Log data processing method and device, electronic equipment and readable storage medium
By using the double buffer mechanism and predetermined event filtering mechanism in the buffer group, the problems of low storage efficiency and large data volume are solved, and efficient system analysis is achieved.
Patent Information
- Application Number
- CN202311587374.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-24
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the storage efficiency of log data and the large amount of stored data lead to low system analysis efficiency.
By using the double buffer mechanism of working buffers and free buffers in the buffer group, log data is written and read asynchronously, avoiding I/O synchronization blocking. At the same time, when a predetermined event occurs, the log data within the time period corresponding to the predetermined event is stored in the file system, and the log data during the normal operation period of the system is filtered to reduce the amount of stored data.
It improves the storage efficiency of log data, reduces the amount of stored data of log data, and improves the efficiency of system analysis.
Smart Images

Figure CN120045525A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and particularly to a method, apparatus, electronic device, and readable storage medium for processing log data. Background Art
[0002] During the daily system development and maintenance phases, developers can analyze system problems based on log data, and then locate and solve the problems occurring in the system.
[0003] In the above process, the storage efficiency and storage data volume of log data are important factors affecting the system analysis efficiency. In related technologies, there are still problems of low storage efficiency and large storage data volume of log data, resulting in low system analysis efficiency. Therefore, how to effectively improve the system analysis efficiency is an urgent problem to be solved currently. Summary of the Invention
[0004] In view of this, embodiments of this application provide a method, apparatus, electronic device, and readable storage medium for processing log data to improve the system analysis efficiency.
[0005] In a first aspect, a method for processing log data is provided, and the method includes:
[0006] Determine log data.
[0007] Write the log data into a working buffer in a buffer group, where the buffer group includes at least one working buffer and at least one idle buffer.
[0008] Start a background thread to store the log data in a time period corresponding to a predetermined event in the idle buffer into a file system.
[0009] In some embodiments, the method further includes:
[0010] In response to the remaining storage space of the working buffer being less than or equal to a first predetermined threshold, switch the working buffer to an idle buffer, and switch the corresponding idle buffer to a working buffer.
[0011] In some embodiments, the storing the log data in a time period corresponding to a predetermined event in the idle buffer into a file system includes:
[0012] Write the log data stored in the idle buffer into a temporary directory, and update the temporary directory.
[0013] In response to triggering a predetermined event, through a predetermined storage window, store the log data in the time period corresponding to the predetermined storage window in the temporary directory into a file system.
[0014] In some embodiments, writing the log data stored in the idle buffer into the temporary directory includes:
[0015] In response to the working buffer being switched to an idle buffer, start a background thread to write the log data stored in the switched idle buffer into the temporary directory. And / or
[0016] In response to the remaining storage space of the working buffer being less than or equal to a second predetermined threshold, start a background thread to write the log data stored in the idle buffer into the temporary directory. And / or
[0017] In response to the current time reaching a predetermined wake-up time, start a background thread to write the log data stored in the idle buffer into the temporary directory.
[0018] In some embodiments, writing the log data stored in the idle buffer into the temporary directory includes:
[0019] Determine the timestamp information corresponding to the log data.
[0020] Cut the log data according to a pre-set interval time parameter and the timestamp information corresponding to the log data to generate multiple snapshot files.
[0021] Write each of the snapshot files into the temporary directory.
[0022] In some embodiments, updating the temporary directory includes:
[0023] According to a pre-set sliding record window, write the newly generated snapshot files into the temporary directory and remove the expired snapshot files from the temporary directory, where the recording duration corresponding to the sliding record window is fixed, and the sliding record window moves forward as the current time moves forward.
[0024] In some embodiments, the start time of the predetermined storage window is before the time of triggering a predetermined event and differs from the time of triggering the predetermined event by a first predetermined duration parameter, and the end time of the predetermined storage window is after the time of triggering the predetermined event and differs from the time of triggering the predetermined event by a second predetermined duration parameter.
[0025] In some embodiments, the first predetermined duration parameter corresponding to the predetermined storage window is greater than or equal to the recording duration corresponding to the sliding record window.
[0026] In some embodiments, the method further includes:
[0027] Detect the dependency relationship between newly collected log data and subsequent log data.
[0028] In response to a dependency relationship existing between the newly collected log data and the subsequent log data, determine that the newly collected log data is global information, and copy the global information to a pre-set header buffer.
[0029] Start a background thread to copy the global information in the header buffer to the file header of the subsequent log data.
[0030] In some embodiments, the predetermined event is a timeout event.
[0031] The method further includes:
[0032] Receive the reporting signals periodically sent by each functional node through a pre-set message subscription node.
[0033] In response to not receiving any reporting signal sent by any of the functional nodes within a predetermined period, determine the faulty node that has not sent the reporting signal.
[0034] Send a fault message to the target subscription topic corresponding to the faulty node, so that the log collection tool corresponding to the faulty node can obtain the fault message.
[0035] In some embodiments, the determining the log data includes:
[0036] Determine the log data through a pre-set log collection tool.
[0037] The writing the log data into the working buffer in the buffer group includes:
[0038] Write the log data into the working buffer in the buffer group through the log collection tool.
[0039] In a second aspect, a log data processing device is provided, the device includes:
[0040] A log data determination module, configured to perform determining the log data.
[0041] A buffer module, configured to perform writing the log data into the working buffer in the buffer group, where the buffer group includes at least one of the working buffers and at least one idle buffer.
[0042] A writing module, configured to perform starting a background thread to store the log data in a time period corresponding to a predetermined event in the idle buffer to the file system.
[0043] In some embodiments, the device further includes:
[0044] A switching module, configured to execute, in response to the remaining storage space of the working buffer being 0 or less than or equal to a first predetermined threshold, switch the working buffer to an idle buffer and switch the corresponding idle buffer to a working buffer.
[0045] In some embodiments, the writing module is specifically configured to execute:
[0046] Write the log data stored in the idle buffer to a temporary directory and update the temporary directory.
[0047] In response to triggering a predetermined event, store the log data in the corresponding time period of the predetermined storage window in the temporary directory to the file system through the predetermined storage window.
