Quick searching and accurate positioning system based on BOSS system log chain
By building a fast search and precise positioning system for log chains in the BOSS system, the problem of difficult to intuitively display dependencies in complex environments and lack of clear mapping of fault conduction paths is solved, and the dynamic adaptability of system dependencies and the accuracy and reliability of fault diagnosis are achieved.
Patent Information
- Application Number
- CN202510172867.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-06
AI Technical Summary
In the complex BOSS system environment, cross-system dependencies are difficult to be intuitively displayed, and the fault conduction path lacks clear mapping, resulting in the challenge of rapid fault diagnosis. The prior art relies on fixed rules and is difficult to adapt to system architecture changes. In a multi-subsystem environment, log format and timing deviations lead to analysis errors, reducing the accuracy of fault location.
Provide a fast search and precise positioning system based on the BOSS system log chain, including a log acquisition module, a dependency construction module, a fault resolution module and a graph maintenance module. The original log data is obtained and sorted through the log acquisition module. The dependency building module builds a cross-system dependency map. The fault analysis module uses the graph to resolve the fault conduction path, and dynamically updates the dependency map through the graph maintenance module to support precise positioning.
This system effectively improves the dynamic adaptability of system dependencies, ensures that the dependencies accurately reflect the current status when the system structure changes, clearly map the fault transmission paths between systems, overcome the analysis errors of traditional methods, improve the accuracy and reliability of fault diagnosis, significantly shorten the fault location time, and improve the system operation and maintenance efficiency.
Smart Images

Figure CN120104573A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of enterprise information management, and in particular to a fast search and precise positioning system based on a BOSS system log chain. Background Art
[0002] In modern enterprise information management, BOSS (Business & Operation Support System) plays a key supporting role and is widely used in communications, finance, electricity and other industries. BOSS systems are usually composed of multiple heterogeneous subsystems. There are complex dependencies between each subsystem, and various business and operation events are recorded through log chains. In order to achieve efficient system operation and maintenance and fault handling, the analysis and utilization of log chains become key links. However, in complex environments, cross-system dependencies are difficult to display intuitively, and fault transmission paths often lack clear mapping, which poses a challenge to rapid fault diagnosis.
[0003] In the prior art, a common method is to analyze the log chain based on log keyword matching or time association to identify the fault transmission relationship between systems. However, this method relies on fixed rules and is difficult to adapt to the ever-changing system architecture. When multiple subsystems are involved, factors such as log format and timing deviation will lead to analysis errors, thereby reducing the accuracy of fault location. Another solution is to use knowledge graph technology to build each system component and its dependencies into a visual model to assist in fault analysis. However, the maintenance of existing knowledge graphs usually relies on manual updates or regular batch updates, which makes it difficult to reflect the dynamic changes of the system in real time and affects the accurate identification of fault transmission paths. In addition, in the face of large-scale log data, existing methods still have significant limitations in retrieval efficiency, data consistency management, and reasoning about the scope of fault impact. Summary of the invention
[0004] The purpose of the present invention is to provide a fast search and precise positioning system based on the BOSS system log chain to solve the problems existing in the prior art.
[0005] To achieve the above object, the present invention provides the following technical solution: a fast search and precise positioning system based on the BOSS system log chain, the system comprising:
[0006] The log acquisition module is used to obtain the original log data generated by cross-system calls and preliminarily sort the logs according to timestamps;
[0007] The dependency building module connected to the log acquisition module is used to build a cross-system dependency graph based on the logs after preliminary sorting. The dependency building module builds a call relationship graph between systems by calculating the call frequency ratio. The specific calculation formula is:
[0008] Among them, R ij represents the call frequency ratio of system i to system j, C ij represents the number of times system i calls system j, C i Indicates the total number of calls to system i, i represents the number of the initiating system of the call, and j represents the number of the target system of the call;
[0009] The fault analysis module connected to the dependency building module is used to analyze the fault conduction path using the dependency graph and generate a link tracking identifier. The fault analysis module uses the fault propagation probability to predict the possibility of system failure. The specific formula is: P ij =R ij ·A j ;
[0010] Among them, P ij A represents the probability that a failure in system i may propagate to system j. j represents the state value of system j, R ij It represents the call frequency ratio of system i calling system j, where i represents the number of the initiating system and j represents the number of the target system.
