Log service identification method and device, equipment and medium

By independently training the log feature library on each service node and comparing it with the total log feature library of the management node, the problem of service node log exception identification in distributed applications is solved, and more accurate service exception judgment and monitoring alarms are achieved.

CN120066898APending Publication Date: 2025-05-30BEIJING QIYI CENTURY SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510197403.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In business applications in distributed deployment mode, the logs generated by each service node exist independently, resulting in increased difficulty in identifying exceptions. Especially when the exception logs account for a low proportion of all logs, it is difficult to identify exceptions of the service node through fixed rules.

Method used

By independently training the log feature library on each service node, and collecting the total log feature library for all service node logs on the management node, comparing the differences between the log template category distribution information of each service node and the total log feature library, and using the preset threshold value to determine whether an abnormality occurred in the service node.

Benefits of technology

It improves the accuracy of service abnormal identification, can accurately determine whether there are abnormalities in the service node, makes up for the shortcomings based on fixed rules, improves the accuracy of monitoring and alarms, and reduces business losses caused by failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066898A_ABST
    Figure CN120066898A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a log service identification method and device, equipment and a medium, the method is applied to a log management platform, the log management platform comprises multiple service nodes corresponding to an application program, the multiple service nodes are connected with the same management node, and the method comprises the steps that a service log feature library of each service node is obtained; acquiring a management log feature library of the management node; and comparing the service log feature library of each service node with the management log feature library, and determining a service identification result of each service node based on a comparison result. According to the embodiment of the invention, whether the service node is abnormal or not can be accurately judged through comparison between the log feature library independently trained by the service log generated on each service node and the total log feature library trained by all the service node logs collected by the management node, the monitoring alarm accuracy is improved, and the business loss caused by faults is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data processing, and particularly to a method, apparatus, device, and medium for identifying log services. Background Art

[0002] Currently, various business application programs, such as video services, audio services, etc., will output printed logs to record important information in key links for scenario requirements such as monitoring and alarming, auditing, and troubleshooting based on the logs.

[0003] Currently, business application programs are usually deployed in a distributed mode with many service nodes. The services on each service node generate logs respectively, and the logs of each service node are collected and summarized to the management end for unified analysis. For example, based on some general and specific rules, abnormal judgments are made on the logs of the service nodes. If the proportion of abnormal logs of the service nodes is not high among all the logs, it will lead to failure to identify the anomalies. Summary of the Invention

[0004] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a method, apparatus, device, and medium for identifying log services.

[0005] An embodiment of the present disclosure provides a method for identifying log services. The method is applied to a log management platform, and the log management platform includes a plurality of service nodes corresponding to application programs. The plurality of service nodes are respectively connected to the same management node, and the method includes: obtaining a service log feature library of each service node; where the service log feature library refers to the distribution information of log template categories of the service node within a target time period; obtaining a management log feature library of the management node; where the management log feature library refers to the distribution information of log template categories of all the service nodes within the target time period; comparing the distribution information of log template categories corresponding to the service log feature library of each service node with the distribution information of log template categories corresponding to the management log feature library to obtain the percentage difference in the distribution of log template categories between each service node and the management node; and determining whether each service node has a service anomaly based on the percentage difference in the distribution of log template categories and a preset percentage threshold for the distribution of log template categories.

[0006] Optionally, obtaining the service log feature library of each service node includes: obtaining multiple service logs of each service node within the target time period; clustering the multiple service logs based on a preset clustering algorithm to obtain multiple service log templates and the log template category corresponding to each service log; determining the log template category distribution information of the multiple service logs as the service log feature library based on the multiple service log templates and the log template category corresponding to each service log.

[0007] Optionally, clustering the multiple service logs based on a preset clustering algorithm to obtain multiple service log templates and the log template category corresponding to each service log includes: obtaining string variables in each service log based on regular matching, and replacing the string variables in each service log with a preset target identifier to obtain multiple preprocessed logs; performing word segmentation processing on each preprocessed log to obtain the word segmentation set and log length corresponding to each preprocessed log, and obtaining the log matching words corresponding to each preprocessed log; comparing the log lengths and the log matching words of any two preprocessed logs, and when the log lengths between any two preprocessed logs are the same and the log matching words between any two preprocessed logs are the same, regarding any two preprocessed logs as two logs to be clustered, calculating the similarity based on the word segmentation sets corresponding to at least the two logs to be clustered, and when the similarity is greater than a preset similarity threshold, performing clustering processing on at least the two logs to be clustered to obtain clustered logs; determining the logs to be processed for which there are no logs to be clustered based on the matching result, and constructing the service log template based on the log lengths, log matching words, and word segmentation sets corresponding to the logs to be processed and the clustered logs, and determining the log template category corresponding to the service log template.

[0008] Optionally, clustering the multiple service logs based on a preset clustering algorithm to obtain multiple service log templates and the log template category corresponding to each service log includes: merging at least two service logs whose string length of the maximum common substring obtained from the multiple service logs is greater than or equal to a preset length threshold to obtain a merged log; wherein, determining the length threshold based on the log lengths of the at least two service logs; updating the non-common substrings in the merged log to the target identifier to obtain an updated log; constructing the service log template based on the service logs with a string length less than the length threshold and the updated log, and determining the log template category corresponding to the service log template.

[0009] Optionally, obtaining the management log feature library of the management node includes: obtaining a plurality of management logs of all the service nodes within the target time period; clustering the plurality of management logs based on a preset clustering algorithm to obtain a plurality of management log templates and a log template category corresponding to each management log template; and determining the log template category distribution information of the plurality of management logs as the management log feature library based on the plurality of management log templates and the log template category corresponding to each management log template.