[0048] In some embodiments, the writing module is specifically configured to execute:
[0049] In response to the working buffer being switched to an idle buffer, start a background thread to write the log data stored in the switched idle buffer to the temporary directory. And / or
[0050] In response to the remaining storage space of the working buffer being less than or equal to a second predetermined threshold, start a background thread to write the log data stored in the idle buffer to the temporary directory. And / or
[0051] In response to the current time reaching a predetermined wake-up time, start a background thread to write the log data stored in the idle buffer to the temporary directory.
[0052] In some embodiments, the writing module is specifically configured to execute:
[0053] Determine the timestamp information corresponding to the log data.
[0054] Cut the log data according to a pre-set interval time parameter and the timestamp information corresponding to the log data to generate a plurality of snapshot files.
[0055] Write each of the snapshot files to the temporary directory.
[0056] In some embodiments, the writing module is specifically configured to execute:
[0057] According to a pre-set sliding recording window, write the newly generated snapshot files to the temporary directory and remove the expired snapshot files from the temporary directory, where the recording duration corresponding to the sliding recording window is fixed and the sliding recording window moves forward as the current time moves forward.
[0058] In some embodiments, the start time corresponding to the predetermined storage window is before the time when a predetermined event is triggered, and the difference from the time when the predetermined event is triggered is a first predetermined duration parameter. The end time corresponding to the predetermined storage window is after the time when the predetermined event is triggered, and the difference from the time when the predetermined event is triggered is a second predetermined duration parameter.
[0059] In some embodiments, the first predetermined duration parameter corresponding to the predetermined storage window is greater than or equal to the recording duration corresponding to the sliding recording window.
[0060] In some embodiments, the apparatus further includes:
[0061] A detection module, configured to detect the dependency relationship between newly acquired log data and subsequent log data.
[0062] A first copy module, configured to, in response to the existence of a dependency relationship between the newly acquired log data and the subsequent log data, determine that the newly acquired log data is global information and copy the global information to a pre-set header buffer.
[0063] A second copy module, configured to start a background thread and copy the global information in the header buffer to the file header of the subsequent log data.
[0064] In some embodiments, the predetermined event is a timeout event.
[0065] The apparatus further includes:
[0066] A receiving module, configured to receive the reporting signals periodically sent by each functional node through a pre-set message subscription node.
[0067] A faulty node determination module, configured to, in response to not receiving the reporting signal sent by any of the functional nodes within a predetermined period, determine the faulty node that has not sent the reporting signal.
[0068] A fault message sending module, configured to send a fault message to the target subscription topic corresponding to the faulty node, so that the log collection tool corresponding to the faulty node can obtain the fault message.
[0069] In some embodiments, the log data determination module is specifically configured to perform:
[0070] Determine the log data through a pre-set log collection tool.
[0071] The buffer module is specifically configured to perform:
[0072] Write the log data into the working buffer in the buffer group through the log collection tool.
[0073] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor, where the memory is used to store one or more computer program instructions, and wherein the one or more computer program instructions are executed by the processor to implement the method as described in the first aspect.
[0074] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which computer program instructions are stored, and the computer program instructions implement the method as described in the first aspect when executed by a processor.
[0075] An embodiment of the present application can ensure that there is no data competition conflict during data access through a buffer group including at least one working buffer and at least one idle buffer, avoid lock synchronization overhead (i.e., avoid I / O synchronization blocking), improve the performance during log collection. Moreover, when a predetermined event occurs, an embodiment of the present application can store the log data during the time period when the predetermined event occurs into the file system, while filtering most of the log data in other time periods (i.e., the time periods when the system is running normally) (i.e., not writing into the file system), which improves the proportion of valid data and reduces the storage data volume of log data. Therefore, the efficiency of system analysis can be effectively improved through an embodiment of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0076] Through the following description of the embodiments of the present application with reference to the accompanying drawings, the above and other objects, features, and advantages of the embodiments of the present application will become clearer. In the drawings:
[0077] Figure 1 is a schematic flowchart of the log data processing method according to an embodiment of the present application;
[0078] Figure 2 is a flowchart of the log data processing method according to an embodiment of the present application;
[0079] Figure 3 is a flowchart of storing log data based on a temporary directory according to an embodiment of the present application;
[0080] Figure 4 is a flowchart of generating a snapshot file and writing it into a temporary directory according to an embodiment of the present application;
[0081] Figure 5 is a schematic diagram of the sliding record window according to an embodiment of the present application;
[0082] Figure 6 is a schematic diagram of the predetermined storage window and the sliding record window according to an embodiment of the present application;
[0083] Figure 7 is a flowchart of storing and using global information according to an embodiment of the present application;
[0084] Figure 8 It is a flowchart for triggering a timeout event in an embodiment of the present application;
[0085] Figure 9 It is a schematic flowchart of another method for processing log data in an embodiment of the present application;
[0086] Figure 10 It is a schematic structural diagram of a log data processing device in an embodiment of the present application;
[0087] Figure 11 It is a schematic structural diagram of an electronic device in an embodiment of the present application. Detailed implementation manners
[0088] The following describes the present application based on embodiments, but the present application is not limited to these embodiments. In the following detailed description of the present application, some specific details are described in detail. Those skilled in the art can fully understand the present application without the description of these details. In order to avoid obscuring the essence of the present application, well-known methods, processes, procedures, elements, and circuits are not described in detail.
[0089] In addition, those of ordinary skill in the art should understand that the accompanying drawings provided herein are all for illustrative purposes and are not necessarily drawn to scale.
[0090] Unless the context clearly requires otherwise, words such as "including", "comprising", and the like in the entire application document should be construed in an inclusive sense rather than an exclusive or exhaustive sense; that is, the meaning of "including but not limited to".
[0091] In the description of the present application, it should be understood that terms such as "first", "second", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. In addition, in the description of the present application, unless otherwise stated, the meaning of "a plurality of" is two or more. In addition, the solutions described in this specification and the embodiments, if related to personal information processing, will be processed on the premise of having a legal basis (such as obtaining the consent of the personal information subject, or being necessary for performing a contract, etc.), and will only be processed within the specified or agreed scope. If the user refuses to process personal information other than the necessary information required for basic functions, it will not affect the user's use of basic functions.
[0092] In the daily system development and maintenance stage, developers can analyze system problems based on log data, and then locate and solve the problems that occur in the system.
