Automatic test method, system and equipment for log analysis system, medium and product

By marking and traceing the test logs of the log analysis system, the problems of low accuracy of test results and inability to automatically test in the existing technology are solved, and efficient and accurate automated testing of the log analysis system is achieved.

CN119961146APending Publication Date: 2025-05-09CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411796668.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

In the face of massive log data, the test results are low and it is impossible to automatically test the log analysis process of the log analysis system.

Method used

By keywording the target fields contained in the target test log, ensure that the keyword tag has a unique identity, and trace the source of the target analysis results based on the keyword tags in the target analysis results, thereby determining whether the test log analysis system can correctly process and analyze the log data.

Benefits of technology

It realizes automated testing of the log analysis process of the log analysis system, improves testing efficiency and accuracy, and can accurately determine whether the log analysis system correctly processes and analyzes log data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961146A_ABST
    Figure CN119961146A_ABST
Patent Text Reader

Abstract

The invention relates to the field of big data automatic testing, and discloses a log analysis system automatic testing method, system, device, medium and product, the method comprises the following steps: carrying out keyword marking on a target field contained in a target test log to obtain a keyword mark corresponding to the target field; inputting the target test log into a log analysis system to obtain a target analysis result corresponding to the target test log; receiving a tracing request; determining a target keyword mark corresponding to a target field in the target analysis result; when it is determined that a target keyword mark in the target analysis result is a keyword mark corresponding to the target field, determining the target test log as a traceability result corresponding to the target analysis result; and determining whether the test log analysis system can correctly process and analyze the log data or not according to a real analysis result corresponding to the target analysis result and the traceability result. According to the method, the target analysis result is traced through the unique keyword mark, and automatic testing of the log analysis system is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of big data automated testing, and in particular to a log analysis system automated testing method, system, equipment, medium and product. Background Art

[0002] In the related art, when testing the log analysis system, most of the time, keywords are used to define the test steps or processes, and then one or more test keywords contained in the test case are used to drive the execution of the test case. Finally, the test log of the failed test is compared with the reference test log, and the comparison is performed manually to analyze the reasons for the test failure. However, when faced with massive data, not only is the efficiency low, but it is also impossible to trace the output data of the log analysis system, that is, it is impossible to determine which data analysis statistics the output data comes from, which not only reduces the accuracy of subsequent test results, but also makes it impossible to perform automated testing on the log analysis process of the log analysis system. Summary of the invention

[0003] In view of this, the present invention provides a log analysis system automated testing method, system, device, medium and product to solve the problem in the related art that the test results have low accuracy and the log analysis process of the log analysis system cannot be automatically tested.

[0004] In a first aspect, the present invention provides a log analysis system automated testing method, the method comprising:

[0005] Perform keyword tagging on the target field contained in the target test log to obtain a keyword tag corresponding to the target field; the keyword tag has a unique identifier;

[0006] Input the target test log into the log analysis system to obtain the target analysis result corresponding to the target test log;

[0007] Receiving a traceability request, the traceability request instructs to trace the target analysis result;

[0008] Determine a target keyword tag corresponding to a target field in a target analysis result;

[0009] When it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field, the target test log is determined as the traceability result corresponding to the target analysis result; wherein the traceability result corresponding to the target analysis result indicates what kind of data is analyzed to obtain the target analysis result;

[0010] Based on the actual analysis results corresponding to the target analysis results and traceability results, determine whether the test log analysis system can correctly process and analyze the log data.

[0011] In an optional implementation, before keyword tagging the target field included in the test log to obtain the keyword tag corresponding to the target field, the method further includes:

[0012] A data stream containing multiple logs is divided into multiple discrete data streams according to a set time interval; each discrete data stream contains multiple test logs; the target test log is any one of the multiple test logs; wherein each test log contains a different target field.

[0013] In an optional implementation, the target field satisfies a first condition; the first condition includes: the target fields are all included in the target test log and the corresponding target analysis results, the numerical values ​​corresponding to the target fields remain unchanged, and the target fields belong to the aggregated dimensions in the log analysis system.

[0014] In an optional implementation, when it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field, after determining the target test log as the tracing result corresponding to the target analysis result, the method further includes:

[0015] Generate a test result set; each test result in the test result set includes a target analysis result and a corresponding traceability result.