[0011] The graph maintenance module connected to the dependency building module and the fault analysis module is used to maintain and update the dependency graph according to the link tracking identifier to achieve accurate positioning in a complex environment.
[0012] Preferably, the log acquisition module includes:
[0013] A log parsing unit, used to extract system call information from raw log data;
[0014] The timestamp sorting unit is used to sort log data according to timestamps, satisfying the following requirements:
[0015] T 1 ≤T 2 ≤...≤T n ;
[0016] Among them, T 1 ,…,T n represents the timestamp of the log, and n represents the total number of log entries.
[0017] Preferably, the graph maintenance module dynamically adjusts the dependency relationship according to the fault propagation path identifier, and the update rule is as follows:ij =ΔP ij β;
[0018] Among them, L ij Indicates the path identification change value of system i calling system j, ΔP ij represents the change in the probability of fault propagation, β represents the dynamic adjustment coefficient, i represents the number of the initiating system of the call, and j represents the number of the target system of the call.
[0019] Preferably, the log acquisition module further includes:
[0020] The log filtering unit is used to remove irrelevant or redundant log data. By setting the log priority threshold, only the log data with a priority higher than the threshold is retained, which meets the following conditions: k >P th ;
[0021] Among them, P k represents the priority of log entry k, P th Indicates the log priority threshold.
[0022] Preferably, the log acquisition module filters the log data by calculating the correlation coefficient of the log entries, and the filtering condition is:
[0023] When R is greater than the preset threshold R th If yes, keep the log entry, otherwise remove it;
[0024] Where R represents the correlation coefficient of log entries, N c Indicates the number of key field matches in the log entry, N t Indicates the total number of fields in the log entry.
[0025] Preferably, the dependency building module establishes a call path according to the system call weight, and the specific calculation formula is: W=F / T;
[0026] Among them, W represents the weight of the call path, F represents the frequency of the call, and T represents the total number of calls.
[0027] Preferably, the fault analysis module analyzes the fault path based on the fault propagation probability, and the specific calculation formula is: P = W × A;
[0028] Among them, P represents the probability of fault propagation, W represents the weight of the call path, and A represents the state value of the target system.
[0029] Preferably, the graph maintenance module dynamically adjusts the dependency graph based on the path call failure rate, and the adjustment rule is: W′=W·(1+F r );
[0030] Where W′ represents the adjusted path weight, W represents the weight of the call path, and F r Indicates the path call failure rate.
[0031] Preferably, the graph maintenance module determines the path to be maintained first according to the path importance coefficient, and the specific calculation formula is: K=W×S;
[0032] Among them, K represents the importance coefficient of the path, W represents the weight of the call path, and S represents the success rate of the path call.
[0033] Preferably, the log acquisition module further includes an abnormal log detection unit, which is used to identify abnormal behavior of the acquired original log data and mark the abnormal log as a priority processing object.