[0010] Optionally, comparing the log template category distribution information corresponding to the service log feature library of each service node with the log template category distribution information corresponding to the management log feature library to obtain the percentage difference in the log template category distribution between each service node and the management node includes: obtaining the log template category distribution information of each service node based on the service log feature library of each service node, and determining the service log template distribution ratio of each service node based on the log template category distribution information of each service node; obtaining the log template category distribution information of the management node based on the management log feature library, and determining the management log template distribution ratio of the management node based on the log template category distribution information of the management node; comparing each service log template distribution ratio with the management log template distribution ratio, and determining the ratio difference of the same log template as the percentage difference in the log template category distribution; correspondingly, determining whether a service exception occurs for each service node based on the percentage difference in the log template category distribution and a preset percentage threshold for the log template category distribution includes: marking the service node corresponding to the service log template distribution ratio with a ratio difference of the same log template greater than or equal to the preset ratio threshold as an abnormal service node.

[0011] Optionally, the method further includes: obtaining the usage information of the application program; obtaining the update log of each service node based on the usage information; and updating the service log feature library and the management log feature library with the update log.

[0012] An embodiment of the present disclosure also provides a log service identification device. The device is applied to a log management platform, and the log management platform includes a plurality of service nodes corresponding to application programs. The plurality of service nodes are respectively connected to the same management node, and includes: a first acquisition module, configured to acquire a service log feature library of each of the service nodes; wherein, the service log feature library refers to the distribution information of log template categories of the service nodes within a target time period; a second acquisition module, configured to acquire a management log feature library of the management node; wherein, the management log feature library refers to the distribution information of log template categories of all the service nodes within the target time period; a comparison module, configured to compare the distribution information of log template categories corresponding to the service log feature library of each service node with the distribution information of log template categories corresponding to the management log feature library, to obtain the percentage difference in the distribution of log template categories between each service node and the management node; a determination module, configured to determine whether a service exception occurs for each service node based on the percentage difference in the distribution of log template categories and a preset percentage threshold for the distribution of log template categories.

[0013] An embodiment of the present disclosure also provides an electronic device, which includes: a processor; a memory for storing executable instructions of the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the log service identification method provided by the embodiment of the present disclosure.

[0014] An embodiment of the present disclosure also provides a computer-readable storage medium, which stores a computer program, and the computer program is used to execute the log service identification method provided by the embodiment of the present disclosure.

[0015] An embodiment of the present disclosure also provides a computer program product, including a computer program, wherein the computer program is executed by a processor to implement the log service identification method provided by the embodiment of the present application.

[0016] In the above technical solution provided by the embodiment of the present disclosure, a log feature library is independently trained from the service logs generated on each service node, and a total log feature library is trained from the logs of all service nodes collected by the management node; the log feature library independently trained from the service logs generated on each service node can accurately reflect the different log features of each service node, thereby improving the accuracy of subsequent exception judgment, and comparing the log feature library independently trained from the service logs generated on each service node with the total log feature library trained from the logs of all service nodes collected by the management node can accurately judge whether there is an exception in the service node, which can make up for the deficiencies based on fixed rules, improve the accuracy of monitoring and alarm, and reduce the business losses caused by failures.

[0017] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure.

[0019] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or in the prior art, the following briefly introduces the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0020] Figure 1 A schematic diagram of a log service identification process provided for the related art;

[0021] Figure 2 A schematic diagram of a process for a log service identification method provided by an embodiment of the present disclosure;

[0022] Figure 3 A schematic diagram of a process for a log service identification method provided by an embodiment of the present disclosure;

[0023] Figure 4 A schematic diagram of a log service identification process provided by an embodiment of the present disclosure;

[0024] Figure 5 A schematic diagram of the structure of a log service identification device provided by an embodiment of the present disclosure;

[0025] Figure 6 A schematic diagram of the structure of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] In order to better understand the above objects, features, and advantages of the present disclosure, the following further describes the solutions of the present disclosure. It should be noted that, without conflict, the embodiments of the present disclosure and the features in the embodiments can be combined with each other.

[0027] Many specific details are set forth in the following description to facilitate a thorough understanding of the present disclosure, but the present disclosure may be practiced in other ways different from those described herein; obviously, the embodiments in the specification are only some embodiments of the present disclosure, not all of the embodiments.

[0028] In the existing log processing scenarios, business applications are instrumented at key points. For example, video applications are instrumented at key points such as click play, like, etc., and are specifically set according to business needs, so as to output corresponding log information to a specified location, usually a certain file on the server where the application is located, and then collected by the log platform for analysis.

[0029] For ease of understanding, reference can be made to Figure 1 a schematic diagram of a log collection process provided by the related art shown below. The log platform in the related art includes a collection module, which is responsible for collecting the logs generated by business applications and transmitting them to a unified log center at the back end; it is generally called a log collection agent and is deployed on the service nodes where business applications are located ( Figure 1 the machines 1, 2, and 3 shown below); a processing module, which is used to receive the logs delivered by the collection module, process them according to business rules, and store them in a log storage system; and an analysis module, which is used to read the logs in the log storage system for analysis and is used in scenarios such as monitoring and alarming, auditing, and troubleshooting.

[0030] It can be understood that current business applications are usually deployed in a distributed mode, with many service nodes. The services on each service node generate logs respectively. The logs of each service node are collected and summarized to the management end for unified analysis. For example, based on some general and specific rules, abnormal judgments are made on the logs of service nodes. If the proportion of abnormal logs of service nodes is not high among all logs, it will lead to failure to identify abnormalities.

[0031] In view of the above problems, the embodiments of the present disclosure propose a log service identification method. A service log feature library is independently trained from the service logs generated on each service node, and a total management log feature library is trained from all the service node logs collected by the background management end. The log template category distribution information corresponding to the service log feature library of each service node is compared with the log template category distribution information corresponding to the management log feature library to obtain the percentage difference in the log template category distribution between each service node and the management node; based on the percentage difference in the log template category distribution and a preset percentage threshold of the log template category distribution, it is determined whether each service node has a service exception. For example, if the percentage difference in the log template category distribution of a service node relative to the management node is greater than the percentage threshold of the log template category distribution, it can be determined that the service node has an abnormality, etc., thereby making up for the deficiencies of fixed rules, improving the accuracy of monitoring and alarming, and reducing the business losses caused by failures.