[0016] In an optional implementation, determining whether the test log analysis system can correctly process and analyze log data according to the target analysis result and the real analysis result corresponding to the traceability result includes:

[0017] When the target analysis result is consistent with the actual analysis result corresponding to the traceability result, it is determined that the test log analysis system can correctly process and analyze the log data;

[0018] When the target analysis result is inconsistent with the actual analysis result corresponding to the traceability result, it is determined that the test log analysis system cannot correctly process and analyze the log data.

[0019] In a second aspect, the present invention provides a log analysis system automated testing system, the system comprising:

[0020] A keyword tagging module is used to perform keyword tagging on a target field contained in a target test log to obtain a keyword tag corresponding to the target field; the keyword tag has a unique identifier;

[0021] The log analysis module is used to input the target test log into the log analysis system to obtain the target analysis result corresponding to the target test log;

[0022] A traceability module is used to receive a traceability request, where the traceability request indicates to trace the target analysis result;

[0023] A target keyword tag module is used to determine the target keyword tag corresponding to the target field in the target analysis result;

[0024] A traceability result acquisition module is used to determine the target test log as the traceability result corresponding to the target analysis result when it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field; wherein the traceability result corresponding to the target analysis result indicates what kind of data the target analysis result is analyzed for;

[0025] The test module is used to determine whether the test log analysis system can correctly process and analyze log data based on the actual analysis results corresponding to the target analysis results and traceability results.

[0026] In an optional embodiment, the system further includes:

[0027] The target test acquisition module is used to divide a data stream containing multiple logs into multiple discrete data streams according to a set time interval; each discrete data stream contains multiple test logs; the target test log is any one of the multiple test logs; wherein each test log contains a different target field.

[0028] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0029] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to cause a computer to execute the method of the first aspect or any corresponding embodiment thereof.

[0030] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions, wherein the computer instructions are used to enable a computer to execute the method of the first aspect or any corresponding embodiment thereof.

[0031] The present invention tags the target fields contained in the target test log with keywords and ensures that the keyword tags are unique, so that the target analysis results can be traced back to the type of data analysis used to obtain the target analysis results according to the keyword tags corresponding to the target fields in the target analysis results, and then determine whether the test log analysis system can correctly process and analyze the log data according to the actual analysis results and the target analysis results corresponding to the traced results, thereby realizing automated testing of the log analysis process of the log analysis system with high efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0033] Figure 1 It is a flow chart of an automated testing method for a log analysis system according to an embodiment of the present invention;

[0034] Figure 2 is a schematic diagram of a data processing process of a log analysis system according to an embodiment of the present invention;

[0035] Figure 3 is a structural block diagram of an automated testing system for a log analysis system according to an embodiment of the present invention;

[0036] Figure 4 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0037] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0038] With the popularization of the Internet and the Internet of Things, the amount of data is growing exponentially, and massive log data has become an important part of big data. Unstructured log data occupies a large part of enterprise data, especially the operation logs of IT systems, user operation behaviors, server system logs, etc. For example, in China Telecom's CDN (Content Delivery Network) products, massive log data will be generated. The log data records the server IP, client IP, access URL, access status, access node, request body and other information accessed by users. By analyzing these massive log data, it is easy to get some user information, such as: the province or city to which the user belongs, the operator, the most favorite services to visit, the generated traffic, etc., and it is also possible to monitor the operation status of many CDN nodes. In order to obtain this useful information, it is necessary to analyze the massive data.

[0039] When the log analysis system faces massive amounts of data, it has high requirements for real-time data processing. Therefore, the core framework in the log analysis system is Sparking Streaming, which is a real-time stream data processing framework with high throughput. Its basic principle is to divide the input log data stream into discrete data streams (Discretized Stream, referred to as DStream) according to time intervals, and then the DStream is processed by the spark Streaming engine and the results are output. However, due to the huge amount of data, each DStream data analysis needs to be counted according to some dimensions. Therefore, the output result is often the data after one or more original log data are analyzed and counted.

[0040] In the related art, when testing the log analysis system, most of the time, keywords are used to define the test steps or processes, and then one or more test keywords contained in the test case are used to drive the execution of the test case. Finally, the test log of the failed test is compared with the reference test log, and the comparison is performed manually to analyze the reasons for the test failure. However, when faced with massive data, not only is the efficiency low, but it is also impossible to trace the output data of the log analysis system, that is, it is impossible to determine which data analysis statistics the output data comes from, which not only reduces the accuracy of subsequent test results, but also makes it impossible to perform automated testing on the log analysis process of the log analysis system.

