Monitoring method and platform for unified acquisition agent, electronic equipment and storage medium
By introducing a unified acquisition agent in the monitoring system, data acquisition and transmission encryption is realized, and through unified account and secret information and configuration management, the information security risks and management complexity of existing acquisition components are solved, and information security and management efficiency are improved.
Patent Information
- Application Number
- CN202510178270.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-18
AI Technical Summary
The existing collection components have information security risks and management complexity, which leads to many challenges for operation and maintenance personnel in monitoring data collection and management.
The monitoring method of a unified acquisition agent is adopted, and the proxy terminal and acquisition module are introduced between the operation and maintenance monitoring system and the monitoring node, data collection and transmission are encrypted, and information security and management efficiency are improved through unified account and secret information and configuration management.
Through encrypted transmission and unified management mechanisms, the security of data transmission and the management efficiency of the acquisition module are effectively improved, the risk of information leakage is reduced, and the data collection and configuration management process is simplified.
Smart Images

Figure CN119996011A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network data security, and in particular to a monitoring method, platform, electronic device and storage medium of a unified acquisition agent. Background Art
[0002] During the operation and maintenance of the application system, the operation and maintenance personnel will use open source tools such as Prometheus to perform basic monitoring of the application system. The monitoring principle of Prometheus is to deploy the corresponding collection components on the server where the monitored object (instance) is located, and transmit the monitoring data to Prometheus through the collection components for processing and display. However, in the specific use process, there are the following disadvantages:
[0003] 1. Existing collection components are usually open source, which may pose information security risks;
[0004] 2. Each type of monitoring object requires at least one corresponding collection component. The number of collection components is large and has a trend of increasing. When controlling different collection components to collect different types of data, a lot of manpower is required. Summary of the invention
[0005] The present invention provides a monitoring method of a unified acquisition agent to solve the drawbacks of acquisition components in the prior art in use.
[0006] In a first aspect, the present invention provides a monitoring method of a unified acquisition agent, which is applied to a monitoring platform, wherein the monitoring platform includes an operation and maintenance monitoring system and multiple monitoring nodes, wherein the operation and maintenance monitoring system includes a call service and Prometheus, and each of the monitoring nodes includes an agent end and multiple acquisition modules that are communicatively connected to the agent end, and each of the acquisition modules is connected to a corresponding instance;
[0007] The calling service calls the interface of the proxy end when receiving the management instruction for the target instance;
[0008] When the interface is called, the agent generates a public key and a private key and stores the private key locally, generates first account and secret information and stores it locally, encrypts the first account and secret information and the public key with a built-in symmetric key of the agent, and sends the encrypted information to the calling service, and the first account and secret information is used to access the agent;
[0009] The calling service decrypts the encrypted first account secret information and public key based on the built-in symmetric key and stores them locally;
[0010] The calling service obtains the monitoring configuration information corresponding to the agent, generates a working file according to the monitoring configuration information and the first account and password information, and pushes the working file to Prometheus, and obtains the collection configuration information corresponding to the target instance, encrypts the collection configuration information by a locally stored public key, and sends the working file to the agent;
[0011] The agent terminal decrypts the collection configuration information according to the private key stored locally and stores it locally;
[0012] Prometheus obtains data of the target instance from the proxy according to the work file.
[0013] In a second aspect, the present invention provides a monitoring platform, including an operation and maintenance monitoring system and a plurality of monitoring nodes, wherein the operation and maintenance monitoring system includes a call service and Prometheus, each of the monitoring nodes includes an agent and a plurality of acquisition modules connected to the agent in communication, each of the acquisition modules is connected to a corresponding instance;
[0014] The calling service is used to call the interface of the agent end when receiving a management instruction for the target instance;
[0015] The agent is used to generate a public key and a private key and store the private key locally when the interface is called, and to generate first account and secret information and store it locally, encrypt the first account and secret information and the public key with the symmetric key built into the agent and send them to the calling service, and the first account and secret information is used to access the agent;
[0016] The calling service is further used to decrypt the encrypted first account secret information and public key based on a built-in symmetric key and store them locally;
[0017] The calling service is further used to obtain the monitoring configuration information corresponding to the agent, generate a working file according to the monitoring configuration information and the first account and password information, and push it to Prometheus; and obtain the collection configuration information corresponding to the agent, encrypt the collection configuration information by a locally stored public key, and send it to the agent;
[0018] The agent is further used to decrypt the collection configuration information according to the private key stored locally and store it locally;
[0019] Prometheus is used to obtain data of the target instance from the proxy according to the work file.
