Log processing method, related equipment and vehicle

By obtaining and parsing exception logs in the Android system, filtering and associating system logs, the problem of low efficiency of exception analysis in the Android system is solved, and more efficient and accurate analysis of abnormal causes is achieved.

CN120011184APending Publication Date: 2025-05-16GREAT WALL MOTOR CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411360444.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-27
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The efficiency of abnormal analysis in Android systems is low, mainly due to the large amount of system data, which leads to the inefficient analysis of abnormal causes.

Method used

A log processing method is proposed, including obtaining the identification information of the exception log and the core process, parsing the exception log to obtain exception information, filtering the system log to obtain candidate system logs, and querying the associated system log through the exception information so that users can analyze the cause of the exception.

Benefits of technology

By filtering and associating logs, the amount of data that needs to be processed during analysis is reduced, the efficiency and accuracy of abnormal cause analysis is improved, and the causes of abnormality can be comprehensively analyzed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120011184A_ABST
    Figure CN120011184A_ABST
Patent Text Reader

Abstract

The invention provides a log processing method, related equipment and a vehicle, and the method is applied to an Android system, and comprises the steps: obtaining an abnormal log of the Android system and first identification information of a core process; and analyzing the abnormal log to obtain abnormal information corresponding to the abnormal log. Reading system logs of the Android system, and screening the system logs according to the abnormal information and the first identification information to obtain candidate system logs. And querying in the candidate system logs according to the exception information to obtain an associated system log, so that a user analyzes an exception reason of the exception log according to the associated system log and the exception log. The number of the system logs related to the core process is large, so that further screening can be performed in the candidate system logs according to the abnormal information to determine the system logs strongly related to the abnormal logs, and the efficiency and accuracy of subsequent abnormal reason analysis can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of Android systems, and in particular to a log processing method, related equipment and vehicles. Background Art

[0002] The Android system may encounter some abnormal conditions during operation, such as application unresponsiveness or application crash. When an abnormal condition occurs, an abnormal log will be generated to record relevant information of the abnormal condition. At present, when analyzing the abnormal cause of the abnormal condition, the system data (such as logs or process data) before and after the abnormality occurs will be combined for analysis. However, the amount of system data is large, resulting in low efficiency in abnormal cause analysis. Summary of the invention

[0003] In view of this, the purpose of this application is to propose a log processing method, related equipment and vehicle to solve the problem of low efficiency of exception analysis in Android system.

[0004] Based on the above purpose, the first aspect of the present application provides a log processing method, which is applied to an Android system, comprising:

[0005] Obtaining the abnormal log of the Android system and the first identification information of the core process;

[0006] Parsing the abnormal log to obtain abnormal information corresponding to the abnormal log;

[0007] Reading a system log of the Android system, and screening the system log according to the abnormal information and the first identification information to obtain a candidate system log;

[0008] According to the abnormal information, the associated system log is queried in the candidate system log to obtain the abnormal system log, so that the user can analyze the abnormal cause of the abnormal log according to the associated system log and the abnormal log.

[0009] Optionally, the exception information includes a second process identifier of a process corresponding to the exception log; the first identification information includes a first process identifier of the core process; and the screening of the system log according to the exception information and the first identification information to obtain a candidate system log includes:

[0010] Search the system log for logs related to the first process identifier and the second process identifier as the candidate system logs.

[0011] Optionally, the exception information includes a package name of an application corresponding to the exception log and an exception time; and querying the candidate system logs to obtain a related system log according to the exception information includes:

[0012] Determine an abnormal time period according to the abnormal time and a first preset time period, and determine a first candidate log from the candidate system logs according to the abnormal time period;

[0013] The associated system log is determined by searching the first candidate log according to the package name.

[0014] Optionally, determining the abnormal time period according to the abnormal moment and a first preset duration, and determining a first candidate log from the candidate system logs according to the abnormal time period includes:

[0015] Determine the abnormal start time and the abnormal end time according to the abnormal time and the first preset time; determine the abnormal time period according to the abnormal start time and the abnormal end time; and use the logs in the candidate system logs that occur within the abnormal time period as the first candidate logs.

[0016] Optionally, querying and determining the associated system log in the first candidate log according to the package name includes:

[0017] Filtering the first candidate logs according to the package name to obtain a first associated log;

[0018] The associated system log is determined by querying the first candidate log according to the first associated log and the second preset time.

