flow sampling parsing, aging and encapsulation, the encapsulated flow sampling message is directly forwarded to the corresponding traffic analysis server through the optimal parsing disk, so that the traffic analysis server can analyze and monitor the current network traffic based on the received flow sampling message.
[0089] It can be seen that in this embodiment, since the target single disk transmits the obtained sampling data to the traffic analysis server based on other service ports (i.e., the optimal analysis single disk), there is no need to occupy the service traffic bandwidth of this disk, thereby avoiding the obvious congestion caused by peak burst data transmission in the network, thereby improving the forwarding performance of the device to a certain extent.
[0090] In summary, through this application, when the target single disk needs to deploy a flow sampling task, the optimal parsing single disk will be selected based on the real-time CPU utilization of each single disk to parse and age the flow sampling message. That is, the flow sampling message obtained on the target single disk will be transferred to other disks for parsing and aging storage, so as to reduce the consumption of the CPU resources of this disk and the consumption of the memory space of this disk. Then, on the basis of rationally utilizing the existing CPU resources of the device, the feasibility of NetFlow flow sampling deployment is guaranteed, so that the flow sampling task can be completed efficiently and the normal operation of the device can be guaranteed to be not affected, so as to improve the fluency and efficiency of the entire device. In addition, the obtained sampling data is transmitted to the traffic analysis server through other service ports, thereby avoiding port congestion and improving the forwarding performance of the device.
[0091] It should be noted that the step numbers of the steps in the embodiments of the present application do not limit the order of the operations in the technical solution of the present application.
[0092] The embodiment of the present application also provides a flow sampling control device, including a main control disk and a target single disk;
[0093] The master control disk is used to poll and obtain the CPU real-time utilization and sampling task status of each single disk; based on the CPU real-time utilization and the sampling task status, it is determined whether there is an optimal parsing single disk, and a judgment result is obtained;
[0094] The target disk is used to determine whether the optimal parsing disk will perform the parsing task when the target disk needs to deploy a flow sampling task, based on the judgment result and the real-time CPU utilization of the target disk; if so, the optimal parsing disk is used to parse the flow sampling message obtained by the target disk to complete the flow sampling task.
[0095] Furthermore, the main control disk is specifically used for:
[0096] Determine whether the real-time CPU utilization of all single disks is greater than or equal to a preset first percentage threshold;
[0097] If so, it is determined that there is no optimal parsing single disk;
[0098] If not, an optimal parsing disk is determined from disks whose CPU real-time utilization is less than a first percentage threshold according to the CPU real-time utilization and the sampling task status.
[0099] Furthermore, the main control disk is also specifically used for:
[0100] When there is at least one first single disk whose CPU real-time utilization is less than the first percentage threshold, determining whether the sampling task status of all first single disks is in the deployed state;
[0101] If so, the first disk with the lowest CPU real-time utilization is selected as the optimal resolution disk;
[0102] If not, the single disk with the lowest CPU real-time utilization is selected from the first single disk whose sampling task status is in the undeployed state as the optimal parsing single disk.
[0103] Furthermore, the target single disk is specifically used for:
[0104] When the result of the judgment is that the optimal resolution disk exists, it is determined whether the CPU real-time utilization rate of the target disk is less than a preset second percentage threshold;
[0105] If so, it is determined that the parsing task is not performed by the optimal parsing disk;
[0106] If not, it is determined that the parsing task is performed by the optimal parsing disk.
[0107] Furthermore, the target single disk is further used for:
[0108] The CPU utilization correction value is calculated based on the standard utilization of the target single disk, the scalable utilization of the target single disk, and the total utilization of all threads corresponding to all single disks in the device;
[0109] The CPU real-time utilization of the target single disk is corrected based on the CPU availability correction value to obtain a corrected CPU real-time utilization, and the step of determining whether the CPU real-time utilization of the target single disk is less than a preset second percentage threshold is performed based on the corrected CPU real-time utilization.
[0110] Furthermore, the target single disk is further used for:
[0111] When the judgment result is that there is no optimal parsing disk or the CPU real-time utilization rate of the target disk is less than the second percentage threshold, it is determined that the target disk will perform the parsing task.
[0112] Furthermore, the optimal parsing disk is further configured to send the new flow sampling message obtained by parsing to the traffic analysis server, so that the traffic analysis server can analyze and monitor the existing network traffic based on the new flow sampling message.
[0113] It should be noted that those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the above-described device and each part can refer to the corresponding process in the aforementioned flow sampling control method embodiment, and will not be repeated here.
[0114] The apparatus provided in the above embodiment can be implemented in the form of a computer program. The computer program can be used in Figure 4 The flow shown is run on a sampling control device.
[0115] An embodiment of the present application further provides a stream sampling control device, comprising: a memory, a processor, and a network interface connected via a system bus, wherein the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement all or part of the steps of the aforementioned stream sampling control method.
[0116] Among them, the network interface is used for network communication, such as sending assigned tasks, etc. Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0117] The processor may be a CPU, other general-purpose processors, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor, or any conventional processor. The processor is the control center of a computer device, connecting various parts of the entire computer device using various interfaces and lines.