[0020] In a third aspect, the present invention provides an electronic device, the electronic device comprising:
[0021] at least one processor; and
[0022] a memory communicatively connected to the at least one processor; wherein,
[0023] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the monitoring method of the unified acquisition agent described in the first aspect of the present invention.
[0024] In a fourth aspect, the present invention provides a computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a processor to implement the monitoring method of the unified acquisition agent described in the first aspect of the present invention when executed.
[0025] The monitoring method of the unified acquisition agent provided by the embodiment of the present invention has the following beneficial effects: the information transmission between the agent end and the calling service is encrypted transmission. Specifically, when the agent end transmits the first account and secret information and the public key to the calling service, a symmetric key is used for encryption. The agent end sends the generated public key to the calling service. The calling service uses the public key to encrypt the subsequently transmitted information. The agent end uses the locally stored private key to decrypt the information, which can effectively achieve secure encryption and avoid information leakage during the information transmission process. On the other hand, the first account and secret information is used to access the agent end, that is, the agent end can use the first account and secret information to authenticate the access request object. Only objects with access rights can obtain the data collected by the acquisition module, that is, a secure access mechanism is set to avoid the risk of information leakage, and the ports of all acquisition modules do not need to be exposed to the outside, which improves information security. In addition, the data to be collected by the acquisition module can be configured through the acquisition configuration information to meet different business needs.
[0026] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0028] Figure 1 This is a schematic diagram of the structure of a monitoring platform provided by an embodiment of the present invention.
[0029] Figure 2It is a flow chart of a monitoring method of a unified acquisition agent provided by an embodiment of the present invention;
[0030] Figure 3 is a flow chart of another monitoring method of a unified acquisition agent provided by an embodiment of the present invention;
[0031] Figure 4 It is a simplified process diagram of a collection module installation provided by an embodiment of the present invention;
[0032] Figure 5 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0033] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0034] In an optional embodiment of the present invention, a monitoring method for a unified collection agent is provided. This embodiment can be applicable to the situation where data collection is performed uniformly on deployed instances. The method can be executed by a monitoring platform. The monitoring platform can be implemented in the form of hardware and / or software. The monitoring platform can be configured in an electronic device.
[0035] Figure 1 A schematic diagram of the structure of a monitoring platform provided by an embodiment of the present invention is shown in FIG. Figure 1 As shown, the monitoring platform includes an operation and maintenance monitoring system 1 and multiple monitoring nodes 2 ( Figure 1 Only one monitoring node is given as an example). The operation and maintenance monitoring system 1 includes a call service 11 and Prometheus 12. Each monitoring node 2 includes an agent 21 and multiple acquisition modules 22 that are communicatively connected to the agent 21. Each acquisition module 22 is connected to a corresponding instance 3. Generally speaking, each acquisition module 22 is connected to one instance 3.
[0036] Figure 2 A flow chart of a monitoring method for a unified acquisition agent provided by an embodiment of the present invention is shown below in conjunction with Figure 1 and Figure 2 Describe the monitoring method of the unified collection agent, including:
[0037] S201. The calling service calls the interface of the agent side when receiving the management instruction for the target instance.
[0038] Instances are objects of data collection and monitoring, including but not limited to operating systems, components, databases, etc. The target instances can be all instances corresponding to the agent, or some instances corresponding to the agent. Each time data is collected or instance management is performed, it is not necessarily for all instances corresponding to the agent, so the target instance can be determined according to actual needs. It should be noted that the target instance and the agent in this step correspond to each other, that is, the agent is responsible for controlling the collection module to collect data from the target instance. An agent supports simultaneous docking of multiple types and multiple numbers of instances, for example: an agent collects 3 redis, 5 mysql, and 1 virtual machine.