[0034] It can be seen from the above technical solution that the present invention has the following beneficial effects:
[0035] This fast search and precise positioning system based on the BOSS system log chain obtains the original log data generated by cross-system calls through the log acquisition module, and preliminarily sorts the logs according to timestamps. The dependency construction module constructs a cross-system dependency graph based on the preliminarily sorted logs. The fault analysis module uses the dependency graph to analyze the fault conduction path and generates a link tracking identifier. The graph maintenance module maintains and updates the dependency graph according to the link tracking identifier to achieve precise positioning in complex environments, effectively improving the dynamic adaptability of system dependencies, ensuring that when the system structure changes, the dependencies can still accurately reflect the current state, and can clearly map the fault conduction path between systems, overcoming the transmission problem. It eliminates the analysis errors of traditional keyword matching and time association methods in complex environments, improves the accuracy and reliability of fault diagnosis, reduces the need for manual intervention, and significantly shortens the fault location time, thereby improving the system operation and maintenance efficiency. It can effectively handle the complexity problems caused by different log formats, timing deviations, and dynamic dependency changes. It has strong adaptability and high practicality, and has significantly improved log retrieval, data consistency management, and fault reasoning efficiency. It can quickly process large-scale log data and conduct effective analysis to ensure efficient operation in complex system environments. It overcomes the limitations of manual updates of traditional knowledge graphs, significantly improves the ability to respond to dynamic changes in the system, and provides strong technical support for accurate fault analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 This is a connection diagram of the system modules of the present invention. DETAILED DESCRIPTION
[0037] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0038] like Figure 1 As shown, the present invention provides a technical solution: a fast search and precise positioning system based on the BOSS system log chain, the system comprising:
[0039] The log acquisition module is used to obtain the original log data generated by cross-system calls and preliminarily sort the logs according to timestamps;
[0040] The dependency building module connected to the log acquisition module is used to build a cross-system dependency graph based on the logs after preliminary sorting. The dependency building module builds a call relationship graph between systems by calculating the call frequency ratio. The specific calculation formula is:
[0041] Among them, R ij represents the call frequency ratio of system i to system j, C ij represents the number of times system i calls system j, C i Indicates the total number of calls to system i, i represents the number of the initiating system of the call, and j represents the number of the target system of the call;
[0042] The fault analysis module connected to the dependency building module is used to analyze the fault conduction path using the dependency graph and generate a link tracking identifier. The fault analysis module uses the fault propagation probability to predict the possibility of system failure. The specific formula is: P ij =R ij ·A j ;
[0043] Among them, P ij A represents the probability that a failure in system i may propagate to system j. j represents the state value of system j, R ij It represents the call frequency ratio of system i calling system j, where i represents the number of the initiating system and j represents the number of the target system.
[0044] The graph maintenance module connected to the dependency building module and the fault analysis module is used to maintain and update the dependency graph according to the link tracking identifier to achieve accurate positioning in a complex environment.
[0045] Based on the time sequence processing of cross-system call logs, the system collects and sorts the scattered original log data through the log acquisition module to ensure the time sequence integrity of the data. The dependency construction module uses the calculation method of the call frequency ratio to automatically generate the dependency graph between systems, so as to clearly show the interaction structure and degree of dependence between the systems. The fault analysis module uses the probability model to accurately predict the fault transmission path by combining the call frequency and the system state value, and quickly identify the key nodes or links that may cause system abnormalities. Finally, the graph maintenance module dynamically updates the dependency graph according to the real-time link tracking identifier to ensure that the graph is consistent with the actual operating state, further improving the positioning accuracy and response speed. Through modular design and optimization of the closed loop of the process, the system realizes the automation of the whole process from log collection to fault location, greatly reducing the need for manual intervention. Compared with the traditional method, the present invention significantly improves the efficiency and accuracy of fault diagnosis. First, by constructing a dynamic dependency graph, the call relationship between complex systems can be intuitively displayed, simplifying the problem troubleshooting process. Secondly, by using the quantitative analysis of the call frequency ratio and the probability of fault propagation, the system can prioritize the key problem points and reduce the analysis complexity caused by the huge amount of information. In addition, the collaborative work between modules ensures that the system has a high degree of real-time and adaptability, can quickly handle changing operating environments, and reduce system downtime caused by failures. Finally, the scalability of the system allows flexible adjustments for different application scenarios, providing enterprises and users with efficient and reliable solutions, and has important value in improving operational stability and reducing operation and maintenance costs.
[0046] The log acquisition module includes: a log parsing unit for extracting system call information from the original log data; a timestamp sorting unit for sorting the log data according to the timestamp to meet the following requirements:
[0047] T 1 ≤T 2 ≤…≤T n ;
[0048] Among them, T 1 , …, T n represents the timestamp of the log, and n represents the total number of log entries.
