Log series connection method and device, equipment and storage medium

By determining the log information and levels of the pending logs in the banking system and matching the corresponding log concatenation tasks, the log concatenation problem is solved, and the efficiency of transaction analysis and fault location is improved.

CN120104586APending Publication Date: 2025-06-06SHANGHAI QINGCHUANG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510262702.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

In banking, as transaction types and volumes amplify, log storage and analysis become complicated, especially when it is impossible to determine the global unique flow number or only local unique flow number, the difficulty of log connection increases, affecting transaction analysis and fault location.

Method used

By determining the log information of the pending log, including the flow number, flow number position information and upstream and downstream connection relationship, dividing the log levels, and matching the corresponding log concatenation tasks according to the level, the connection of the pending logs belonging to the same transaction in the first system is realized.

Benefits of technology

It effectively solves the problem of log concatenation under different log situations, improves the efficiency of log analysis and fault location, and ensures accurate connection of the same transaction log in the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120104586A_ABST
    Figure CN120104586A_ABST
Patent Text Reader

Abstract

The invention discloses a log series connection method and device, equipment and a storage medium. The method comprises the following steps: determining log information of a to-be-processed log of a first system, wherein the log information comprises a serial number, serial number position information and an upstream and downstream connection relationship; determining the log level of the to-be-processed log according to the log information of the to-be-processed log of the first system; determining a log series task matched with the log level according to the log information; and connecting logs to be processed of the first system in series according to the log series task. According to the technical scheme, the log series task matched with the log level of the to-be-processed log is determined according to the serial number, the serial number position information and the upstream and downstream connection relation in the to-be-processed log in the first system; the to-be-processed logs belonging to the same transaction in the first system are connected in series according to the log generation sequence and the upstream and downstream connection relation, and the method for connecting the logs belonging to the same transaction in the system in series is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of log processing technology, and in particular to a log concatenation method, device, equipment and storage medium. Background Art

[0002] The transaction log stores detailed information about a transaction and plays an important role in analyzing banking business needs, such as statistics on important business indicators such as transaction volume and transaction success rate, collection and analysis of core transaction links, and fault location.

[0003] However, with the continuous development of banking business, the types and volume of transactions are rapidly expanding. The logs of large systems can reach tens of TB per day. Logs of different transactions are often mixed together and stored in one file. Sometimes, a transaction log is stored in different system files according to the logs generated by different systems. If you want to perform the above transaction log analysis, you need to identify the logs belonging to the same transaction and connect each log in sequence.

[0004] Generally speaking, there will be a globally unique serial number representing a transaction in the transaction log. If the location of the serial number in the log is known, it is easy to concatenate the logs based on the serial number. However, in some scenarios, the specific location of the global serial number cannot be known, or some system logs only have a locally unique serial number that can be used as an identifier to identify a transaction, that is, the serial number is only unique within a period of time. There are even some logs that have no serial number that can be used for concatenation. In the above situations, the quality of the log itself is getting worse and worse, and the difficulty of log concatenation is also increasing. Therefore, there is an urgent need for a log concatenation method that can be used for different log situations. Summary of the invention

[0005] The present invention provides a log series connection method, device, equipment and storage medium to realize a log series connection method belonging to the same transaction in a system.

[0006] In a first aspect, an embodiment of the present invention provides a log concatenation method, the method comprising:

[0007] Determine log information of a log to be processed of the first system, the log information including a serial number, serial number position information and upstream and downstream connection relationship, the serial number is an identifier representing a transaction, the serial number position information is the position of the serial number in each log to be processed, and the upstream and downstream connection relationship is the connection relationship between each second system recording the log; the first system includes at least one second system;

[0008] Determine the log level of the log to be processed according to the log information, wherein the log level is used to indicate the degree of perfection of the log information of the log to be processed;

[0009] According to the log information, a log concatenation task matching the log level is determined; wherein different log levels are matched with different log concatenation tasks; the log concatenation task is used to concatenate the to-be-processed logs belonging to the same transaction in the first system according to the upstream and downstream connection relationship and the order of log generation; the log generation time is used to indicate the order in which the logs are recorded in the first system;

[0010] The to-be-processed logs of the first system are concatenated according to the log concatenation task.

[0011] In a second aspect, an embodiment of the present invention further provides a log serial connection device, the device comprising:

[0012] A log information determination module is used to determine the log information of the to-be-processed log of the first system, wherein the log information includes a serial number, serial number position information, and an upstream and downstream connection relationship, wherein the serial number is an identifier representing a transaction, the serial number position information is the position of the serial number in each to-be-processed log, and the upstream and downstream connection relationship is the connection relationship between the second systems recording the logs; the first system includes at least one second system; and the second systems have an upstream and downstream relationship;

[0013] A log level determination module, used to determine the log level of the log to be processed according to the log information of the log to be processed of the first system, wherein the log level is used to indicate the degree of perfection of the log information of the log to be processed;

[0014] A log series task determination module is used to determine a log series task that matches the log level according to the log information; wherein different log levels match different log series tasks; the log series task is used to series the to-be-processed logs belonging to the same transaction in the first system according to the upstream and downstream connection relationship and the order of log generation; the log generation time is used to indicate the time when the log is recorded in the first system;

[0015] The log concatenation module is used to concatenate the to-be-processed logs of the first system according to the log concatenation task.