[0039] Specifically, the calling service may be provided with a management page, through which the user may input management instructions for the target instance; for example, the management page may also be provided with management buttons for each agent, and upon receiving a click operation on the management button for the agent, the interface of the agent is determined to be called; in addition, the calling service may also trigger the operation of calling the interface of any agent through instructions sent by other systems.
[0040] S202: When the interface is called, the agent generates a public key and a private key and stores the private key locally, generates first account and password information and stores it locally, encrypts the first account and password information and the public key using a symmetric key built into the agent, and then sends the encrypted information to the calling service.
[0041] The private key and public key generated by the agent correspond to each other, and only the corresponding private key can decrypt the data encrypted by the public key. The private key and public key have different roles in the encryption and decryption process. The public key is only disclosed to the operation and maintenance monitoring system and is used to encrypt data. The private key is unique and confidential to the agent and is used to decrypt the data encrypted by the public key. Therefore, the agent needs to store the generated private key.
[0042] The first account and password information generated and stored by the agent is used to access the agent, that is, the permission verification information when the external system accesses the agent. The reason for setting the first account and password information is that: since the port provided by the agent is exposed to the outside, there is a possibility that monitoring data can be obtained through the port without verification. Some users may not be able to open the firewall for interception due to business reasons, so it is necessary to provide an authentication and verification mechanism to only allow Prometheus in the operation and maintenance monitoring system to obtain data. Therefore, the logic of account and password authentication is added, and the first account and password information is generated and provided to the operation and maintenance monitoring system. The operation and maintenance monitoring system accesses the agent through the first account and password information.
[0043] The first account and password information generated by each agent is different, which can avoid the risk of all agents sharing the same account and password information and being stolen at the same time, thereby reducing the risk of information leakage.
[0044] After being generated, the first account and secret information and the public key are encrypted by the symmetric key built into the proxy and then sent to the calling service, which can also prevent the first account and secret information from being leaked during the transmission process.
[0045] S203: The calling service decrypts the encrypted first account and secret information and the public key based on the built-in symmetric key and stores them locally.
[0046] The calling service and the agent both have the same built-in symmetric key, and the calling service decrypts the encrypted first account and secret information and public key based on the built-in symmetric key. The operation and maintenance monitoring system is also provided with a database, and the first account and secret information and the public key can be stored in the local database of the calling service. It should be noted that the symmetric key is only used in the process of transmitting the first account and secret information, and the public key and private key used subsequently are all generated separately by the agent.
[0047] S204, calling the service to obtain the monitoring configuration information corresponding to the agent, generating a work file according to the monitoring configuration information and the first account and password information and pushing it to Prometheus, and obtaining the collection configuration information corresponding to the target instance, encrypting the collection configuration information by the locally stored public key and sending it to the agent.
[0048] The monitoring configuration information is the configuration information required by Prometheus to monitor the agent. For example, since there are a large number of agents, the monitoring configuration information may include the IP address of the agent, and Prometheus may generate a monitoring task for the IP address to request access to the agent.
[0049] The collection configuration information is the configuration information required by the agent (through the collection module) to collect data from the target instance. The collection configuration information may include the label information of the collection module, the IP address, and the account and password information, component parameters, ports, etc. required to access the instance. The collection configuration information can be provided by the user and can be specifically developed according to business needs. For example, business A needs to collect data from instances X1, X2, and X5, and business B needs to collect data from instances X2, X3, and X5. By setting different collection configuration information, the effect of collecting different data can be achieved. Each agent is set with a unique IP address, and each collection configuration information can correspond to the IP address of the agent, that is, it can be sent to the correct agent.
[0050] S205. The agent decrypts the collection configuration information according to the private key stored locally and stores it locally.