[0019] Optionally, the querying and determining the associated system log in the first candidate log according to the first associated log and the second preset time period includes:

[0020] Taking the time corresponding to the first association log as the association end time, and determining the association start time according to the association end time and the second preset duration;

[0021] The logs generated at the time between the association start time and the association end time in the first candidate logs are used as the associated system logs.

[0022] Optionally, the obtaining of the abnormal log of the Android system and the first identification information of the core process includes:

[0023] The abnormal log and the first identification information are respectively obtained through a command line tool of the Android system.

[0024] The second aspect of the present application further provides a log processing device, which is applied to an Android system, comprising:

[0025] An acquisition module is configured to acquire the abnormal log of the Android system and the first identification information of the core process;

[0026] A parsing module is configured to parse the abnormal log to obtain abnormal information corresponding to the abnormal log;

[0027] a screening module configured to read the system log of the Android system, screen the system log according to the abnormal information and the first identification information, and obtain a candidate system log;

[0028] The query module is configured to query the candidate system logs to obtain the associated system logs according to the abnormal information, so that the user can analyze the abnormal cause of the abnormal log according to the associated system logs and the abnormal logs.

[0029] The third aspect of the present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the method described in the first aspect when executing the computer program.

[0030] A fourth aspect of the present application also provides a vehicle, comprising the electronic device as described in the third aspect.

[0031] As can be seen from the above, the log processing method, related equipment and vehicle provided by the present application are applied to the Android system, including obtaining the abnormal log of the Android system and the first identification information of the core process. The abnormal log is a log generated when the application program in the Android system runs abnormally, in which the abnormal information is recorded. The core process is an important process in the operation process of the Android system, and most applications run in this process. The abnormal log is parsed to obtain the abnormal information corresponding to the abnormal log, and the abnormal information can be used as a keyword to retrieve the relevant log in the subsequent abnormal cause analysis process. Read the system log of the Android system, and filter the system log according to the abnormal information and the first identification information to obtain the candidate system log. Through the abnormal information and the first identification information, some system logs that are not related to the abnormal cause can be eliminated, reducing the amount of data that needs to be processed in the subsequent analysis. Due to the large correlation of the abnormal cause, the abnormal cause cannot be fully analyzed only by the system log associated with the abnormal information, and the candidate system log of the present application includes not only the log associated with the abnormal information, but also the log associated with the core process, so it is conducive to a comprehensive analysis of the abnormal cause. According to the abnormal information, the associated system log is queried in the candidate system log, so that the user can analyze the abnormal cause of the abnormal log according to the associated system log and the abnormal log. Since the number of system logs related to the core process is large, further screening can be performed in the candidate system logs according to the abnormal information to determine the system logs that are strongly related to the abnormal log, which is conducive to improving the efficiency and accuracy of subsequent abnormal cause analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the present application or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0033] Figure 1 A flow chart of a log processing method according to an embodiment of the present application;

[0034] Figure 2 This is a schematic diagram of the structure of a log processing device according to an embodiment of the present application;

[0035] Figure 3 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0036] In order to make the objectives, technical solutions and advantages of the present application more clearly understood, the present application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.

[0037] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should be the usual meanings understood by people with ordinary skills in the field to which the present application belongs. The "first", "second" and similar words used in the embodiments of the present application do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0038] As described in the background technology, the Android system is one of the commonly used operating systems, and many mobile terminals or car terminals use the Android operating system. Some abnormal conditions may occur during the operation of the Android system, among which the more common ones are Application Not Responding (ANR) and Application Crash. ANR is an error state in the Android system, which is mainly manifested in that the application process fails to respond to user input or fails to perform main UI thread operations within a period of time. After ANR occurs, the Android system will generate a corresponding ANR file, which records the abnormal information when ANR occurs. Crash refers to an application that exits abnormally or stops running due to some reasons, which is usually caused by errors or exceptions in the program. This abnormal exit may be caused by a variety of reasons such as code errors, insufficient resources, system resource competition, etc. After Crash occurs, the Android system will generate a corresponding Crash file, which records the abnormal information when Crash occurs.

