Log automatic detection method, device and equipment and storage medium
By generating log detection scripts and automatically traversing the device, the problems of complex and low ease of use in the existing technology are solved, and efficient and convenient automatic log detection is achieved.
Patent Information
- Application Number
- CN202510029683.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-13
Smart Images

Figure CN119989340A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of log detection technology, and in particular to a log automatic detection method, device, equipment and storage medium. Background Art
[0002] System logs record information about hardware, software, and system problems in the system. They can also monitor events that occur in the system. Users can use them to check the cause of errors or find traces left by attackers when attacked. How to quickly find these contents from the logs, how to locate important information of concern from a large number of logs, and how to quickly notify after discovering an abnormality, all of these require some effective automated detection and analysis solutions.
[0003] There are many mature log frameworks and collection methods, such as ELK, rsyslog, syslog, cls, etc., but they focus more on log transfer and analysis, and are large in size. They need to rely on many and complex peripheral technologies when setting up the environment, which is not conducive to rapid deployment. Their log collection methods require the integration of collectors on the device side in advance. They have limitations for some existing devices or low-end devices and are not easy to use. Summary of the invention
[0004] The embodiment of the present invention provides a log automatic detection method, which can reduce the difficulty of environment deployment, realize convenient automatic detection of logs, and effectively improve the usability and efficiency of the log detection method.
[0005] In a first aspect, an embodiment of the present invention provides a log automatic detection method, comprising:
[0006] Obtain configuration parameters input by the user, and generate a log detection script according to the configuration parameters; wherein the configuration parameters include the IP address segment to be scanned and the login information of the device to be detected;
[0007] Traversing all devices to be detected in the to-be-detected IP address segment at a preset time interval, obtaining the connection status of the devices to be detected, and when the connection status is online, adding the devices to be detected to a pre-built detection sequence;
[0008] For each device to be detected in the detection sequence, use the login information of the device to be detected to perform a login operation, and run the log detection script after the login is successful;
[0009] The script running result of the log detection script is received, and when the log abnormality information in the script running result meets the preset alarm condition, log alarm information is generated.
[0010] Furthermore, the configuration parameters also include log scanning rules, log detection rules, abnormal log quantity threshold, abnormal alarm rules and log detection end conditions.
[0011] Further, traversing all devices to be detected in the to-be-detected IP address segment at a preset time interval to obtain the connection status of the devices to be detected includes:
[0012] Traversing all the devices to be detected in the IP address segment to be scanned at a preset time interval, and executing a ping command on each of the devices to be detected;
[0013] When receiving a response message returned by the ping command, determining that the connection status of the device to be detected is an online status;
[0014] When no response message returned by the ping command is received, it is determined that the connection state of the device to be detected is an offline state.
[0015] Further, the login information of the device to be detected includes an account and password combination of the device to be detected, and the account and password combination includes an account and several passwords of the device to be detected. Then, the login operation is performed using the login information of the device to be detected, and the log detection script is run after the login is successful, including:
[0016] Use the account and password in the account and password combination to perform ssh login to the device to be detected;
[0017] If all passwords fail to log in successfully, skip the device to be detected and perform the login operation on the next device to be detected in the detection sequence;
[0018] If any password can successfully log in to the device to be detected, the log detection script is run in the device to be detected after the login is successful.
[0019] Furthermore, the method further comprises:
[0020] When the connection state is offline, determining whether the device to be detected is already in the detection sequence;
[0021] If so, determine whether the detection result of the device to be detected is valid. When the detection result is invalid, remove the device to be detected from the detection sequence. When the detection result is not invalid, do not process it.
[0022] If not, the step of obtaining the connection status of the device to be detected and subsequent steps are performed again in the next traversal after the time interval.
[0023] Furthermore, after the log detection script is run after the login is successful, it also includes:
[0024] Use the file search instruction preset in the device to be detected to perform file search to obtain a log file;
[0025] The log file is subjected to log detection using a preset file analysis instruction, and a script running result of the log detection script is generated.
