Log output method and device, storage medium and electronic equipment
By dynamically generating log output strategies within the target time period and adjusting the log output level, troubleshooting problems caused by static configuration of log level in the existing technology are solved, and more efficient log management and troubleshooting are achieved.
Patent Information
- Application Number
- CN202510031572.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-23
AI Technical Summary
The log-level static configuration in the prior art makes it difficult to adapt to troubleshooting requirements.
When the number of abnormal logs output by the target business system reaches the threshold during the target time period, the first output strategy and the second output strategy are dynamically generated, and the log output level is adjusted to meet the troubleshooting needs.
By dynamically adjusting the log output level, the system can output richer log information, improve troubleshooting efficiency, and reduce unnecessary performance and storage overhead.
Smart Images

Figure CN120029867A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computers, and in particular to a log output method and device, a storage medium, and an electronic device. Background Art
[0002] In the field of software development, log output is a key means of system monitoring and troubleshooting. Traditional log management methods rely on developers to statically set log levels in the code. In production environments, log levels are often set higher for performance and storage costs, such as ERROR. However, when the system is abnormal or has problems that are difficult to locate, this statically set log level may not provide enough information. Developers usually need to trace back the code and manually adjust the log level to obtain more detailed log information to quickly locate the problem.
[0003] In other words, the log output method provided in the related art still has the technical problem of being difficult to adapt to troubleshooting needs due to the static configuration of the log level.
[0004] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention
[0005] The embodiments of the present application provide a log output method and device, a storage medium, and an electronic device to at least solve the technical problem that static configuration of log levels is difficult to adapt to troubleshooting needs.
[0006] According to one aspect of an embodiment of the present application, a log output method is provided, comprising: when the number of abnormal logs output by a target business system to a log management module within a target time period reaches a quantity threshold, generating a first output strategy and a second output strategy for the target business system, wherein the first output strategy includes a first output level of a target account that triggers the abnormal log, and the second output strategy includes a second output level of a target function object corresponding to a target business interface that triggers the abnormal log; when an initial log acquired by the target business system is triggered by a target account and the log level of the initial log matches the first output level, outputting the initial log to the log management module; when the initial log is triggered by a target function object and the log level of the initial log matches the second output level, outputting the initial log to the log management module; wherein the first output level is lower than a first threshold, and the second output level is lower than a second threshold, and the lower the output level, the more types of logs are output from the target business system.
[0007] According to another aspect of an embodiment of the present application, a log output device is also provided, including: a generation unit, which is used to generate a first output strategy and a second output strategy for the target business system when the number of abnormal logs output by the target business system to the log management module within a target time period reaches a quantity threshold, wherein the first output strategy includes a first output level of the target account that triggers the abnormal log, and the second output strategy includes a second output level of the target function object corresponding to the target business interface that triggers the abnormal log; a first output unit, which is used to output the initial log to the log management module when the initial log obtained by the target business system is triggered by the target account and the log level of the initial log matches the first output level; a second output unit, which is used to output the initial log to the log management module when the initial log is triggered by the target function object and the log level of the initial log matches the second output level; wherein the first output level is lower than the first threshold, and the second output level is lower than the second threshold, and the lower the output level, the more types of logs are output from the target business system.
[0008] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the above-mentioned log output method when running.
[0009] According to another aspect of the embodiments of the present application, a computer program product or a computer program is provided, the computer program product or the computer program including computer instructions, the computer instructions being stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above log output method.
[0010] According to another aspect of the embodiments of the present application, there is further provided an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the log output method through the computer program.
[0011] In an embodiment of the present application, when the number of abnormal logs output to the log management module by the target business system in the target time period reaches the quantity threshold, the first output strategy and the second output strategy are generated for the target business system, wherein the first output strategy includes the first output level of the target account that triggers the abnormal log, and the second output strategy includes the second output level of the target function object corresponding to the target business interface that triggers the abnormal log; when the initial log obtained by the target business system is triggered by the target account, and the log level of the initial log matches the first output level, the initial log is output to the log management module; when the initial log is triggered by the target function object, and the log level of the initial log matches the second output level, the initial log is output to the log management module; wherein the first output level is lower than the first threshold, and the second output level is lower than the second threshold, and the lower the output level, the more types of logs are output from the target business system. In other words, using an embodiment of the present application, on the one hand, when it is detected that the number of abnormal logs in the target time period reaches the quantity threshold, the first output strategy and the second output strategy are generated for the target business system, allowing the system to dynamically adjust the output level of the log at runtime, thereby adapting to the needs of troubleshooting. The generation of this dynamic strategy goes beyond the traditional static log level setting and provides a more flexible log management method. On the other hand, the first output strategy is for the exception log triggered by a specific target account, while the second output strategy is for the exception log triggered by the target function object corresponding to the specific target business interface. In other words, the system can selectively record more detailed logs for accounts and interfaces that may have problems, reduce the output of irrelevant logs, and thus optimize storage costs and system performance. On the other hand, by dynamically adjusting the log output level to a lower level, the system can output richer log information, which helps developers and operation and maintenance personnel to understand the system status more accurately, so as to quickly locate and troubleshoot problems. Compared with static log level management, this improvement significantly improves the efficiency of troubleshooting. In summary, using the embodiment of the present application, the effectiveness of logs in troubleshooting is improved, while reducing unnecessary performance and storage overhead, solving the log output method provided in the prior art, and the technical problem of being difficult to adapt to troubleshooting needs due to the static configuration of the log level. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0013] Figure 1 is a flowchart of an optional log output method according to an embodiment of the present application;
[0014] Figure 2is a schematic diagram of an optional log output method according to an embodiment of the present application;
[0015] Figure 3 is a schematic diagram of an optional log output method according to an embodiment of the present application;
[0016] Figure 4 is a schematic diagram of another optional log output method according to an embodiment of the present application;
[0017] Figure 5 is a schematic diagram of another optional log output method according to an embodiment of the present application;
[0018] Figure 6 is a flowchart of an optional log output method according to an embodiment of the present application;
[0019] Figure 7 is a schematic diagram of an optional log output method according to an embodiment of the present application;
[0020] Figure 8 is a flowchart of an optional log output method according to an embodiment of the present application;
[0021] Figure 9 is a schematic structural diagram of an optional log output device according to an embodiment of the present application;
[0022] Figure 10 It is a schematic diagram of the structure of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0023] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0025] Optionally, the resource management method described above may be applied to, but not limited to, the following scenarios:
[0026] 1) Online service troubleshooting, for example, in a video playback scenario, when the playback system source address interface receives multiple requests with non-200 status codes within a few minutes, this may indicate that the playback service has encountered a failure or performance bottleneck. At this time, a first output strategy is generated for the playback system, and the log output level of the user account (target account) associated with the abnormal request is adjusted to INFO (first output level), and a second output strategy is generated to adjust the log output level of the function related to the interface in system A to INFO (second output level). In this way, any INFO or higher level logs triggered by the target account, or INFO or higher level logs triggered by the target function object, will be collected in the log management module to help the operation and maintenance team quickly locate and analyze problems.