[0016] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, a log concatenation method as described in any one of the embodiments of the present invention is implemented.

[0017] In a fourth aspect, an embodiment of the present invention further provides a storage medium storing computer executable instructions, wherein the computer executable instructions, when executed by a computer processor, are used to execute the log concatenation method as described in any one of the embodiments of the present invention.

[0018] The technical solution of the embodiment of the present invention determines the log concatenation task that matches the log level of the log to be processed through the serial number, serial number position information and upstream and downstream connection relationship in the log to be processed in the first system, so that the logs to be processed belonging to the same transaction in the first system are concatenated in chronological order and upstream and downstream connection relationships, thereby realizing a method for concatenating logs belonging to the same transaction in the system.

[0019] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0021] Figure 1 This is a flow chart of a log concatenation method provided by Embodiment 1 of the present invention;

[0022] Figure 2 is a flow chart of a multi-system log concatenation method under different circumstances provided by the first embodiment of the present invention;

[0023] Figure 3 It is a structural schematic diagram of a log series connection device provided by Embodiment 2 of the present invention;

[0024] Figure 4 The present invention is a schematic diagram of the structure of an electronic device for implementing the log serial connection method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0025] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0026] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0027] Embodiment 1

[0028] Figure 1 A flow chart of a log series method is provided for the first embodiment of the present invention. This embodiment is applicable to log series situations. The method can be executed by a log series device. The log series device can be implemented in the form of hardware and / or software. The log series device can be configured in any electronic device with network communication and computing. Figure 1 As shown, the method includes:

[0029] S110: Determine log information of the log to be processed of the first system.

[0030] In this embodiment, the log information includes a serial number, serial number position information and upstream and downstream connection relationship, the serial number is an identifier representing a transaction, the serial number position information is the position of the serial number in each log to be processed, and the upstream and downstream connection relationship is the order in which each log to be processed exists in each second system. Among them, the first system includes at least one second system.

[0031] It should be noted that the "first" and "second" in this embodiment are used to distinguish similar systems, rather than to describe a specific order or sequence. The technical background of this embodiment is that in some large systems, a day's log can reach tens of TB, and logs of different transactions are often mixed together and stored in one file. Sometimes a transaction log is stored in different system files according to logs generated by different systems.

[0032] It is understandable that in a complex system architecture, there are usually upstream and downstream relationships between the subsystems, and data and business processes will flow between these systems in a certain order. Generally speaking, the upstream system completes the relevant operations and generates logs first, and the downstream system processes and generates corresponding logs based on the output results of the upstream system.

[0033] The first system of this embodiment is a large target system, and the second system is a subsystem in the first system. For example, in a bank target system, there are upstream and downstream relationships between different subsystems to achieve the flow and data interaction of various bank businesses. If the first system is a bank system, the second system can be a core business system, an online banking system, a payment and clearing system, a customer relationship management system, a financial management system, etc. There is an upstream and downstream connection relationship between the second systems generated by a transaction log.

[0034] S120: Determine the log level of the log to be processed according to the log information.

[0035] In this embodiment, the log level is used to indicate the degree of completeness of the log information of the log to be processed.

[0036] In order to solve the log concatenation method under different log information conditions, this embodiment prioritizes the log level when the log information of the log to be processed is different. Further, the corresponding log concatenation task flow can be matched according to different log levels, which helps the system better manage and utilize log data.

[0037] In this embodiment, the logs to be processed are divided into different log levels according to the degree of perfection of the log information of the logs to be processed in the first system. Further, in practical applications, the log levels can be divided into different levels according to whether the log information is perfect and whether the content of the log information is critical.

[0038] As an optional but non-limiting implementation, determining the log level of the log to be processed according to the log information includes:

[0039] If the log information of the log to be processed does not include the serial number, the serial number position information and the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the first level;

[0040] If the log to be processed contains a serial number but does not contain the serial number position information and the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the second level;

[0041] If the log to be processed includes the serial number and the position information of the serial number and does not include the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the third level;

[0042] If the log to be processed includes a serial number, serial number position information, and an upstream and downstream connection relationship, it is determined that the log level of the log to be processed is the fourth level.

[0043] It should be noted that the present embodiment describes the conditions for classifying log levels, and the log level is determined based on whether the log contains a serial number, serial number position information, and an upstream and downstream connection relationship.