[0026] Further, the receiving of the script running result of the log detection script, when the log abnormality information in the script running result meets the preset alarm condition, generates log alarm information, including:
[0027] Receive the running result of the log detection script, and obtain the log exception information in the running result;
[0028] When the number of the log exception information is greater than or equal to the threshold value of the number of abnormal logs, an alarm message is generated, and the log exception information and the alarm message are returned to relevant technical personnel.
[0029] In a second aspect, an embodiment of the present invention provides a log automatic detection device, comprising:
[0030] A detection script generation module, used to obtain configuration parameters input by a user and generate a log detection script according to the configuration parameters; wherein the configuration parameters include the IP address segment to be scanned and the login information of the device to be detected;
[0031] A device status judgment module is used to traverse all devices to be detected in the IP address segment to be scanned at a preset time interval, obtain the connection status of the device to be detected, and when the connection status is online, add the device to be detected to a pre-built detection sequence;
[0032] A detection script running module, used to log in each device to be detected in the detection sequence using the login information of the device to be detected, and run the log detection script after the login is successful;
[0033] The log abnormality alarm module is used to receive the script running result of the log detection script, and generate log alarm information when the log abnormality information in the script running result meets the preset alarm condition.
[0034] In a third aspect, an embodiment of the present invention provides an electronic device, including:
[0035] Memory for storing computer programs;
[0036] A processor, configured to execute the computer program;
[0037] Wherein, when the processor executes the computer program, the log automatic detection method described in any one of the first aspects above is implemented.
[0038] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed, the automatic log detection method described in any one of the first aspects above is implemented.
[0039] Compared with the prior art, an automatic log detection method provided by an embodiment of the present invention has the beneficial effects of: obtaining configuration parameters input by a user, generating a log detection script according to the configuration parameters; wherein the configuration parameters include an IP address segment to be scanned and login information of a device to be detected; traversing all devices to be detected in the IP address segment to be scanned at a preset time interval, obtaining the connection status of the device to be detected, and when the connection status is online, adding the device to be detected to a pre-built detection sequence; for each device to be detected in the detection sequence, performing a login operation using the login information of the device to be detected, and running the log detection script after successful login; receiving a script running result of the log detection script, and generating log alarm information when log abnormality information in the script running result meets a preset alarm condition; the present invention can reduce the difficulty of environment deployment, realize convenient automatic detection of logs, and effectively improve the ease of use and efficiency of the log detection method. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical features of the embodiments of the present invention, the drawings required for use in the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.
[0041] Figure 1 It is a flow chart of an embodiment of a log automatic detection method provided by the present invention;
[0042] Figure 2 It is a structural schematic diagram of an embodiment of a log automatic detection device provided by the present invention;
[0043] Figure 3 It is a structural schematic diagram of an embodiment of an electronic device provided by the present invention. DETAILED DESCRIPTION
[0044] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0045] It should be noted that although the functional modules are divided in the device schematic and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart.
[0046] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which the present invention belongs. The terms used herein are only for the purpose of describing the embodiments of the present invention and are not intended to limit the present invention.
[0047] In a first aspect, an embodiment of the present invention provides a method for automatically detecting logs. Figure 1 , which is a flow chart of an embodiment of a log automatic detection method provided by the present invention.
[0048] like Figure 1 As shown, the method comprises the following steps:
[0049] S1: Obtain configuration parameters input by a user, and generate a log detection script according to the configuration parameters; wherein the configuration parameters include the IP address segment to be scanned and the login information of the device to be detected;
[0050] S2: traverse all devices to be detected in the IP address segment to be scanned at preset time intervals, obtain the connection status of the devices to be detected, and when the connection status is online, add the devices to be detected to a pre-built detection sequence;
[0051] S3: For each device to be detected in the detection sequence, log in using the login information of the device to be detected, and run the log detection script after the login is successful;
[0052] S4: receiving the script running result of the log detection script, and generating log alarm information when the log abnormality information in the script running result meets the preset alarm condition.