[0027] 2) System performance optimization. In system operation and maintenance, when it is detected that a specific business system frequently has performance warnings or errors in the log within a specific time period, the first output strategy and the second output strategy can be applied to adjust the log output level of the associated user operations (target account) and system functions (target function object) to a more detailed level (such as INFO or DEBUG) in order to better understand the reasons for the performance degradation and perform targeted optimization.
[0028] 3) Grayscale release or functional testing: During grayscale release, only some users (target accounts) can access new functions or versions. Using the first output strategy, the log output level of these users can be adjusted to a more detailed level to collect the operation data of the new function or version in a small range of users for functional verification and troubleshooting. At the same time, the second output strategy can adjust the log output level of key functions or interfaces in the new function to ensure that more operation details can be obtained during functional testing.
[0029] Optionally, as an alternative solution, as Figure 1 shown, the above method for outputting logs includes:
[0030] S102, when the number of exception logs output by the target business system to the log management module within the target time period reaches the quantity threshold, generate a first output policy and a second output policy for the target business system. Among them, the first output policy includes the first output level of the target account that triggers the exception log, and the second output policy includes the second output level of the target function object corresponding to the target business interface that triggers the exception log.
[0031] It should be noted that the above target time period can, but is not limited to, indicate the time period for monitoring and log analysis, and can be set as a periodic time window. For example, calculate the number of exception logs every 1 minute, etc. This is not limited in this embodiment. Further, the above target business system can, but is not limited to, indicate any running software system, and this system needs to output logs to record its running status and events. For example, the video playback business system in the video playback business scenario, the authentication system responsible for user authentication, etc. This is not limited in this embodiment either.
[0032] Further, the above log management module is used to indicate the component responsible for collecting, storing, and analyzing logs. The logs of all business systems will ultimately be output to the log management module for unified management and analysis. It should be noted that in some embodiments, the log management module may, but is not limited to, include a log collection sub-module and a log alarm sub-module.
[0033] Specifically, the above log collection sub-module is used to uniformly collect log information from each business system. The log data generated in the business system is first processed through formatting to ensure the consistency and readability of the log data. Then, these formatted log data are leveled through a queue. That is, when the log data volume suddenly increases, the queue can temporarily store the extra data to prevent the log processing system from being overloaded. After that, these log data are stored on the disk for subsequent analysis and long-term storage. The above log alarm sub-module is used to continuously monitor the collected log data according to the pre-set alarm rules. For example, the alarm rule can be set as "when the number of a certain log reaches M within N minutes, trigger an alarm". When this rule condition is met, the log alarm sub-module will trigger an alarm, which can be sending a text message alarm to the operation and maintenance personnel, or triggering other alarm mechanisms within the system. For example, sending the alarm information to the policy generation module so that the policy generation module generates a log output policy for the relevant business system.
[0034] Furthermore, the above-mentioned abnormal log can be used, but not limited to, to indicate that when an abnormality or error occurs during the operation of the system, the abnormal log is generated. It can include, but not limited to: error log, log with the status code as the target status code, and timeout log, etc., which are not limited in this embodiment. Among them, the above-mentioned target status code can be used, but not limited to, to indicate a non-200 status code.
[0035] Optionally, in some embodiments, the quantity threshold is a quantity standard, and when the number of abnormal logs exceeds this threshold within the target time period, a specific log output policy will be generated. For example, it can be set that when the number of abnormal logs with non-200 status codes per minute on the B interface of system A exceeds 10, the generation of a hot policy is triggered.
[0036] It should be noted that, in some embodiments, the statistical unit of the number of the above-mentioned exception logs in the above-mentioned step S102 can be a business interface or the entire system. For example, when the number of all exception logs output by the entire target business system within the target time period reaches a quantity threshold, a first output strategy and a second output strategy can be generated; or when the number of exception logs corresponding to a certain business interface output by the target business system within the target time period reaches a quantity threshold, a first output strategy and a second output strategy can be generated. This is not limited in the present embodiment.
[0037] It should be noted that the above-mentioned target account can be but is not limited to being used to indicate a specific user account that triggers an exception log. The above-mentioned first output policy is a log output policy for a specific user (i.e., the target account), which will change the log output level of the user's operation to collect more information about the user's operation. For example, if user u123 frequently triggers the exception log of system A, a first output policy will be generated. When the business system outputs the log triggered by user u123, it will determine whether to output the log according to the log output level indicated in the first output policy, and will no longer use the default log output level originally set by the business system to determine whether to output the log. For another example, the above-mentioned first output policy can be but is not limited to the following: Figure 2 As shown, it includes the unique identifier of the target account, the unique identifier of the device used by the target account, the network address of the device used by the target account, and the above-mentioned first output level.
[0038] It should be further explained that the first output strategy may also be called and used by other business systems in the same business scenario as the target business system, which is not limited in this embodiment.
[0039] Further, the above-mentioned first output level can be, but is not limited to, used to indicate the log output level in the first output strategy, which is lower than the conventional first threshold. For example, if the first threshold is ERROR, the first output level is set to INFO, which means that the system will record all INFO-level logs related to the target user's operation. Among them, ERROR and INFO are two of the four log output levels used by the log framework Log4J. The four log output levels used by Log4J include: DEBUG is mainly used to print some running information during the development process, INFO is used to output some important information about the program running in the production environment, WARN indicates that there will be potential errors, and ERROR indicates that although an error event occurs, it still does not affect the continued operation of the system. If the log is set at a certain level, then logs with a higher priority than this level can be printed out. For example, if the priority is set to WARN, then the ERROR and WARN levels of logs can be output normally, while the INFO and DEBUG level logs will be ignored.