[0093] Taking an autonomous driving system as an example, the autonomous driving system has strong real-time requirements. Currently, during the research and development stage of the L4-level autonomous driving system (the current autonomous driving systems are generally divided into 6 levels from L0 to L5, with the lowest automation level at L0 and the highest at L5), system timeout problems still occur, severely restricting the actual implementation and application of autonomous driving technology. To analyze the timeout problems, developers need to perform system analysis based on log data, and then locate and solve the timeout problems that occur in the autonomous driving system.
[0094] Similarly, for system problems that occur in any other applicable scenarios (such as public service platforms like online car-hailing services), developers can also perform system analysis based on log data.
[0095] During the above system analysis process, the storage efficiency of log data and the amount of stored data are important factors affecting the system analysis efficiency. In related technologies, after collecting log data, the log data is directly stored and the stored log data is uploaded to the background for developers to view.
[0096] However, if an input / output (I / O) blockage occurs (that is, when multiple processes simultaneously preempt processor resources, causing the processes that do not obtain resources to be forced to wait, also known as I / O synchronous blockage), the process of collecting and storing log data needs to wait for an uncertain period of time before it can continue to run to store log data. Therefore, the above situation will lead to a decrease in the storage efficiency of log data, and further lead to a decrease in the system analysis efficiency.
[0097] In addition, as the number of logs gradually increases, the amount of stored data corresponding to the log data will also increase. When the amount of stored data corresponding to the log data is large, developers need to spend a lot of time screening the log data to be analyzed one by one from the huge amount of log data, which further leads to a decrease in the system analysis efficiency.
[0098] That is to say, the related technologies currently still have problems of low storage efficiency of log data and large amount of stored data, resulting in low system analysis efficiency. Therefore, how to effectively improve the system analysis efficiency is an urgent problem to be solved currently.
[0099] To solve the above problems, the embodiments of this application provide a method for processing log data to effectively improve the system analysis efficiency. Among them, this method can be applied to an electronic device, and the electronic device can be a terminal device or a server. The terminal device can be a smart phone, a tablet computer, a vehicle control terminal, or a personal computer (PC), etc. The server can be a single server, or a server cluster configured in a distributed manner, or a cloud server.
[0100] Specifically, as Figure 1 shown, after the log data 11 collected in the embodiment of the present application is determined, the log data 11 can be written into the working buffer 121 in the buffer group 12, as Figure 1 shown, the buffer group 12 can include at least one working buffer 121 and at least one idle buffer 122, and the working buffer 121 and the idle buffer 122 can be switched so that the idle buffer 122 can replace the working buffer 121. Wherein, the number of the working buffer 121 and the idle buffer 122 can be set according to the actual situation, and the embodiment of the present application takes one working buffer 121 and one idle buffer 122 as an example.
[0101] Furthermore, the embodiment of the present application can also start a background thread 13 to store the log data in the time period corresponding to the predetermined event in the idle buffer 122 into the file system 14.
[0102] In the above process, since the embodiment of the present application writes log data into the working buffer 121 and reads log data from the idle buffer 122, therefore, the embodiment of the present application can decouple the two steps of "writing log data into the buffer" and "reading log data from the buffer", so that these two steps can be performed asynchronously, avoiding the above-mentioned I / O blocking problem, effectively improving the storage efficiency of log data, and further improving the system analysis efficiency.
[0103] In addition, since the embodiment of the present application only stores the log data in the time period corresponding to the predetermined event into the file system 14, and the log data in other time periods (that is, the time periods when the system is running normally) will not be written into the file system 14, therefore, when the embodiment of the present application writes log data into the file system 14, it realizes the filtering of log data, only retains the log data corresponding to the predetermined event, improves the proportion of valid data, reduces the storage data volume of log data, and improves the system analysis efficiency.
[0104] Specifically, as Figure 2 shown, the log data processing method of the embodiment of the present application can include the following steps:
[0105] In step S110, determine the log data.
[0106] Among them, the log data is used to record the system actions that occur when the system of the corresponding device is working. Taking an autonomous driving system as an example, an autonomous driving vehicle can include multiple functional nodes at the application layer such as perception, prediction, planning, tracking, and positioning. When the autonomous driving vehicle is working, it can collect the action data of the above-mentioned functional nodes and record them in the log data.
[0107] In an alternative embodiment, step S110 may be performed as follows: determining log data through a pre-set log collection tool, where the pre-set log collection tool may be an extended Berkeley Packet Filter (eBPF) or other applicable log collection tools. EBPF is an extension of the Berkeley Packet Filter (BPF) technology, which provides a mechanism to run a small program when kernel events and application events occur and can be used for system tracing and log collection. There are multiple development frameworks for EBPF technology (such as the lib-bpf framework written in C language), and these frameworks can provide users with a more convenient EBPF program development solution in the Linux (an operating system) kernel. In the embodiments of the present application, EBPF or other applicable log collection tools may be used to collect the log data corresponding to the system.
[0108] In step S120, write the log data into the working buffer in the buffer group.
[0109] Among them, the buffer group includes at least one working buffer and at least one idle buffer. In practical applications, the working buffer and the idle buffer can be exchanged so that the working buffer can continuously receive log data, avoiding data transmission blocking problems caused by insufficient storage space. In addition, since the working buffer is only responsible for receiving log data and the reading of log data is completed by the interaction between the background thread and the idle buffer, when one of the buffers (i.e., the working buffer) is being written with log data, the background thread always interacts with the unused log data in the other buffer (i.e., the idle buffer), which not only ensures that there is no data competition conflict during access but also avoids lock synchronization overhead (i.e., avoids I / O synchronization blocking), improving the performance during log collection.
[0110] In an alternative embodiment, the embodiments of the present application may, in response to the remaining storage space of the working buffer being less than or equal to the first predetermined threshold, switch the working buffer to an idle buffer and switch the corresponding idle buffer to a working buffer.
[0111] Among them, the first predetermined threshold can be a threshold set according to the actual situation. For example, the first predetermined threshold can be 0%, 5%, 10%, 15%, etc. By setting the first predetermined threshold, the embodiments of the present application can switch the buffer before or when the working buffer is full, so that log data can be continuously written into the buffer. In addition, if the first predetermined threshold is a value greater than 0, the embodiments of the present application can achieve early buffer switching, further avoiding data transmission blocking problems in special situations (for example, in special situations such as a sharp increase in the amount of log data, if the remaining storage space of the working buffer is small, the storage space of the working buffer may be filled in a short time, and the unwritten log data needs to wait until the buffer switching is completed before it can continue to be written).