[0032] Figure 2The flowchart of a log service recognition method provided by an embodiment of the present disclosure. This method can be applied to an electronic device including a central processing unit, such as a computer, a mobile phone, a tablet computer, a television, a server, etc., which is not limited herein. As Figure 2 shown, this method is applied to a log management platform. The log management platform includes multiple service nodes corresponding to application programs. The multiple service nodes are respectively connected to the same management node, and mainly includes the following steps S202 to S206:

[0033] Step S202, obtain the service log feature library of each service node; wherein, the service log feature library refers to the distribution information of the log template categories of the service node within the target time period.

[0034] In the embodiment of the present disclosure, the services of the application program are provided by multiple service nodes. That is to say, different service nodes usually share the services of the entire application program on average. Therefore, at the same time, the logs on different service nodes should be similar.

[0035] In the embodiment of the present disclosure, the target time period can be selected according to the actual application scenario, such as one day, two days, etc.

[0036] In the embodiment of the present disclosure, there are many ways to obtain the service log feature library of each service node. As an example, for each service node, during the running of the application program, obtain all the service logs of the service node within the target time period, and cluster all the service logs through a preset clustering algorithm to obtain multiple service log templates and the log template category corresponding to each service log. Determine the distribution information of the log template categories of the multiple service logs as the service log feature library according to the multiple service log templates and the log template category corresponding to each service log.

[0037] As another example, for each service node, during the running of the application program, obtain all the service logs of the service node within the target time period, obtain the service log template corresponding to each service log, and determine the log template category. Merge the service log templates belonging to the same log template category, so as to determine the distribution information of the log template categories of the multiple service logs as the service log feature library according to the merged service log templates and the corresponding log template categories. The above two methods are only examples, and the embodiment of the present disclosure does not specifically limit the method of obtaining the service log feature library of each service node.

[0038] Step S204, obtain the management log feature library of the management node; wherein, the management log feature library refers to the distribution information of the log template categories of all service nodes within the target time period.

[0039] In an embodiment of the present disclosure, the services of the application are provided by multiple service nodes, and the multiple service nodes are connected to the same management node. The management node can obtain the service logs generated by all service nodes.

[0040] In an embodiment of the present disclosure, the target time period can be selected according to the actual application scenario, such as one day, two days, etc.

[0041] In an embodiment of the present disclosure, there are many ways to obtain the management log feature library of the management node. As an example, during the running of the application, the management node obtains all the service logs of each service node within the target time period as management logs, and clusters all the management logs through a preset clustering algorithm, so as to obtain multiple management log templates and the log template categories corresponding to each management log template. The log template category distribution information of the multiple management logs is determined based on the multiple management log templates and the log template categories corresponding to each management log template as the management log feature library.

[0042] As another example, during the running of the application, all the service logs of all service nodes within the target time period are obtained as management logs, the management log template corresponding to each management log is obtained, and the log template category is determined. The management log templates belonging to the same log template category are merged, so as to determine the log template category distribution information of the multiple management logs as the management log feature library based on the merged management log templates and the corresponding log template categories. The above two methods are only examples, and the embodiments of the present disclosure do not specifically limit the method of obtaining the management log feature library of each management node.

[0043] Step S206: Compare the log template category distribution information corresponding to the service log feature library of each service node with the log template category distribution information corresponding to the management log feature library to obtain the percentage difference in the log template category distribution between each service node and the management node.

[0044] Step S208: Determine whether a service exception occurs for each service node based on the percentage difference in the log template category distribution and a preset percentage threshold of the log template category distribution.

[0045] It can be understood that for each service node, the service log feature library of each service node can be constructed through the service logs on each service node within the target time period. That is to say, the number of service nodes is the same as the number of service log feature libraries.

[0046] In the embodiments of the present disclosure, the service log feature library of each service node is compared with the management log feature library respectively. That is to say, the log template category distribution information of each service node is compared with the log template category distribution information of the management node, so as to determine the service recognition result of each service node based on the comparison result. Wherein, the service recognition result can be that the service node is an abnormal service node or a normal service node.

[0047] In the embodiments of the present disclosure, there are many ways to compare the service log feature library of each service node with the management log feature library and determine the service recognition result of each service node based on the comparison result. As an example, the log template category distribution information of each service node is obtained based on the service log feature library of each service node, and the service log template distribution ratio of each service node is determined based on the log template category distribution information of each service node. The log template category distribution information of the management node is obtained based on the management log feature library, and the management log template distribution ratio of the management node is determined based on the log template category distribution information of the management node. The service log template distribution ratio of each service node is compared with the management log template distribution ratio of the management node, and the ratio difference of the same log template is determined as the percentage difference of the log template category distribution between each service node and the management node. Whether each service node has a service exception is determined based on the percentage difference of the log template category distribution and a preset percentage threshold of the log template category distribution. That is, the service node corresponding to the service log template distribution ratio with the ratio difference of the same log template greater than or equal to the preset ratio threshold is marked as an abnormal service node as the service recognition result, and the service node corresponding to the service log template distribution ratio with the ratio difference of the same log template less than the ratio threshold is marked as a normal service node as the service recognition result.

[0048] As another example, the number of each service log template of each service node is obtained based on the service log feature library of each service node, and the number of each management log template of each management node is obtained based on the management log feature library of each management node. The percentage of different log templates is determined. When the percentage of different log templates is greater than the preset percentage threshold, the service node is marked as an abnormal service node as the service recognition result, otherwise it is marked as a normal service node as the service recognition result.