[0044] If the log information of the log to be processed does not contain any key information, that is, does not contain the serial number, serial number position information and upstream and downstream connection relationship, the log level of the log to be processed is determined to be the first level, and the log format is as follows: [time] [log content].

[0045] If the log information of the log to be processed contains only one key information, that is, it only contains the serial number but does not contain the serial number position information and the upstream and downstream connection relationship, then the log level of the log to be processed is determined to be the second level, and the log format is as follows: [time] [thread number] [log content (containing the serial number that can be used to connect the same transaction log)].

[0046] If the log information of the log to be processed contains two key information, namely, the serial number and the position information of the serial number but does not contain the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the third level, and the log format is as follows: [time] [global serial number] [log content].

[0047] If the log information of the log to be processed contains all three key information, namely the serial number, the serial number position information and the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the fourth level, and the log format is as follows: [time] [global serial number] [TraceId] [SpanId] [parentSpanId] [log content]. Among them, SpanId and parentSpanId indicate the upstream and downstream connection relationship between the logs to be processed.

[0048] It is understandable that a higher log level indicates more complete log information, and it is easier to connect the pending logs belonging to the same transaction. In this embodiment, the pending logs are divided into different log levels, which helps the system to better manage and utilize log data and improve the efficiency of log connection.

[0049] S130: Determine, according to the log information, a log concatenation task that matches the log level.

[0050] In this embodiment, the log concatenation task is used to concatenate the pending logs belonging to the same transaction in the first system according to the upstream and downstream connection relationship and the order of log generation, wherein different log levels are matched with different log concatenation tasks. The log generation time is used to indicate the time when the log is recorded in each system. It is understandable that many systems have parallel processing capabilities, and multiple businesses may be carried out at the same time, resulting in that even if there is an upstream and downstream relationship between the systems, the log generation time between different systems may not completely conform to the normal time sequence.

[0051] It should be noted that for logs to be processed containing different log information, the corresponding log series tasks are different. In this embodiment, the log series tasks matching the log level can be determined according to the known log information.

[0052] As an optional but non-limiting implementation, determining the log concatenation task matching the log level according to the log information further includes steps A1-A5:

[0053] Step A1: If the log information of the log to be processed does not include the serial number, serial number position information and upstream and downstream connection relationship, the log series task matching the first level is determined to be determining the log sequence pattern belonging to the same transaction in the logs to be processed in each second system.

[0054] Step A2: concatenate the to-be-processed logs of the same transaction in a single second system according to the log sequence mode.

[0055] Step A3: determining a matching relationship between log sequence patterns among the second systems; the matching relationship between the log sequence patterns is used to represent logs belonging to the same transaction in the first system.

[0056] Step A4: Determine the connection relationship between the second systems according to the matching relationship of the log sequence patterns.

[0057] Step A5: Connect the to-be-processed logs belonging to the same transaction in the first system according to the connection relationship between the second systems.

[0058] In this embodiment, the log sequence pattern is a log template of the log to be processed, and the log sequence pattern can be determined by the log template of the log to be processed. The matching relationship of the log sequence pattern is used to represent the logs belonging to the same transaction in the first system (in each second system).

[0059] It should be noted that the log templates belonging to the same transaction in the system are usually the same, and contain the same log information elements, such as log generation time, communication connection interface, serial number, physical address, etc.

[0060] In actual application, when the log information does not contain the serial number, serial number location information, and upstream and downstream connection relationship, and it is impossible to determine the logs belonging to the same transaction based on the serial number, the log template can be extracted first, and the log sequence pattern can be mined based on the log template to determine the unprocessed logs with the same log sequence pattern in each second system. Further, the matching relationship of the log sequence patterns between each second system is determined, and the connection relationship between the second systems is determined based on the matching relationship of the log sequence patterns. Further, based on the connection relationship between each second system, the unprocessed logs belonging to the same transaction in the first system are connected.

[0061] Specifically, the log concatenation task matching the first level is to first mine the log sequence pattern in a single second system using an MDL-based method. Specifically, the problem can be defined as: given a sequence S, find the best log sequence pattern set Make the description length The minimum value, that is Furthermore, when formulating the encoding scheme of the log sequence pattern, in addition to considering the content of the log sequence pattern, the time interval between log events is determined. For each log sequence pattern, all instances corresponding to the log sequence pattern in the log sequence pattern are determined, and the time interval between log events of each instance is counted to form a distribution histogram. The description length of the log sequence pattern is = description length of log sequence pattern content + description length of time interval distribution histogram. After formulating the log sequence pattern encoding scheme, the log sequence pattern is encoded. The codewords of the log sequence pattern and histogram are used to replace the instances of the pattern in the log sequence pattern. After that, the log sequence pattern set is mined through iterative search based on MDL, that is, the best log pattern sequence set is found, that is, the minimization problem described above. The basic process is as follows:

[0062] 1. Log sequence pattern set in the initial state is empty;

[0063] 2. Mining the log sequence pattern P with the best compression capability from the log sequence pattern, that is, is the minimum log sequence pattern;

[0064] 3. Add the log sequence pattern P to the collection And encode the instance of log sequence pattern P in sequence S;

[0065] 4. Repeat steps 2-3 until the sequence cannot be compressed further.