[0040] Optionally, in some embodiments, the second output strategy is similar to the first output strategy, but the second output strategy is a log output strategy for a specific functional module, and is used to adjust the log output level of these functional modules to collect more detailed operation information. The second output level is the log output level in the second output strategy, which is lower than the conventional second threshold. For example, the second threshold is ERROR, and the second output level is set to INFO. For another example, the second output strategy can be, but is not limited to, Figure 3 As shown, it includes the system name of the target business system, the class and method name corresponding to the target business interface, the log output level of the second output strategy, and the start time and end time of the second output strategy.
[0041] Furthermore, the target business interface may be, but is not limited to, used to indicate a specific interface for triggering an exception log in the target business system. The target function object may be, but is not limited to, used to indicate a specific code segment or function for implementing the function of the target business interface, such as a method in a class for implementing the target interface. For example, if the requests received by business interface A frequently return many non-200 status codes, it will be regarded as an abnormal situation, and then the second output strategy will be generated based on the class methods declared in business interface A.
[0042] S104: When the initial log acquired by the target business system is triggered by the target account and the log level of the initial log matches the first output level, the initial log is output to the log management module.
[0043] It should be noted that, in some embodiments, the initial log may be, but is not limited to, used to indicate a log record generated in the target business system, for example, a log generated by the system when a user request or system event occurs.
[0044] S106, when the initial log is triggered by the target function object and the log level of the initial log matches the second output level, the initial log is output to the log management module; wherein the first output level is lower than the first threshold, and the second output level is lower than the second threshold, and the lower the output level, the more types of logs are output from the target business system.
[0045] Optionally, as an optional example, the above steps may be explained by, but not limited to, the following examples:
[0046] Assume that at 14:05, the number of non-200 status code requests received by the B interface of the A system exceeds a preset threshold of 10, triggering an alarm message indicating the generation of a hot policy.
[0047] Then, a policy is generated (used to represent the first output policy mentioned above) to adjust the log output level of user account u123 that frequently requests interface B from ERROR to INFO, which means that system A will record all INFO-level logs of user u123, including all its request and response details. Another policy is generated (used to represent the second output policy mentioned above) to adjust the log output level of method C that processes interface B requests in system A from ERROR to INFO, ensuring that the system can record all internal processing flows of interface B in detail.
[0048] Next, when system A processes user u123's request again, if the initial log level generated is INFO, this log will be output to the log management module. Similarly, if the initial log level generated when method C is executed is INFO, this log will also be output to the log management module, ensuring that every step of the system's internal processing is recorded in detail.
[0049] It should be noted that the above example is an optional example provided to facilitate explanation of the above log output method, and there is no limitation on the specific implementation of the above log output method.
[0050] Adopt the embodiment of the present application, on the one hand, when the number of abnormal logs in the target time period reaches the quantity threshold, the target business system generates the first output strategy and the second output strategy, allowing the system to dynamically adjust the output level of the log at runtime, so as to adapt to the needs of troubleshooting. The generation of this dynamic strategy exceeds the traditional static log level setting and provides a more flexible log management method. On the other hand, the first output strategy is for the abnormal log triggered by a specific target account, and the second output strategy is for the abnormal log triggered by the target function object corresponding to the specific target business interface. In other words, the system can selectively record more detailed logs for accounts and interfaces that may have problems, reduce the output of irrelevant logs, thereby optimizing storage costs and system performance. On the other hand, by dynamically adjusting the log output level to a lower level, the system can output richer log information, which helps developers and operation and maintenance personnel to understand the system status more accurately, so as to quickly locate and troubleshoot problems. Compared with static log level management, this improvement significantly improves the efficiency of troubleshooting. In summary, the embodiments of the present application improve the effectiveness of logs in troubleshooting, while reducing unnecessary performance and storage overhead, and solve the technical problem that the log output method provided in the prior art is difficult to adapt to troubleshooting needs due to the static configuration of the log level.
[0051] Optionally, as an optional solution, when the number of abnormal logs output by the target business system to the log management module within the target time period reaches a quantity threshold, generating a first output strategy and a second output strategy for the target business system includes:
[0052] S1, when the log management module determines that the number of abnormal logs reaches a number threshold within a target time period, determine a target service interface for triggering the abnormal log.
[0053] It should be noted that, when the log management module determines that the number of abnormal logs reaches a quantity threshold, the target business interface for triggering the abnormal log can be but is not limited to being used to indicate that the log alarm sub-module in the log management module determines that the number of abnormal logs reaches a quantity threshold, and determines the target business interface for triggering the abnormal log.
[0054] S2, using the log management module to generate alarm information, and sending the alarm information to the policy generation module, wherein the alarm information includes the system identifier of the target business system and the interface identifier of the target business interface.
[0055] It should be noted that the above-mentioned use of the log management module to generate alarm information and send the alarm information to the strategy generation module may include but is not limited to: using the above-mentioned log alarm submodule to generate alarm information and send the alarm information to the strategy generation module.
[0056] Optionally. The system identifier is used to uniquely identify the target business system, and may be, but not limited to, a system name or a system identification code for indicating the target business system, and is not limited to this in the present embodiment. Similarly, the interface identifier may be, but not limited to, a system name or an interface identification code for indicating the target business interface, and is not limited to this in the present embodiment.
[0057] It should be noted that after the above alarm information is generated, it can include but is not limited to: using the above log alarm submodule to send the above alarm information to the reference account used to maintain the above target business system. For example, the alarm information is sent to the reference account used to maintain the above target business system by email, SMS, etc., so that the reference account can perform abnormality inspection on the target business system.
[0058] S3: When the policy generation module receives the alarm information, the policy generation module is used to generate a first output policy and a second output policy for the target business system.
[0059] Optionally, the above-mentioned policy generation module may include, but is not limited to: a policy generation triggering submodule, an output policy generation submodule and an output policy arrangement submodule.
[0060] Specifically, the policy generation trigger submodule is used to receive alarm information from the log management module. When the log management module detects that the number of abnormal logs exceeds the preset threshold, it will generate an alarm message, which contains the system name and interface name that triggered the abnormality. After receiving this alarm message, the policy generation trigger submodule will further analyze the class name and method name associated with the business interface indicated by the above interface name, as well as other systems and interfaces that the interface may depend on. After obtaining this information, the policy generation trigger submodule will notify the output policy generation submodule to generate the policy.
[0061] Furthermore, the output strategy generation submodule is used to generate a first output strategy and a second output strategy based on the information provided by the strategy generation trigger submodule. The first output strategy usually reduces the log output level to INFO or DEBUG for a specific user account that triggers an exception, so as to collect more details about the user operation. The second output strategy also reduces the log output level to INFO or DEBUG for a specific method in the business system, so as to obtain detailed information during the execution of the interface or method.