[0053] In the specific implementation, this application uses the Jenkins environment to implement automatic log detection. First, download the latest Jenkins war installation package from the open source website (https: / / www.jenkins.io / ), download this Jenkins version and mention the version of the Java environment it depends on, install it according to the instructions of the official website, and install the required Jenkins plug-ins in the Jenkins plug-in management interface, such as the parameterized process plug-in Build With Parameters and the email plug-in Email ExtensionPlugin, etc. After installing and deploying the Java environment, use the java-jar jenkins.war command to start the Jenkins service. The whole process is convenient and simple, and there is no other additional configuration requirements.
[0054] Furthermore, create a new log automatic detection task on Jenkins, open the configuration page of the task, select the "General" tab configuration page, check "Parameterized build process", add some required configuration parameters, including the IP address segment to be scanned and the login information of the device to be detected, etc. The IP address segment to be scanned includes the start IP address and the end IP address of the scan, both of which are parameters in character form, and then check "Concurrent build when necessary" to reasonably use the server resources specified by the node to avoid idle resources. Waste, then open the "Build Environment" tab and check "Add timestamp prefix to build log", so that the output information of the Jenkins detection task can carry time information, which is convenient for the analysis and location of later problems. After creating a new log automatic detection task, clean up the process files left over by expired tasks according to the rules, reclaim the node resource storage space, and create the basic directory required for the current task. The subsequent process data of the task will be stored in this directory. Finally, click the "Post-build Operation" tab, add an "Editable Email Notification" step, use the Jenkins email template configuration, and send an email notification after exiting.
[0055] After receiving the configuration parameters input by the user, a log detection script is generated according to the configuration parameters. The syntax of the shell script is combined with the configuration parameters to dynamically generate a python script for detecting logs in the directory created in the previous step. The sshpass tool can also be used to generate shell scripts. For example, in the process of generating the python script, the paramiko module in Python is first imported to implement SSH connection and remote command execution. At the same time, the configuration parameters input by the user are obtained, and the tail-f command is remotely executed in the terminal to detect the log files in the device to be detected in real time. The -s parameter is combined with the preset log scanning time interval to control the time interval for tail to read data, further reducing the pressure on the terminal. After reading the log data returned by the remote command, scan and detect according to the log detection rules to identify whether there is abnormal data, and make statistics on the abnormal data. The statistical abnormal data is compared with the preset alarm conditions. If the number of abnormal logs meets the preset alarm conditions, a log alarm information is generated.
[0056] The present invention realizes log detection based on Jenkins. The B / S architecture of Jenkins and its construction parameterization method can quickly and simply visualize the parameter configuration of the detection task, which is convenient for users to use. The framework-type process configuration mode is also convenient for maintenance personnel to maintain the process and perform later optimization. The log additional timestamp function provided by Jenkins can synchronize the time information of the log information of the detection equipment for the second time. The log has the timestamp information of the unified reference time, which reduces the difficulty of analyzing the synchronization problem during the joint debugging of multiple systems. The "post-construction operation" process configuration mode of Jenkins can trigger an email notification in time when the process exits, so that the maintenance personnel can be notified in time that the current automatic detection has been exited and invalid, so as to prompt them to follow up the maintenance in time and improve the work efficiency.
[0057] In summary, the present invention obtains configuration parameters input by a user, and generates a log detection script according to the configuration parameters; wherein the configuration parameters include an IP address segment to be scanned and login information of a device to be detected; traverses all devices to be detected in the IP address segment to be scanned at a preset time interval, obtains the connection status of the device to be detected, and when the connection status is online, adds the device to be detected to a pre-built detection sequence; for each device to be detected in the detection sequence, performs a login operation using the login information of the device to be detected, and runs the log detection script after successful login; receives a script running result of the log detection script, and generates log alarm information when the log abnormality information in the script running result meets a preset alarm condition; the present invention can simplify the process of environment deployment, reduce the difficulty of environment deployment, expand the scope of application of the log detection method, realize convenient and automatic detection of logs, effectively improve the ease of use and efficiency of the log detection method, and provide an efficient, convenient and reliable solution for the field of log detection.