[0112] In an alternative embodiment, the process of writing log data into the working buffer can also be executed by the above-mentioned log collection tool. Specifically, step S120 can be executed as: writing the log data into the working buffer in the buffer group through the log collection tool. Among them, the log collection tool can be eBPF or other applicable log collection tools.
[0113] In step S130, start a background thread to store the log data in the time period corresponding to the predetermined event in the idle buffer into the file system.
[0114] That is to say, the embodiments of the present application can use the above-mentioned dual-buffer mechanism (that is, a buffer group including at least one working buffer and at least one idle buffer) to ensure that there is no data competition conflict during data access, avoid lock synchronization overhead (that is, avoid I / O synchronization blocking), improve the performance during log collection, and moreover, when a predetermined event occurs, the embodiments of the present application can store the log data in the time period when the predetermined event occurs into the file system, and filter most of the other time periods (that is, the time periods when the system is running normally) (that is, not write into the file system), improve the proportion of valid data, and reduce the storage data volume of log data. Therefore, the efficiency of system analysis can be effectively improved through the embodiments of the present application.
[0115] Among them, the time period corresponding to the predetermined event includes at least the moment when the predetermined event is triggered, and the length of this time period can be set according to the actual situation. For example, this time period can be 5 minutes or 10 minutes, etc.
[0116] In addition, in the embodiments of the present application, the process of writing log data to the working buffer (i.e., the above-mentioned step S120) and the process of reading the free buffer and writing the log data to the file system (i.e., the above-mentioned step S130) are asynchronous. That is to say, the background thread of the embodiments of the present application does not have to maintain a real-time working state, and only needs to be started under specific circumstances (i.e., when a predetermined event occurs) and store the log data in the corresponding time period of the predetermined event in the free buffer to the file system.
[0117] Furthermore, for the log data generated during the normal operation of the system, if the system remains in normal operation for a long time, the log data generated during the normal operation of the system may occupy a large storage space in the buffer group. In response to this situation, on the one hand, in the embodiments of the present application, when the storage space of the buffer group is insufficient, some of the earliest stored log data can be deleted to keep the buffer group having sufficient storage space. On the other hand, in the embodiments of the present application, a temporary directory can also be maintained to transfer the log data in the free buffer to the temporary directory in a timely manner, so as to keep the buffer group having sufficient storage space.
[0118] In an alternative embodiment, for the above-mentioned temporary directory, as Figure 3 shown, step S130 may include the following steps:
[0119] In step S131, write the log data stored in the free buffer to the temporary directory and update the temporary directory.
[0120] Among them, after the embodiments of the present application write the log data stored in the free buffer to the temporary directory, the log data stored in the corresponding free buffer can be deleted to keep the buffer group having sufficient storage space.
[0121] In step S132, in response to triggering a predetermined event, through a predetermined storage window, store the log data in the corresponding time period of the predetermined storage window in the temporary directory to the file system.
[0122] Among them, the predetermined storage window is the time period corresponding to the predetermined event. The embodiments of the present application can mark the time period corresponding to the predetermined event by setting the predetermined storage window, so as to realize storing the log data in the corresponding time period of the predetermined event in the free buffer to the file system.
[0123] By transferring the log data in the free buffer to the temporary directory, the embodiments of the present application can effectively clean the log data in the buffer, so as to keep the buffer group having sufficient storage space.
[0124] In an alternative embodiment, for the timing of writing log data to the temporary directory, step S131 may include the following steps:
[0125] In step A1, in response to the working buffer being switched to an idle buffer, a background thread is started to write the log data stored in the switched idle buffer into a temporary directory.
[0126] In this case, the embodiment of the present application can start a background thread immediately after the mutual switching between the working buffer and the idle buffer, and write the log data stored in the switched idle buffer into the temporary directory through the background thread. That is to say, the embodiment of the present application can write the log data into the temporary directory every time the buffer is switched, so as to maximize the remaining storage space in the buffer and avoid data transmission blocking problems in special cases.
[0127] In step A2, in response to the remaining storage space of the working buffer being less than or equal to a second predetermined threshold, a background thread is started to write the log data stored in the idle buffer into the temporary directory.
[0128] Wherein, the second predetermined threshold may be the same as the above-mentioned first predetermined threshold, or may be set separately according to actual situations. For example, the second predetermined threshold may be 5%, 20%, or 50%, etc.
[0129] In this case, when the amount of data stored in the working buffer reaches a certain level (that is, the remaining storage space is less than or equal to the second predetermined threshold), the embodiment of the present application can start a background thread in advance to write the log data stored in the idle buffer into the temporary directory, so as to realize cleaning the log data stored in each idle buffer in advance, so that the idle buffer can be switched with the working buffer at any time, and avoid data transmission blocking problems in special cases.
[0130] In step A3, in response to the current time reaching a predetermined wake-up time, a background thread is started to write the log data stored in the idle buffer into the temporary directory.
[0131] Wherein, the predetermined wake-up time may be a preset wake-up period. For example, the predetermined wake-up time may be a wake-up period with a period of 5 minutes, 10 minutes, or 30 minutes, etc. The embodiment of the present application can start a background thread every time the predetermined wake-up time is reached to write the log data stored in the idle buffer into the temporary directory. In this way, the log data stored in each idle buffer can be periodically cleaned, so that the idle buffer can be switched with the working buffer at any time, and avoid data transmission blocking problems in special cases.
[0132] It should be noted that the above steps A1 - A3 are multiple parallel ways to start the background thread, and the embodiment of the present application can select any one or more steps from them to wake up the background thread.
[0133] In an alternative embodiment, to reduce the storage amount of log data and improve the analysis efficiency of developers, the embodiments of the present application may adopt snapshot technology to process log data. Specifically, as Figure 4 shown, the above step S131 may include the following steps:
[0134] In step S1311, determine the timestamp information corresponding to the log data.
[0135] The timestamp information is used to represent the time when the log data is collected. The embodiments of the present application may segment the log data based on the timestamp information to determine multiple snapshot files.