[0049] The above are only examples of comparing the service log feature library of each service node with the management log feature library and determining the service recognition result of each service node based on the comparison result. The present disclosure does not limit the specific implementation manner of comparing the service log feature library of each service node with the management log feature library and determining the service recognition result of each service node based on the comparison result.

[0050] In summary, the log service identification method according to the embodiments of the present disclosure is applied to a log management platform. The log management platform includes multiple service nodes corresponding to application programs, and the multiple service nodes are respectively connected to the same management node. The method includes: obtaining the service log feature library of each service node; wherein, the service log feature library refers to the distribution information of log template categories of the service node within a target time period; obtaining the management log feature library of the management node; wherein, the management log feature library refers to the distribution information of log template categories of all service nodes within the target time period; comparing the distribution information of log template categories corresponding to the service log feature library of each service node with the distribution information of log template categories corresponding to the management log feature library to obtain the percentage difference in the distribution of log template categories between each service node and the management node; determining whether a service exception occurs for each service node based on the percentage difference in the distribution of log template categories and a preset percentage threshold for the distribution of log template categories. Thus, by comparing the log feature library independently trained from the service logs generated on each service node with the total log feature library trained from the logs of all service nodes collected by the management node, it is possible to accurately determine whether there is an exception in the service node, make up for the deficiencies based on fixed rules, improve the accuracy of monitoring and alarm, and reduce the business losses caused by failures.

[0051] In some embodiments, obtaining the service log feature library of each service node includes: obtaining multiple service logs of each service node within a target time period; clustering the multiple service logs based on a preset clustering algorithm to obtain multiple service log templates and the log template category corresponding to each service log; determining the distribution information of log template categories of the multiple service logs as the service log feature library based on the multiple service log templates and the log template category corresponding to each service log.

[0052] In the embodiments of the present disclosure, different clustering algorithms can be preset to cluster all service logs of each service node within a target time period, and multiple service log templates and the log template categories corresponding to each service log can be obtained; as an example, string variables in each service log are obtained based on regular matching, and the string variables in each service log are replaced with preset target identifiers to obtain multiple preprocessed logs. Each preprocessed log is subjected to word segmentation processing to obtain the word segmentation set and the log length corresponding to each preprocessed log, and the log matching words corresponding to each preprocessed log are obtained. The log lengths and log matching words of any two preprocessed logs are compared. When the log lengths between any two preprocessed logs are the same and the log matching words between any two preprocessed logs are the same, the two preprocessed logs are used as two logs to be clustered. The similarity is calculated based on the word segmentation sets corresponding to at least two logs to be clustered. When the similarity is greater than a preset similarity threshold, at least two logs to be clustered are clustered to obtain clustered logs; the logs to be processed for which there are no logs to be clustered are determined based on the matching results, and service log templates are constructed based on the log lengths, log matching words, and word segmentation sets corresponding to the logs to be processed and the clustered logs, and the log template categories corresponding to the service log templates are determined.

[0053] Among them, regular matching means presetting a rule string, then matching each service log with the preset rule string, determining the matching strings in each service log as string variables, and replacing the string variables in each service log with preset target identifiers. That is to say, the string variables are replaced by the target identifiers, and the target identifiers can be selected and set as needed. For example, "*" etc. can be used as the target identifier.

[0054] Specifically, after replacing the string variables in each service log with preset target identifiers to obtain multiple preprocessed logs, that is, the preprocessed logs are the logs with variables replaced by target identifiers; then each preprocessed log is subjected to word segmentation processing through a word segmentation tool or algorithm, so that multiple word segments corresponding to each preprocessed log can be obtained as the word segmentation set, and the number of word segments of the multiple word segments is counted as the log length; in addition, the prefix words of each preprocessed log are obtained as the log matching words corresponding to each preprocessed log.

[0055] Further, for all preprocessed logs, any preprocessed log is matched with other preprocessed logs. First, the log matching words of the preprocessed log are matched. If there are the same log matching words, then the log lengths of the preprocessed logs are further matched. If the log lengths are the same, these preprocessed logs are determined as the logs to be clustered. Further, the similarity of the word segmentation sets corresponding to the logs to be clustered is calculated, and all clustered logs with a similarity greater than the preset similarity threshold are clustered to obtain the clustered logs; the similarity threshold can be set according to actual application needs, that is, all logs to be clustered are merged to obtain a clustered log.

[0056] It can also be understood that there are unmatched preprocessed logs among all preprocessed logs, that is, preprocessed logs with no same log matching words, or preprocessed logs with the same matching words but different log lengths, or preprocessed logs with the same matching words, the same log lengths but a similarity less than the similarity threshold. The logs to be processed without logs to be clustered, and service log templates are constructed based on the log lengths, log matching words, and word segmentation sets corresponding to the logs to be processed and the clustered logs, and the log template categories corresponding to the service log templates are determined, that is, the service log templates corresponding to the logs to be processed and the clustered logs are determined, and all service log templates are obtained; among them, the lengths of each template in the service log template can be determined based on the log length, and the service log template includes information such as time, log level, program method, log source, and specific content, which can be determined through the log matching words and the word segmentation set; among them, the service log template has a corresponding log template category, and the log template category corresponding to the service log can be determined by judging which service log template the service log belongs to, and finally the distribution information of the log template categories of multiple service logs is obtained as the service log feature library.

[0057] As another example, at least two service logs whose string lengths of the maximum common substrings obtained from multiple service logs are greater than or equal to the preset length threshold are merged to obtain a merged log; among them, the length threshold is determined based on the log lengths of at least two service logs; the non-common substrings in the merged log are updated to target identifiers to obtain an updated log; a service log template is constructed based on the service logs with string lengths less than the length threshold and the updated log, and the log template category corresponding to the service log template is determined.