[0058] In an optional implementation, the configuration parameters further include log scanning rules, device traversal time intervals, log detection rules, abnormality alarm rules, and log detection end conditions.
[0059] Specifically, the log scanning rules include log directory scanning rules and log scanning time intervals. The log directory scanning rules are character-based parameters used to instruct the Jenkins log detection script on how to scan valid logs. The log scanning time interval is a character-based parameter used to instruct the log detection script on the time interval for scanning logs, which can reduce the CPU collection load on the terminal. The device traversal time interval is a string-based parameter used to specify the interval at which the devices to be detected in the IP address segment to be scanned are traversed. Reasonable setting of the device detection time interval can make the timeliness of the perceived device more in line with user needs. The log detection rules are character-based parameters used to instruct the log detection script to detect whether there is abnormal information in the log, such as the perception of sh of a specific string. ell's regular expression. The abnormal alarm rules include the abnormal log quantity threshold, whether to send email notification when the threshold is triggered, the email statistical report cycle, and the email address for receiving emails. The abnormal log quantity threshold is a character-based parameter, which is used to specify how many abnormal logs are detected to trigger the abnormal alarm. Whether to send email notification when the threshold is triggered is a Boolean-based parameter, which is used to specify whether to send email notifications when there are abnormal alarm events. The email statistical report cycle is a string-based parameter, which is used to configure the cycle time for regularly sending email statistical reports. The email address for receiving emails is a string-based parameter, which is used to configure the target population for sending the above emails. The log detection end condition is used to specify the exit condition for the end of log detection, which can avoid infinite task running and wasting system resources.
[0060] In an optional implementation, traversing all devices to be detected in the to-be-detected IP address segment at a preset time interval to obtain the connection status of the devices to be detected includes:
[0061] Traversing all the devices to be detected in the IP address segment to be scanned at a preset time interval, and executing a ping command on each of the devices to be detected;
[0062] When receiving a response message returned by the ping command, determining that the connection status of the device to be detected is an online status;
[0063] When no response message returned by the ping command is received, it is determined that the connection state of the device to be detected is an offline state.
[0064] Specifically, Jenkins starts a loop task for continuously discovering valid online devices. At each device traversal time interval, it performs a traversal operation on all devices to be detected in the scanned IP address segment, cyclically pings all devices to be detected, and detects which devices to be detected can be pinged.
[0065] It can be understood that the Ping command is a network tool that determines whether the target device is reachable by sending an ICMP (Internet Control Message Protocol) data packet to the target device and waiting for a response message from the target device. When the ping command is executed on the device to be detected and a response message returned by the ping command is received, it indicates that the device to be detected can be pinged through, and the connection status of the device to be detected is determined to be online. If no response message returned by the ping command is received, the connection status of the device to be detected is determined to be offline.
[0066] In an optional implementation, the login information of the device to be detected includes an account and password combination of the device to be detected, and the account and password combination includes an account and several passwords of the device to be detected. Then, the login operation is performed using the login information of the device to be detected, and the log detection script is run after the login is successful, including:
[0067] Use the account and password in the account and password combination to perform ssh login to the device to be detected;
[0068] If all passwords fail to log in successfully, skip the device to be detected and perform the login operation on the next device to be detected in the detection sequence;
[0069] If any password can successfully log in to the device to be detected, the log detection script is run in the device to be detected after the login is successful.
[0070] Specifically, the account and password combination in the login information of the device to be detected is used to try to log in to the device to be detected through ssh. If all passwords have been tried and login is still unsuccessful, the device to be detected is skipped and the login operation is performed on the next device to be detected in the detection sequence. If a certain password is used to successfully log in to the device, a log detection script is executed on the device, and the IP, account and password of the device to be detected are passed to the log detection script as parameters to start log detection for the device.