[0136] In step S1312, cut the log data according to the preset interval time parameter and the timestamp information corresponding to the log data to generate multiple snapshot files.
[0137] The interval time parameter is used to represent the time interval for cutting the log data, that is, the time length corresponding to each snapshot file.
[0138] In step S1313, write each snapshot file into the temporary directory.
[0139] By segmenting the log data into snapshot files, the embodiments of the present application can effectively manage the log data, reduce the storage amount of the log data, and improve the analysis efficiency of developers.
[0140] Further, in an alternative embodiment, after generating the snapshot file, the process of updating the temporary directory may be executed as follows: according to the preset sliding record window, write the newly generated snapshot file into the temporary directory, and remove the expired snapshot file from the temporary directory. The recording duration corresponding to the sliding record window is fixed, and the sliding record window moves forward as the current moment moves forward.
[0141] Specifically, as Figure 5 shown, the recording duration corresponding to the sliding record window 51 is a fixed duration, and the sliding record window 51 moves forward as the current moment moves forward. As Figure 5 shown, Figure 5It includes a total of 6 snapshot files from Snapshot 1 to Snapshot 6. Snapshot 1 and Snapshot 2 are snapshot files on the left side of the sliding record window 51 (i.e., on the left side of the expiration moment). At this time, the embodiments of the present application can remove Snapshot 1 and Snapshot 2 from the temporary directory. Correspondingly, Snapshot 3 to Snapshot 6 are the snapshot files included in the sliding record window 51, that is to say, Snapshot 3 to Snapshot 6 are the snapshot files recorded in the temporary directory. It should be noted that Snapshot 3 is a snapshot file that overlaps with the sliding record window 51, that is, a part of Snapshot 3 is in the sliding record window 51, and the other part is not in the sliding record window 51. In view of this situation, the embodiments of the present application can either retain Snapshot 3 or remove Snapshot 3.
[0142] Therefore, by writing the newly generated snapshot files into the temporary directory and removing the expired snapshot files from the temporary directory, the embodiments of the present application can always maintain a certain data storage capacity in the temporary directory, thereby reducing the total storage capacity of the log data and improving the analysis efficiency of developers.
[0143] In an optional implementation manner, the start moment corresponding to the predetermined storage window of the embodiments of the present application is before the moment of triggering the predetermined event, and is different from the moment of triggering the predetermined event by a first predetermined time length parameter. The end moment corresponding to the predetermined storage window is after the moment of triggering the predetermined event, and is different from the moment of triggering the predetermined event by a second predetermined time length parameter.
[0144] Wherein, the first predetermined time length parameter and the second predetermined time length parameter can be values set according to the actual situation. For example, the first predetermined time length parameter can be a time length such as 3 minutes, 5 minutes or 10 minutes, etc., and the second predetermined time length parameter can also be a time length such as 3 minutes, 5 minutes or 10 minutes, etc. In addition, the first predetermined time length parameter and the second predetermined time length parameter can be the same or different.
[0145] By setting the predetermined storage window, the embodiments of the present application can only store the log data before and after the triggering moment when the predetermined event is triggered into the file system, that is, only retain the log data corresponding to the predetermined event, realizing the filtering of the log data, increasing the proportion of valid data, reducing the storage data volume of the log data, and improving the efficiency of system analysis.
[0146] Furthermore, in combination with the above-mentioned sliding record window, the embodiments of the present application can, while using the sliding record window to maintain the snapshot files in the temporary directory, use the predetermined storage window to store the snapshot files corresponding to the predetermined event into the file system.
[0147] Such as Figure 6As shown, when the embodiment of the present application maintains a temporary directory by means of a sliding record window 51 (that is, writing newly generated snapshot files into the temporary directory and removing expired snapshot files from the temporary directory), if a predetermined event is triggered at a trigger time 62, the embodiment of the present application sets a predetermined storage window 61 at the same time as the triggering of the predetermined event (that is, at the trigger time 62).
[0148] Wherein, the start time of the predetermined storage window 61 is before the trigger time 62 of the triggered predetermined event and differs from the trigger time 62 by a first predetermined time length parameter. The end time of the predetermined storage window 61 is after the trigger time 62 and differs from the trigger time 62 by a second predetermined time length parameter. The first predetermined time length parameter and the second predetermined time length parameter may be the same or different.
[0149] Furthermore, the embodiment of the present application may store the snapshot files within the time range indicated by the predetermined storage window 61 into the file system to report the log data when the predetermined event occurs. It should be noted that after the appearance of the predetermined storage window 61 (that is, after the triggering of the predetermined event), although the sliding record window 51 will still move forward as the current time moves forward, however, since the embodiment of the present application will store the snapshot files within the time range indicated by the predetermined storage window 61 into the file system, therefore, the embodiment of the present application will not remove the snapshot files that are within the time range indicated by the predetermined storage window 61 and are expired snapshot files relative to the sliding record window 51 (such as Figure 6 snapshot 3 in).
[0150] In addition, in an alternative embodiment, the first predetermined time length parameter corresponding to the predetermined storage window of the embodiment of the present application may be greater than or equal to the record time length corresponding to the sliding record window. As Figure 6 shown, the first predetermined time length parameter corresponding to the predetermined storage window 61 may be greater than or equal to the record time length corresponding to the sliding record window 51. That is to say, in this case, when the start time of the predetermined storage window 61 is at the trigger time 62, it may be flush with the left side of the sliding record window 51 or to the left of the sliding record window 51. In this way, it can be ensured that the predetermined storage window 61 can cover all the snapshot files recorded in the sliding record window 51, ensuring the integrity of the log data corresponding to the predetermined event.
[0151] It should be noted that Snapshot 3 is a snapshot file that overlaps with the predetermined storage window 61, that is, a part of Snapshot 3 is within the predetermined storage window 61, while the other part is not within the predetermined storage window 61. In this case, the embodiment of the present application can either retain Snapshot 3 or remove Snapshot 3. By setting the predetermined storage window, the embodiment of the present application can store only the log data before and after the trigger moment when a predetermined event is triggered into the file system, that is, only retain the log data corresponding to the predetermined event, realizing the filtering of log data, improving the proportion of valid data, reducing the storage data volume of log data, and improving the efficiency of system analysis.
