A log-based analysis method and device, electronic equipment and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-07
- Publication Date
- 2026-08-11
AI Technical Summary
尽管大型语言模型在许多自然语言处理任务上表现出色,但它们的决策过程往往是黑盒的,缺乏直观的解释性,效率低并且关联性差
[0021]本发明实施例的技术方案,通过获取与当前查询条件对应的日志集,并根据预设的日志分析数量阈值,来确定出待分析日志集;获取与各待分析日志分别对应的目标标识符,并通过预设标识符类型分类处理方法进行匹配,得到各标识符待分析日志;通过预设分块数量,来对各标识符待分析日志进行分块处理,分别得到与各目标标识符对应的至少一个当前分块结果;按照分块结果训练方法来对各当前分块结果进行训练,确定出各当前分块结果分别对应的临时Lora参数权重,并确定出日志分析结果和反馈操作。解决了日志分析时间成本高和关联性差的问题,可以更好地对大量的日志进行分析处理,可以更好地对日志上下文进行关联处理,降低了日志分析的难度,提高了日志分析的速率和准确率,节约了时间成本。
Smart Images

Figure CN118227580B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a log analysis-based method, apparatus, electronic device, and storage medium. Background Technology
[0002] With the rapid development of artificial intelligence technology, log data is becoming increasingly abundant. Due to the special format and structure of log data, log data analysis is also crucial.
[0003] In the process of developing this invention, the inventors discovered the following shortcomings in existing technologies: Currently, attempts are made to directly analyze log data using large pre-trained language models. However, because log files typically contain a large number of technical terms, abbreviations, domain-specific markup languages, and other non-standard language usages, the log format follows specific templates or structures that are difficult for models designed for processing natural language text to directly understand and process. Furthermore, due to limitations in contextual relevance, log analysis often requires understanding long-term dependencies across multiple entries. Although large language models perform well on many natural language processing tasks, their decision-making processes are often black-box, lack intuitive interpretability, are inefficient, and have poor correlation. Summary of the Invention
[0004] This invention provides a log analysis method, apparatus, electronic device, and storage medium to improve the speed and accuracy of log analysis and save time costs.
[0005] According to one aspect of the present invention, a log analysis method is provided, comprising:
[0006] Obtain the log set corresponding to the current query conditions, and determine the log set to be analyzed based on the preset log analysis quantity threshold;
[0007] The log set to be analyzed includes at least one log entry to be analyzed.
[0008] Obtain the target identifiers corresponding to each of the logs to be analyzed, and match them using a preset identifier type classification processing method to obtain the logs to be analyzed for each identifier;
[0009] By pre-setting the number of blocks, the log to be analyzed by each identifier is divided into blocks, and at least one current block result corresponding to each target identifier is obtained.
[0010] The current block result is trained according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result;
[0011] Based on the weights of each temporary LoRa parameter and the results of each current block, the log analysis results corresponding to the current query conditions are determined, and the log analysis results are fed back.
[0012] According to another aspect of the present invention, a log analysis apparatus is provided, comprising:
[0013] The log set to be analyzed module is used to obtain the log set corresponding to the current query conditions and determine the log set to be analyzed based on the preset log analysis quantity threshold.
[0014] The log set to be analyzed includes at least one log entry to be analyzed.
[0015] The identifier-to-analyze log acquisition module is used to obtain the target identifiers corresponding to each of the logs to be analyzed, and to match them using a preset identifier type classification processing method to obtain the logs to be analyzed for each identifier.
[0016] The current block result acquisition module is used to divide the log to be analyzed by each identifier into blocks by a preset number of blocks, and obtain at least one current block result corresponding to each target identifier.
[0017] The temporary LoRa parameter weight determination module is used to train each current block result according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result.
[0018] The log analysis result feedback module is used to determine the log analysis result corresponding to the current query condition based on the weight of each temporary LoRa parameter and the result of each current block, and to feed back the log analysis result.
[0019] According to another aspect of the present invention, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the log analysis method described in any embodiment of the present invention.
[0020] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the log analysis method according to any embodiment of the present invention.