[0071] It can be understood that the present invention can realize the self-discovery function of new devices joining the network or reconnecting to the network by scanning all devices to be detected in the IP address segment and using the configured account and password to detect the devices to be detected, thereby simplifying the process of devices joining the detection sequence and realizing self-discovery of devices without new configuration and intervention.
[0072] In an optional embodiment, the method further includes:
[0073] When the connection state is offline, determining whether the device to be detected is already in the detection sequence;
[0074] If so, determine whether the detection result of the device to be detected is valid. When the detection result is invalid, remove the device to be detected from the detection sequence. When the detection result is not invalid, do not process it.
[0075] If not, the step of obtaining the connection status of the device to be detected and subsequent steps are performed again in the next traversal after the time interval.
[0076] Specifically, when the ping command is executed on the device to be detected and no response message is received from the ping command, it indicates that the device to be detected is not online. It is necessary to determine whether the device is in the detection sequence. If it is in the detection sequence, check whether its detection result is still valid. If the detection result is invalid, remove the device from the detection sequence. If the detection result is not invalid, do not perform any processing on the device.
[0077] If the device is not in the detection sequence, its connection status is re-detected in the next traversal after the time interval.
[0078] In an optional implementation, after the log detection script is run after the login is successful, the method further includes:
[0079] Use the file search instruction preset in the device to be detected to perform file search to obtain a log file;
[0080] The log file is subjected to log detection using a preset file analysis instruction, and a script running result of the log detection script is generated.
[0081] Specifically, the log detection script uses the preset file search instructions in the device to be detected to perform file search. For example, the device's own find command can be used to scan the log. The find command is a command used to find files in Unix and Unix-like systems. Files can be searched in a directory tree according to specified conditions. After the log file is scanned, the log file is subjected to log detection using preset file analysis instructions. For example, the tail command can be used for real-time collection. The tail command is a command used to view the content at the end of a file in Unix and Unix-like systems. The updated content of the file can be displayed in real time. After the tail command is executed, the script running result of the log detection script is generated.
[0082] It can be understood that the present invention utilizes shell find and tail instructions supported by Linux systems to realize log collection, combined with Python's remote SSH connection control, which reduces the pressure of terminal CPU in collecting and analyzing logs. There is no need to deploy new tools and load configuration on the terminal device, which reduces the design difficulty.
[0083] In an optional implementation, the receiving of the script running result of the log detection script, and generating log alarm information when the log abnormality information in the script running result meets the preset alarm condition, includes:
[0084] Receive the running result of the log detection script, and obtain the log exception information in the running result;
[0085] When the number of the log exception information is greater than or equal to the threshold value of the number of abnormal logs, an alarm message is generated, and the log exception information and the alarm message are returned to relevant technical personnel.
[0086] Specifically, the running results returned after the log detection script is executed are received, and all log exception information is extracted. When the number of log exception information is greater than or equal to a preset exception log number threshold, it is considered that the alarm triggering condition has been met, and the system generates an alarm message. By configuring the exception alarm rules in the parameters, the email address for receiving the alarm message is obtained, and the alarm message is sent to the email address, which is then returned to the relevant technical personnel.
[0087] In a second aspect, an embodiment of the present invention provides a log automatic detection device, see Figure 2 , which is a structural diagram of an embodiment of a log automatic detection device provided by the present invention.
[0088] like Figure 2 As shown, the device comprises:
[0089] The detection script generation module 21 is used to obtain the configuration parameters input by the user and generate a log detection script according to the configuration parameters; wherein the configuration parameters include the IP address segment to be scanned and the login information of the device to be detected;
[0090] The device status judgment module 22 is used to traverse all the devices to be detected in the IP address segment to be scanned at a preset time interval, obtain the connection status of the devices to be detected, and when the connection status is online, add the devices to be detected to a pre-built detection sequence;
[0091] A detection script running module 23 is used to log in each device to be detected in the detection sequence using the login information of the device to be detected, and run the log detection script after the login is successful;
[0092] The log abnormality alarm module 24 is used to receive the script running result of the log detection script, and generate log alarm information when the log abnormality information in the script running result meets the preset alarm condition.