[0058] Specifically, compare multiple service logs generated during the operation of the application in the target time period, obtain the longest common substring between the service logs, calculate the string length of the longest common substring, and merge at least two service logs whose string length of the longest common substring is greater than or equal to the length threshold. That is, merge all the strings corresponding to at least two service logs and only keep one copy of the same string to obtain the merged log. Among them, to improve the merging effect, determine the length threshold based on the log lengths of at least two service logs, such as 0.5 to 1 times the log length corresponding to any one of the at least two service logs, or directly use the longest log length among the at least two service logs as the length threshold.

[0059] It can be understood that the string of the longest common string being greater than or equal to the length threshold indicates that the corresponding two or more service logs are similar logs and can share a log template. Therefore, the merged log can be analyzed to obtain one or more log strings that form the log template of the merged log. In addition, there may be service logs that are not merged among the multiple service logs, that is, the service log has no similar logs and needs to be analyzed separately to determine one or more log strings as the log template of the service log and determine the log template category corresponding to the service log template.

[0060] In the above solution, multiple service logs of the application can be analyzed to flexibly construct the log feature library corresponding to the application. By comparing the log feature library independently trained from the service logs generated on each service node with the total log feature library collected by the management node from all service node logs, it can be accurately determined whether there is an abnormality in the service node, improving the efficiency and effect of service anomaly recognition.

[0061] In some embodiments, obtaining the management log feature library of the management node includes: obtaining multiple management logs of all service nodes in the target time period, clustering the multiple management logs based on a preset clustering algorithm to obtain multiple management log templates and the log template category corresponding to each management log template, and determining the log template category distribution information of the multiple management logs as the management log feature library based on the multiple management log templates and the log template category corresponding to each management log template.

[0062] In the embodiments of the present disclosure, different clustering algorithms can be preset to perform clustering processing on all service logs of the management node within a target time period, and multiple management log templates and the log template categories corresponding to each management log can be obtained; as an example, string variables in each management log are obtained based on regular matching, and the string variables in each management log are replaced with preset target identifiers to obtain multiple preprocessed logs. Word segmentation processing is performed on each preprocessed log to obtain the word segmentation set and log length corresponding to each preprocessed log, and the log matching words corresponding to each preprocessed log are obtained. Based on the log length and log matching words, the preprocessed logs are matched. When determining at least two logs to be clustered based on the matching result, similarity calculation is performed based on the word segmentation sets corresponding to the at least two logs to be clustered. When the similarity is greater than a preset similarity threshold, the at least two logs to be clustered are clustered to obtain clustered logs; the logs to be processed for which there are no logs to be clustered are determined based on the matching result, and management log templates are constructed based on the log lengths, log matching words, and word segmentation sets corresponding to the logs to be processed and the clustered logs, and the log template categories corresponding to the management log templates are determined.

[0063] As another example, at least two management logs for which the string length of the maximum common substring obtained from multiple management logs is greater than or equal to a preset length threshold are merged to obtain a merged log; wherein, the length threshold is determined based on the log lengths of the at least two management logs; the non-common substrings in the merged log are updated to target identifiers to obtain an updated log; management log templates are constructed based on the management logs with string lengths less than the length threshold and the updated log, and the log template categories corresponding to the management log templates are determined.

[0064] In the above solution, all service logs of all service nodes can be analyzed as management logs to flexibly construct a log feature library corresponding to the application program. By comparing the log feature library independently trained from the service logs generated on each service node with the total log feature library trained from all service node logs collected by the management node, it can be accurately determined whether there is an abnormality in the service node, improving the efficiency and effect of service anomaly recognition.

[0065] In some embodiments, the service log feature library of each service node is compared with the management log feature library, and the service recognition result of each service node is determined based on the comparison result, including: obtaining the log template category distribution information of each service node based on the service log feature library of each service node, and determining the service log template distribution ratio of each service node based on the log template category distribution information of each service node; obtaining the log template category distribution information of the management node based on the management log feature library, and determining the management log template distribution ratio of the management node based on the log template category distribution information of the management node; comparing each service log template distribution ratio with the management log template distribution ratio, and determining the ratio difference of the same log template as the percentage difference of the log template category distribution between each service node and the management node; marking the service node corresponding to the service log template distribution ratio with the ratio difference of the same log template greater than or equal to the preset ratio threshold as an abnormal service node as the service recognition result.

[0066] In the embodiments of the present disclosure, the services of the application program are provided by multiple service nodes. Different service nodes usually share the services of the entire application program on average. Therefore, within the same target time period, the logs on different service nodes should be similar. Therefore, the log feature libraries on each service node and the log feature library on the management node are the same or not very different.

[0067] Specifically, the log template category distribution information of each service node is obtained according to the service log feature library of each service node. That is to say, all service log templates included in each service node can be obtained, as well as the log template category distribution corresponding to each service log template. For example, the log template categories corresponding to the service log templates of a service node include A, B, C, and D. There are a total of 10 logs within the preset time period. The log template category distribution information of each service node counted is, for example, AABBBCCCDD. Thus, the service log template distribution ratio of each service node can be determined according to the log template category distribution information. For example, the distribution ratio of log template A is 0.2, and for another example, the distribution ratio of log template B is 0.3, etc.

[0068] Specifically, obtain the distribution information of the log template categories of the management node according to the management log feature library of the management node. That is to say, all management log templates in the management node can be obtained, as well as the distribution of log template categories corresponding to each management log template. For example, the log template categories corresponding to the management log template of a management node include A, B, C, and D. The management node is connected to two service nodes. There are a total of 20 logs from the two service nodes within a preset time period. The obtained distribution information of the log template categories of the management node is, for example, AABBAABBBBCCCCCCDDDD. Thus, the distribution ratio of the service log templates of the management node can be determined according to the distribution information of the log template categories. For example, the distribution ratio of log template A is 0.2, and for another example, the distribution ratio of log template B is 0.3, etc. If the difference in the ratio of the same log template of each service node described above is 0, it is determined as a normal service node.