[0062] Furthermore, the output policy arrangement submodule is used to organize the configurations of all business systems after the output policy is generated to ensure that the generated policy does not conflict with other configurations. It also provides an interface for business systems to pull the latest log output rules. For example, system A and system B can regularly pull the latest global rules and method rules through this interface to update the internal log output control. At the same time, the output policy arrangement submodule will automatically remove expired or no longer applicable rules to keep the rule list updated and valid, and avoid invalid log output or system performance impact caused by outdated rules.
[0063] Using the embodiment of the present application, on the one hand, after receiving the alarm information, the policy generation module generates a first output policy (such as increasing detailed log output) and a second output policy (such as temporarily reducing the log level) for the affected business system. It ensures that when an exception occurs, the log output policy can be automatically adjusted to collect more details that are helpful for problem location, while avoiding delays and errors in manually adjusting the policy. On the other hand, the automatic sending of alarm information and the automatic generation of policies reduce the need for manual intervention, and can automatically complete the entire process from detecting anomalies to generating dynamic policies, allowing operations and development personnel to focus more on problem solving rather than policy adjustment.
[0064] Optionally, as an optional solution, before generating the first output strategy and the second output strategy for the target business system, the method further includes:
[0065] Determine each business system in the business system set as the current business system in turn and perform the following steps:
[0066] S1, obtaining the current class object, current function object and current business interface corresponding to the current business system, wherein the class object includes multiple function objects, and the function objects are used to implement the functions corresponding to the business interface.
[0067] It should be noted that the above business system set is used to indicate the set of all business systems in a service architecture that may need to output logs. For example, the service architecture includes business systems such as system A, system B, and system C, which constitute the business system set.
[0068] Furthermore, the above-mentioned current business system is a business system being analyzed selected from the business system set during the processing. Optionally, the above-mentioned class object is a class in object-oriented programming. The class is the basic unit in object-oriented programming. It is a data type used to define the structure and behavior of an object. A class contains not only data attributes (member variables), but also methods (member methods) for operating on data. In object-oriented programming, an object is an instance of a class. A class provides a blueprint or template for creating a series of similar objects.
[0069] Furthermore, the above function object can be used, but is not limited to, to indicate a method, which is a function in a class used to perform a specific behavior or task, such as processing data, performing calculations, or triggering events.
[0070] Furthermore, the above business interface is used to define the contract of the common set of behaviors that a class must implement. An interface usually contains only the method signature (i.e. the name, parameters and return type of the method) without any implementation details. A class can implement one or more interfaces. In other words, a class must provide implementations of all methods in the interface. Interfaces provide a way for different classes to be called in a unified way without having to care about their specific implementation details.
[0071] S2, stores the dependency relationship between the current business interface and the reference business interface on which the current business interface depends into the target storage structure, and stores the logical relationship between the current class object, the current function object and the current business interface into the target storage structure; wherein the business system set includes the target business system.
[0072] It should be noted that the above steps S1 and S2 can be but are not limited to being executed by a code analysis module. The above code analysis module is used to analyze the structure and logic of the business code in each business system. The analysis results include which interfaces the service has, which internal methods the interfaces correspond to, which interfaces of other services the methods depend on, and the analysis results are stored.
[0073] Optionally, the dependency relationship between the above-mentioned business interfaces means that one business interface needs to call another business interface to complete its function. The logical relationship between the above-mentioned current class object, the current function object and the current business interface can be, but is not limited to, used to indicate the relationship between class objects, function objects and business interfaces, and describes the execution process and calling logic within the business system. For example, in the current business system, class object A implements the function of interface C by calling function object B, which is the logical relationship between class object A implementing interface C by calling function object B. For another example, assuming that the system name of the current business system is X1, X1 includes interface A1 and interface A2, the class and method corresponding to interface A1 are method C1 in class B1, and the class and method corresponding to interface A2 are method C1 in class B2, where interface A1 depends on interface A3 of business system X2, then the information stored by the current business system X1 in the above-mentioned target storage structure can be, but is not limited to, as follows Figure 4 shown.
[0074] The target function object corresponding to the target business interface and the target business system where the target business interface is located are determined from the target storage structure.
[0075] Optionally, the determination of the target function object corresponding to the target service interface and the target service system where the target service interface is located from the target storage structure may include, but is not limited to: using the above-mentioned policy generation trigger sub-module to determine the target function object corresponding to the target service interface from the target storage structure. So that the output policy generation sub-module generates the first output policy and the second output policy according to the above-mentioned target function object, target service system, account identifier of the target account, and other information.
[0076] It should be noted that, in some embodiments, the above-mentioned target storage structure is a database or data structure used to store the dependencies and logical relationships between service systems, class objects, function objects, and service interfaces. Such as, table structure or other structures, which are not limited in this embodiment either.
[0077] By adopting the embodiments of the present application, by storing the dependency relationships between class objects, function objects, and service interfaces in a service system, as well as the logical relationships between class objects, function objects, and service interfaces in the target storage structure, the relevance between each component can be quickly and accurately understood. This storage mechanism provides comprehensive system architecture information for subsequent exception log analysis and policy generation, which helps to more accurately locate problems.
[0078] Optionally, as an alternative solution, the method for outputting logs further includes:
[0079] S1. Determine the dependency interfaces on which the target service interface depends from the target storage structure.
[0080] S2. Determine the reference service system where the dependency interface is located from the target storage structure.
[0081] For example, when the above-mentioned policy generation trigger sub-module obtains the above-mentioned alarm information, it will extract the system identifier and interface identifier carried in the alarm information, and then determine that the interface used to trigger the above-mentioned exception log is the target service interface according to the system identifier and interface identifier, and the exception log is output by the target service system. Then, as Figure 5 shown, extract the relationships related to the target service interface from the target storage structure, including: the system name of the target service system, the interface name of the target service interface, the class name and method name corresponding to the target service interface, the dependency interface name of the dependency interface on which the target service interface depends and the name of the dependency service system where the dependency interface is located, as well as the class name and method name corresponding to the dependency interface.
[0082] S3, generate a third output strategy and a fourth output strategy for the reference business system, wherein the third output strategy includes a third output level corresponding to the target account that triggers the exception log, and the fourth output strategy includes a fourth output level corresponding to the reference function object corresponding to the dependent interface, the third output level is lower than the third threshold, and the fourth output level is lower than the fourth threshold. The lower the output level, the more types of logs are output from the target business system.