[0093] In an optional implementation, the configuration parameters further include log scanning rules, log detection rules, abnormality alarm rules and log detection end conditions.
[0094] In an optional implementation, the device status determination module 22 is further configured to:
[0095] Traversing all the devices to be detected in the IP address segment to be scanned at a preset time interval, and executing a ping command on each of the devices to be detected;
[0096] When receiving a response message returned by the ping command, determining that the connection status of the device to be detected is an online status;
[0097] When no response message returned by the ping command is received, it is determined that the connection state of the device to be detected is an offline state.
[0098] In an optional implementation, the login information of the device to be detected includes an account and password combination of the device to be detected, and the account and password combination includes an account and several passwords of the device to be detected. Then, the detection script running module 23 is further used to:
[0099] Use the account and password in the account and password combination to perform ssh login to the device to be detected;
[0100] If all passwords fail to log in successfully, skip the device to be detected and perform the login operation on the next device to be detected in the detection sequence;
[0101] If any password can successfully log in to the device to be detected, the log detection script is run in the device to be detected after the login is successful.
[0102] In an optional embodiment, the device is also used for:
[0103] When the connection state is offline, determining whether the device to be detected is already in the detection sequence;
[0104] If so, determine whether the detection result of the device to be detected is valid. When the detection result is invalid, remove the device to be detected from the detection sequence. When the detection result is not invalid, do not process it.
[0105] If not, the step of obtaining the connection status of the device to be detected and subsequent steps are performed again in the next traversal after the time interval.
[0106] In an optional embodiment, the device is also used for:
[0107] Use the file search instruction preset in the device to be detected to perform file search to obtain a log file;
[0108] The log file is subjected to log detection using a preset file analysis instruction, and a script running result of the log detection script is generated.
[0109] In an optional implementation, the log abnormality alarm module 24 is further used to:
[0110] Receive the running result of the log detection script, and obtain the log exception information in the running result;
[0111] When the number of the log exception information is greater than or equal to a preset threshold value of the number of exception logs, an alarm message is generated, and the log exception information and the alarm message are returned to relevant technical personnel.
[0112] In a third aspect, an embodiment of the present invention provides an electronic device, see Figure 3 , which is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention.
[0113] like Figure 3 As shown, the device includes:
[0114] A memory 31, used for storing computer programs;
[0115] A processor 32, configured to execute the computer program;
[0116] When the processor 32 executes the computer program, the automatic log detection method as described in any of the above embodiments is implemented.
[0117] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory 31 and executed by the processor 32 to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of implementing specific functions, which are used to describe the execution process of the computer program in the electronic device.
[0118] The processor 32 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0119] The memory 31 can be used to store the computer program and / or module, and the processor 32 realizes various functions of the electronic device by running or executing the computer program and / or module stored in the memory 31, and calling the data stored in the memory 31. The memory 31 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory 31 can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (SecureDigital, SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0120] It should be noted that the above electronic device includes, but is not limited to, a processor and a memory. Those skilled in the art can understand that Figure 3The structural diagram is merely an example of the electronic device described above and does not constitute a limitation on the electronic device, and may include more components than shown in the figure, or a combination of certain components, or different components.
[0121] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed, the automatic log detection method described in any of the above embodiments is implemented.
[0122] It should be understood that the present invention implements all or part of the process in the above-mentioned log automatic detection method, and can also be completed by instructing related hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above-mentioned log automatic detection method. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal and software distribution medium, etc.
[0123] The above description is only a preferred embodiment of the present invention, but the protection scope of the present invention is not limited thereto. It should be pointed out that for those skilled in the art, several equivalent obvious variations and / or equivalent substitutions can be made without departing from the technical principles of the present invention. These obvious variations and / or equivalent substitutions should also be regarded as the protection scope of the present invention.