[0069] For another example, the obtained distribution information of the log template categories of the management node is, for example, AABBBBBBBBCCCCCCDDDD. Thus, the distribution ratio of the service log templates of the management node can be determined according to the distribution information of the log template categories. For example, the distribution ratio of log template A is 0.1, and for another example, the distribution ratio of log template B is 0.4, etc. If the difference in the ratio of the same log template of each service node described above is 0.1, and for example, the ratio threshold is 0.05, the service node corresponding to the distribution ratio of the service log template where the difference in the ratio of the same log template is greater than or equal to the preset ratio threshold is marked as an abnormal service node as the service recognition result.

[0070] Among them, the ratio threshold can be flexibly set according to actual application needs.

[0071] In the above solution, determine whether service anomalies occur in each service node by comparing the distribution ratio of service log templates and the distribution ratio of management log templates, thereby improving the accuracy of comparing the log feature library and ultimately improving the accuracy of service anomaly recognition.

[0072] In some embodiments, the method further includes: obtaining the usage information of the application program; obtaining the update logs of each service node based on the usage information; and updating the service log feature library and the management log feature library with the obtained update logs.

[0073] In the embodiments of the present disclosure, the usage information includes information such as the usage time and usage location of the application program, so as to determine that the number of generated logs is relatively large. Therefore, re-obtain the update logs of the application program, that is, the newly generated logs are used to construct a new log feature library in the foregoing manner, and the log templates in the log feature library can also be updated, such as adding or deleting, in the foregoing manner.

[0074] Therefore, the log feature library can be updated in a timely manner based on the specific usage information of the application, further ensuring the accuracy of the log feature library comparison and improving the service anomaly recognition effect.

[0075] Figure 3 FIG. is a schematic flowchart of a log service recognition method provided by an embodiment of the present disclosure. The method mainly includes the following steps S302 to step S314:

[0076] Step S302, obtain multiple service logs of each service node within a target time period, and cluster the multiple service logs based on a preset clustering algorithm to obtain multiple service log templates and the log template category corresponding to each service log.

[0077] Step S304, determine the log template category distribution information of the multiple service logs as the service log feature library based on the multiple service log templates and the log template category corresponding to each service log.

[0078] Step S306, obtain multiple management logs of all service nodes within a target time period, and cluster the multiple management logs based on a preset clustering algorithm to obtain multiple management log templates and the log template category corresponding to each management log template.

[0079] Step S308, determine the log template category distribution information of the multiple management logs as the management log feature library based on the multiple management log templates and the log template category corresponding to each management log template.

[0080] Step S310, obtain the log template category distribution information of each service node based on the service log feature library of each service node, and determine the service log template distribution ratio of each service node based on the log template category distribution information of each service node.

[0081] Step S312, obtain the log template category distribution information of the management node based on the management log feature library, and determine the management log template distribution ratio of the management node based on the log template category distribution information of the management node.

[0082] Step S314, compare the service log template distribution ratio and the management log template distribution ratio of each service log, determine the ratio difference of the same log template, and mark the service node corresponding to the service log template distribution ratio with the ratio difference of the same log template greater than or equal to a preset ratio threshold as an abnormal service node.

[0083] Exemplarily, as Figure 4 shown, the service node, that is, each machine ( Figure 4The log collection modules on the shown Machines 1, 2, and 3 transmit the local logs within a certain time period to the local log feature library construction module, which independently constructs a local log feature library (such as the client log feature library shown in Figure 4 ) based on a preset clustering algorithm, and continuously updates the local log feature library based on newly generated logs; the management node, which can also be understood as the background server, trains a log feature library for business logs based on the logs collected from all machines (such as the server log feature library shown in Figure 4 ); the log analysis and monitoring and alarm module compares the client log feature library and the server log feature library. If a certain client log feature library deviates too much from the server log feature library, that is, the percentage difference in the log template category distribution of the service node relative to the management node is greater than the log template category distribution percentage threshold, it means that there may be a problem with the service of this node, and an alarm can be issued or intelligent and automated processing can be performed.

[0084] In summary, for the log service identification method provided in the embodiments of the present disclosure, a log feature library is independently trained from the service logs generated on each service node, and a total log feature library is trained from the logs of all service nodes collected by the management node; the log feature library independently trained from the service logs generated on each service node can accurately reflect the different characteristics of each service node, thereby improving the accuracy of subsequent anomaly judgment, and comparing the log feature library independently trained from the service logs generated on each service node with the total log feature library trained from the logs of all service nodes collected by the management node can accurately determine whether there is an anomaly in the service node, which can make up for the deficiencies based on fixed rules, improve the accuracy of monitoring and alarm, and reduce the business losses caused by failures.

[0085] Corresponding to the foregoing log service identification method, the embodiments of the present disclosure further provide a log service identification device. Figure 5 As shown in the structural schematic diagram of a log service identification device provided in the embodiments of the present disclosure, the device can be implemented by software and / or hardware. The device is applied to a log management platform, and the log management platform includes a plurality of service nodes corresponding to application programs. The plurality of service nodes are respectively connected to the same management node, and includes:

[0086] A first acquisition module 502, configured to acquire the service log feature library of each of the service nodes; wherein, the service log feature library refers to the log template category distribution information of the service node within a target time period;

[0087] A second acquisition module 504, configured to acquire the management log feature library of the management node; wherein, the management log feature library refers to the log template category distribution information of all the service nodes within the target time period;

[0088] A comparison module 506 is configured to compare the log template category distribution information corresponding to the service log feature library of each of the service nodes with the log template category distribution information corresponding to the management log feature library, so as to obtain the percentage difference in the log template category distribution between each of the service nodes and the management node.

[0089] A determination module 508 is configured to determine whether a service exception occurs for each of the service nodes based on the percentage difference in the log template category distribution and a preset percentage threshold for the log template category distribution.