[0066] In fact, replacing the instances in the log sequence pattern with the best sequence set is the process of completing the log concatenation (within a single second system). For the concatenation between multiple second systems, the log sequence patterns in a single second system are used as log templates, and the connection of the log sequence patterns between multiple second systems is used as the pattern sequence. The above single system log sequence pattern mining process is repeated to obtain the connection relationship between multiple systems, and then the pending logs belonging to the same transaction in the first system are connected according to the connection relationship between each second system.

[0067] As an optional but non-limiting implementation, determining a log concatenation task matching the log level according to the log information further includes steps B1-B7:

[0068] Step B1: If the log information of the log to be processed contains a serial number but does not contain serial number position information and upstream and downstream connection relationships, the log concatenation task matching the second level is determined to perform structured processing on the log to be processed in the second system to extract log templates and log variables.

[0069] Step B2: filtering the log template and log variable according to the first filtering condition, and determining the serial number of the to-be-processed log representing the same transaction in a single second system from the log variable.

[0070] Step B3: according to the serial number, the to-be-processed logs belonging to the same transaction in a single second system are connected in series.

[0071] Step B4: Determine the log sequence pattern of the to-be-processed logs belonging to the same transaction in the second system.

[0072] Step B5: filtering the log sequence pattern and the log variable according to the second filtering condition, and determining the matching relationship between the serial numbers of the to-be-processed logs representing the same transaction between the second systems from the log sequence pattern.

[0073] Step B6: Determine the connection relationship between the second systems according to the matching relationship of the serial numbers of the logs to be processed.

[0074] Step B7: connecting the to-be-processed logs belonging to the same transaction between the second systems according to the connection relationship between the second systems.

[0075] In this embodiment, the first filtering condition is used to filter the log template and log variables to determine the serial number of the log to be processed representing the same transaction in a single second system from the log variables, and the second filtering condition is used to filter the log sequence pattern and log variables to determine the matching relationship between the serial numbers of the logs to be processed representing the same transaction between the second systems from the log sequence pattern. Among them, the first filtering condition can be that the number of occurrences of the log variable or log template is less than a preset threshold, and the second filtering condition can be that the number of log variable values ​​is less than the number of log sequence patterns. It should be noted that the first filtering condition and the second filtering condition are not specifically limited in this embodiment.

[0076] Specifically, the log concatenation task matching the second level is to mine the serial number that can be used to concatenate a transaction, so it is necessary to extract various variables from the log. First, the logs to be processed are structured and the log generation time, template, and variable information are extracted. Further, the logs to be processed are structured and possible concatenation rules are mined based on the variable values ​​and log templates of each log to be processed.

[0077] The steps for concatenating the to-be-processed logs belonging to the same transaction within a single second system may be:

[0078] 1. For each variable value, count the log templates in which it appears and the number of times it appears in the log template;

[0079] 2. Filter out variable values ​​whose occurrence times are less than or equal to a certain threshold;

[0080] 3. For each template variable combination, count the variable values;

[0081] 4. Clustering of template variable combinations;

[0082] 5. Filter out template variable combinations whose number of variable values ​​is less than or equal to a certain threshold;

[0083] 6. Filter out the "included" log template combinations, and the resulting ones are the internal serial rules of a single system.

[0084] The steps for connecting the to-be-processed logs belonging to the same transaction between the two second systems may be:

[0085] 1. For each variable value, count the variable values ​​that appear in each system template and log sequence pattern in each second system;

[0086] 2. Filter out variable values ​​with system number < 2;

[0087] 3. For each system template variable combination, count its variable values;

[0088] 4. System template variable combination clustering;

[0089] 5. Filter out system template variable combinations whose number of variable values ​​is less than or equal to the threshold;

[0090] 6. Filter out the "included" system template combination, and the result is the series connection rule between the two systems. Finally, according to the connection relationship between each second system, the pending logs belonging to the same transaction in the first system are connected.

[0091] As an optional but non-limiting implementation, determining a log concatenation task matching the log level according to the log information further includes steps C1-C3:

[0092] Step C1: If the log information of the log to be processed includes the serial number and the position information of the serial number and does not include the upstream and downstream connection relationship, the log series task matching the third level is determined to be determining the serial numbers of the logs to be processed belonging to the same transaction between the second systems.

[0093] Step C2: Determine the connection relationship between the second systems according to the serial number.