Claims
1. A log automatic detection method, characterized in that: include: Obtain configuration parameters input by the user, and generate a log detection script according to the configuration parameters; wherein the configuration parameters include the IP address segment to be scanned and the login information of the device to be detected; Traversing all devices to be detected in the to-be-detected IP address segment at a preset time interval, obtaining the connection status of the devices to be detected, and when the connection status is online, adding the devices to be detected to a pre-built detection sequence; For each device to be detected in the detection sequence, use the login information of the device to be detected to perform a login operation, and run the log detection script after the login is successful; The script running result of the log detection script is received, and when the log abnormality information in the script running result meets the preset alarm condition, log alarm information is generated.
2. The log automatic detection method according to claim 1, characterized in that: The configuration parameters also include log scanning rules, log detection rules, abnormal alarm rules and log detection end conditions.
3. The log automatic detection method according to claim 1, characterized in that: The step of traversing all devices to be detected in the to-be-detected IP address segment at a preset time interval to obtain the connection status of the devices to be detected includes: Traversing all the devices to be detected in the IP address segment to be scanned at a preset time interval, and executing a ping command on each of the devices to be detected; When receiving a response message returned by the ping command, determining that the connection status of the device to be detected is an online status; When no response message returned by the ping command is received, it is determined that the connection state of the device to be detected is an offline state.
4. The log automatic detection method according to claim 1, characterized in that: The login information of the device to be detected includes an account and password combination of the device to be detected, and the account and password combination includes an account and several passwords of the device to be detected. Then, the login operation is performed using the login information of the device to be detected, and the log detection script is run after the login is successful, including: Use the account and password in the account and password combination to perform ssh login to the device to be detected; If all passwords fail to log in successfully, skip the device to be detected and perform the login operation on the next device to be detected in the detection sequence; If any password can successfully log in to the device to be detected, the log detection script is run in the device to be detected after the login is successful.
5. The log automatic detection method according to claim 1, characterized in that: The method further comprises: When the connection state is offline, determining whether the device to be detected is already in the detection sequence; If so, determine whether the detection result of the device to be detected is valid. When the detection result is invalid, remove the device to be detected from the detection sequence. When the detection result is not invalid, do not process it. If not, the step of obtaining the connection status of the device to be detected and subsequent steps are performed again in the next traversal after the time interval.
6. The log automatic detection method according to claim 1, characterized in that: After the log detection script is run after the login is successful, the method further includes: Use the file search instruction preset in the device to be detected to perform file search to obtain a log file; The log file is subjected to log detection using a preset file analysis instruction, and a script running result of the log detection script is generated.
7. The log automatic detection method according to claim 1, characterized in that: The receiving of the script running result of the log detection script, and generating log alarm information when the log abnormality information in the script running result meets the preset alarm condition, includes: Receive the running result of the log detection script, and obtain the log exception information in the running result; When the number of the log exception information is greater than or equal to a preset threshold value of the number of exception logs, an alarm message is generated, and the log exception information and the alarm message are returned to relevant technical personnel.
8. A log automatic detection device, characterized in that: include: A detection script generation module, used to obtain configuration parameters input by a user and generate a log detection script according to the configuration parameters; wherein the configuration parameters include the IP address segment to be scanned and the login information of the device to be detected; A device status judgment module is used to traverse all devices to be detected in the IP address segment to be scanned at a preset time interval, obtain the connection status of the device to be detected, and when the connection status is online, add the device to be detected to a pre-built detection sequence; A detection script running module, used to log in each device to be detected in the detection sequence using the login information of the device to be detected, and run the log detection script after the login is successful; The log abnormality alarm module is used to receive the script running result of the log detection script, and generate log alarm information when the log abnormality information in the script running result meets the preset alarm condition.
9. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to execute the computer program; Wherein, when the processor executes the computer program, the log automatic detection method as described in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the automatic log detection method according to any one of claims 1 to 7 is implemented.