[0049] The log parsing unit identifies and extracts key information related to cross-system calls, such as the caller, the callee, and the call time, by analyzing the original log data, laying the foundation for subsequent operations. The timestamp sorting unit uses the timestamp information to arrange the parsed log data in chronological order to ensure the integrity and consistency of the data sequence. In practical applications, the functions of this module can be implemented by an efficient sorting algorithm (such as quick sort or merge sort), thereby ensuring the rapid processing capability of massive log data. The sorting result provides accurate data support for subsequent dependency construction and fault propagation path analysis. The log acquisition module in the present invention can effectively extract key information from the original log data, and sort it in chronological order, providing high-quality input data for subsequent analysis processes. By means of timestamp sorting, not only can the temporal logical consistency of the data be ensured, but also the accuracy and efficiency of fault analysis can be improved. In addition, the module has high-performance characteristics for the processing of log data, can cope with the parsing and sorting requirements of massive log data in large-scale systems, and provides a reliable basis for fault location of complex systems.
[0050] The graph maintenance module dynamically adjusts the dependency relationship according to the fault propagation path identifier. The update rules are as follows: ij =ΔP ij β;
[0051] Among them, L ij Indicates the path identification change value of system i calling system j, ΔP ij represents the change in the probability of fault propagation, β represents the dynamic adjustment coefficient, i represents the number of the initiating system of the call, and j represents the number of the target system of the call.
[0052] The graph maintenance module monitors the changes of fault propagation path identifiers in real time and calculates the adjustment amount of the path identifier using the update rule. When the fault propagation probability of a system changes, the system will weight the path identifier according to the dynamic adjustment coefficient to reflect the latest dependency and risk distribution. This module dynamically maintains the dependency graph through a cyclic update mechanism to ensure that the system can quickly respond to the changing trend of fault propagation in a complex environment and always maintain the accuracy and timeliness of the dependency graph. At the same time, the selection of the dynamic adjustment coefficient can be flexibly configured according to the needs of the application scenario, thereby taking into account stability and sensitivity. The graph maintenance module in the present invention enables the system to track and reflect the changes of fault propagation paths in complex environments in real time through a dynamic adjustment mechanism. Compared with the traditional static dependency graph, this module significantly improves the adaptability and accuracy of the system in dealing with dynamic environments. The combination of the change amount of the fault propagation probability and the dynamic adjustment coefficient not only improves the flexibility of the update rule, but also optimizes the system's ability to identify critical paths, thereby effectively shortening the fault response time. Finally, the present invention provides strong technical support for real-time fault monitoring and dynamic diagnosis of complex cross-systems, reducing the overall operation risk of the system.
[0053] The log acquisition module further includes a log filtering unit for eliminating irrelevant or redundant log data, and by setting a log priority threshold, only retaining log data with a priority higher than the threshold, which meets the following conditions: k >P th ;
[0054] Among them, P k represents the priority of log entry k, P th Indicates the log priority threshold.
[0055] The log filtering unit filters and optimizes the original log data by analyzing the priority attribute of each log to reduce the interference of irrelevant or low-priority logs on subsequent analysis. k It can be dynamically calculated based on the source of the log, event level (such as INFO, WARNING, ERROR) or other weight parameters. The system first assigns a corresponding priority value to each log and sets a threshold P. th, remove log data below the threshold. This filtering process can significantly reduce the amount of log data, improve the processing efficiency of subsequent modules (such as dependency building and fault analysis modules), and ensure that analysis resources are focused on more important log information. By introducing the log filtering unit, the present invention further optimizes the performance of the log acquisition module. Unlike the traditional method of directly processing all log data, this unit effectively reduces the amount of irrelevant data through a priority screening mechanism, reducing the computing and storage burden of the system. In addition, the flexibility of priority screening enables the system to adjust the threshold for different application scenarios, thereby balancing data accuracy and processing efficiency. Ultimately, this module improves the adaptability of the system in complex environments, making subsequent dependency analysis and fault location more accurate and efficient.
[0056] The log acquisition module filters the log data by calculating the correlation coefficient of the log entries. The filtering conditions are:
[0057] When R is greater than the preset threshold R th If , the log entry is retained, otherwise it is removed;
[0058] Where R represents the correlation coefficient of log entries, N c Indicates the number of key field matches in the log entry, N t Indicates the total number of fields in the log entry.