[0094] Step C3: connecting the to-be-processed logs belonging to the same transaction in the first system according to the connection relationship between the second systems.

[0095] In this embodiment, if the log information of the log to be processed includes the serial number and the position information of the serial number but does not include the upstream and downstream connection relationship, the log to be processed belonging to the same transaction can be directly located according to the serial number and the position information of the serial number in the log information. Further, according to the connection relationship between each second system, the log to be processed belonging to the same transaction in the first system is connected.

[0096] In this embodiment, the log concatenation task matching the third level is to directly find the logs belonging to the same transaction based on the global serial number, and then mine the system connection relationship or the upstream and downstream connection relationship and upstream and downstream connection positions of the logs based on the log generation time, and further concatenate the logs belonging to the same transaction according to the connection relationship between the systems or the upstream and downstream connection relationship of the logs.

[0097] As an optional but non-limiting implementation, the to-be-processed logs belonging to the same transaction in the first system are connected according to the connection relationship between the second systems, including steps D1-D2:

[0098] Step D1: According to the connection relationship between the second systems, the upstream and downstream connection relationship and the upstream and downstream connection positions of the to-be-processed logs belonging to the same transaction between the second systems are determined.

[0099] Step D2: connecting the to-be-processed logs belonging to the same transaction in the first system according to the upstream and downstream connection relationship and the upstream and downstream connection positions.

[0100] In this embodiment, the connection relationship between the second systems includes the upstream and downstream connection relationship and upstream and downstream connection positions of the to-be-processed logs belonging to the same transaction between the second systems.

[0101] It should be noted that the upstream and downstream connection positions can be used to connect the pending logs belonging to the same transaction in two systems, and the upstream and downstream connection positions indicate the generation time sequence of the pending logs belonging to the same transaction in the two systems.

[0102] In this embodiment, based on the connection relationship between each second system, the upstream and downstream connection relationship and the upstream and downstream connection positions of the pending logs belonging to the same transaction between each second system are determined. Furthermore, based on the upstream and downstream connection relationship and the upstream and downstream connection positions of the pending logs belonging to the same transaction between each second system, the pending logs belonging to the same transaction in the first system can be connected.

[0103] As an optional but non-limiting implementation, determining the upstream and downstream connection relationships and upstream and downstream connection positions between the second systems according to the connection relationships between the second systems includes steps E1-E2:

[0104] Step E1: determining the time span of the logs to be processed belonging to the same transaction in the third system, and determining the time interval of the logs to be processed belonging to the same transaction in the fourth system.

[0105] Step E2: According to the time span and time interval, determine the upstream and downstream connection relationship and upstream and downstream connection positions of the logs to be processed between the third system and the fourth system that have a connection relationship.

[0106] In this embodiment, the time span is the difference between the log generation time of the first log to be processed and the last log to be processed belonging to the same transaction in the third system, and the time interval is the difference between the log generation time of two adjacent consecutive logs to be processed belonging to the same transaction in the fourth system. The third system and the fourth system belong to the second system, and the third system and the fourth system have a connection relationship.

[0107] It should be noted that the "third" and "fourth" in this embodiment are used to distinguish similar systems, but are not used to describe a specific order or sequence.

[0108] Specifically, the log concatenation process in this embodiment is to first find the logs belonging to the same transaction, and then mine the upstream and downstream connection relationship and upstream and downstream connection positions of the logs according to the log generation time to concatenate the logs belonging to the same transaction.

[0109] However, in this embodiment, since the time of each second system may be offset, the logs to be processed between different systems cannot be directly connected in the order of log generation time.

[0110] In this embodiment, the method for connecting the logs to be processed between different systems is, for a transaction log, calculating the time span of the log in each second system and the time interval between two adjacent logs. If the time span of a system log is less than the time interval between two adjacent logs of another system, it is considered that the first system may be downstream of the second system, and the log of the first system can be inserted between the two logs of the second system. According to the above method, if it is found that there are systems 2 and 3 downstream of system 1, and system 3 downstream of system 2, then the relationship can be obtained: the downstream of system 1 is system 2, and the downstream of system 2 is system 3. If it is found that both positions of system 1 may be inserted into system 2 or system 3, it means that there are systems 2 and system 3 downstream of system 1, and they are inserted into the two positions of system 1 in the order of time.

[0111] As an optional but non-limiting implementation, determining the upstream and downstream connection relationship and upstream and downstream connection positions of the logs to be processed between the third system and the fourth system having a connection relationship according to the time span and the time interval includes:

[0112] If the time span of the to-be-processed logs of the third system is smaller than the time interval of the to-be-processed logs of the fourth system, it is determined that the to-be-processed logs belonging to the same transaction in the third system are downstream of the to-be-processed logs belonging to the same transaction in the fourth system, and the position between two adjacent and continuous to-be-processed logs belonging to the same transaction in the fourth system is the upstream and downstream connection position of the to-be-processed logs belonging to the same transaction in the third system;

[0113] Otherwise, it is determined that the pending log belonging to the same transaction in the third system is upstream of the pending log belonging to the same transaction in the fourth system, and the position between two adjacent and continuous pending logs belonging to the same transaction in the third system is the upstream and downstream connection position of the pending log belonging to the same transaction in the fourth system.