[0051] The collection configuration information is the configuration information required by the agent (through the collection module) to collect data from the target instance. Therefore, the agent needs to obtain and save the collection configuration information. Since the collection configuration information sent by the calling service is encrypted with a public key, the agent can use the locally stored private key corresponding to the public key to decrypt and obtain the collection configuration file. Since the private key is unique to the agent, only the agent can decrypt the file encrypted by the public key. Even other agents cannot read the file encrypted by the public key. Through public key encryption transmission and agent local private key decryption, it can avoid the leakage of files caused by accidental sending or theft during the sending process.
[0052] S206. Prometheus obtains data of the target instance from the proxy according to the work file.
[0053] The work file includes the configuration information required for data collection (collection configuration file) and the authentication information required for accessing the agent (first account and password information), so Prometheus can successfully call the agent to obtain data from the target instance.
[0054] It can be seen that a monitoring node only needs to enable one proxy port. When prometheus obtains data, it can obtain all the monitoring data of the backend through this port. There is no need to expose the port of each collection module, and prometheus does not need to connect to the port of each collection module.
[0055] Optionally, the external IP of the acquisition module can be changed to a preset fixed IP (non-real IP), such as 127.0.0.1; the purpose of changing the external IP address is mainly to hide the real IP information, protect database privacy and information security, and prevent malicious tracking and attacks. The real IP address of the acquisition module can be provided to the agent through the acquisition configuration information for data call.
[0056] In order to clearly and concisely explain the generation, transmission and application process of the first account and secret information, public key and private key, Figure 3 And the following example illustrates, Figure 3 A process diagram of the monitoring method for a unified acquisition agent, such as Figure 3 As shown in the figure, the monitoring method of the unified collection agent mainly includes:
[0057] S11. The user clicks "Accept Management";
[0058] S12, calling the service to send a management request to the agent;
[0059] S13, the agent generates first account and password information;
[0060] S14, the agent (locally) stores the first account and password information;
[0061] S15, the agent generates a public key and a private key;
[0062] S16, the agent locally stores the private key;
[0063] S17, the agent encrypts the first account and secret information and the public key;
[0064] Specifically, the first account secret information and the public key are encrypted by a built-in symmetric key; S18, the agent returns the (encrypted) first account secret information and the public key to the calling service;
[0065] S19, calling the service to decrypt the first account and password information and the public key and store them;
[0066] Specifically, the first account secret information and the public key are decrypted by the built-in symmetric key and stored in a local database;
[0067] S21, calling the service to obtain collection configuration information;
[0068] S22, calling the service to collect configuration information using public key encryption;
[0069] S23, calling the service to send the collection configuration information to the agent;
[0070] S24, the agent decrypts the collection configuration information and stores it locally;
[0071] Specifically, decryption is performed using the private key corresponding to the public key;
[0072] S31, calling the service to obtain the monitoring configuration file;
[0073] S32, calling the service to generate a work file according to the monitoring configuration file and the first account and password information;
[0074] S33, calling the service to send the work file to Prometeus;
[0075] S34, Prometeus requests data from the agent according to the work file.
[0076] Among them, S13-S14 is the process of generating and storing the first account and secret information, S15-S16 is the process of generating a public key, a private key and saving the private key, the order of occurrence of these two processes is interchangeable, and the present invention does not limit this. S21-S24 is the process of transmitting the collection configuration file, and S31-S34 is the process of generating and applying the working file.
[0077] The monitoring method of the unified acquisition agent provided by the embodiment of the present invention has the following beneficial effects: the information transmission between the agent end and the calling service is encrypted transmission. Specifically, when the agent end transmits the first account and secret information and the public key to the calling service, a symmetric key is used for encryption. The agent end sends the generated public key to the calling service. The calling service uses the public key to encrypt the subsequently transmitted information. The agent end uses the locally stored private key to decrypt the information, which can effectively achieve secure encryption and avoid information leakage during the information transmission process. On the other hand, the first account and secret information is used to access the agent end, that is, the agent end can use the first account and secret information to authenticate the access request object. Only objects with access rights can obtain the data collected by the acquisition module, that is, a secure access mechanism is set to avoid the risk of information leakage, and the ports of all acquisition modules do not need to be exposed to the outside, which improves information security. In addition, the data to be collected by the acquisition module can be configured through the acquisition configuration information to meet different business needs.