[0021] The technical solution of this invention obtains a log set corresponding to the current query conditions and determines the log set to be analyzed based on a preset log analysis quantity threshold; obtains target identifiers corresponding to each log to be analyzed and matches them using a preset identifier type classification processing method to obtain logs to be analyzed for each identifier; divides each log to be analyzed for each identifier into blocks using a preset number of blocks, obtaining at least one current block result corresponding to each target identifier; trains each current block result according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result, and determines the log analysis results and feedback operations. This solves the problems of high time cost and poor correlation in log analysis, enabling better analysis and processing of large amounts of logs, better correlation processing of log context, reducing the difficulty of log analysis, improving the speed and accuracy of log analysis, and saving time costs.
[0022] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a flowchart of a log analysis method provided in Embodiment 1 of the present invention;
[0025] Figure 2 This is a schematic diagram of the structure of a log analysis device according to Embodiment 2 of the present invention;
[0026] Figure 3 This is a schematic diagram of the structure of an electronic device provided according to Embodiment 3 of the present invention. Detailed Implementation
[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "target," "current," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0029] Example 1
[0030] Figure 1 The flowchart of a log analysis method is provided in Embodiment 1 of the present invention. This embodiment is applicable to the analysis and processing of log data. The method can be executed by a log analysis device, which can be implemented in hardware and / or software.
[0031] Correspondingly, such as Figure 1 As shown, the method includes:
[0032] S110. Obtain the log set corresponding to the current query conditions, and determine the log set to be analyzed based on the preset log analysis quantity threshold.
[0033] The log set to be analyzed includes at least one log entry.
[0034] Here, the current query condition can be a query condition entered by the user. The log set can be a collection of logs retrieved based on the current query condition. The log analysis quantity threshold can be a pre-set threshold for the number of logs to be analyzed. The log set to be analyzed can be the set of logs that need to be analyzed.
[0035] For example, suppose a query based on the current query conditions yields a log set of 24,000 log entries. If the threshold for log analysis is 20,000 entries, then 20,000 log entries can be selected from this set to determine the log set to be analyzed.
[0036] S120. Obtain the target identifiers corresponding to each of the logs to be analyzed, and match them using a preset identifier type classification processing method to obtain the logs to be analyzed for each identifier.
[0037] The target identifier can be an identifier contained in the logs. Each log entry may contain the same or different identifiers. Logs can be categorized using identifiers, with logs containing the same identifier showing higher correlation. The preset identifier type classification method can be a method for classifying logs based on identifiers. The logs to be analyzed can be multiple logs corresponding to different identifiers.
[0038] In this embodiment, the preset identifier type may include, but is not limited to, thread operation number, trajectory number, and user number.
[0039] Optionally, the step of obtaining the target identifier corresponding to each of the logs to be analyzed and matching them using a preset identifier type classification processing method to obtain the logs to be analyzed for each identifier includes: sequentially obtaining a current preset identifier in a preset identifier type; matching each target identifier with the current preset identifier using the preset identifier type classification processing method to obtain the current identifier logs to be analyzed; returning to execute the operation of sequentially obtaining a current preset identifier in a preset identifier type until all current preset identifiers in the preset identifier type have been traversed; determining whether there are any unmatched target identifiers; if so, determining the logs to be analyzed corresponding to the unmatched target identifiers as unmatched identifier logs to be analyzed, and obtaining the logs to be analyzed for each identifier based on the current identifier logs to be analyzed and the unmatched identifier logs to be analyzed; if not, determining the current identifier logs to be analyzed as the logs to be analyzed for each identifier.
[0040] The current preset identifier can be an identifier randomly obtained from the preset identifier type. The log to be analyzed for the current identifier can be at least one log to be analyzed corresponding to the current preset identifier.
[0041] For example, suppose the preset identifier type includes four current preset identifiers (current preset identifier 1, current preset identifier 2, current preset identifier 3, and current preset identifier 4). Specifically, suppose that in the logs to be analyzed, 5000 target identifiers match current preset identifier 1; 3550 target identifiers match current preset identifier 2; 3450 target identifiers match current preset identifier 3; 6000 target identifiers match current preset identifier 4; and the remaining 2000 log entries cannot be matched with the preset identifier type.