[0083] It should be noted that, in some embodiments, the third output strategy can be used, but is not limited to, to indicate the first output strategy, and can generate one of the two. Further, the specific implementation of the third generation strategy and the fourth generation strategy can refer to the relevant embodiments of the first generation strategy and the second generation strategy above, which will not be repeated here.
[0084] Optionally, when generating the third output strategy and the fourth output strategy, the reference business system may use the third output strategy and the fourth output strategy to determine whether the relevant initial log needs to be output. For the specific implementation methods, please refer to the implementation methods of the first output strategy and the second output strategy, which will not be repeated here.
[0085] By adopting the embodiment of the present application, on the one hand, by generating the third output strategy and the fourth output strategy for the reference business system where the dependent interface is located, the consistency of the log output level of the associated system is ensured, which helps to obtain comprehensive log information when troubleshooting, rather than just the information of a single business system. On the other hand, the exceptions of the dependent interface often involve the interaction of multiple systems. Lowering the log output level of the system where the dependent interface is located can capture more details and help developers deeply understand the root cause of the problem, rather than just the surface phenomenon.
[0086] Optionally, as an optional solution, it is characterized in that after generating the first output strategy and the second output strategy for the target business system, it also includes:
[0087] When the current time does not meet the policy effectiveness condition of the first output policy, the policy state of the first output policy is modified to an invalid state that prohibits use, and the first output policy is removed from the policy storage space used to store the first output policy.
[0088] It should be noted that the policy effectiveness condition of the above-mentioned first output policy may be, but is not limited to, a rule for indicating the effectiveness time of the output policy. For example, the first output policy may be specified to take effect within 10 minutes after the alarm event.
[0089] When the current time does not satisfy the policy effectiveness condition of the second output policy, the policy state of the second output policy is modified to an invalid state, and the second output policy is removed from the policy storage space.
[0090] It should be noted that the policy effectiveness condition of the second output policy may be, but is not limited to, a rule for indicating the effectiveness time of the second output policy. For example, the second output policy may be specified to take effect within 5 minutes after an alarm event.
[0091] Furthermore, the above-mentioned policy status can be, but is not limited to, used to indicate the current status of the output policy, which usually has two states: effective and ineffective. The policy status of effective means that the output policy is applied, and the system will output logs according to the output level specified by the policy. The policy status of ineffective means that the policy will not be applied, and even if it has been stored in the policy storage space, the system will not output logs according to the policy. Optionally, the above-mentioned policy storage space can be, but is not limited to, a data structure or database for storing output policies.
[0092] Optionally, in some embodiments, the above operations of modifying the policy states of the first output policy and the second output policy and removing the first output policy and the second output policy may be, but are not limited to, performed by an output policy arrangement submodule.
[0093] For example, the above steps can be explained by the following examples, but are not limited to:
[0094] After the first output policy is generated, it is assumed that the policy is effective only within 10 minutes after the alarm event occurs. In other words, 10 minutes after the alarm event occurs, the first output policy will automatically become invalid and will no longer be applied. Correspondingly, after the second output policy is generated, it is assumed that the policy is effective only within 5 minutes after the alarm event occurs. In other words, 5 minutes after the alarm event occurs, the second output policy will automatically become invalid and will no longer be applied.
[0095] It should be noted that the above example is an optional example provided to facilitate explanation of the above log output method, and there is no limitation on the specific implementation of the above log output method.
[0096] By using the embodiment of the present application, on the one hand, by automatically judging whether the current time satisfies the dynamically generated policy entry-into-force condition, the timeliness and effectiveness of the log output policy can be guaranteed, and the policy can be prevented from existing for a long time and no longer being applicable, which helps to reduce unnecessary log output and maintain the efficient use of log system resources. On the other hand, when the target time period ends or the number of abnormal logs no longer reaches the threshold, the policy generation module can automatically invalidate the first output policy and the second output policy, and remove them from the storage space. This feature avoids redundant storage of policies, reduces the occupancy of storage space, and ensures the clarity of the policy library and the reduction of maintenance costs.
[0097] Optionally, as an optional solution, the log output method further includes:
[0098] S1, when a target function module that allows reference accounts to be used is configured for a target business system, a fifth output policy is generated for the target business system, wherein the fifth output policy includes a fifth output level of the reference account, and the fifth output level is lower than a fifth threshold.
[0099] It should be noted that the fifth output strategy is an output rule generated when the reference account uses the target functional module, which is intended to record the reference account's operations in a specific functional module in more detail. The strategy includes the fifth output level of the reference account, which is set lower than the conventional output level (fifth threshold) to collect more information.
[0100] Furthermore, the target functional modules may be, but are not limited to, modules that require special attention in the system, which may be newly developed functions or modules under testing, for example, some functional modules that are only grayed out and available to some users.
[0101] S2: When the first initial log acquired by the target business system is triggered by the reference account and the log level of the first initial log matches the fifth output level, the first initial log is output to the log management module.
[0102] Optionally, the fifth output level is a level set in the fifth output policy for controlling the detail of log output triggered by the reference account. The fifth threshold is the system default log output level, such as the ERROR level. The fifth output level is lower than the fifth threshold, which means that it allows more log information to be output, including more detailed logs such as INFO and DEBUG.
[0103] It should be noted that, in this embodiment, the output policies that can be configured for the business system include two categories, one is the global policy (refer to the first output policy, the third output policy and the fifth output policy), that is, it indicates the log output policy corresponding to a specific user, and the other is the method policy (refer to the second output policy and the fourth output policy), that is, it specifies the log output policy corresponding to a specific method of a specific class. It should be noted that the method policy and method policy here can be manually modified according to needs.
[0104] By using the embodiment of the present application, on the one hand, when the reference account encounters a problem when using a specific functional module, the fifth output strategy can ensure that the system outputs enough detailed logs to help developers quickly understand the root cause of the problem and shorten the troubleshooting time. On the other hand, grayscale testing usually involves a small number of users or specific accounts. By reducing the log output level of these accounts, detailed feedback from these users when using new functions or new versions can be collected without significantly affecting the overall operating efficiency of the system.
[0105] Optionally, as an optional solution, after generating the first output strategy and the second output strategy for the target business system, the method further includes:
[0106] S1, when the initial log is not triggered by the target account and the initial log is not triggered by the target function object, obtain the default output level configured for the target business system.
[0107] It should be noted that the above default output level can be, but is not limited to, a baseline level used to control the log output detail level of the target business system when there is no special output policy intervention. For example, the system may output only ERROR-level logs by default so that the problem can be quickly located when a serious error occurs.