[0078] In an optional embodiment, Prometheus obtains data of the target instance from the agent according to the work file, including: Prometheus accesses the agent according to the work file request; the agent matches the first account and password information in the request sent by Prometheus with the first account and password information stored locally, and when the match is successful, provides collection configuration information to the collection module to collect data for the target instance, and feeds back the obtained data to Prometheus.
[0079] Exemplarily, the working file includes the first account and password information and the monitoring configuration information. The monitoring configuration information includes the IP address of the agent. When Prometheus requests the agent to obtain indicator data, it generates an access request according to the first account and password information and sends it to the agent pointed to by the IP address. The agent verifies the first account and password information in the access request. After the verification, the agent calls the MySQL collection module with the configuration information. The MySQL collection module collects indicator data for the MySQL instance and returns the data to the agent, which is uniformly provided to Prometheus by the agent. The collection module no longer stores business information, account information, parameter information, etc., and is uniformly managed by the agent, which simplifies the structure and functional requirements of the collection module.
[0080] In an optional embodiment, the collection configuration information includes second account and secret information corresponding to the target instance, and the agent provides the collection configuration information to the collection module to collect data from the target instance, including: the agent module provides the collection configuration information to the collection module; the collection module accesses the target instance through the second account and secret information in the collection configuration information to collect data from the target instance, and feeds back the collected data to the agent.
[0081] Some instances need to be accessed through an account and password. In this case, the second account and password information required to access the instance can be configured in the collection configuration information, so that the collection module can pass the identity authentication of the instance and obtain data collection permissions. Since the second account and password information is encrypted as the collection configuration information and transmitted to the corresponding agent, only the corresponding agent can decrypt and obtain the second account and password information, which improves the information security when collecting instance data.
[0082] In an optional embodiment, after the acquisition module feeds back the collected data to the agent, the agent adds a label to the data collected by the acquisition module according to the locally stored acquisition configuration information, and the label includes the monitoring type and target instance information, so that the operation and maintenance monitoring system can conveniently classify and analyze the collected data.
[0083] In addition, the proxy integrates the PING / TELENT function. The proxy monitors the connectivity between nodes (collection modules), sends the target list through the console, performs connectivity detection on the IP and port in the target list, and returns the detection results to prometheus according to the indicator data.
[0084] In an optional embodiment, the operation and maintenance monitoring system further includes an installation package repository, and the calling service further includes a console connected to the agent. The monitoring method of the unified acquisition agent further includes:
[0085] When the console receives a user instruction, it obtains notification information from the user instruction and transmits it to the corresponding agent after encrypting it with the locally stored public key. The user instruction is an update instruction or an installation instruction. The notification information includes the installation package address, installation package version and the temporary access key required to access the installation package repository; the agent decrypts the notification information with the locally stored private key, pulls the installation package from the installation package repository to the local monitoring node based on the notification information and performs the installation operation. After completing the installation operation, it feedbacks the installation completion information to the console.
[0086] Specifically, the user can click on the update agent in a monitoring node of the system to which the user belongs on the operation and maintenance monitoring system page. After receiving the user's command, the console in the operation and maintenance monitoring system sends the notification information to the corresponding child node. When the console sends the notification, it will encrypt the notification information and send it to the corresponding agent. The notification information includes: the installation package address (the storage directory of the installation package), the installation package version and the temporary access key required to access the installation package warehouse (the expiration time is set according to the actual situation). After the agent performs local decryption with the local private key, it obtains the corresponding notification information. The agent accesses the collection module warehouse with the temporary access key, obtains the collection module installation package of the corresponding version, and pulls the installation package to the local monitoring node, and performs installation and activation operations. After the agent completes the execution, it returns the relevant information to the console. Among them, the communication between the agent and the console is through the https protocol, and the agent self-signs the certificate, and the validity period of the certificate can be set to be long-term.
[0087] The simplified process of collecting module installation is as follows Figure 4 As shown, it mainly includes:
[0088] 1. User trigger;
[0089] Trigger the installation or update command of the installation package on the user side.