[0152] In an alternative embodiment, in order to improve the integrity of the log data written to the file system for facilitating the parsing of the log data, as Figure 7 shown, the embodiment of the present application may further include the following steps:
[0153] In step S210, detect the dependency relationship between the newly collected log data and the subsequent log data.
[0154] Among them, the dependency relationship may include data dependency relationships such as reference, call, retrieval, etc. The embodiment of the present application can determine whether there is a dependency relationship between the newly collected log data and the subsequent log data through the above log collection tool or other applicable tools.
[0155] In step S220, in response to the existence of a dependency relationship between the newly collected log data and the subsequent log data, determine the newly collected log data as global information and copy the global information to a pre-set header buffer.
[0156] Among them, the global information is the log data that has a dependency relationship with the subsequent log data. The header buffer is a buffer independent of the working buffer and the free buffer, and it can be dedicated to storing global information.
[0157] In step S230, start a background thread to copy the global information in the header buffer to the file header of the subsequent log data.
[0158] Among them, the embodiment of the present application copies the global information to the file header of the subsequent log data with a dependency relationship, so that the subsequent log data can include all information with a dependency relationship, thereby improving the integrity of the log data and facilitating the parsing of the log data.
[0159] Especially in scenarios where snapshot files need to be generated, since log data needs to be segmented during the generation of snapshot files, the snapshot segmentation mechanism usually requires that there is no information dependency between snapshot files. Otherwise, when an expired snapshot file is deleted, all log information in subsequent snapshot files that depends on this snapshot file cannot be parsed. In response to this situation, the embodiments of the present application can, based on the above-mentioned header buffer, enable the background thread to copy the global information to the header of the snapshot file when generating the snapshot file corresponding to the subsequent log data, so that the snapshot file corresponding to the subsequent log data includes all information with dependency relationships, thereby improving the integrity of the log data for facilitating the parsing of the log data.
[0160] In addition, to save the storage space of the electronic device, the embodiments of the present application can only store the complete data of the first storage call stack (i.e., the above-mentioned global information) and store the stack ID of the call stack in the log collection tool (which can also be other applicable tools). In this way, if the same call stack appears subsequently, the embodiments of the present application can be parsed and restored only through the stack ID to obtain the complete data content, thereby achieving the purpose of saving storage space.
[0161] In an optional implementation manner, the predetermined event of the embodiments of the present application can be a timeout event, where the timeout event can be a timeout event of an autonomous driving system or a timeout event that occurs in other systems (such as a car-hailing public service platform system).
[0162] For the timeout event, as Figure 8 shown, the embodiments of the present application can further include the following steps:
[0163] In step S310, receive the reporting signals periodically sent by each functional node through a pre-set message subscription node.
[0164] Among them, the message subscription mechanism refers to a mechanism for realizing information exchange in a distributed computing environment. This mechanism can pre-define the topic and message type of the message. Then, the publisher (i.e., the message subscription node of the embodiments of the present application) publishes the message to a specific topic, and the subscriber (i.e., the log collection tool corresponding to each functional node of the embodiments of the present application) receives it by subscribing to the same topic. This mechanism realizes the loose coupling between the publisher and the subscriber, thereby improving the scalability and flexibility of the system. In the embodiments of the present application, the message subscription node can be the Robot Operating System (ROS), or other applicable message subscription nodes. ROS provides a mature and effective management mechanism, enabling each software and hardware module in the system to interact effectively.
[0165] In the embodiments of the present application, each functional node can periodically send a specific reporting signal (such as a heartbeat data packet) to the message subscription node (such as ROS middleware), so that the message subscription node can determine whether each functional node is running normally. If the message subscription node does not receive the signal reported by the functional node within the specified time (i.e., the above period), the message subscription node can determine that the functional node has a timeout problem, that is, a timeout event occurs.
[0166] In step S320, in response to not receiving the reporting signal sent by any functional node within a predetermined period, determine the faulty node that has not sent the reporting signal.
[0167] Wherein, the faulty node is the functional node that has a timeout problem.
[0168] In step S330, send a fault message to the target subscription topic corresponding to the faulty node, so that the log collection tool corresponding to the faulty node can obtain the fault message.
[0169] Wherein, the fault message at least includes the identifier corresponding to the faulty node. Taking the autonomous driving system as an example, in the embodiments of the present application, a log collection tool management node can be created in the ROS system (i.e., the message subscription node), and this node can be responsible for starting all log collection tools. After each log collection tool is started, it can use the local socket mechanism of Linux to create a unique socket file in the / var / run directory and obtain information from it. When the log collection tool management node subscribes to the fault message from the ROS system, it can parse out the corresponding faulty node from it and determine the log collection tool corresponding to the faulty node. Further, the log collection tool management node can use the above-created socket file to send a message to the log collection tool corresponding to the faulty node to start a background thread and store the log data in the time period corresponding to the timeout event in the idle buffer to the file system.
[0170] That is to say, when a timeout event occurs, the embodiment of the present application can send a failure message to the target subscription topic corresponding to the faulty node. Correspondingly, since the log collection tool corresponding to each functional node (or the above-mentioned log collection tool management node) subscribes to the target subscription topic, the log collection tool corresponding to the faulty node can obtain the failure message from the target subscription topic in the first place to trigger the timeout event (i.e., the predetermined event), thereby triggering the start of a background thread and storing the log data in the time period corresponding to the timeout event in the idle buffer to the file system. During this process, since the embodiment of the present application can utilize the above-mentioned double buffer mechanism (i.e., a buffer group including at least one working buffer and at least one idle buffer) to ensure that there is no data competition conflict during data access, avoid lock synchronization overhead (i.e., avoid I / O synchronization blocking), and improve the performance during log collection. Moreover, when the embodiment of the present application writes log data to the file system, it realizes the filtering of log data, only retains the log data corresponding to the predetermined event, effectively improves the proportion of valid data, and reduces the storage data volume of log data. Therefore, the efficiency of system analysis can be effectively improved through the embodiment of the present application.
[0171] Combined with the above embodiments, as Figure 9 shown, during the normal operation stage of the system, the log collection tool 905 can collect the log data of the corresponding functional node and write the log data into the working buffer in the buffer group 906. The buffer group 906 includes at least one working buffer and at least one idle buffer, and the working buffer can be exchanged with the idle buffer, so that the working buffer can continuously receive log data, avoiding data transmission blocking problems caused by insufficient storage space. In addition, if the log collection tool 905 detects a dependency relationship between the newly collected log data and the subsequent log data, the log collection tool 905 can determine the newly collected log data as global information and copy the global information to the pre-set header buffer 907.