[0041] Based on this, the present invention provides an automated testing method for a log analysis system. By keyword-tagging the target fields contained in the target test log and ensuring that the keyword tags are unique, it is possible to trace back the target analysis results according to the keyword tags corresponding to the target fields in the target analysis results to determine what type of data analysis the target analysis results are obtained from. Then, based on the actual analysis results and the target analysis results corresponding to the traceability results, it is determined whether the test log analysis system can correctly process and analyze the log data, thereby enabling automated testing of the log analysis process of the log analysis system with high efficiency.

[0042] An embodiment of the present invention provides an automated testing method for a log analysis system. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0043] Figure 1 FIG. 1 is a flow chart of an automated testing method for a log analysis system according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:

[0044] Step S101, keyword tagging is performed on a target field contained in a target test log to obtain a keyword tag corresponding to the target field, wherein the keyword tag has a unique identifier.

[0045] Among them, Figure 2 As shown in the figure, the log analysis system uses the map operator to perform basic operations such as filtering, conversion, and calculation for each DStream containing a large number of raw logs, implements the basic functions of log analysis, and outputs DStreams that meet business needs. For example, the province or city the visiting customer comes from, which operator it comes from, which CDN node it visits, and the traffic generated by the customer, and then performs aggregation operations to obtain the statistical analysis results of the current DStream.

[0046] Due to the aggregation operation of the log analysis system, it is impossible to know which one or several pieces of input data the output data is processed from. Therefore, the target field is marked with a keyword tag with a unique identifier so that the input data can be traced back from the unique identifier in the output data.

[0047] In step S101, a target field to be marked is determined in the test log, and after the target field is determined, a keyword tag with a unique identifier is used to mark the field with a keyword.

[0048] In some optional implementations, the target field satisfies a first condition; the first condition includes: the target fields are all included in the target test log and the corresponding target analysis results, the numerical values ​​corresponding to the target fields remain unchanged, and the target fields belong to the aggregated dimensions in the log analysis system.

[0049] Among them, the dimension in the aggregation operation refers to categorized qualitative data, which is used to describe different aspects or attributes of the data. The dimension itself is not aggregated and is mainly used to provide contextual information of the data. For example, in sales data, "product category" is a dimension that describes different aspects of sales data, but does not perform numerical calculations. The measure in the aggregation operation is aggregatable quantitative data, which is used to represent the statistical value of a certain dimension. Measures can perform numerical calculations, such as summation, average, etc. In sales data, "sales" is a measure, and the total sales can be calculated by summing the sales data of different product categories.

[0050] In data analysis, dimensions and measures work together to help users understand data from different perspectives. For example, in sales data analysis, you can use "product category" as a dimension and "sales" as a measure. Through aggregation calculations, you can get the total sales of each product category, which helps companies understand which product categories perform well and which ones need improvement.

[0051] Therefore, the embodiment of the present invention uses the aggregation dimension as one of the conditions for selecting the target field, which can ensure that the aggregation operation is performed on the specified target field instead of the entire document, thereby improving the test accuracy of the log analysis system and being able to clearly know the actual result after aggregation, ensuring that the aggregation operation will not go wrong.

[0052] In addition, the target fields are included in the target test log and the corresponding target analysis results, and the corresponding values ​​of the target fields remain unchanged in order to ensure that the same target fields appear in the output results, so that the input data can be traced later according to the keyword tags corresponding to the target fields.

[0053] As an example, taking China Telecom CDN logs as an example, the domain name is the unique identifier of the customer in the original log. Its value will not change before and after the analysis. It is also an important statistical indicator, that is, the dimension of aggregation. Therefore, it can be used as the target field to be marked.

[0054] Secondly, after selecting the target field, the target field is marked with keywords. The keyword tag must ensure global uniqueness, for example, UUID (Universally Unique Identifier) ​​can be used.

[0055] Among them, UUID is a software-constructed standard that can ensure its uniqueness and persistence in time and space. It is usually used to generate unique identifiers in distributed systems, such as logging.

[0056] Due to the use of unique keyword tags, input data and output data can achieve a one-to-one correspondence, and the output data can also be traced through this globally unique keyword tag.

[0057] Step S102: input the target test log into the log analysis system to obtain the target analysis result corresponding to the target test log.

[0058] Step S103: receiving a traceability request, where the traceability request indicates to trace the target analysis result.