[0090] 2. The console sends notification information to the agent;
[0091] The console generates notification information based on the instruction and sends it to the agent;
[0092] 3. The agent obtains the deployment file from the collection module warehouse;
[0093] 4. The agent installs the collection module locally.
[0094] Under the premise that the corresponding acquisition module installation package is stored in the acquisition module warehouse, the user can deploy the acquisition module on the user side, which greatly reduces the workload of installing and deploying the acquisition module, especially when there are a large number of acquisition modules, the advantages of this solution are more prominent. In addition, after the monitoring platform of the present invention is developed, the acquisition module can be developed in a targeted manner according to business needs, which can not only meet the functional requirements of the acquisition module in different periods, but also reduce the deployment workload.
[0095] In an optional embodiment, the calling service further includes a console connected to the agent, the console is provided with a management page, and the monitoring method of the unified acquisition agent further includes:
[0096] The agent obtains the indicator information and feeds back the indicator information to the console. The indicator information includes the running status of the agent, the running status of the collection module connected to the agent, and the number of collection instances.
[0097] In addition, users can also select indicator information in the management page of the console and send it to the agent. The agent will filter the indicator information reported by the collection module according to the indicator information in the collection configuration file, and filter the indicator data outside the collection range, which can reduce the transmission and storage of redundant data and facilitate the operation and maintenance monitoring system to accurately and effectively monitor the instance data. Users can also manage the agent on the management page, including updating the collection module, checking the agent status, checking the collection module status, and managing and associating the instance. The corresponding relationship between the collection module and the instance can be reasonably and flexibly configured according to actual needs. Each collection module does not necessarily collect the instance deployed on the current server. For example, when the performance of service A is limited and not enough to deploy more collection modules, some collection modules can be deployed on server B and used to collect data from the instance deployed on server A.
[0098] In an optional embodiment, the agent restarts the acquisition module when the operation state of the acquisition module is abnormal operation. Abnormal operation includes downtime and stop operation. The acquisition module is controlled by the agent. When the acquisition module is abnormally operated, it usually cannot be automatically restored. The agent restarts the abnormally operating acquisition module, which greatly reduces the failure time of the entire monitoring platform and can avoid missing instance data and reducing the monitoring quality.
[0099] Corresponding to the above-mentioned monitoring method of the unified acquisition agent, the present invention also provides a monitoring platform. Figure 1 A schematic diagram of the structure of a monitoring platform provided by an embodiment of the present invention. The monitoring platform includes an operation and maintenance monitoring system 1 and multiple monitoring nodes 2 ( Figure 1 Only one monitoring node is given as an example). The operation and maintenance monitoring system 1 includes a call service 11 and Prometheus 12. Each monitoring node 2 includes an agent 21 and multiple collection modules 22 that are communicatively connected to the agent 21. Each collection module 22 is connected to a corresponding instance 3. Generally speaking, each collection module 22 is connected to one instance 3.
[0100] The functions of each node in the monitoring platform are as follows:
[0101] The calling service is used to call the interface of the agent end when receiving a management instruction for the target instance;
[0102] The agent is used to generate a public key and a private key and store the private key locally when the interface is called, and to generate first account and secret information and store it locally, encrypt the first account and secret information and the public key with the symmetric key built into the agent and send them to the calling service, and the first account and secret information is used to access the agent;
[0103] The calling service is further used to decrypt the encrypted first account secret information and public key based on a built-in symmetric key and store them locally;
[0104] The calling service is further used to obtain monitoring configuration information corresponding to the agent, generate a working file according to the monitoring configuration information and the first account and password information, and push it to Prometheus; and obtain collection configuration information corresponding to the target instance, encrypt the collection configuration information by a locally stored public key, and send it to the agent;
[0105] The agent terminal decrypts the collection configuration information according to the private key stored locally and stores it locally;
[0106] Prometheus is used to obtain data of the target instance from the proxy according to the work file.