[0059] In the processing of raw log data, the log acquisition module evaluates the content of each log by calculating the correlation coefficient R of the log entry. The system first parses the field content in the log and identifies the keyword fields related to fault analysis or dependency analysis. Then, according to the number of keyword field matches N c and the total number of fields in the log entry N t , calculate the correlation coefficient R. Only when R exceeds the preset threshold R th , the log entry will be retained as input data for subsequent module analysis. Through this screening process, the impact of irrelevant or low-relevance logs on system performance can be significantly reduced, and the efficiency and accuracy of subsequent analysis steps can be improved. The present invention effectively improves the accuracy of log data screening and the overall efficiency of system processing by introducing a log screening mechanism based on correlation coefficients. Compared with the traditional static rule filtering method, the dynamic calculation method of the correlation coefficient can adapt to the analysis requirements in different scenarios, ensuring that the screened log entries are highly relevant to the fault analysis objectives, thereby optimizing the utilization efficiency of system resources. In addition, the threshold R th Flexible settings enable the system to be personalized for specific application scenarios and maintain efficient fault location capabilities even when the data volume is large or the log noise is high.
[0060] The dependency building module establishes the call path according to the system call weight. The specific calculation formula is:
[0061] W = F / T;
[0062] Among them, W represents the weight of the call path, F represents the frequency of the call, and T represents the total number of calls.
[0063] The dependency building module extracts the frequency F and total number of calls T of each call by analyzing the cross-system call log, and then calculates the weight W of the call path. The weight value W represents the importance of a certain call path in the inter-system dependency relationship, and is used to identify the critical path or high-frequency call relationship. In actual operation, the module first parses the call log, counts the occurrence frequency and total number of calls of each call, and then calculates the path weight according to the formula W=F / T. The weight value can be directly used for the visualization of the dependency graph and the input of the subsequent fault analysis module, helping the system to quickly identify possible critical dependencies, thereby optimizing the analysis efficiency. By introducing a path calculation mechanism based on call weights, the present invention can accurately measure the importance of the call relationship between systems. Compared with the traditional dependency graph construction method, the analysis based only on the call frequency or total number of times is likely to ignore the role of the critical path, while the weight calculation method can comprehensively consider the relative relationship between the call frequency and the total number of calls, highlighting the importance of high-impact paths between systems, thereby more efficiently supporting subsequent fault propagation analysis and location. In addition, the introduction of call path weights can also optimize resource allocation strategies, such as preferentially monitoring the operating status of high-weight paths, and further improving the operating stability of the system.
[0064] The fault analysis module analyzes the fault path based on the fault propagation probability. The specific calculation formula is:
[0065] P = W × A;
[0066] Among them, P represents the probability of fault propagation, W represents the weight of the call path, and A represents the state value of the target system.
[0067] The fault analysis module calculates the probability P of fault propagation by combining the call path weight W and the target system state value A. The call path weight W is provided by the dependency building module and reflects the importance of the call path between systems, while the target system state value A represents the health level or fault risk coefficient of the target system. When a system fails, the module uses the weight W and the state value A to determine the probability P of the fault propagating to the target system through the call path. By analyzing the fault propagation probability of all relevant paths, the system can quickly identify the key systems and their paths that may be affected, thereby providing guidance for subsequent fault location and processing. Through the analysis method based on the fault propagation probability, the present invention can significantly improve the efficiency and accuracy of fault propagation path analysis in complex systems. Compared with the traditional method that relies on manual judgment or static rule derivation, the present invention uses a mathematical model to automatically calculate the fault propagation probability P, which can not only quantify the propagation risk, but also dynamically reflect the changes in the system state, and support real-time fault location. In addition, the combination of weight W and state value A ensures the comprehensiveness and flexibility of the analysis results, which helps to predict potential high-risk paths in advance, thereby reducing system downtime and improving operational stability.
[0068] The graph maintenance module dynamically adjusts the dependency graph based on the path call failure rate, and its adjustment rule is: W′=W·(1+F r );
[0069] Where W′ represents the adjusted path weight, W represents the weight of the call path, and F r Indicates the path call failure rate.