[0039] After an abnormal situation occurs, developers usually analyze the cause of the abnormal situation based on the abnormal log (such as ANR files, Crash files, etc.). However, since the abnormal situation usually involves many reasons and is related to many processes in the Android system, it is impossible to comprehensively and accurately check the cause of the abnormal situation based on the abnormal log alone. Therefore, developers will also analyze the cause of the abnormal situation in combination with some system logs or process-related data before and after the abnormal situation occurs. However, the system logs or process-related data contain a lot of redundant data, which brings great trouble to the investigation of the cause of the abnormality, resulting in reduced efficiency of abnormal analysis.

[0040] In view of this, this application proposes a daily processing method that can combine the abnormal log and the system log to jointly investigate the abnormal cause to ensure the comprehensiveness of the investigation. At the same time, due to the large number of system logs, in order to reduce the workload of investigation, a method for screening system logs based on abnormal logs and core threads is also proposed to streamline the system logs to remove system logs that are not related to the abnormal cause, which greatly reduces the workload of investigating the abnormal cause and improves the efficiency and accuracy of investigating the abnormal cause.

[0041] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0042] This application proposes a log processing method, refer to Figure 1 , applied to Android system, including the following steps:

[0043] Step 102: Obtain the abnormal log of the Android system and the first identification information of the core process.

[0044] Specifically, if an abnormal operation occurs during the operation of an application in the Android system, an abnormal log is usually generated. The daily log is used to record the abnormal information related to the abnormal condition. Therefore, after determining that an abnormal condition has occurred in the system, the abnormal log can be obtained for subsequent investigation of the cause of the abnormality. Exemplarily, the abnormal log can be an ANR file or a Crash file.

[0045] In addition, since the causes of the exception are relatively broad, it may not be possible to fully or accurately investigate the causes of the exception based solely on the exception log. Therefore, in this application, it is also necessary to additionally obtain the first identification information of the core process. The core process is the main process in the Android system. Exemplarily, the core process may be the system_server process, which is responsible for starting and managing various services in the system. Most services run in this process. The core process includes the system operation information during the application runtime period and the time periods before and after the runtime period, that is, the core process includes associated data related to the cause of the exception. The data in the core process helps to comprehensively investigate the cause of the exception.

[0046] The first identification information may be a unique identification of the core process, such as a process identifier (PID). A PID is a number or identifier used to uniquely identify each process in an operating system.

[0047] Step 104: parse the exception log to obtain exception information corresponding to the exception log.

[0048] Specifically, the exception log contains information generated during the operation of the application. By parsing the acquired exception log, the exception information can be determined. Exemplarily, the exception information includes the exception time when the application runs abnormally, the process ID and process name of the process generated by the application running, etc. Exemplarily, the process ID can be the PID of the process, such as PID13912, the exception time can be 2022-12-01 12:35:55, and the process name is com.beantechs.stemcells:plugin1.

[0049] Step 106: read the system log of the Android system, and filter the system log according to the abnormal information and the first identification information to obtain candidate system logs.

[0050] Specifically, after determining the abnormal information and the first identification information, all system logs generated by the Android system can be screened to determine the system logs related to the abnormal information and the core process. Further, after reading the system log, the system log is screened according to the abnormal information and the first identification information. The abnormal information contains the identification information of the abnormal process, and the first identification information contains the identification information of the core process. The system logs related to the abnormal process and the core process can be screened according to the abnormal information and the first identification information. The cause of the abnormality can be checked through the content recorded in the system log. The system log obtained after screening is recorded as a candidate system log.

[0051] Step 108: According to the abnormal information, the associated system log is queried in the candidate system log to obtain the associated system log, so that the user can analyze the abnormal cause of the abnormal log according to the associated system log and the abnormal log.

[0052] Specifically, the candidate system logs include logs related to the core process, and the logs related to the core process include logs related to exceptions and logs unrelated to exceptions. Generally speaking, the data in the system log file is redundant and contains a large amount of content unrelated to exceptions. Therefore, at this time, it is necessary to filter the system logs that have been filtered once again according to the exception information to further narrow the scope of the system logs and reduce the amount of data for subsequent investigation. The system logs filtered according to the exception information are recorded as associated system logs. Developers can conduct a comprehensive investigation of the causes of the exceptions based on the exception logs and associated system logs to avoid missing the causes of the exceptions and causing exception investigation errors.