[0172] Furthermore, the background thread 908 can read the log data from the idle buffer in the buffer group 906, write the log data into the temporary directory 909 in the form of a snapshot file, and maintain the temporary directory 909 through a sliding record window (i.e., write the newly generated snapshot file into the temporary directory 909 and remove the expired snapshot file from the temporary directory 909). At the same time, if the global information is stored in the header buffer 907, the background thread 908 can read the global information (or the stack ID of the global information) from the header buffer 907 and copy the global information (or the stack ID of the global information) to the header of the snapshot file with a dependency relationship.
[0173] For the timeout event, one or more functional nodes 901 ( Figure 9As shown, a reporting signal can be periodically sent to the message subscription node 902. When the message subscription node 902 does not receive any reporting signal sent by any functional node 901 within a predetermined period, the message subscription node 902 can determine the faulty node that has not sent the reporting signal and publish a fault message to the target subscription topic 903. Correspondingly, the log collection tool management node 904 can subscribe to the fault message in the target subscription topic 903 and parse the corresponding faulty node from it. Further, the log collection tool management node 904 can send the fault message to the log collection tool 905 corresponding to the faulty node to trigger a timeout event.
[0174] After triggering the timeout event, the background thread 908 can write the snapshot file within the corresponding time period of the predetermined storage window (i.e., the time period corresponding to the timeout event) into the file system 910 through the predetermined storage window. During this process, since the embodiments of the present application can store only the log data (i.e., the snapshot file) before and after the triggering moment when the timeout event is triggered into the file system, that is, only the log data corresponding to the timeout event is retained, therefore, the embodiments of the present application can achieve filtering of the log data, improve the proportion of valid data, reduce the storage data volume of the log data, and improve the efficiency of system analysis.
[0175] Based on the same technical concept, the embodiments of the present application also provide a log data processing device, as Figure 10 shown, the device includes: a log data determination module 101, a buffer module 102, and a writing module 103.
[0176] The log data determination module 101 is configured to determine log data.
[0177] The buffer module 102 is configured to write the log data into a working buffer in the buffer group, where the buffer group includes at least one working buffer and at least one idle buffer.
[0178] The writing module 103 is configured to start a background thread and store the log data in the idle buffer within the time period corresponding to a predetermined event into the file system.
[0179] In some embodiments, the device further includes:
[0180] A switching module, configured to, in response to the remaining storage space of the working buffer being less than or equal to a first predetermined threshold, switch the working buffer to an idle buffer and switch the corresponding idle buffer to a working buffer.
[0181] In some embodiments, the writing module 103 is specifically configured to:
[0182] Write the log data stored in the idle buffer to a temporary directory and update the temporary directory.
[0183] In response to triggering a predetermined event, store the log data in the time period corresponding to the predetermined storage window in the temporary directory into the file system through the predetermined storage window.
[0184] In some embodiments, the writing module 103 is specifically configured to execute:
[0185] In response to the working buffer being switched to an idle buffer, start a background thread to write the log data stored in the switched idle buffer to the temporary directory. And / or
[0186] In response to the remaining storage space of the working buffer being less than or equal to a second predetermined threshold, start a background thread to write the log data stored in the idle buffer to the temporary directory. And / or
[0187] In response to the current time reaching a predetermined wake-up time, start a background thread to write the log data stored in the idle buffer to the temporary directory.
[0188] In some embodiments, the writing module 103 is specifically configured to execute:
[0189] Determine the timestamp information corresponding to the log data.
[0190] Cut the log data according to a pre-set interval time parameter and the timestamp information corresponding to the log data to generate a plurality of snapshot files.
[0191] Write each of the snapshot files to the temporary directory.
[0192] In some embodiments, the writing module 103 is specifically configured to execute:
[0193] According to a pre-set sliding record window, write the newly generated snapshot files to the temporary directory and remove the expired snapshot files from the temporary directory, wherein the recording duration corresponding to the sliding record window is fixed, and the sliding record window moves forward as the current time moves forward.
[0194] In some embodiments, the start time corresponding to the predetermined storage window is before the time of triggering the predetermined event and differs from the time of triggering the predetermined event by a first predetermined duration parameter, and the end time corresponding to the predetermined storage window is after the time of triggering the predetermined event and differs from the time of triggering the predetermined event by a second predetermined duration parameter.
[0195] In some embodiments, the first predetermined duration parameter corresponding to the predetermined storage window is greater than or equal to the recording duration corresponding to the sliding record window.
[0196] In some embodiments, the apparatus further comprises:
[0197] A detection module, configured to detect the dependency relationship between newly collected log data and subsequent log data.
[0198] A first copy module, configured to determine that the newly collected log data is global information in response to the existence of a dependency relationship between the newly collected log data and the subsequent log data, and copy the global information to a pre-set header buffer.
[0199] A second copy module, configured to start a background thread and copy the global information in the header buffer to the file header of the subsequent log data.
[0200] In some embodiments, the predetermined event is a timeout event.
[0201] The apparatus further comprises:
[0202] A receiving module, configured to receive the reporting signals periodically sent by each functional node through a pre-set message subscription node.
[0203] A faulty node determination module, configured to determine a faulty node that has not sent a reporting signal in response to not receiving a reporting signal sent by any of the functional nodes within a predetermined period.
[0204] A fault message sending module, configured to send a fault message to a target subscription topic corresponding to the faulty node, so that a log collection tool corresponding to the faulty node can obtain the fault message.
[0205] In some embodiments, the log data determination module 101 is specifically configured to:
[0206] Determine the log data through a pre-set log collection tool.
[0207] The buffer module 102 is specifically configured to:
[0208] Write the log data into a working buffer in a buffer group through the log collection tool.
[0209] Embodiments of the present application can ensure that there is no data competition conflict during data access through a buffer group including at least one working buffer and at least one idle buffer, avoid lock synchronization overhead (i.e., avoid I / O synchronization blocking), and improve the performance during log collection. Moreover, when a predetermined event occurs, embodiments of the present application can store the log data during the time period when the predetermined event occurs into the file system, while filtering most of the other time periods (i.e., the time periods when the system is running normally) of the log data (i.e., not writing into the file system), which increases the proportion of valid data and reduces the storage data volume of the log data. Therefore, the efficiency of system analysis can be effectively improved through embodiments of the present application.