[0107] Optionally, Prometheus, for accessing the proxy according to the work file request;
[0108] The proxy end is further used to match the first account and password information in the request sent by Prometheus with the first account and password information stored locally, and when the match is successful, provide the collection configuration information to the collection module to collect data for the target instance, and feed back the obtained data to Prometheus.
[0109] Optionally, the collection configuration information includes second account and password information corresponding to the target instance.
[0110] The proxy module is further used to provide the acquisition configuration information to the acquisition module;
[0111] The collection module is further used to access the target instance through the second account and password information in the collection configuration information to collect data from the target instance and feed back the collected data to the agent.
[0112] Optionally, the agent is further used to add a label identifier to the data collected by the collection module according to the collection configuration information stored locally, and the label identifier includes the monitoring type and information of the target instance.
[0113] Optionally, the operation and maintenance monitoring system further includes an installation package warehouse, and the calling service further includes a console connected to the agent.
[0114] The console is further configured to, upon receiving a user instruction, obtain notification information from the user instruction and transmit the information to the corresponding agent after encrypting the information using a locally stored public key, wherein the user instruction is an update instruction or an installation instruction, and the notification information includes an installation package address, an installation package version, and a temporary access key required for accessing the installation package repository;
[0115] The agent is also used to decrypt the notification information using a locally stored private key, pull the installation package from the installation package warehouse to the monitoring node based on the notification information and perform the installation operation locally, and after completing the installation operation, feedback the installation completion information to the console.
[0116] Optionally, the calling service further includes a console connected to the agent, wherein the console is provided with a management page.
[0117] The agent is also used to obtain indicator information and feed back the indicator information to the console. The indicator information includes the running status of the agent, the running status of the collection module connected to the agent, and the number of collection instances.
[0118] Optionally, the agent terminal is further used to restart the acquisition module when the operation status of the acquisition module is abnormal operation.
[0119] The monitoring platform provided by the embodiment of the present invention can execute the monitoring method of the unified acquisition agent provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0120] Figure 5 A schematic diagram of an electronic device 40 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0121] like Figure 5As shown, the electronic device 40 includes at least one processor 41, and a memory connected to the at least one processor 41, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 to the random access memory (RAM) 43. In the RAM 43, various programs and data required for the operation of the electronic device 40 can also be stored. The processor 41, the ROM 42, and the RAM 43 are connected to each other through a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0122] A number of components in the electronic device 40 are connected to the I / O interface 45, including: an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0123] The processor 41 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The processor 41 executes the various methods and processes described above, such as the monitoring method of the unified acquisition agent.
[0124] In some embodiments, the monitoring method of the unified acquisition agent may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded into the RAM 43 and executed by the processor 41, one or more steps of the monitoring method of the unified acquisition agent described above may be performed. Alternatively, in other embodiments, the processor 41 may be configured to execute the monitoring method of the unified acquisition agent by any other appropriate means (e.g., by means of firmware).
[0125] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0126] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0127] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0128] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0129] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0130] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.
[0131] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
[0132] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A monitoring method for a unified acquisition agent, characterized in that: Applied to a monitoring platform, the monitoring platform includes an operation and maintenance monitoring system and multiple monitoring nodes, the operation and maintenance monitoring system includes a call service and Prometheus, each of the monitoring nodes includes an agent and multiple acquisition modules connected to the agent, and each of the acquisition modules is connected to a corresponding instance; The calling service calls the interface of the proxy end when receiving the management instruction for the target instance; When the interface is called, the agent generates a public key and a private key and stores the private key locally, generates first account and secret information and stores it locally, encrypts the first account and secret information and the public key with a built-in symmetric key of the agent, and sends the encrypted information to the calling service, and the first account and secret information is used to access the agent; The calling service decrypts the encrypted first account secret information and public key based on the built-in symmetric key and stores them locally; The calling service obtains the monitoring configuration information corresponding to the agent, generates a working file according to the monitoring configuration information and the first account and password information, and pushes the working file to Prometheus, and obtains the collection configuration information corresponding to the target instance, encrypts the collection configuration information by a locally stored public key, and sends the working file to the agent; The agent terminal decrypts the collection configuration information according to the private key stored locally and stores it locally; Prometheus obtains data of the target instance from the proxy according to the work file.