[0059] In step S103, the target analysis result corresponding to the target test log is traced according to the traceability request.

[0060] Step S104, determining a target keyword tag corresponding to a target field in the target analysis result;

[0061] Step S105: When it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field, the target test log is determined as the traceability result corresponding to the target analysis result; wherein the traceability result corresponding to the target analysis result indicates what kind of data is analyzed to obtain the target analysis result.

[0062] In step S104 and step S105, when the log analysis system processes log data, due to data flow processing logic errors, data format damage or inconsistency in the data flow, insufficient cluster resources, improper program parallelism settings, concurrency problems in the code, etc., the output results may not be consistent with expectations. Therefore, the keyword tags corresponding to the target field in the target analysis result may not be the keyword tags corresponding to the target field in the target test log. Therefore, only when the target keyword tag in the target analysis result is the keyword tag corresponding to the target field, the target test log is the traceability result corresponding to the target analysis result;

[0063] Step S106: Determine whether the test log analysis system can correctly process and analyze the log data according to the target analysis result and the real analysis result corresponding to the traceability result.

[0064] Among them, the actual analysis result corresponding to the traceability result can be the accurate analysis result output by the target test log through other log analysis systems that meet the test requirements, or it can be the theoretical analysis result derived from the calculation process of the target test log through the log analysis system.

[0065] In some optional implementations, determining whether the test log analysis system can correctly process and analyze log data according to the target analysis result and the real analysis result corresponding to the traceability result includes:

[0066] When the target analysis result is consistent with the actual analysis result corresponding to the traceability result, it is determined that the test log analysis system can correctly process and analyze the log data;

[0067] When the target analysis result is inconsistent with the actual analysis result corresponding to the traceability result, it is determined that the test log analysis system cannot correctly process and analyze the log data.

[0068] In some optional implementations, before keyword tagging the target field contained in the test log to obtain the keyword tag corresponding to the target field, the log analysis system automated testing method further includes:

[0069] A data stream containing multiple logs is divided into multiple discrete data streams according to a set time interval; each discrete data stream contains multiple test logs; the target test log is any one of the multiple test logs; wherein each test log contains a different target field.

[0070] In some optional implementations, when it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field, after determining the target test log as the tracing result corresponding to the target analysis result, the log analysis system automated testing method further includes:

[0071] Generate a test result set; each test result in the test result set includes a target analysis result and a corresponding traceability result.

[0072] The embodiment of the present invention may also generate multiple test logs, and compare each target analysis result corresponding to the multiple test logs.

[0073] In this embodiment, a log analysis system automated testing system is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware for a predetermined function. Although the systems described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0074] The embodiment of the present invention provides a log analysis system automated testing system, such as Figure 3 As shown, including:

[0075] The keyword tag module 301 is used to perform keyword tagging on the target field contained in the target test log to obtain the keyword tag corresponding to the target field; the keyword tag has a unique identifier;

[0076] The log analysis module 302 is used to input the target test log into the log analysis system to obtain the target analysis result corresponding to the target test log;

[0077] The tracing module 303 is used to receive a tracing request, where the tracing request indicates to trace the target analysis result;

[0078] A target keyword tag module 304 is used to determine a target keyword tag corresponding to a target field in a target analysis result;

[0079] The traceability result acquisition module 305 is used to determine the target test log as the traceability result corresponding to the target analysis result when it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field; wherein the traceability result corresponding to the target analysis result indicates what kind of data the target analysis result is analyzed for;

[0080] The test module 306 is used to determine whether the test log analysis system can correctly process and analyze the log data according to the target analysis result and the real analysis result corresponding to the traceability result.

[0081] In some optional implementations, the log analysis system automated testing system further includes:

[0082] The target test acquisition module 307 is used to divide the data stream containing multiple logs into multiple discrete data streams according to a set time interval; each discrete data stream contains multiple test logs; the target test log is any one of the multiple test logs; wherein each test log contains a different target field.

[0083] In some optional implementations, the log analysis system automated testing system further includes:

[0084] The test result set generating module 308 is used to generate a test result set; each test result in the test result set includes a target analysis result and a corresponding traceability result.

[0085] In some optional implementations, the testing module 306 further includes:

[0086] The first test result unit 3061 determines that the test log analysis system can correctly process and analyze log data when the target analysis result is consistent with the real analysis result corresponding to the traceability result;

[0087] The second test result unit 3062 is used to determine that the test log analysis system cannot correctly process and analyze the log data when the target analysis result is inconsistent with the actual analysis result corresponding to the traceability result.