[0053] Based on the above steps 102 to 108, this embodiment provides a log processing method, which is applied to the Android system, including obtaining the abnormal log of the Android system and the first identification information of the core process. The abnormal log is a log generated when an application program in the Android system runs abnormally, in which the abnormal information is recorded. The core process is an important process in the operation process of the Android system, and most applications run in this process. The abnormal log is parsed to obtain the abnormal information corresponding to the abnormal log, and the abnormal information can be used as a keyword to retrieve the relevant logs in the subsequent abnormal cause analysis process. The system log of the Android system is read, and the system log is screened according to the abnormal information and the first identification information to obtain a candidate system log. The system log that is not related to the abnormal cause can be eliminated by the abnormal information and the first identification information, thereby reducing the amount of data to be processed in the subsequent analysis. Due to the large correlation of the abnormal cause, the abnormal cause cannot be fully analyzed only by the system log associated with the abnormal information, and the candidate system log of the present application includes not only the log associated with the abnormal information, but also the log associated with the core process, so it is conducive to a comprehensive analysis of the abnormal cause. According to the abnormal information, the associated system log is queried in the candidate system log, so that the user can analyze the abnormal cause of the abnormal log according to the associated system log and the abnormal log. Since the number of system logs related to the core process is large, further screening can be performed in the candidate system logs according to the abnormal information to determine the system logs that are strongly related to the abnormal log, which is conducive to improving the efficiency and accuracy of subsequent abnormal cause analysis.

[0054] The method for determining the candidate system logs is described in detail below.

[0055] In some embodiments, the exception information includes a second process identifier of a process corresponding to the exception log; the first identification information includes a first process identifier of the core process; and the filtering of the system log according to the exception information and the first identification information to obtain a candidate system log includes:

[0056] Search the system log for logs related to the first process identifier and the second process identifier as the candidate system logs.

[0057] Specifically, the first identification information may be the PID of the core process, and the exception information includes the PID of the abnormal process corresponding to the exception log. Usually, the system log records the running data of each process in the Android system, and each process has a corresponding PID. Therefore, the corresponding system log content can be queried in the Android system according to the PID. During specific implementation, the PID of the core process and the PID of the abnormal process are used as matching keywords, respectively, and matching is performed in the system log to determine the system logs recording the core process and the abnormal process as candidate system logs. Through the method of this embodiment, the system logs can be preliminarily screened, and the system logs irrelevant to the abnormal process and the core process can be removed, and most of the irrelevant content can be eliminated, thereby achieving a preliminary simplification of the system logs, which is conducive to improving the efficiency of subsequent abnormal cause investigation.

[0058] The following describes a method for determining associated system logs through a specific embodiment.

[0059] In some embodiments, the exception information includes a package name and an exception time of an application corresponding to the exception log; and querying the candidate system logs to obtain the associated system logs according to the exception information includes:

[0060] Determine an abnormal time period according to the abnormal time and a first preset time period, and determine a first candidate log from the candidate system logs according to the abnormal time period;

[0061] The associated system log is determined by searching the first candidate log according to the package name.

[0062] Specifically, the exception information includes the package name and the abnormal time of the application recorded in the exception log. Each application corresponds to a unique package name, and the process generated during the operation of the application corresponds to a unique process name. The process names corresponding to different processes generated by the same application are different. The package name of the application can be determined by the process name. Exemplarily, the package name of the application can be com.beantechs.stemcells, and the corresponding process name can be com.beantechs.stemcells:plugin1. When determining the associated system log in the first candidate log according to the exception information, the abnormal period is first determined according to the abnormal time and the first preset duration. The abnormal period is also the period when the abnormal moment occurs. The system log in this period has a strong correlation with the abnormal cause. Therefore, it is necessary to determine the first candidate log in the candidate system log according to the abnormal period. In addition, since the Android system will run multiple processes simultaneously in the same period, after determining the first candidate log corresponding to the abnormal period, the first candidate log can also be further screened according to the package name to determine the system log directly related to the abnormal process, which is recorded as the associated system log. Through the method of this embodiment, the system log can be screened twice according to the abnormal information to further exclude irrelevant logs, and the system log can be streamlined twice to further improve the efficiency of abnormal cause investigation.

[0063] The following describes a method for determining the first candidate log through a specific embodiment.