[0070] The graph maintenance module uses the path call failure rate F r The path weight W is dynamically adjusted, and the updated weight W′ reflects the actual reliability of the path in the dependency graph. Specifically, the system monitors the failure rate F of the calling path. r To obtain the operation stability of the path, when the failure rate is high, the path weight W′ will be adjusted by the formula W′=W·(1+F r ) to emphasize the risk and importance of the path in the dependency relationship. On the contrary, when the path call is stable, the failure rate F r The adjustment range of path weight is also small. Through this dynamic adjustment mechanism, the system can reflect the change of path call status in real time, providing a more timely basis for fault location and priority processing of high-risk paths. rThe introduction of has realized the dynamic adjustment of the dependency graph and significantly improved the system's adaptability in complex environments. Compared with the traditional static path weight calculation method, the dynamic adjustment rule can reflect the reliability changes of path calls in real time, ensuring the accuracy and timeliness of the dependency graph. The dynamic update of path weights not only helps to identify critical paths, but also provides a reference for priority scheduling, thereby optimizing resource allocation and improving system operation efficiency. Ultimately, the present invention provides a more intelligent solution for fault diagnosis and management of complex systems, effectively reducing system operation risks.
[0071] The graph maintenance module determines the priority maintenance path according to the path importance coefficient. The specific calculation formula is: K = W × S;
[0072] Among them, K represents the importance coefficient of the path, W represents the weight of the call path, and S represents the success rate of the path call.
[0073] The graph maintenance module dynamically determines the priority maintenance path by calculating the importance coefficient K of the path. The call path weight W represents the influence of the path in the dependency relationship, and the path call success rate S represents the reliability of the path. The module combines these two indicators and comprehensively evaluates the importance of the path through the formula K=W×S. When the importance coefficient K of the path is high, the system prioritizes the maintenance of the path to ensure the accuracy and real-time performance of the key path in the dependency graph. In practical applications, the module can trigger the calculation of the importance coefficient of the path regularly or on demand, and optimize the maintenance strategy based on the calculation results, so that system resources are concentrated on high-priority paths, thereby improving maintenance efficiency and system performance. The present invention significantly improves the efficiency and accuracy of dependency graph maintenance through a priority maintenance mechanism based on the path importance coefficient K. Compared with the traditional method of maintaining all paths according to a fixed strategy, the present method can dynamically identify the key path, prioritize the limited maintenance resources to the high-priority path, and avoid unnecessary waste of resources. In addition, the combination of the path weight W and the success rate S makes the calculation of the importance coefficient more comprehensive, which not only reflects the importance of the path, but also takes into account its actual stability, thereby optimizing the reliability and real-time performance of the dependency graph.
[0074] The log acquisition module further includes an abnormal log detection unit, which is used to identify abnormal behavior of the acquired raw log data and mark the abnormal log as a priority processing object. The abnormal log detection unit automatically identifies potential abnormal behavior by analyzing the behavioral features in the raw log data. The unit uses an abnormal detection algorithm to scan and process the log data in real time. Specifically, the module uses a variety of technologies (such as rule matching, statistical analysis, machine learning algorithms, etc.) to parse the log content, and combines the abnormal feature library, historical data patterns or real-time monitoring information to determine whether the log has abnormal behavior. Once an abnormal log is detected, the module marks it as a priority processing object and passes the relevant information to the dependency building module and the fault analysis module to speed up the response to abnormal situations. Through the role of this unit, the system can effectively filter abnormal data and give priority attention in the initial stage of log processing, thereby improving the pertinence and efficiency of fault analysis. The present invention enhances the system's ability to quickly identify potential faults and abnormal behaviors by introducing an abnormal log detection unit in the log acquisition module. Compared with the traditional log processing method, the abnormal detection unit can monitor the abnormal features in the log in real time and mark it as a priority processing object, significantly shortening the response time from log acquisition to fault location. In addition, the unit can improve the ability to identify new or hidden anomalies by continuously expanding the anomaly feature library and optimizing the detection algorithm, thereby further enhancing the reliability and stability of the system. Ultimately, the present invention provides strong technical support for fault location and early warning of complex systems, reducing the risk of system operation.