[0118] The memory can be used to store computer programs and / or modules. The processor implements various functions of the computer device by running or executing the computer programs and / or modules stored in the memory, and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area. The program storage area can store an operating system, at least one application required for a function (such as a video playback function, an image playback function, etc.), etc.; the data storage area can store data created based on the use of the mobile phone (such as video data, image data, etc.). In addition, the memory can include high-speed random access memory and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, an SMC (SmartMediaCard, smart memory card), an SD (Secure Digital) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0119] The embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, all or part of the steps of the aforementioned flow sampling control method are implemented.
[0120] The embodiments of the present application implement all or part of the aforementioned processes, and may also be completed by instructing related hardware through a computer program. The computer program may be stored in a computer-readable storage medium, and when the computer program is executed by a processor, the steps of each of the above methods may be implemented. Among them, the computer program includes computer program code, and the computer program code may be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, ROM (Read-Only memory), RAM (Random Access memory), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0121] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, servers, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage) containing computer-usable program code.
[0122] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems) and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0123] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.
[0124] The foregoing is merely a list of specific embodiments of the present application, intended to enable those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the broadest scope consistent with the principles and novel features of the present application.
Claims
1. A flow sampling control method, characterized in that: The following steps are involved: Poll to obtain the real-time CPU utilization and sampling task status of each single disk; Determine whether there is an optimal parsing disk based on the CPU real-time utilization and the sampling task status, and obtain a determination result; When a stream sampling task needs to be deployed on a target disk, the optimal parsing disk is determined to perform the parsing task based on the judgment result and the target disk's CPU real-time utilization. If so, the flow sampling message obtained by the target disk is parsed based on the optimal parsing disk to complete the flow sampling task.
2. The flow sampling control method according to claim 1, wherein: The determining whether there is an optimal parsing disk based on the CPU real-time utilization and the sampling task status, and obtaining a determination result, includes: Determine whether the real-time CPU utilization of all single disks is greater than or equal to a preset first percentage threshold; If so, it is determined that there is no optimal parsing single disk; If not, an optimal parsing disk is determined from disks whose CPU real-time utilization is less than a first percentage threshold according to the CPU real-time utilization and the sampling task status.
3. The flow sampling control method according to claim 2, wherein: The determining, according to the CPU real-time utilization and the sampling task status, an optimal parsing disk from the disks whose CPU real-time utilization is less than a first percentage threshold, includes: When there is at least one first single disk whose CPU real-time utilization is less than the first percentage threshold, determining whether the sampling task status of all first single disks is in the deployed state; If so, the first disk with the lowest CPU real-time utilization is selected as the optimal resolution disk; If not, the single disk with the lowest CPU real-time utilization is selected from the first single disk whose sampling task status is in the undeployed state as the optimal parsing single disk.
4. The flow sampling control method according to claim 1, wherein: The determining whether to use the optimal parsing disk to perform the parsing task based on the judgment result and the real-time CPU utilization of the target disk includes: When the result of the judgment is that the optimal resolution disk exists, it is determined whether the CPU real-time utilization rate of the target disk is less than a preset second percentage threshold; If so, it is determined that the parsing task is not performed by the optimal parsing disk; If not, it is determined that the parsing task is performed by the optimal parsing disk.
5. The flow sampling control method according to claim 4, wherein: Before the step of determining whether the real-time CPU utilization of the target single disk is less than a preset second percentage threshold, the method further includes: The CPU utilization correction value is calculated based on the standard utilization of the target single disk, the scalable utilization of the target single disk, and the total utilization of all threads corresponding to all single disks in the device; The CPU real-time utilization of the target single disk is corrected based on the CPU availability correction value to obtain a corrected CPU real-time utilization, and the step of determining whether the CPU real-time utilization of the target single disk is less than a preset second percentage threshold is performed based on the corrected CPU real-time utilization.
6. The flow sampling control method according to claim 4, wherein: The method further comprises: When the judgment result is that there is no optimal parsing disk or the CPU real-time utilization rate of the target disk is less than the second percentage threshold, it is determined that the target disk will perform the parsing task.
7. The flow sampling control method according to claim 1, wherein: After the step of parsing the stream sampling message obtained by the target disk based on the optimal parsing disk, the method further includes: The new flow sampling message obtained by parsing is sent to the traffic analysis server through the optimal parsing disk, so that the traffic analysis server can analyze and monitor the current network traffic based on the new flow sampling message.
8. A flow sampling control device, characterized in that: Including master disk and target disk; The master control disk is used to poll and obtain the CPU real-time utilization and sampling task status of each single disk; based on the CPU real-time utilization and the sampling task status, it is determined whether there is an optimal parsing single disk, and a judgment result is obtained; The target disk is used to determine whether the optimal parsing disk will perform the parsing task when the target disk needs to deploy a flow sampling task, based on the judgment result and the real-time CPU utilization of the target disk; if so, the optimal parsing disk is used to parse the flow sampling message obtained by the target disk to complete the flow sampling task.
9. A flow sampling control device, characterized in that: include: A memory and a processor, wherein the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the flow sampling control method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a computer, the computer is caused to execute the flow sampling control method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Scheduling method of task running and related device
CN108897622A
Distributed crawler implementation method and device
CN112597372A