[0064] In some embodiments, determining the abnormal time period according to the abnormal time and the first preset duration, and determining the first candidate log from the candidate system logs according to the abnormal time period includes:

[0065] Determine the abnormal start time and the abnormal end time according to the abnormal time and the first preset time; determine the abnormal time period according to the abnormal start time and the abnormal end time; and use the logs in the candidate system logs that occur within the abnormal time period as the first candidate logs.

[0066] Specifically, the first preset duration is predetermined according to actual needs, for example, the first preset duration is 5s or 10s. According to the abnormal moment and the first preset duration, the abnormal start time and the abnormal end time can be determined respectively. For example, when the first preset duration is 5s, the moment corresponding to the first 5s of the abnormal moment is the abnormal start time, and the moment corresponding to the last 5s of the abnormal moment is the abnormal end time. The duration between the abnormal start time and the abnormal end time is the abnormal period. After determining the abnormal period, the system logs generated during the abnormal period are screened out as the first candidate logs. In other words, the first candidate log is all system logs related to abnormal processes and cores generated by the Android system when an abnormality occurs during the operation of the application. Since the generated time period is the same, the probability that the first candidate log contains data that is strongly related to the cause of the abnormality is relatively large. By combining the abnormal log and the first candidate log, the cause of the abnormality can be accurately located, thereby improving the accuracy of the abnormal cause investigation.

[0067] After the first candidate log is determined, it is necessary to further determine the associated system log according to the package name, which is specifically described in the following embodiment.

[0068] In some embodiments, querying and determining the associated system log in the first candidate log according to the package name includes:

[0069] Filtering the first candidate logs according to the package name to obtain a first associated log;

[0070] The associated system log is determined by querying the first candidate log according to the first associated log and the second preset time.

[0071] Specifically, the package name is used to identify the application. By filtering the first candidate log by the package name, the system log related to the application with abnormal operation can be determined in the first candidate log. Although the time period of the first candidate log is the same as the abnormal time period of the abnormal process, since the Android system runs multiple processes at the same time, the first candidate log may also include content unrelated to the abnormality. Therefore, it is necessary to further filter the first candidate log according to the package name that can identify the application. The process name of each process is recorded in the system log. The package name of the application can be determined according to the process name. Therefore, the package name can be used as a matching keyword to filter the system log. In specific implementation, the package name is used as a matching keyword to match in the first candidate log, and the log obtained by matching is used as the first associated log. Exemplarily, if the abnormal log is an ANR file, the matching keyword template is "ANR in packageName", packageName is the package name, and when the package name is com.xt.client, the matching keyword is "ANR in com.xt.client". The first associated log can be determined by matching the keyword.

[0072] The system log will record the process name of each process, and will also record the time corresponding to the process. The first associated log determined by the package name is only the system log at a time close to the abnormal time. Before the abnormality occurs, the system usually has some data changes, which can characterize the impending abnormality. Therefore, in order to analyze the cause of the abnormality, the system log generated in a period of time before the abnormal moment can also be combined to analyze the cause of the abnormality, which is conducive to comprehensively capturing the cause of the abnormality. The second preset time is pre-set according to demand. The second preset time is used to limit the specific time of a period before the abnormal moment. Exemplarily, the second preset time can be 2 minutes. After determining the first associated log, the system log when the abnormality occurs is determined, and then the system log in a period of time before the abnormality occurs is determined according to the second preset time, that is, the associated system log. Through the method of this embodiment, not only can the first associated log directly related to the abnormal process be determined, but also the associated system log that can cause the abnormal process to occur can be determined according to the first associated log and the second preset time, which provides an analysis data basis for the subsequent accurate investigation of the cause of the abnormality.

[0073] The following describes how to determine the associated system log according to the first associated log and the second preset time through a specific embodiment.

[0074] In some embodiments, querying and determining the associated system log in the first candidate log according to the first associated log and the second preset time length includes:

[0075] Taking the time corresponding to the first association log as the association end time, and determining the association start time according to the association end time and the second preset duration;

[0076] The logs generated at the time between the association start time and the association end time in the first candidate logs are used as the associated system logs.