[0042] Specifically, within the preset identifier type, one current preset identifier is obtained sequentially; let's assume the first obtained is current preset identifier 1. Further, using the preset identifier type classification processing method, each target identifier is matched with current preset identifier 1 to obtain the logs to be analyzed for the current identifier, resulting in 5000 logs to be analyzed (the logs matched with current preset identifier 1 are: 5000 logs to be analyzed).
[0043] Similarly, it is necessary to obtain the current preset identifier 2, the current preset identifier 3 and the current preset identifier 4 in sequence, and determine the current identifier log to be analyzed corresponding to the current preset identifier 2, the current preset identifier 3 and the current preset identifier 4 respectively.
[0044] Furthermore, it is necessary to determine whether there are any unmatched target identifiers. Since there are 2,000 log entries to be analyzed that cannot be matched with the preset identifier type, these 2,000 log entries to be analyzed are identified as a new type of current identifier log entries to be analyzed, and combined with the above 4 groups of current identifier log entries to be analyzed to form the final identifier log entries to be analyzed.
[0045] Alternatively, assuming that no log entry to be analyzed cannot be matched with the preset identifier type, the above four groups of current identifier log entries to be analyzed will be used to form the final identifier log entry to be analyzed.
[0046] The advantage of this setup is that it allows for better handling of log analysis. By classifying logs based on target identifiers, the correlation between log categories can be improved, thereby increasing the accuracy and efficiency of log analysis.
[0047] S130. By pre-setting the number of blocks, the log to be analyzed by each identifier is divided into blocks to obtain at least one current block result corresponding to each target identifier.
[0048] The preset number of blocks can be a pre-set number of blocks for the log. The current block result can be the result of dividing multiple log entries with identifiers to be analyzed into blocks.
[0049] Optionally, the step of dividing the logs to be analyzed for each identifier into blocks by a preset number of blocks, and obtaining at least one current block result corresponding to each target identifier, includes: sequentially obtaining one current identifier log to be analyzed from each identifier log; dividing the current identifier log to be analyzed into blocks by a preset number of blocks, and performing a remainder operation on the preset number of blocks by the number of logs corresponding to the current identifier log to be analyzed, to obtain a remainder result; determining whether the remainder result is zero, if so, obtaining each current block result corresponding to the current identifier log to be analyzed; if not, extracting the number of current identifier logs corresponding to the remainder result from the current identifier log to be analyzed, determining it as one current block result, and combining it with the remaining current block results corresponding to the current identifier logs to be analyzed to determine at least one current block result; returning to execute the operation of sequentially obtaining one current identifier log to be analyzed from each identifier log to be analyzed, until all identifier logs to be analyzed are traversed to obtain at least one current block result corresponding to each target identifier.
[0050] Continuing the previous example, let's assume the following: The number of log entries to be analyzed for the current identifier that match the current preset identifier 1 is 5000. Let's assume the preset block size is 20.
[0051] First, the log to be analyzed by the current identifier is divided into blocks. The number of logs (5000) corresponding to the current identifier is divided by the preset number of blocks (20) and the remainder is zero. Since the remainder is zero, the current block results corresponding to the current identifier are obtained (that is, 5000 is divisible by 20, the quotient is 250, which means there are 250 current block results).
[0052] Furthermore, assuming the obtained current identifier log to be analyzed is: the current identifier log to be analyzed that matches the current preset identifier 2 is: 3550 log entries to be analyzed.
[0053] Similarly, by taking the remainder of the number of logs (3550) corresponding to the current identifier to be analyzed and the preset block number (20), the remainder result is 10, and the corresponding quotient is 177. The number of current identifier logs to be analyzed corresponding to the remainder result (10) is then determined as one current block result, meaning this current block result includes 10 current identifier logs to be analyzed. Since the quotient is 177, 177 current block results can be obtained. Combining these with the current block results consisting of 10 current identifier logs to be analyzed, 178 current block results can be obtained.