[0108] S2: When the log level of the initial log matches the default output level, the initial log is output to the log management module.
[0109] For example, when the target business system obtains the initial log, the logic for determining whether to output the initial log may be, but is not limited to, referring to Figure 6 , specifically, Figure 6 As shown:
[0110] Execute step S602, the target business system obtains the initial log;
[0111] Then, step S604 is performed to determine whether the user account used to trigger the initial log matches the user account recorded in the first output policy;
[0112] Then, if the user account used to trigger the initial log matches the user account recorded in the first output policy, executing step S606-1 to determine whether to output the initial log using the first output policy;
[0113] In the case that the user account used to trigger the initial log does not match the user account recorded in the first output policy, executing step S606-2 to determine whether the class and method used to trigger the initial log match the class and method recorded in the second output policy;
[0114] Then, when the class and method for triggering the initial log match the class and method recorded in the second output policy, step S608-1 is executed to determine whether to output the initial log using the second output policy;
[0115] When the class and method used to trigger the initial log do not match the class and method recorded in the second output policy, step S608-2 is executed to determine whether to output the initial log using the default policy of the target disk service system.
[0116] Optionally, as an optional solution, the log output method further includes:
[0117] When a specific system event is detected, such as a performance bottleneck, system failure, or security event, it automatically triggers an immediate adjustment of the log output level and generates an emergency output strategy, where the emergency output strategy includes a specific time window, a target business system, a target functional module, and an emergency output level, and the emergency output level is lower than a preset emergency threshold;
[0118] When any log related to the target business system and target functional module is detected within the specific time window, if the level of the log matches the emergency output level, it is output to the log management module to facilitate rapid problem location.
[0119] It should be noted that in addition to the conventional log output strategy, the system should have the ability to respond quickly to emergencies. For example, when the system performance is significantly reduced (performance bottleneck), the system crashes abnormally (system failure), or a potential security threat (security incident) is detected, the log management module will automatically start the emergency response mechanism. This mechanism includes generating an emergency output strategy, which defines in detail a specific time window (for example, 10 minutes after the incident), target business systems that require special attention (such as payment systems), and target functional modules (such as processing functions of payment interfaces). The emergency output level set in the emergency output strategy (for example, DEBUG or INFO) is lower than the preset emergency threshold (such as WARN or ERROR), which means that during the emergency response, the system will output more detailed log information to facilitate rapid problem detection and response.
[0120] By adopting the above-mentioned embodiment, when a security incident is detected, the log output level is adjusted immediately, which helps to quickly collect detailed records of system activities and provide data support for subsequent security analysis and protection.
[0121] Optionally, as an optional example, the overall system framework of the log output method can be but is not limited to reference Figure 7 ,like Figure 7 The overall framework shown includes: log strategy background 702 (used to represent the above-mentioned strategy generation module), business system 704, code intelligent analysis background 706 (used to represent the above-mentioned code analysis module), log analysis background 708 (used to represent the above-mentioned log management module), and the functions of each of the above modules are described in detail below:
[0122] 1) The code intelligent analysis background is used to analyze the structure and logic of the business code. The analysis results include which interfaces the service has, which internal methods the interfaces correspond to, which interfaces of other services the methods depend on, and the analysis results are stored.
[0123] 2) The log analysis background includes a log collection module (used to represent the log collection submodule) and a log analysis alarm module (used to represent the log alarm submodule). The log collection module is used to uniformly collect and store the logs output by the business system, that is, the logs are formatted, flow through the queue and stored on the disk after peak shaving. The log analysis alarm module can configure alarm strategies based on the logs. When the alarm strategy is reached, it can trigger alarm prompts such as text messages, and can also trigger notification events of other business systems.
[0124] 3) The log policy background includes a trigger condition setting module (used to represent the policy generation trigger submodule), a log rule setting module (used to represent the output policy generation submodule), and a rule sorting and verification module (used to represent the output policy sorting submodule). The trigger condition setting is to automatically set the log rules through the event of the log analysis alarm. When the alarm rule of the log analysis alarm configuration module of the log analysis background is triggered, the alarm event will be notified to the condition trigger setting module, where the event information includes: the system name and interface name of the alarm. After receiving the alarm event notification, according to the system name and interface, the results are obtained from the code intelligent analysis, and the class name and method name of the system corresponding to the system name and interface name are obtained, and the class name and method name that depend on the system name and interface name are also obtained. The log rule setting module is used to set the output level of the log for the class name, method name or user unique identifier, device unique identifier, etc. of the business system (such as setting global policy and method policy). The rule sorting and verification module is used to sort and verify all the configurations of the business system, and then provide an interface for the business system to pull. Global rules (used to represent global policies) and method rules (used to represent method policies) are distributed to the business system through an interface, and expired rules in the method rules are also removed.
[0125] 4) The business system includes a rule pulling module, a log output module, a log rule matching module and a business code. The rule pulling module is used to periodically pull the log policy of this business system from the log policy background and store it in the memory of the business system. The business code is the logic code for this business system to implement specific business. The log rule matching module is used to determine whether there are new dynamic rules applied to the current log when the log is output, and if so, use the new rules. The log output module is used to output the log to the log collection module of the log analysis background.
[0126] Optionally, as an optional example, it is possible but not limited to Figure 8 The following steps are used to illustrate the output method of the above logs:
[0127] Execute step S802 to store the business logic relationship of each business system in the target storage structure. Specifically, each business system in the business system set is sequentially determined as the current business system and the following steps are performed: obtain the current class object, current function object and current business interface corresponding to the current business system, wherein the class object includes multiple function objects, and the function object is used to implement the function corresponding to the business interface; store the dependency relationship between the current business interface and the reference business interface on which the current business interface depends in the target storage structure, and store the logical relationship between the current class object, the current function object and the current business interface in the target storage structure; wherein the business system set includes the target business system.
[0128] Execute step S804, and when the target interface in the target business system triggers an alarm message, obtain the business relationship of the target interface. Specifically, when the number of abnormal logs output by the target business system to the log management module in the target time period reaches a quantity threshold, determine from the target storage structure the target function object corresponding to the target business interface and the target business system where the target business interface is located, as well as the dependent interface on which the target business interface depends and the reference business system where the dependent interface is located.