[0114] In this embodiment, it is understandable that when the time span of a system log is shorter than the time interval between two adjacent logs of another system, it can be inferred from the time dimension that the former may have completed its own business processing between two operations of the latter. This means that the former's business may depend on the latter's output, that is, the former may be the latter's downstream system.

[0115] Assume that there are core business system A and financial management system B in the banking system. Core business system A processes various transactions of customers, such as deposits, withdrawals, transfers, etc., while financial management system B performs financial accounting and report generation based on the transaction results of core business system A.

[0116] Core business system A processes a deposit transaction and generates a log at 10:00 am, and then processes a withdrawal transaction and generates the next log at 10:30 am. The time interval between these two adjacent logs is 30 minutes.

[0117] Financial management system B processed the financial accounting based on the previous deposit business of core business system A between 10:10 and 10:20 in the morning and generated the corresponding log, with a time span of 10 minutes. Since 10 minutes is less than 30 minutes, it can be inferred from the time relationship that financial management system B may be the downstream system of core business system A. After completing a business in core business system A, it uses its results for subsequent financial processing.

[0118] As an optional but non-limiting implementation, determining a log concatenation task matching the log level according to the log information further includes steps F1-F2:

[0119] Step F1: If the log information of the log to be processed includes a serial number, serial number position information, and upstream and downstream connection relationships, the log concatenation task matching the fourth level is determined as follows: determining the logs to be processed belonging to the same transaction in a single second system according to the serial number, and concatenating the logs to be processed belonging to the same transaction in each second system.

[0120] Step F2: Connect the to-be-processed logs belonging to the same transaction in the first system in series according to the connection relationship between the second systems.

[0121] In this embodiment, the log concatenation task matching the fourth level is to directly find the logs belonging to the same transaction according to the global serial number, and then determine the upstream and downstream connection relationship according to the log parameters SpanId and parentSpanId of the log to be processed, and concatenate the logs belonging to the same transaction in the first system according to the upstream and downstream connection relationship.

[0122] S140: Concatenate the to-be-processed logs of the first system according to the log concatenation task.

[0123] In this embodiment, after the log level of the to-be-processed log of the first system is determined, the to-be-processed log of the first system may be concatenated according to the log concatenation task matching the log level.

[0124] It should be noted that, in actual applications, after the logs to be processed are concatenated, the connection relationships between the second systems that have appeared may also be summarized for use in subsequent data analysis.

[0125] See also Figure 2 The flowchart of the multi-system log concatenation method under different circumstances is shown. First, the maturity model of the log is defined, and the maturity of the log is divided into four log levels: L1, L2, L3, and L4, with the degree of perfection of the log information increasing in sequence. After obtaining a transaction log file, structured log data is obtained through data processing, and variables in the log information are extracted.

[0126] If the log level belongs to the first level L1, it is necessary to mine the log sequence pattern, determine the upstream and downstream connection relationship and the upstream and downstream connection position according to the log sequence pattern, and concatenate the logs belonging to the same transaction according to the log sequence pattern; if the log level belongs to the second level L2, it is necessary to analyze the log variables, mine the serial numbers that can be used to concatenate the logs, determine the upstream and downstream connection positions and the upstream and downstream connection relationships of the logs in the system, and concatenate the logs belonging to the same transaction according to the serial numbers; if the log level belongs to the third level L3, it is necessary to determine the upstream and downstream connection positions and the upstream and downstream connection relationships, and concatenate the logs belonging to the same transaction according to the serial numbers and the upstream and downstream connection positions; if the log level belongs to the fourth level L4, the logs can be directly concatenated according to the serial number and the call relationship information (upstream and downstream connection relationship).

[0127] The technical solution of the embodiment of the present invention determines the log concatenation task that matches the log level of the log to be processed through the serial number, serial number position information and upstream and downstream connection relationship in the log to be processed in the first system, so that the logs to be processed belonging to the same transaction in the first system are concatenated in chronological order and upstream and downstream connection relationships, thereby realizing a method for concatenating logs belonging to the same transaction in the system.