[0210] Figure 11 is a schematic diagram of an electronic device according to an embodiment of the present application. As Figure 11 shown, Figure 11 the electronic device shown is a general address query device, which includes a general computer hardware structure, and at least includes a processor 111 and a memory 112. The processor 111 and the memory 112 are connected through a bus 113. The memory 112 is suitable for storing instructions or programs executable by the processor 111. The processor 111 can be an independent microprocessor or a set of one or more microprocessors. Thus, the processor 111 processes data and controls other devices by executing the instructions stored in the memory 112 to implement the method flow of the embodiment of the present application as described above. The bus 113 connects the above-mentioned multiple components together, and at the same time connects the above-mentioned components to a display controller 114, a display device, and an input / output (I / O) device 115. The input / output (I / O) device 115 can be a mouse, a keyboard, a modem, a network interface, a touch input device, a body sensing input device, a printer, and other devices well known in the art. Typically, the input / output (I / O) device 115 is connected to the system through an input / output (I / O) controller 116.
[0211] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a device (equipment), or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be implemented as a computer program product on one or more computer-readable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0212] The present application is described with reference to the flowcharts of methods, devices (equipment), and computer program products according to embodiments of the present application. It should be understood that each process in the flowchart can be implemented by computer program instructions.
[0213] These computer program instructions can be stored in a computer-readable memory that directs a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the function specified in one or more of the procedures. Figure 1 for one or more of the procedures.
[0214] These computer program instructions may also be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the function specified in one or more of the procedures. Figure 1 for one or more of the procedures.
[0215] Another embodiment of the present application relates to a non-volatile storage medium for storing a computer-readable program for a computer to execute part or all of the method embodiments described above.
[0216] That is, those skilled in the art can understand that all or part of the steps of implementing the methods of the above embodiments can be completed by specifying relevant hardware through a program, which is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
[0217] The foregoing are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and changes. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A method for processing log data, characterized in that, the method includes: determining log data; writing the log data into a working buffer in a buffer group, where the buffer group includes at least one of the working buffers and at least one idle buffer; starting a background thread to store the log data in a time period corresponding to a predetermined event in the idle buffer into a file system.
2. The method according to claim 1, characterized in that, the method further includes: in response to the remaining storage space of the working buffer being less than or equal to a first predetermined threshold, switching the working buffer to an idle buffer and switching the corresponding idle buffer to a working buffer.
3. The method according to claim 1, characterized in that, storing the log data in a time period corresponding to a predetermined event in the idle buffer into the file system includes: writing the log data stored in the idle buffer into a temporary directory and updating the temporary directory; in response to triggering a predetermined event, storing the log data in a time period corresponding to the predetermined storage window in the temporary directory into the file system through the predetermined storage window.
4. The method according to claim 3, characterized in that, writing the log data stored in the idle buffer into the temporary directory includes: in response to the working buffer being switched to an idle buffer, starting a background thread to write the log data stored in the switched idle buffer into the temporary directory; and / or in response to the remaining storage space of the working buffer being less than or equal to a second predetermined threshold, starting a background thread to write the log data stored in the idle buffer into the temporary directory; and / or in response to the current time reaching a predetermined wake-up time, starting a background thread to write the log data stored in the idle buffer into the temporary directory.
5. The method according to claim 3, characterized in that, writing the log data stored in the idle buffer into the temporary directory includes: determining the timestamp information corresponding to the log data; cutting the log data according to a preset interval time parameter and the timestamp information corresponding to the log data to generate a plurality of snapshot files; writing each of the snapshot files into the temporary directory.
6. The method according to claim 5, characterized in that, updating the temporary directory includes: writing newly generated snapshot files into the temporary directory according to a preset sliding record window and removing expired snapshot files from the temporary directory, where the recording duration corresponding to the sliding record window is fixed and the sliding record window moves forward as the current time moves forward.
7. The method according to claim 6, characterized in that, the start time corresponding to the predetermined storage window is before the time of triggering the predetermined event and differs from the time of triggering the predetermined event by a first predetermined duration parameter, and the end time corresponding to the predetermined storage window is after the time of triggering the predetermined event and differs from the time of triggering the predetermined event by a second predetermined duration parameter.
8. The method according to claim 7, characterized in that, The first predetermined duration parameter corresponding to the predetermined storage window is greater than or equal to the recording duration corresponding to the sliding recording window.
9. The method according to claim 1, wherein, the method further includes: detecting the dependency relationship between newly collected log data and subsequent log data; in response to the existence of a dependency relationship between the newly collected log data and the subsequent log data, determining the newly collected log data as global information, and copying the global information to a pre-set header buffer; starting a background thread to copy the global information in the header buffer to the file header of the subsequent log data.
10. The method according to claim 1, wherein, the predetermined event is a timeout event; the method further includes: receiving the reporting signals periodically sent by each functional node through a pre-set message subscription node; in response to not receiving any reporting signal sent by any of the functional nodes within a predetermined period, determining the faulty node that has not sent the reporting signal; sending a fault message to the target subscription topic corresponding to the faulty node, so that the log collection tool corresponding to the faulty node can obtain the fault message.
11. The method according to claim 1, wherein, the determining the log data includes: determining the log data through a pre-set log collection tool; the writing the log data into the working buffer in the buffer group includes: writing the log data into the working buffer in the buffer group through the log collection tool.
12. A log data processing device, wherein, the device includes: a log data determination module configured to execute the determination of log data; a buffering module configured to execute writing the log data into the working buffer in the buffer group, where the buffer group includes at least one of the working buffers and at least one idle buffer; a writing module configured to execute starting a background thread to store the log data in the time period corresponding to the predetermined event in the idle buffer into the file system.
13. An electronic device, including a memory and a processor, wherein, the memory is used to store one or more computer program instructions, and wherein the one or more computer program instructions are executed by the processor to implement the method according to any one of claims 1-11.
14. A computer-readable storage medium, wherein, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1-11.
Citation Information
Cited By
Kernel log management method, system and device, storage medium and program product
CN122431990A