[0129] Then, step S806 is executed to generate a first output strategy and a second output strategy for the target business system, and a third output strategy and a fourth output strategy for the reference business system, wherein the first output strategy includes a first output level of the target account that triggers the exception log, the second output strategy includes a second output level of the target function object corresponding to the target business interface that triggers the exception log, the third output strategy includes a third output level corresponding to the target account that triggers the exception log, the fourth output strategy includes a fourth output level corresponding to the reference function object corresponding to the dependent interface, the third output level is lower than the third threshold, and the fourth output level is lower than the fourth threshold;
[0130] Then, step S808 is performed to determine whether the user account used to trigger the initial log matches the user account recorded in the first output policy in the case of the initial log acquired by the target business system.
[0131] Next, when the user account used to trigger the initial log matches the user account recorded in the first output policy, step S810-1 is executed to determine whether to output the initial log using the first output policy;
[0132] If the user account used to trigger the initial log does not match the user account recorded in the first output policy, step S810 - 2 is performed to determine whether the class and method used to trigger the initial log match the class and method recorded in the second output policy.
[0133] When the class and method for triggering the initial log match the class and method recorded in the second output policy, executing step S812-1, determining whether to output the initial log using the second output policy;
[0134] When the class and method used to trigger the initial log do not match the class and method recorded in the second output policy, step S812 - 2 is executed to determine whether to output the initial log using the default policy of the target business system.
[0135] Next, executing step S814, in the case where the target business system is configured with a target function module that allows the reference account to use, generating a fifth output policy for the target business system, wherein the fifth output policy includes a fifth output level of the reference account, and the fifth output level is lower than a fifth threshold;
[0136] Then, step S816 is executed, and when the first initial log acquired by the target business system is triggered by the reference account and the log level of the first initial log matches the fifth output level, the first initial log is output to the log management module.
[0137] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0138] According to another aspect of the embodiment of the present application, a log output device for implementing the log output method is also provided. Figure 9 As shown, the device comprises:
[0139] A generating unit 902 is used to generate a first output strategy and a second output strategy for the target business system when the number of abnormal logs outputted by the target business system to the log management module within the target time period reaches a number threshold, wherein the first output strategy includes a first output level of the target account that triggers the abnormal log, and the second output strategy includes a second output level of the target function object corresponding to the target business interface that triggers the abnormal log;
[0140] The first output unit 904 is used to output the initial log to the log management module when the initial log acquired by the target business system is triggered by the target account and the log level of the initial log matches the first output level;
[0141] The second output unit 906 is used to output the initial log to the log management module when the initial log is triggered by the target function object and the log level of the initial log matches the second output level; wherein the first output level is lower than the first threshold, and the second output level is lower than the second threshold, and the lower the output level, the more types of logs are output from the target business system.
[0142] Optionally, in this embodiment, the above-mentioned generation unit includes: a determination module, which is used to determine the target business interface for triggering the abnormal log when the log management module determines that the number of abnormal logs reaches a quantity threshold; a sending module, which is used to generate alarm information using the log management module and send the alarm information to the policy generation module, wherein the alarm information includes the system identifier of the target business system and the interface identifier of the target business interface; a generation module, which is used to generate a first output policy and a second output policy for the target business system using the policy generation module when the policy generation module receives the alarm information.
[0143] Optionally, in this embodiment, the above-mentioned device also includes: a relationship storage unit, which is used to determine each business system in the business system set as the current business system in turn and perform the following steps: obtain the current class object, current function object and current business interface corresponding to the current business system, wherein the class object includes multiple function objects, and the function object is used to implement the function corresponding to the business interface; store the dependency relationship between the current business interface and the reference business interface on which the current business interface depends to the target storage structure, and store the logical relationship between the current class object and the current function object and the current business interface to the target storage structure; wherein the business system set includes the target business system; a first determination unit, which is used to determine the target function object corresponding to the target business interface and the target business system where the target business interface is located from the target storage structure.
[0144] Optionally, in this embodiment, the above-mentioned device also includes: a second determination unit, used to determine the dependent interface on which the target business interface depends from the target storage structure; a third determination unit, used to determine the reference business system where the dependent interface is located from the target storage structure; a first generation unit, used to generate a third output strategy and a fourth output strategy for the reference business system, wherein the third output strategy includes a third output level corresponding to the target account that triggers the exception log, and the fourth output strategy includes a fourth output level corresponding to the reference function object corresponding to the dependent interface, the third output level is lower than the third threshold, and the fourth output level is lower than the fourth threshold, and the lower the output level, the more types of logs are output from the target business system.
[0145] Optionally, in this embodiment, the above-mentioned device also includes: a first removal unit, which is used to modify the policy state of the first output policy to an invalid state prohibited from being used when the policy effectiveness condition of the first output policy is not met at the current time, and remove the first output policy from the policy storage space used to store the first output policy; a second removal unit, which is used to modify the policy state of the second output policy to an invalid state when the policy effectiveness condition of the second output policy is not met at the current time, and remove the second output policy from the policy storage space.
[0146] Optionally, in this embodiment, the above-mentioned device also includes: a second generation unit, used to generate a fifth output strategy for the target business system when the target business system is configured with a target function module that allows the reference account to be used, wherein the fifth output strategy includes a fifth output level of the reference account, and the fifth output level is lower than a fifth threshold; a third output unit, used to output the first initial log to the log management module when the first initial log obtained by the target business system is triggered by the reference account and the log level of the first initial log matches the fifth output level.
[0147] For a specific embodiment, reference may be made to the example shown in the above log output method, which will not be described in detail in this embodiment.
[0148] According to another aspect of the embodiment of the present application, an electronic device for implementing the above log output method is also provided. This embodiment is described by taking the electronic device as a server as an example. Figure 10 As shown, the electronic device includes a memory 1002 and a processor 1004. The memory 1002 stores a computer program, and the processor 1004 is configured to execute the steps in any of the above method embodiments through the computer program.
[0149] Optionally, in this embodiment, the electronic device may be located in at least one network device among a plurality of network devices of a computer network.
[0150] Optionally, in this embodiment, the processor may be configured to execute the steps in the log output method through a computer program.
[0151] Alternatively, a person skilled in the art may understand that: Figure 10 The structure shown is for illustration only, and the electronic device may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (Mobile Internet Devices, MID), a PAD, or other terminal devices. Figure 10 The structure of the electronic device is not limited. Figure 10 More or fewer components (such as network interfaces, etc.) as shown in, or with Figure 10 Different configurations are shown.