[0128] Embodiment 2

[0129] Figure 3 This is a schematic diagram of the structure of a log series connection device provided in the third embodiment of the present invention. This embodiment is applicable to log series connection situations. The log series connection device can be implemented in the form of hardware and / or software. The log series connection device can be configured in any electronic device with network communication and computing capabilities. Figure 3 As shown, the device comprises:

[0130] The log information determination module 310 is used to determine the log information of the to-be-processed log of the first system, wherein the log information includes a serial number, serial number position information, and an upstream and downstream connection relationship, wherein the serial number is an identifier representing a transaction, the serial number position information is the position of the serial number in each to-be-processed log, and the upstream and downstream connection relationship is the connection relationship between the second systems recording the logs; the first system includes at least one second system; and the second systems have an upstream and downstream relationship;

[0131] The log level determination module 320 is used to determine the log level of the log to be processed according to the log information of the log to be processed of the first system, wherein the log level is used to indicate the degree of perfection of the log information of the log to be processed;

[0132] The log concatenation task determination module 330 is used to determine the log concatenation task matching the log level according to the log information; wherein different log levels are matched with different log concatenation tasks; the log concatenation task is used to concatenate the to-be-processed logs belonging to the same transaction in the first system according to the upstream and downstream connection relationship and the order of log generation; the log generation time is used to indicate the time when the log is recorded in the first system;

[0133] The log concatenation module 340 is used to concatenate the to-be-processed logs of the first system according to the log concatenation task.

[0134] Optionally, determining the log level of the log to be processed according to the log information includes:

[0135] If the log information of the log to be processed does not include the serial number, the serial number position information and the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the first level;

[0136] If the log to be processed contains a serial number but does not contain the serial number position information and the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the second level;

[0137] If the log to be processed includes the serial number and the position information of the serial number and does not include the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the third level;

[0138] If the log to be processed includes a serial number, serial number position information, and an upstream and downstream connection relationship, it is determined that the log level of the log to be processed is the fourth level.

[0139] Optionally, determining, according to the log information, a log concatenation task matching the log level includes:

[0140] If the log information of the log to be processed does not include the serial number, the serial number position information and the upstream and downstream connection relationship, the log series task matching the first level is determined to be: determining the log sequence pattern belonging to the same transaction in the logs to be processed in each second system; the log sequence pattern is determined by the log template of the log to be processed;

[0141] Concatenating the to-be-processed logs of the same transaction in a single second system according to the log sequence mode;

[0142] Determine a matching relationship between log sequence patterns of each second system; the matching relationship of the log sequence pattern is used to represent logs belonging to the same transaction in the first system;

[0143] Determining a connection relationship between the second systems according to a matching relationship of the log sequence patterns;

[0144] According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction in the first system are connected.

[0145] Optionally, determining, according to the log information, a log concatenation task matching the log level further includes:

[0146] If the log information of the log to be processed contains a serial number but does not contain the serial number position information and the upstream and downstream connection relationship, the log concatenation task matching the second level is determined to perform structured processing on the log to be processed in the second system to extract the log template and log variables;

[0147] Filter the log template and the log variable according to the first filtering condition, and determine the serial number of the to-be-processed log representing the same transaction in a single second system from the log variable;

[0148] According to the serial number, the to-be-processed logs belonging to the same transaction in a single second system are connected in series;

[0149] determining a log sequence pattern of pending logs belonging to the same transaction in the second system;

[0150] Filter the log sequence pattern and the log variable according to the second filtering condition, and determine the matching relationship between the serial numbers of the to-be-processed logs representing the same transaction between the second systems from the log sequence pattern;

[0151] Determining the connection relationship between the second systems according to the matching relationship of the serial numbers of the logs to be processed;

[0152] According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction between the second systems are connected.

[0153] Optionally, determining, according to the log information, a log concatenation task matching the log level further includes:

[0154] If the log information of the log to be processed includes the serial number and the serial number position information and does not include the upstream and downstream connection relationship, the log concatenation task matching the third level is determined to be determining the serial numbers of the logs to be processed belonging to the same transaction between the second systems;

[0155] Determine the connection relationship between the second systems according to the serial number;

[0156] According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction in the first system are connected.

[0157] Optionally, determining, according to the log information, a log concatenation task matching the log level further includes:

[0158] If the log information of the log to be processed includes a serial number, serial number position information, and upstream and downstream connection relationships, the log concatenation task matching the fourth level is determined as: determining the logs to be processed belonging to the same transaction in a single second system according to the serial number, and concatenating the logs to be processed belonging to the same transaction in each second system;

[0159] According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction in the first system are connected in series.

[0160] Optionally, connecting the to-be-processed logs belonging to the same transaction in the first system according to the connection relationship between the second systems includes:

[0161] According to the connection relationship between the second systems, determine the upstream and downstream connection relationship and upstream and downstream connection positions of the to-be-processed logs belonging to the same transaction between the second systems;

[0162] According to the upstream and downstream connection relationship and the upstream and downstream connection positions, the to-be-processed logs belonging to the same transaction in the first system are connected.