[0054] Similarly, we can obtain the current identifier log to be analyzed that matches the current preset identifier 3, the current identifier log to be analyzed that matches the current preset identifier 4, and the current block results corresponding to the 2000 logs to be analyzed that are determined to be a new type of current identifier log to be analyzed.
[0055] The advantage of this setting is that it allows for better block processing of the log to be analyzed with the current identifier, facilitates the training of the block results, and determines more accurate log analysis results.
[0056] S140. Train each current block result according to the block result training method to determine the temporary Lora parameter weights corresponding to each current block result.
[0057] The block result training method can be a method of training each current block result. The temporary LoRa parameter weights can be obtained by training the current block results to obtain the LoRa parameter weights corresponding to each current block result.
[0058] Optionally, the step of training each current block result according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result includes: obtaining the timestamp corresponding to each current block result, and sorting according to the timestamp to determine the time sorting result of the current block result; obtaining and training the target current block result according to the time sorting result of the current block result to obtain the target network token and temporary LoRa parameter weights, and adding the target network token to the next target current block result for training; returning to execute the operation of obtaining and training the target current block result to obtain the target network token and temporary LoRa parameter weights, until all current block results have been traversed, thus obtaining the temporary LoRa parameter weights corresponding to each current block result.
[0059] The timestamp can be a time label that matches each current block result. Since a timestamp can be matched with each current block result when it is determined, the current block results can be sorted according to the size of the timestamps to determine the time sorting result.
[0060] Continuing from the previous example, for the 250 current block results corresponding to the current preset identifier 1, the timestamps corresponding to these 250 current block results can be obtained respectively, and sorted according to the timestamps to obtain the corresponding current block result time sorting result (for example: current block result 1, current block result 2, current block result 3, ..., current block result 250).
[0061] Furthermore, firstly, the current block result 1 is acquired and trained to obtain the target network token 1 and the temporary LoRa parameter weight 1. The target network token 1 is then added to the next target current block result (i.e., current block result 2) for training. Next, current block result 2 (containing target network token 1) is trained to obtain the target network token 2 and the temporary LoRa parameter weight 2. Correspondingly, target network token 2 can be added to current block result 3 for training, and so on, until each current block result is traversed, and the corresponding temporary LoRa parameter weights for each current block result are obtained.
[0062] S150. Based on the weights of each temporary LoRa parameter and the results of each current block, determine the log analysis results corresponding to the current query conditions, and feed back the log analysis results.
[0063] The log analysis results can be the results obtained from analyzing the log set to be analyzed.
[0064] Specifically, the log analysis results include questions for each target and the corresponding answers to those questions.
[0065] Optionally, determining the log analysis result corresponding to the current query condition based on the weights of each temporary LoRa parameter and the results of each current block, and feeding back the log analysis result, includes: determining at least one system question based on the weights of each temporary LoRa parameter and the results of each current block; receiving at least one target question from the user, and determining whether each target question can match the system question; if so, feeding back each target question and the answer corresponding to each target question.
[0066] In this embodiment, the system can determine one or more system-asked questions based on the weights of each temporary LoRa parameter. Generally, the system selects the temporary LoRa parameter with the largest weight and the current block result that matches it. Furthermore, the system pre-filters questions that are either numerical or time-related, and asks questions that are neither numerical nor time-related.
[0067] Furthermore, assuming the system presents three system questions, these three system questions can be displayed on a system page. After receiving these three system questions, users can select one or more questions as their target questions, or users can edit a new target question themselves to provide feedback.
[0068] Accordingly, it is also necessary to determine whether each target question matches the system's question. If so, the target question and its corresponding answer are provided. If they do not match, and the user raises a question of numerical or time type, an additional process is required. Specifically, the log set to be analyzed needs to be traversed to obtain the results corresponding to the user's question of numerical or time type.
[0069] At the same time, each round of dialogue (the target question and the corresponding answer) needs to be recorded for retraining to improve the relevance and accuracy of log analysis.