[0152] Among them, the memory 1002 can be used to store software programs and modules, such as the program instructions / modules corresponding to the log output method and device in the embodiment of the present application. The processor 1004 executes various functional applications and data processing by running the software programs and modules stored in the memory 1002, that is, realizing the above-mentioned log output method. The memory 1002 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 1002 may further include a memory remotely located relative to the processor 1004, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof. As an example, Figure 10 As shown, the memory 1002 may include but is not limited to the generation unit 902, the first output unit 904 and the second output unit 906 in the log output device. In addition, other module units in the log output device may also be included but are not limited to, which will not be repeated in this example.
[0153] Optionally, the transmission device 1006 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wired network and a wireless network. In one example, the transmission device 1006 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices and routers via a network cable so as to communicate with the Internet or a local area network. In one example, the transmission device 1006 is a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0154] In addition, the electronic device further includes: a display 1008 and a connection bus 1010 for connecting various module components in the electronic device.
[0155] In other embodiments, the terminal device or server may be a node in a distributed system, wherein the distributed system may be a blockchain system, and the blockchain system may be a distributed system formed by connecting the multiple nodes through network communication. The nodes may form a point-to-point network, and any form of computing device, such as a server, terminal or other electronic device, may become a node in the blockchain system by joining the point-to-point network.
[0156] According to one aspect of the present application, a computer program product is provided, the computer program product comprising a computer program / instruction, the computer program / instruction comprising a program code for executing the above method. In such an embodiment, the computer program can be downloaded and installed from a network through a communication part, and / or installed from a removable medium. When the computer program is executed by a central processing unit, various functions provided by the embodiments of the present application are executed.
[0157] According to one aspect of the present application, another computer program product is also provided, including a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the method in each embodiment of the present application are implemented.
[0158] According to one aspect of the present application, a computer-readable storage medium is provided, and a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above method.
[0159] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for executing the steps in the log output method.
[0160] Optionally, in the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.
[0161] Optionally, in this embodiment, a person of ordinary skill in the art may understand that all or part of the steps in the various methods of the above embodiments may be completed by instructing hardware related to the terminal device through a program, and the program may be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, etc.
[0162] If the integrated unit in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in the above computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing one or more computer devices (which can be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in various embodiments of this application.
[0163] In the above embodiments of this application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0164] In several embodiments provided in this application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.
[0165] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0166] In addition, the functional units in various embodiments of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0167] The above is only the preferred embodiment of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of this application.
Claims
1. A log output method, characterized in that: include: When the number of abnormal logs output by the target business system to the log management module within the target time period reaches a number threshold, a first output strategy and a second output strategy are generated for the target business system, wherein the first output strategy includes a first output level of a target account that triggers the abnormal log, and the second output strategy includes a second output level of a target function object corresponding to a target business interface that triggers the abnormal log; When the initial log acquired by the target business system is triggered by the target account and the log level of the initial log matches the first output level, outputting the initial log to the log management module; When the initial log is triggered by the target function object and the log level of the initial log matches the second output level, outputting the initial log to the log management module; The first output level is lower than a first threshold, and the second output level is lower than a second threshold. The lower the output level, the more types of logs are output from the target business system.
2. The method according to claim 1, characterized in that When the number of abnormal logs outputted by the target business system to the log management module within the target time period reaches a number threshold, generating a first output strategy and a second output strategy for the target business system includes: When the log management module determines that the number of the abnormal logs reaches the number threshold within the target time period, determining the target service interface for triggering the abnormal log; Generate alarm information by using the log management module, and send the alarm information to the policy generation module, wherein the alarm information includes the system identifier of the target business system and the interface identifier of the target business interface; When the policy generation module receives the alarm information, the policy generation module is used to generate the first output policy and the second output policy for the target business system.
3. The method according to claim 1, characterized in that Before generating the first output strategy and the second output strategy for the target business system, the method further includes: Determine each business system in the business system set as the current business system in turn and perform the following steps: obtain the current class object, current function object and current business interface corresponding to the current business system, wherein the class object includes multiple function objects, and the function object is used to implement the function corresponding to the business interface; store the dependency relationship between the current business interface and the reference business interface on which the current business interface depends in the target storage structure, and store the logical relationship between the current class object, the current function object and the current business interface in the target storage structure; wherein the business system set includes the target business system; The target function object corresponding to the target business interface and the target business system where the target business interface is located are determined from the target storage structure.
4. The method according to claim 3, characterized in that The log output method also includes: Determine, from the target storage structure, a dependent interface on which the target service interface depends; Determine the reference business system where the dependent interface is located from the target storage structure; A third output strategy and a fourth output strategy are generated for the reference business system, wherein the third output strategy includes a third output level corresponding to the target account that triggers the exception log, and the fourth output strategy includes a fourth output level corresponding to the reference function object corresponding to the dependent interface, and the third output level is lower than a third threshold, and the fourth output level is lower than a fourth threshold.
5. The method according to any one of claims 1 to 4, characterized in that After generating the first output strategy and the second output strategy for the target business system, the method further includes: When the current time does not satisfy the policy effectiveness condition of the first output policy, modify the policy state of the first output policy to an invalid state that prohibits use, and remove the first output policy from the policy storage space used to store the first output policy; When the current time does not satisfy the policy effectiveness condition of the second output policy, the policy state of the second output policy is modified to the invalid state, and the second output policy is removed from the policy storage space.
6. The method according to any one of claims 1 to 4, characterized in that The log output method further includes: In the case where a target function module that allows the reference account to be used is configured for the target business system, a fifth output policy is generated for the target business system, wherein the fifth output policy includes a fifth output level of the reference account, and the fifth output level is lower than a fifth threshold; When the first initial log acquired by the target business system is triggered by the reference account and the log level of the first initial log matches the fifth output level, the first initial log is output to the log management module.
7. A log output device, characterized in that: include: A generating unit, configured to generate a first output strategy and a second output strategy for the target business system when the number of abnormal logs outputted by the target business system to the log management module within a target time period reaches a number threshold, wherein the first output strategy includes a first output level of a target account that triggers the abnormal log, and the second output strategy includes a second output level of a target function object corresponding to a target business interface that triggers the abnormal log; a first output unit, configured to output the initial log obtained by the target business system to the log management module if the initial log is triggered by the target account and the log level of the initial log matches the first output level; A second output unit is used to output the initial log to the log management module when the initial log is triggered by the target function object and the log level of the initial log matches the second output level; wherein the first output level is lower than a first threshold, and the second output level is lower than a second threshold, and the lower the output level, the more types of logs are output from the target business system.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein the program is executed by a processor to perform the method described in any one of claims 1 to 6.
9. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to execute the method according to any one of claims 1 to 6 through the computer program.