[0077] Specifically, the moment corresponding to the first associated log is used as the associated end moment. For example, the associated end moment is 2024-09-08 18:28:38. The associated start moment is determined according to the associated end moment and the second preset duration. If the second preset duration is 2 minutes, the associated start moment is the moment 2 minutes before the associated end moment occurs. Continuing with the above example, the associated start moment is 2024-09-08 18:26:38. Afterwards, the system log generated between the associated start moment and the associated end moment is used as the associated system log. In specific implementation, the system logs located between the associated start moment and the associated end moment are screened in the first candidate log, and this part of the logs is extracted as the associated system log. Through the method of this embodiment, the associated system logs with a strong correlation with the abnormal cause can be accurately determined. The associated system logs are not only strongly correlated with the application corresponding to the abnormal process, but also strongly correlated with the abnormal moment when the abnormal process occurs. That is, the system logs related to the abnormal cause are accurately locked in the system log, which greatly reduces the scope of abnormal cause investigation on the basis of ensuring the accuracy of abnormal investigation and improves the investigation efficiency.

[0078] The following describes a method for obtaining an abnormal log and the first identification information through a specific embodiment.

[0079] In some embodiments, obtaining the abnormal log of the Android system and the first identification information of the core process includes:

[0080] The abnormal log and the first identification information are respectively obtained through a command line tool of the Android system.

[0081] Specifically, in the Android system, the exception log and the first identification information can be obtained through the command line tool. Exemplarily, the command line tool can be an adb tool. When the exception log is an ANR file, the ANR file can be obtained by constructing an adb command, such as the adb command is adb shell cat / data / anr / traces.txt, which is used to view the latest ANR file content. ANR files are usually located in the / data / anr / directory, and the file name is traces.txt. The ANR file records detailed information about the application when an ANR situation occurs, including memory usage, thread status, function calls, etc. This information is very valuable for exception troubleshooting and can help locate and solve performance problems, optimize application performance, and improve user experience.

[0082] When obtaining the first identification information, it can also be achieved by constructing an adb command. For example, the adb command is adb shellps|grep system_server, which is used to view the PID of the process. The first identification information obtained can specifically be PID1111. Through the method of this embodiment, the abnormal log and the first identification information can be obtained quickly and accurately.

[0083] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the described method.

[0084] It should be noted that the above describes some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0085] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a log processing device.

[0086] refer to Figure 2 The log processing device is applied to the Android system and includes:

[0087] An acquisition module 202 is configured to acquire the abnormal log of the Android system and the first identification information of the core process;

[0088] The parsing module 204 is configured to parse the abnormal log to obtain abnormal information corresponding to the abnormal log;

[0089] A screening module 206 is configured to read the system log of the Android system, screen the system log according to the abnormal information and the first identification information, and obtain a candidate system log;

[0090] The query module 208 is configured to query the candidate system logs to obtain associated system logs according to the abnormal information, so that the user can analyze the abnormal cause of the abnormal log according to the associated system logs and the abnormal log.

[0091] In some embodiments, the exception information includes a second process identifier of the process corresponding to the exception log; the screening module 206 is further configured to search the system log for logs related to the first process identifier and the second process identifier as the candidate system log.

[0092] In some embodiments, the exception information includes the package name of the application corresponding to the exception log and the exception time; the query module 208 is also configured to determine the exception time period based on the exception time and the first preset time period, and determine the first candidate log in the candidate system log according to the exception time period; and determine the associated system log by querying in the first candidate log according to the package name.

[0093] In some embodiments, the query module 208 is also configured to determine the abnormal start time and the abnormal end time based on the abnormal time and the first preset duration; determine the abnormal time period based on the abnormal start time and the abnormal end time; and use the logs in the candidate system logs that occur within the abnormal time period as the first candidate logs.

[0094] In some embodiments, the query module 208 is further configured to filter the first candidate logs according to the package name to obtain a first associated log;

[0095] The associated system log is determined by querying the first candidate log according to the first associated log and the second preset time.

[0096] In some embodiments, the query module 208 is further configured to use the time corresponding to the first association log as the association end time, and determine the association start time according to the association end time and the second preset duration;

[0097] The logs generated at the time between the association start time and the association end time in the first candidate logs are used as the associated system logs.

[0098] In some embodiments, the acquisition module 202 is further configured to respectively acquire the abnormal log and the first identification information through a command line tool of the Android system.

[0099] For the convenience of description, the above device is described in terms of functions divided into various modules. Of course, when implementing the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0100] The device of the above embodiment is used to implement the corresponding log processing method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.