[0090] In the above device provided by the embodiments of the present disclosure, a log feature library is independently trained from the service logs generated on each service node, and a total log feature library is trained from all the service node logs collected by the management node; the log feature library independently trained from the service logs generated on each service node can accurately reflect the different log features of each service node, thereby improving the accuracy of subsequent anomaly judgment, and comparing the log feature library independently trained from the service logs generated on each service node with the total log feature library trained from all the service node logs collected by the management node can accurately determine whether there is an anomaly in the service node, which can make up for the deficiencies based on fixed rules, improve the accuracy of monitoring and alarm, and reduce the business losses caused by failures.

[0091] In some embodiments, the first acquisition module 502 includes: an acquisition unit configured to acquire a plurality of service logs of each of the service nodes within the target time period; a clustering unit configured to cluster the plurality of service logs based on a preset clustering algorithm to obtain a plurality of service log templates and the log template category corresponding to each of the service logs; and a determination unit configured to determine the log template category distribution information of the plurality of service logs as the service log feature library based on the plurality of service log templates and the log template category corresponding to each of the service logs.

[0092] In some embodiments, the clustering unit is specifically configured to: obtain variables in each service log based on regular matching, and replace string variables in each service log with a preset target identifier to obtain a plurality of preprocessed logs; perform word segmentation on each of the preprocessed logs to obtain a word segmentation set and a log length corresponding to each of the preprocessed logs, and obtain a log matching word corresponding to each of the preprocessed logs; compare the log lengths and the log matching words of any two of the preprocessed logs, and when the log lengths between any two of the preprocessed logs are the same and the log matching words between any two of the preprocessed logs are the same, use any two of the preprocessed logs as two logs to be clustered; calculate a similarity based on at least the word segmentation sets corresponding to the two logs to be clustered, and when the similarity is greater than a preset similarity threshold, perform clustering processing on at least the two logs to be clustered to obtain clustered logs; determine a log to be processed for which there are no logs to be clustered based on the matching result, construct the service log template based on the log length, log matching word, and word segmentation set corresponding to the log to be processed and the clustered logs, and determine the log template category corresponding to the service log template.

[0093] In some embodiments, the clustering unit is specifically configured to: merge at least two service logs obtained from the plurality of service logs, where the string length of the maximum common substring is greater than or equal to a preset length threshold, to obtain a merged log; where the length threshold is determined based on the log lengths of the at least two service logs; update non-common substrings in the merged log to the target identifier to obtain an updated log; construct the service log template based on the service logs with a string length less than the length threshold and the updated log, and determine the log template category corresponding to the service log template.

[0094] In some embodiments, the second obtaining module 504 is specifically configured to: obtain a plurality of management logs of all the service nodes within the target time period; perform clustering on the plurality of management logs based on a preset clustering algorithm to obtain a plurality of management log templates and the log template category corresponding to each of the management log templates; determine the log template category distribution information of the plurality of management logs as the management log feature library based on the plurality of management log templates and the log template category corresponding to each of the management log templates.

[0095] In some embodiments, the comparison module 506 is specifically configured to: obtain the log template category distribution information of each service node based on the service log feature library of each service node, and determine the service log template distribution ratio of each service node based on the log template category distribution information of each service node; obtain the log template category distribution information of the management node based on the management log feature library, and determine the management log template distribution ratio of the management node based on the log template category distribution information of the management node; compare each service log template distribution ratio with the management log template distribution ratio, and determine the ratio difference of the same log template as the log template category distribution percentage difference; correspondingly, the determination module 508 is specifically configured to: mark the service node corresponding to the service log template distribution ratio with the ratio difference of the same log template being greater than or equal to a preset ratio threshold as an abnormal service node.

[0096] In some embodiments, the apparatus further includes: a third acquisition module, configured to acquire usage information of the application program; a fourth acquisition module, configured to acquire an update log of each service node based on the usage information; an update module, configured to update the service log feature library and the management log feature library by acquiring the update log.

[0097] The log service recognition apparatus provided by the embodiments of the present disclosure can execute the log service recognition method provided by any embodiment of the present disclosure, and has corresponding functional modules and beneficial effects for executing the method.

[0098] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process of the apparatus embodiments described above can refer to the corresponding process in the method embodiments, and will not be described in detail here.

[0099] The embodiments of the present disclosure provide an electronic device, which includes: a storage device on which a computer program is stored; a processing device, configured to execute the computer program in the storage device to implement the steps of any method in the present disclosure.

[0100] Next, refer to Figure 6 , which shows a schematic structural diagram of an electronic device 600 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0101] As shown Figure 6 in FIG. 4, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0102] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 6 FIG. 4 shows the electronic device 600 having various devices, it should be understood that it is not required to implement or include all the shown devices. Instead, more or fewer devices may be implemented or included.

[0103] Specifically, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above functions defined in the method of the embodiment of the present disclosure are executed.

[0104] In addition to the above methods and devices, embodiments of the present disclosure may also be computer program products, which include computer program instructions that, when run on a processor, cause the processor to execute the image processing methods provided by the embodiments of the present disclosure. The computer program products may be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present disclosure. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0105] In addition, embodiments of the present disclosure may also be computer-readable storage media, on which computer program instructions are stored, and when the computer program instructions are run on a processor, the processor is caused to execute the log collection method provided by the embodiments of the present disclosure.

[0106] The computer-readable storage media may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, include but not be limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0107] Embodiments of the present disclosure also provide a computer program product, including a computer program / instructions, which when executed by a processor implement the log collection method in the embodiments of the present disclosure.

[0108] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the users and the users' authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0109] For example, when responding to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the present disclosure's technical solution based on the prompt message.