2. The method according to claim 1, characterized in that The Prometheus obtains the data of the target instance from the proxy according to the work file, including: Prometheus accesses the proxy terminal according to the work file request; The proxy matches the first account and password information in the request sent by Prometheus with the first account and password information stored locally, and when the match succeeds, provides the collection configuration information to the collection module to collect data for the target instance, and feeds the obtained data back to Prometheus.
3. The method according to claim 2, characterized in that The collection configuration information includes second account and password information corresponding to the target instance, and the agent provides the collection configuration information to the collection module to collect data for the target instance, including: The proxy module provides the acquisition configuration information to the acquisition module; The collection module accesses the target instance through the second account and password information in the collection configuration information to collect data from the target instance, and feeds back the collected data to the agent.
4. The method according to claim 3, characterized in that After the collection module feeds back the collected data to the agent, the method further includes: The agent adds a label identifier to the data collected by the collection module according to the collection configuration information stored locally, and the label identifier includes the monitoring type and information of the target instance.
5. The method according to any one of claims 1 to 4, characterized in that: The operation and maintenance monitoring system further includes an installation package warehouse, the calling service further includes a console connected to the agent, and the method further includes: When the console receives a user instruction, it obtains notification information from the user instruction and transmits it to the corresponding agent after encrypting it with a locally stored public key. The user instruction is an update instruction or an installation instruction. The notification information includes the installation package address, the installation package version and a temporary access key required to access the installation package warehouse. The agent decrypts the notification information through a locally stored private key, pulls the installation package from the installation package warehouse to the monitoring node based on the notification information and performs the installation operation locally, and after completing the installation operation, feeds back the installation completion information to the console.
6. The method according to any one of claims 1 to 4, characterized in that: The calling service further includes a console connected to the agent, the console is provided with a management page, and the method further includes: The agent terminal acquires indicator information and feeds back the indicator information to the console, wherein the indicator information includes the running status of the agent terminal, the running status of the collection module connected to the agent terminal, and the number of collection instances.
7. The method according to claim 6, characterized in that Also includes: When the operation status of the acquisition module is abnormal, the agent restarts the acquisition module.
8. A monitoring platform, characterized in that: include: An operation and maintenance monitoring system and multiple monitoring nodes, wherein the operation and maintenance monitoring system includes a call service and Prometheus, each of the monitoring nodes includes an agent and multiple acquisition modules that are communicatively connected to the agent, and each of the acquisition modules is connected to a corresponding instance; The calling service is used to call the interface of the agent end when receiving a management instruction for the target instance; The agent is used to generate a public key and a private key and store the private key locally when the interface is called, and to generate first account and secret information and store it locally, encrypt the first account and secret information and the public key with the symmetric key built into the agent and send them to the calling service, and the first account and secret information is used to access the agent; The calling service is further used to decrypt the encrypted first account secret information and public key based on a built-in symmetric key and store them locally; The calling service is further used to obtain monitoring configuration information corresponding to the agent, generate a working file according to the monitoring configuration information and the first account and password information, and push it to Prometheus; and obtain collection configuration information corresponding to the target instance, encrypt the collection configuration information by a locally stored public key, and send it to the agent; The agent is further used to decrypt the collection configuration information according to the private key stored locally and store it locally; Prometheus is used to obtain data of the target instance from the proxy according to the work file.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the monitoring method of the unified acquisition agent according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the monitoring method of the unified acquisition agent according to any one of claims 1 to 7 when executed.
Citation Information
Patent Citations
Method and system of automatically monitoring database service, storage medium and electronic equipment
CN107844399A
Database password operation and maintenance method and device, equipment, storage medium and program product
CN116383855A
Monitoring data acquisition method, device, equipment and medium
CN116800835A
Fingerprint authentication method and device, electronic equipment and storage medium
CN117370959A
Private cloud monitoring method and apparatus based on non-flat network, and computer device and storage medium
WO2021184586A1