[0101] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the log processing method described in any of the above embodiments when executing the program.

[0102] Figure 3 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 in the device.

[0103] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0104] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0105] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0106] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).

[0107] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0108] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.

[0109] The electronic device of the above embodiment is used to implement the corresponding log processing method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0110] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the log processing method described in any of the above embodiments.

[0111] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0112] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the log processing method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0113] Based on the same concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a computer program product, including computer program instructions. When the computer program instructions are run on a computer, the computer executes the method described in any of the above embodiments, which has the beneficial effects of the corresponding method embodiments and will not be repeated here.

[0114] A person skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application is limited to these examples. In line with the concept of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0115] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present application difficult to understand, the known power supply / ground connection with the integrated circuit (IC) chip and other components may or may not be shown in the provided drawings. In addition, the device can be shown in the form of a block diagram to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform to be implemented in the embodiments of the present application (that is, these details should be fully within the scope of understanding of those skilled in the art). In the case of elaborating specific details (e.g., circuits) to describe exemplary embodiments of the present application, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.

[0116] Although the present application has been described in conjunction with specific embodiments of the present application, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.

[0117] The embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the present application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the protection scope of the present application.

Claims

1. A log processing method, characterized in that: Applicable to Android system, including: Obtaining the abnormal log of the Android system and the first identification information of the core process; Parsing the abnormal log to obtain abnormal information corresponding to the abnormal log; Reading a system log of the Android system, and screening the system log according to the abnormal information and the first identification information to obtain a candidate system log; According to the abnormal information, the associated system log is queried in the candidate system log to obtain the abnormal system log, so that the user can analyze the abnormal cause of the abnormal log according to the associated system log and the abnormal log.

2. The method according to claim 1, characterized in that The exception information includes a second process identifier of the process corresponding to the exception log; the first identification information includes a first process identifier of the core process; The screening of the system log according to the abnormal information and the first identification information to obtain a candidate system log includes: Search the system log for logs related to the first process identifier and the second process identifier as the candidate system logs.

3. The method according to claim 1, characterized in that The exception information includes the package name of the application corresponding to the exception log and the exception time; the querying and obtaining the associated system log in the candidate system log according to the exception information includes: Determine an abnormal time period according to the abnormal time and a first preset time period, and determine a first candidate log from the candidate system logs according to the abnormal time period; The associated system log is determined by searching the first candidate log according to the package name.

4. The method according to claim 3, characterized in that The determining the abnormal time period according to the abnormal time and the first preset time period, and determining the first candidate log from the candidate system logs according to the abnormal time period, comprises: Determine the abnormal start time and the abnormal end time according to the abnormal time and the first preset time; determine the abnormal time period according to the abnormal start time and the abnormal end time; and use the logs in the candidate system logs that occur within the abnormal time period as the first candidate logs.

5. The method according to claim 3, characterized in that: Searching and determining the associated system log in the first candidate log according to the package name includes: Filtering the first candidate logs according to the package name to obtain a first associated log; The associated system log is determined by querying the first candidate log according to the first associated log and the second preset time.

6. The method according to claim 5, characterized in that The querying and determining the associated system log in the first candidate log according to the first associated log and the second preset time length includes: Taking the time corresponding to the first association log as the association end time, and determining the association start time according to the association end time and the second preset duration; The logs generated at the time between the association start time and the association end time in the first candidate logs are used as the associated system logs.

7. The method according to claim 1, characterized in that The obtaining of the abnormal log of the Android system and the first identification information of the core process includes: The abnormal log and the first identification information are respectively obtained through a command line tool of the Android system.

8. A log processing device, characterized in that: Applicable to Android system, including: An acquisition module is configured to acquire the abnormal log of the Android system and the first identification information of the core process; A parsing module is configured to parse the abnormal log to obtain abnormal information corresponding to the abnormal log; a screening module configured to read the system log of the Android system, screen the system log according to the abnormal information and the first identification information, and obtain a candidate system log; The query module is configured to query the candidate system logs to obtain the associated system logs according to the abnormal information, so that the user can analyze the abnormal cause of the abnormal log according to the associated system logs and the abnormal logs.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 1 to 7 is implemented.

10. A vehicle, characterized in that: The vehicle comprises the electronic device as claimed in claim 9.