[0110] As an optional but non-limiting implementation manner, when responding to receiving an active request from a user, the manner of sending a prompt message to the user can be, for example, in the form of a pop-up window. The prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0111] It can be understood that the above process of notifying and obtaining user authorization is only illustrative and does not limit the implementation manner of the present disclosure. Other manners that comply with relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0112] It should be noted that in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0113] The above are only specific implementation manners of the present disclosure, enabling those skilled in the art to understand or implement the present disclosure. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to these embodiments described herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. A log service identification method, characterized in that: The method is applied to a log management platform, the log management platform includes a plurality of service nodes corresponding to an application program, the plurality of service nodes are respectively connected to the same management node, and includes: Obtaining a service log feature library of each of the service nodes; wherein the service log feature library refers to log template category distribution information of the service nodes within a target time period; Acquire a management log feature library of the management node; wherein the management log feature library refers to log template category distribution information of all the service nodes within the target time period; Compare the log template category distribution information corresponding to the service log feature library of each of the service nodes with the log template category distribution information corresponding to the management log feature library to obtain the log template category distribution percentage difference between each of the service nodes and the management node; Whether a service abnormality occurs in each of the service nodes is determined based on the log template category distribution percentage difference and a preset log template category distribution percentage threshold.

2. The method according to claim 1, characterized in that The obtaining of the service log feature library of each service node includes: Obtaining multiple service logs of each of the service nodes within the target time period; Clustering the multiple service logs based on a preset clustering algorithm to obtain multiple service log templates and a log template category corresponding to each of the service logs; Based on the multiple service log templates and the log template category corresponding to each of the service logs, log template category distribution information of the multiple service logs is determined as the service log feature library.

3. The method according to claim 2, characterized in that The clustering of the plurality of service logs based on a preset clustering algorithm to obtain a plurality of service log templates and a log template category corresponding to each of the service logs includes: Obtaining a string variable in each service log based on regular matching, and replacing the string variable in each service log with a preset target identifier to obtain multiple pre-processed logs; Perform word segmentation processing on each of the preprocessed logs, obtain a word segmentation set and a log length corresponding to each of the preprocessed logs, and obtain a log matching word corresponding to each of the preprocessed logs; Comparing the log lengths and the log matching words of any two of the pre-processed logs, and taking any two of the pre-processed logs as two logs to be clustered when the log lengths of any two of the pre-processed logs are the same and the log matching words of any two of the pre-processed logs are the same; Performing similarity calculation based on the word segmentation sets corresponding to at least the two logs to be clustered, and when the similarity is greater than a preset similarity threshold, clustering the at least two logs to be clustered to obtain clustered logs; Obtain a log to be processed for which no log to be clustered exists, construct the service log template based on the log length, log matching words and word segmentation set corresponding to the log to be processed and the clustering log, and determine the log template category corresponding to the service log template.

4. The method according to claim 2, characterized in that: The clustering of the plurality of service logs based on a preset clustering algorithm to obtain a plurality of service log templates and a log template category corresponding to each of the service logs includes: At least two service logs corresponding to the maximum common substring whose string length is greater than or equal to a preset length threshold are obtained from the multiple service logs and merged to obtain a merged log; wherein the length threshold is determined based on the log length of the at least two service logs; Updating the non-common substring in the merge log to the target identifier to obtain an update log; The service log template is constructed based on the service log whose character string length is less than the length threshold and the update log, and a log template category corresponding to the service log template is determined.

5. The method according to claim 1, characterized in that The obtaining of the management log feature library of the management node includes: Obtaining multiple management logs of all the service nodes within the target time period; Clustering the multiple management logs based on a preset clustering algorithm to obtain multiple management log templates and a log template category corresponding to each of the management log templates; Based on the multiple management log templates and the log template category corresponding to each of the management log templates, log template category distribution information of the multiple management logs is determined as the management log feature library.

6. The method according to claim 1, characterized in that The log template category distribution information corresponding to the service log feature library of each of the service nodes is compared with the log template category distribution information corresponding to the management log feature library to obtain the log template category distribution percentage difference between each of the service nodes and the management node, including: Determine the service log template distribution ratio of each service node based on the log template category distribution information of each service node; Determining a management log template distribution ratio of the management node based on the log template category distribution information of the management node; Comparing the distribution ratio of each of the service log templates with the distribution ratio of the management log template, and determining the ratio difference of the same log template as the log template category distribution percentage difference; Correspondingly, determining whether a service abnormality occurs in each of the service nodes based on the log template category distribution percentage difference and a preset log template category distribution percentage threshold includes: The service nodes corresponding to the service log template distribution ratios whose ratio difference of the same log template is greater than or equal to a preset ratio threshold are marked as abnormal service nodes.

7. The method according to claim 1, characterized in that The method further comprises: Obtaining usage information of the application; Obtaining an update log of each of the service nodes based on the usage information; The update log is obtained to update the service log feature library and the management log feature library.

8. A log service identification device, characterized in that: The device is applied to a log management platform, the log management platform includes a plurality of service nodes corresponding to the application program, the plurality of service nodes are respectively connected to the same management node, and includes: A first acquisition module is used to acquire a service log feature library of each of the service nodes; wherein the service log feature library refers to log template category distribution information of the service node within a target time period; A second acquisition module is used to acquire a management log feature library of the management node; wherein the management log feature library refers to log template category distribution information of all the service nodes within the target time period; A comparison module, used to compare the log template category distribution information corresponding to the service log feature library of each of the service nodes with the log template category distribution information corresponding to the management log feature library, to obtain the log template category distribution percentage difference between each of the service nodes and the management node; The determination module is used to determine whether a service abnormality occurs in each of the service nodes based on the log template category distribution percentage difference and a preset log template category distribution percentage threshold.

9. An electronic device, characterized in that: The electronic device comprises: a storage device having a computer program stored thereon; A processing device, used to execute the computer program in the storage device to implement the steps of the log service identification method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and the computer program is used to execute the log service identification method described in any one of claims 1 to 7.