[0070] Specifically, after determining the log analysis result corresponding to the current query condition based on the weights of each temporary LoRa parameter and the current block results, and feeding back the log analysis result, the process further includes: retraining each target question, the answer corresponding to each target question, and the log set to be analyzed according to the block result training method to determine each new temporary LoRa parameter weight; determining a new log analysis result corresponding to the current query condition based on each new temporary LoRa parameter weight and the new current block results, and feeding back the new log analysis result.
[0071] In this embodiment, it is necessary to obtain the target questions, the corresponding answers to each target question, and the log set to be analyzed. By performing the retraining operation in the previous manner, new temporary LoRa parameter weights and new current block results can be obtained. This also allows for the re-questioning and re-answering of the system, which can improve the accuracy of log analysis results, facilitate log analysis and processing operations, and increase the reusability of the log analysis system model.
[0072] Optionally, after determining the new log analysis result corresponding to the current query condition based on the new temporary LoRa parameter weights and the new current block results, and feeding back the new log analysis result, the method further includes: deleting the temporary LoRa parameter weights and the new temporary LoRa parameter weights after receiving the user's feedback instruction to end the dialogue.
[0073] In this embodiment, after determining that the user has ended the current conversation, it is necessary to delete the temporary LoRa parameter weights and the new temporary LoRa parameter weights. Since the current query conditions selected by the user are different each time, the set of logs to be analyzed is also different, and each log analysis is a new task. Deleting the temporary LoRa parameter weights and the new temporary LoRa parameter weights reduces the burden on the system's data storage and reduces interference with the system, thereby reducing the difficulty of log analysis and improving the speed and accuracy of log analysis.
[0074] The technical solution of this invention obtains a log set corresponding to the current query conditions and determines the log set to be analyzed based on a preset log analysis quantity threshold; obtains target identifiers corresponding to each log to be analyzed and matches them using a preset identifier type classification processing method to obtain logs to be analyzed for each identifier; divides each log to be analyzed for each identifier into blocks using a preset number of blocks, obtaining at least one current block result corresponding to each target identifier; trains each current block result according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result, and determines the log analysis results and feedback operations. This solves the problems of high time cost and poor correlation in log analysis, enabling better analysis and processing of large amounts of logs, better correlation processing of log context, reducing the difficulty of log analysis, improving the speed and accuracy of log analysis, and saving time costs.
[0075] Example 2
[0076] Figure 2 This is a schematic diagram of a log analysis device provided in Embodiment 2 of the present invention. The log analysis device provided in this embodiment can be implemented by software and / or hardware, and can be configured in a terminal device or server to implement a log analysis method according to an embodiment of the present invention. Figure 2 As shown, the device includes: a log set determination module 210, a log identifier acquisition module 220, a current block result acquisition module 230, a temporary LoRa parameter weight determination module 240, and a log analysis result feedback module 250.
[0077] The log set determination module 210 is used to obtain the log set corresponding to the current query conditions and determine the log set to be analyzed based on a preset log analysis quantity threshold.
[0078] The log set to be analyzed includes at least one log entry to be analyzed.
[0079] The identifier-to-analyze log acquisition module 220 is used to obtain the target identifiers corresponding to each of the logs to be analyzed, and to match them using a preset identifier type classification processing method to obtain each identifier-to-analyze log.
[0080] The current block result acquisition module 230 is used to divide the log to be analyzed by each identifier into blocks by a preset number of blocks, and obtain at least one current block result corresponding to each target identifier.
[0081] The temporary Lora parameter weight determination module 240 is used to train each current block result according to the block result training method to determine the temporary Lora parameter weights corresponding to each current block result.
[0082] The log analysis result feedback module 250 is used to determine the log analysis result corresponding to the current query condition based on the weight of each temporary LoRa parameter and the result of each current block, and to feed back the log analysis result.