[0075] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A fast search and precise positioning system based on the BOSS system log chain, characterized in that: The system comprises: The log acquisition module is used to obtain the original log data generated by cross-system calls and preliminarily sort the logs according to timestamps; The dependency building module connected to the log acquisition module is used to build a cross-system dependency graph based on the logs after preliminary sorting. The dependency building module builds a call relationship graph between systems by calculating the call frequency ratio. The specific calculation formula is: Among them, R ij represents the call frequency ratio of system i to system j, C ij represents the number of times system i calls system j, C i Indicates the total number of calls to system i, i represents the number of the initiating system of the call, and j represents the number of the target system of the call; The fault analysis module connected to the dependency building module is used to analyze the fault conduction path using the dependency graph and generate a link tracking identifier. The fault analysis module uses the fault propagation probability to predict the possibility of system failure. The specific formula is: P ij =R ij ·A j ; Among them, P ij A represents the probability that a failure in system i may propagate to system j. j represents the state value of system j, R ij It represents the call frequency ratio of system i calling system j, where i represents the number of the initiating system and j represents the number of the target system. The graph maintenance module connected to the dependency building module and the fault analysis module is used to maintain and update the dependency graph according to the link tracking identifier to achieve accurate positioning in a complex environment.
2. According to claim 1, a fast search and precise positioning system based on the BOSS system log chain is characterized in that: The log acquisition module includes: A log parsing unit, used to extract system call information from raw log data; The timestamp sorting unit is used to sort log data according to timestamps, satisfying the following requirements: T1≤T2≤…≤T n ; Among them, T1, ..., T n represents the timestamp of the log, and n represents the total number of log entries.
3. According to claim 1, a fast search and precise positioning system based on the BOSS system log chain is characterized in that: The graph maintenance module dynamically adjusts the dependency relationship according to the fault propagation path identifier, and the update rule is as follows: ij =ΔP ij β; Among them, L ij Indicates the path identification change value of system i calling system j, ΔP ij represents the change in the probability of fault propagation, β represents the dynamic adjustment coefficient, i represents the number of the initiating system of the call, and j represents the number of the target system of the call.
4. According to claim 1, a fast search and precise positioning system based on the BOSS system log chain is characterized in that: The log acquisition module further includes: The log filtering unit is used to remove irrelevant or redundant log data. By setting the log priority threshold, only the log data with a priority higher than the threshold is retained, which meets the following conditions: k >P th ; Among them, P k represents the priority of log entry k, P th Indicates the log priority threshold.
5. According to claim 1, a fast search and precise positioning system based on the BOSS system log chain is characterized in that: The log acquisition module filters the log data by calculating the correlation coefficient of the log entries, and the filtering conditions are: When R is greater than the preset threshold R th If yes, keep the log entry, otherwise remove it; Where R represents the correlation coefficient of log entries, N c Indicates the number of key field matches in the log entry, N t Indicates the total number of fields in the log entry.
6. According to claim 1, a fast search and precise positioning system based on BOSS system log chain, characterized in that: The dependency relationship building module establishes a call path according to the system call weight, and the specific calculation formula is: W=F / T; Among them, W represents the weight of the call path, F represents the frequency of the call, and T represents the total number of calls.
7. According to claim 1, a fast search and precise positioning system based on BOSS system log chain is characterized in that: The fault analysis module analyzes the fault path based on the fault propagation probability, and the specific calculation formula is: P = W × A; Among them, P represents the probability of fault propagation, W represents the weight of the call path, and A represents the state value of the target system.
8. According to claim 1, a fast search and precise positioning system based on BOSS system log chain is characterized in that: The graph maintenance module dynamically adjusts the dependency graph based on the path call failure rate, and the adjustment rule is: W′=W·(1+F r ); Where W′ represents the adjusted path weight, W represents the weight of the call path, and F r Indicates the path call failure rate.
9. According to claim 1, a fast search and precise positioning system based on BOSS system log chain, characterized in that: The graph maintenance module determines the path to be maintained first according to the path importance coefficient, and the specific calculation formula is: K = W × S; Among them, K represents the importance coefficient of the path, W represents the weight of the call path, and S represents the success rate of the path call.
10. The fast search and precise positioning system based on the BOSS system log chain according to claim 1 is characterized by: The log acquisition module further includes an abnormal log detection unit, which is used to identify abnormal behavior of the acquired original log data and mark the abnormal log as a priority processing object.