[0088] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0089] A log analysis system automated testing system in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0090] The embodiment of the present invention also provides a computer device having the above Figure 3 The log analysis system shown is an automated testing system.

[0091] See also Figure 4, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses for communication, and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed in the computer device, including instructions stored in or on the memory to display graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 4 A processor 10 is taken as an example.

[0092] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0093] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0094] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0095] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0096] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 4 The example of connecting through bus is taken in the following.

[0097] The input device 30 can receive input digital or character information, and generate key signal input related to the user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a track pad, a touch pad, an indicator bar, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (e.g., an LED) and a tactile feedback device (e.g., a vibration motor), etc. The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display and a plasma display. In some optional embodiments, the display device can be a touch screen.

[0098] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0099] A portion of the embodiments of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of computer program instructions in a computer-readable medium includes, but is not limited to, source files, executable files, installation package files, etc., and accordingly, the way in which the computer program instructions are executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.

[0100] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A log analysis system automated testing method, characterized in that: The method comprises: Perform keyword tagging on the target field contained in the target test log to obtain a keyword tag corresponding to the target field; the keyword tag has a unique identifier; Input the target test log into the log analysis system to obtain the target analysis result corresponding to the target test log; Receiving a traceability request, the traceability request instructs to trace the target analysis result; Determine a target keyword tag corresponding to a target field in a target analysis result; When it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field, the target test log is determined as the traceability result corresponding to the target analysis result; wherein the traceability result corresponding to the target analysis result indicates what kind of data is analyzed to obtain the target analysis result; Based on the actual analysis results corresponding to the target analysis results and traceability results, determine whether the test log analysis system can correctly process and analyze the log data.

2. The method according to claim 1, characterized in that: Before keyword tagging the target field contained in the test log to obtain the keyword tag corresponding to the target field, the method further includes: A data stream containing multiple logs is divided into multiple discrete data streams according to a set time interval; each discrete data stream contains multiple test logs; the target test log is any one of the multiple test logs; wherein each test log contains a different target field.

3. The method according to claim 2, characterized in that The target field satisfies the first condition; the first condition includes: the target fields are all included in the target test log and the corresponding target analysis results, the numerical values ​​corresponding to the target fields remain unchanged, and the target fields belong to the aggregated dimensions in the log analysis system.

4. The method according to claim 2, characterized in that: When it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field, after determining the target test log as the tracing result corresponding to the target analysis result, the method further includes: Generate a test result set; each test result in the test result set includes a target analysis result and a corresponding traceability result.

5. The method according to claim 2, characterized in that: Determining whether the test log analysis system can correctly process and analyze log data based on the target analysis result and the real analysis result corresponding to the traceability result includes: When the target analysis result is consistent with the actual analysis result corresponding to the traceability result, it is determined that the test log analysis system can correctly process and analyze the log data; When the target analysis result is inconsistent with the actual analysis result corresponding to the traceability result, it is determined that the test log analysis system cannot correctly process and analyze the log data.

6. A log analysis system automated testing system, characterized in that: The system comprises: A keyword tagging module is used to perform keyword tagging on a target field contained in a target test log to obtain a keyword tag corresponding to the target field; the keyword tag has a unique identifier; The log analysis module is used to input the target test log into the log analysis system to obtain the target analysis result corresponding to the target test log; A traceability module is used to receive a traceability request, where the traceability request indicates to trace the target analysis result; A target keyword tag module is used to determine the target keyword tag corresponding to the target field in the target analysis result; A traceability result acquisition module is used to determine the target test log as the traceability result corresponding to the target analysis result when it is determined that the target keyword tag in the target analysis result is the keyword tag corresponding to the target field; wherein the traceability result corresponding to the target analysis result indicates what kind of data the target analysis result is analyzed for; The test module is used to determine whether the test log analysis system can correctly process and analyze log data based on the actual analysis results corresponding to the target analysis results and traceability results.

7. The system according to claim 6, characterized in that The system further comprises: The target test acquisition module is used to divide a data stream containing multiple logs into multiple discrete data streams according to a set time interval; each discrete data stream contains multiple test logs; the target test log is any one of the multiple test logs; wherein each test log contains a different target field.

8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 5 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 5.

10. A computer program product, characterized in that The method comprises computer instructions for causing a computer to execute the method according to any one of claims 1 to 5.