[0083] The technical solution of this invention obtains a log set corresponding to the current query conditions and determines the log set to be analyzed based on a preset log analysis quantity threshold; obtains target identifiers corresponding to each log to be analyzed and matches them using a preset identifier type classification processing method to obtain logs to be analyzed for each identifier; divides each log to be analyzed for each identifier into blocks using a preset number of blocks, obtaining at least one current block result corresponding to each target identifier; trains each current block result according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result, and determines the log analysis results and feedback operations. This solves the problems of high time cost and poor correlation in log analysis, enabling better analysis and processing of large amounts of logs, better correlation processing of log context, reducing the difficulty of log analysis, improving the speed and accuracy of log analysis, and saving time costs.
[0084] Based on the above embodiments, the identifier analysis log acquisition module 220 can be specifically used for: sequentially acquiring a current preset identifier from a preset identifier type; matching each target identifier with the current preset identifier using a preset identifier type classification processing method to obtain the current identifier analysis log; returning to execute the operation of sequentially acquiring a current preset identifier from the preset identifier type until all current preset identifiers in the preset identifier type have been traversed; determining whether there is an unmatched target identifier, and if so, determining the analysis log corresponding to the unmatched target identifier as the unmatched identifier analysis log, and obtaining each identifier analysis log based on each current identifier analysis log and the unmatched identifier analysis log; if not, determining each current identifier analysis log as the identifier analysis log.
[0085] Based on the above embodiments, the current block result obtaining module 230 can be specifically used for: sequentially obtaining a current identifier to be analyzed log from each identifier to be analyzed log; dividing the current identifier to be analyzed log into blocks using a preset number of blocks, and performing a remainder operation on the preset number of blocks using the number of logs corresponding to the current identifier to be analyzed log to obtain a remainder result; determining whether the remainder result is zero, and if so, obtaining each current block result corresponding to the current identifier to be analyzed log; if not, extracting the number of current identifier to be analyzed logs corresponding to the remainder result from the current identifier to be analyzed logs, determining it as a current block result, and combining it with each current block result corresponding to the remaining current identifier to be analyzed logs to determine at least one current block result; returning to execute the operation of sequentially obtaining a current identifier to be analyzed log from each identifier to be analyzed log until all identifier to be analyzed logs have been traversed to obtain at least one current block result corresponding to each target identifier.
[0086] Based on the above embodiments, the temporary LoRa parameter weight determination module 240 can be specifically used to: obtain the timestamps corresponding to each current block result, and sort them according to the timestamps to determine the time sorting result of the current block result; obtain and train the target current block result according to the time sorting result of the current block result to obtain the target network token and temporary LoRa parameter weights, and add the target network token to the next target current block result for training; return to execute the operation of obtaining and training the target current block result to obtain the target network token and temporary LoRa parameter weights, until all current block results are traversed, and then obtain the temporary LoRa parameter weights corresponding to each current block result.
[0087] Based on the above embodiments, the log analysis results include each target question and the corresponding answer for each target question; the log analysis result feedback module 250 can be specifically used to: determine at least one system question based on the weights of each temporary LoRa parameter and each current block result; receive at least one target question from the user, and determine whether each target question can match the system question; if so, feed back each target question and the corresponding answer for each target question.
[0088] Based on the above embodiments, a new log analysis result feedback module is also included, which can be specifically used to: retrain each target question, the answer corresponding to each target question, and the log set to be analyzed according to the block result training method to determine each new temporary LoRa parameter weight; determine the new log analysis result corresponding to the current query condition based on each new temporary LoRa parameter weight and each new current block result, and feed back the new log analysis result.
[0089] Based on the above embodiments, a deletion module is also included, which can be specifically used to: after determining the new log analysis result corresponding to the current query condition based on the new temporary LoRa parameter weights and the new current block results, and feeding back the new log analysis result, delete the temporary LoRa parameter weights and the new temporary LoRa parameter weights after receiving the user's feedback end dialog instruction.
[0090] The log analysis device provided in the embodiments of the present invention can execute the log analysis method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.
[0091] Example 3
[0092] Figure 3 A schematic diagram of an electronic device 10, which can be used to implement Embodiment 3 of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0093] like Figure 3As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0094] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0095] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as log analysis methods.
[0096] In some embodiments, the log analysis method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or mounted on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the log analysis method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the log analysis method by any other suitable means (e.g., by means of firmware).
[0097] The method includes: acquiring a log set corresponding to the current query condition, and determining the log set to be analyzed based on a preset log analysis quantity threshold; wherein the log set to be analyzed includes at least one log to be analyzed; acquiring target identifiers corresponding to each of the logs to be analyzed, and matching them using a preset identifier type classification processing method to obtain logs to be analyzed for each identifier; dividing the logs to be analyzed for each identifier into blocks using a preset number of blocks, and obtaining at least one current block result corresponding to each of the target identifiers; training each current block result according to a block result training method to determine the temporary LoRa parameter weights corresponding to each current block result; determining the log analysis result corresponding to the current query condition based on the temporary LoRa parameter weights and the current block results, and feeding back the log analysis result.
[0098] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0099] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0100] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0101] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0102] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0103] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0104] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0105] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
[0106] Example 4
[0107] Embodiment 4 of the present invention also provides a computer-readable storage medium, wherein the computer-readable instructions, when executed by a computer processor, are used to execute a log analysis method. The method includes: acquiring a log set corresponding to a current query condition, and determining a log set to be analyzed based on a preset log analysis quantity threshold; wherein the log set to be analyzed includes at least one log to be analyzed; acquiring target identifiers corresponding to each of the logs to be analyzed, and matching them using a preset identifier type classification processing method to obtain logs to be analyzed for each identifier; dividing the logs to be analyzed for each identifier into blocks using a preset number of blocks, and obtaining at least one current block result corresponding to each of the target identifiers; training each current block result according to a block result training method to determine temporary LoRa parameter weights corresponding to each current block result; determining the log analysis result corresponding to the current query condition based on the temporary LoRa parameter weights and the current block results, and feeding back the log analysis result.
[0108] Of course, the computer-executable instructions provided in the embodiments of the present invention, which include a computer-readable storage medium, are not limited to the method operations described above, but can also perform related operations in the log analysis method provided in any embodiment of the present invention.
[0109] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0110] It is worth noting that in the embodiments of the log analysis device described above, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.
[0111] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A log analysis method, characterized in that, include: Obtain the log set corresponding to the current query conditions, and determine the log set to be analyzed based on the preset log analysis quantity threshold; The log set to be analyzed includes at least one log entry to be analyzed. Obtain the target identifiers corresponding to each of the logs to be analyzed, and match them using a preset identifier type classification processing method to obtain the logs to be analyzed for each identifier; By pre-setting the number of blocks, the log to be analyzed by each identifier is divided into blocks, and at least one current block result corresponding to each target identifier is obtained. The current block result is trained according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result; Based on the weights of each temporary LoRa parameter and the results of each current block, the log analysis results corresponding to the current query conditions are determined, and the log analysis results are fed back. The step of training each current block result according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result includes: Obtain the timestamp corresponding to each current block result, and sort them according to the timestamps to determine the time sorting result of the current block results; Based on the current block result time sorting result, obtain and train the target current block result to obtain the target network token and temporary LoRa parameter weights, and add the target network token to the next target current block result for training; Return to the operation of obtaining and training the target current block result to obtain the target network token and temporary LoRa parameter weights, until all the current block results are traversed, and then obtain the temporary LoRa parameter weights corresponding to each current block result.
2. The method according to claim 1, characterized in that, The process of obtaining the target identifiers corresponding to each of the logs to be analyzed, and matching them using a preset identifier type classification processing method to obtain the logs to be analyzed for each identifier, includes: In the preset identifier types, retrieve one current preset identifier in sequence; By using a preset identifier type classification processing method, each target identifier is matched with the current preset identifier to obtain the log to be analyzed for the current identifier; Return to the operation of sequentially obtaining a current preset identifier in the preset identifier type until all current preset identifiers in the preset identifier type have been traversed; Determine whether there is an unmatched target identifier. If so, determine the log to be analyzed corresponding to the unmatched target identifier as the log to be analyzed for the unmatched identifier. Based on the current log to be analyzed for each identifier and the log to be analyzed for the unmatched identifier, obtain the log to be analyzed for each identifier. If not, then the logs to be analyzed for each current identifier will be determined as the logs to be analyzed for each identifier.
3. The method according to claim 2, characterized in that, The process of dividing the log to be analyzed into blocks by pre-set number of blocks, and obtaining at least one current block result corresponding to each target identifier, includes: In each identifier's log to be analyzed, retrieve one current identifier's log to be analyzed in turn; The log to be analyzed by the current identifier is divided into blocks by a preset number of blocks, and the preset number of blocks is moduloed by the number of logs corresponding to the current identifier to obtain the modulo result. Determine if the remainder result is zero. If it is, obtain the results of each current block corresponding to the log to be analyzed for the current identifier. If not, extract the number of logs to be analyzed for the current identifier corresponding to the remainder result from the log to be analyzed for the current identifier, determine it as a current block result, and combine it with the results of each current block corresponding to the remaining logs to be analyzed for the current identifier to determine at least one current block result. Return to the operation of sequentially obtaining one current identifier to be analyzed log in each identifier to be analyzed log until all identifiers to be analyzed log are traversed, so as to obtain at least one current block result corresponding to each target identifier.
4. The method according to claim 3, characterized in that, The log analysis results include the questions asked for each target and the corresponding answers for each question asked for each target. The process involves determining the log analysis results corresponding to the current query conditions based on the weights of each temporary LoRa parameter and the results of each current block, and then feeding back the log analysis results, including: Based on the weights of each temporary LoRa parameter and the results of each current block, at least one system query question is determined; The system receives at least one target question from a user and determines whether each target question matches the system's question. If so, it provides feedback on each target question and the corresponding answer.
5. The method according to claim 4, characterized in that, After determining the log analysis result corresponding to the current query condition based on the weights of each temporary LoRa parameter and the results of each current block, and feeding back the log analysis result, the process further includes: Based on the block-based training method, the target questions, the corresponding answers to each target question, and the log set to be analyzed are retrained to determine the weights of each new temporary LoRa parameter. Based on the weights of each new temporary LoRa parameter and the results of each new current block, a new log analysis result corresponding to the current query condition is determined, and the new log analysis result is fed back.
6. The method according to claim 5, characterized in that, After determining the new log analysis results corresponding to the current query conditions based on the weights of each new temporary LoRa parameter and each new current block result, and feeding back the new log analysis results, the process further includes: After receiving the user's feedback to end the dialogue, delete the temporary Lora parameter weight and create a new temporary Lora parameter weight.
7. A log analysis device, characterized in that, include: The log set to be analyzed module is used to obtain the log set corresponding to the current query conditions and determine the log set to be analyzed based on the preset log analysis quantity threshold. The log set to be analyzed includes at least one log entry to be analyzed. The identifier-to-analyze log acquisition module is used to obtain the target identifiers corresponding to each of the logs to be analyzed, and to match them using a preset identifier type classification processing method to obtain the logs to be analyzed for each identifier. The current block result acquisition module is used to divide the log to be analyzed by each identifier into blocks by a preset number of blocks, and obtain at least one current block result corresponding to each target identifier. The temporary LoRa parameter weight determination module is used to train each current block result according to the block result training method to determine the temporary LoRa parameter weights corresponding to each current block result. The log analysis result feedback module is used to determine the log analysis result corresponding to the current query condition based on the weight of each temporary LoRa parameter and the result of each current block, and to feed back the log analysis result. The temporary LoRa parameter weight determination module is used for: Obtain the timestamps corresponding to each current block result, and sort them according to the timestamps to determine the time sorting result of the current block results; based on the time sorting result of the current block results, obtain and train the target current block result to obtain the target network token and temporary LoRa parameter weights, and add the target network token to the next target current block result for training; return to execute the operation of obtaining and training the target current block result to obtain the target network token and temporary LoRa parameter weights, until all current block results have been traversed, and then obtain the temporary LoRa parameter weights corresponding to each current block result.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the log analysis method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the log analysis method as described in any one of claims 1-6.
Citation Information
Patent Citations
Information processing method and device, electronic equipment and medium
CN117592103A
Log analysis system
US20160197952A1