[0163] Optionally, determining the upstream and downstream connection relationships and upstream and downstream connection positions between the second systems according to the connection relationships between the second systems includes:

[0164] Determine the time span of the logs to be processed belonging to the same transaction in the third system, and determine the time interval of the logs to be processed belonging to the same transaction in the fourth system; the time span is the difference between the log generation time of the first log to be processed and the last log to be processed belonging to the same transaction in the third system, and the time interval is the difference between the log generation time of two adjacent and continuous logs to be processed belonging to the same transaction in the fourth system; the third system and the fourth system belong to the second system; the third system and the fourth system have a connection relationship;

[0165] According to the time span and time interval, the upstream and downstream connection relationship and upstream and downstream connection positions of the logs to be processed between the third system and the fourth system having a connection relationship are determined.

[0166] Optionally, determining the upstream and downstream connection relationship and upstream and downstream connection positions of the logs to be processed between the third system and the fourth system having a connection relationship according to the time span and the time interval includes:

[0167] If the time span of the to-be-processed logs of the third system is smaller than the time interval of the to-be-processed logs of the fourth system, it is determined that the to-be-processed logs belonging to the same transaction in the third system are downstream of the to-be-processed logs belonging to the same transaction in the fourth system, and the position between two adjacent and continuous to-be-processed logs belonging to the same transaction in the fourth system is the upstream and downstream connection position of the to-be-processed logs belonging to the same transaction in the third system;

[0168] Otherwise, it is determined that the pending log belonging to the same transaction in the third system is upstream of the pending log belonging to the same transaction in the fourth system, and the position between two adjacent and continuous pending logs belonging to the same transaction in the third system is the upstream and downstream connection position of the pending log belonging to the same transaction in the fourth system.

[0169] The technical solution of the embodiment of the present invention determines the log concatenation task that matches the log level of the log to be processed through the serial number, serial number position information and upstream and downstream connection relationship in the log to be processed in the first system, so that the logs to be processed belonging to the same transaction in the first system are concatenated in chronological order and upstream and downstream connection relationships, thereby realizing a method for concatenating logs belonging to the same transaction in the system.

[0170] The log series connection device provided in the embodiment of the present invention can execute the log series connection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0171] Embodiment 3

[0172] Figure 4 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0173] like Figure 4As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0174] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0175] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The processor 11 executes the various methods and processes described above, such as the log concatenation method.

[0176] In some embodiments, the log concatenation method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the log concatenation method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to perform the log concatenation method in any other appropriate manner (e.g., by means of firmware).

[0177] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0178] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0179] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0180] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0181] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0182] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0183] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0184] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A log concatenation method, characterized in that: include: Determine log information of a log to be processed of the first system, the log information including a serial number, serial number position information and upstream and downstream connection relationship, the serial number is an identifier representing a transaction, the serial number position information is the position of the serial number in each log to be processed, and the upstream and downstream connection relationship is the connection relationship between each second system recording the log; the first system includes at least one second system; Determine the log level of the log to be processed according to the log information, wherein the log level is used to indicate the degree of perfection of the log information of the log to be processed; According to the log information, a log concatenation task matching the log level is determined; wherein different log levels are matched with different log concatenation tasks; the log concatenation task is used to concatenate the to-be-processed logs belonging to the same transaction in the first system according to the upstream and downstream connection relationship and the order of log generation; the log generation time is used to indicate the order in which the logs are recorded in the first system; The to-be-processed logs of the first system are concatenated according to the log concatenation task.

2. The method according to claim 1, characterized in that Determine the log level of the log to be processed according to the log information, including: If the log information of the log to be processed does not include the serial number, the serial number position information and the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the first level; If the log to be processed contains a serial number but does not contain the serial number position information and the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the second level; If the log to be processed includes the serial number and the position information of the serial number and does not include the upstream and downstream connection relationship, the log level of the log to be processed is determined to be the third level; If the log to be processed includes a serial number, serial number position information, and an upstream and downstream connection relationship, it is determined that the log level of the log to be processed is the fourth level.

3. The method according to claim 2, characterized in that Determining, according to the log information, a log concatenation task matching the log level, including: If the log information of the log to be processed does not include the serial number, the serial number position information and the upstream and downstream connection relationship, the log series task matching the first level is determined to be: determining the log sequence pattern belonging to the same transaction in the logs to be processed in each second system; the log sequence pattern is determined by the log template of the log to be processed; Concatenating the to-be-processed logs of the same transaction in a single second system according to the log sequence mode; Determine a matching relationship between log sequence patterns of each second system; the matching relationship of the log sequence pattern is used to represent logs belonging to the same transaction in the first system; Determining a connection relationship between the second systems according to a matching relationship of the log sequence patterns; According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction in the first system are connected.

4. The method according to claim 2, characterized in that: Determining, according to the log information, a log concatenation task matching the log level, further comprising: If the log information of the log to be processed contains a serial number but does not contain the serial number position information and the upstream and downstream connection relationship, the log concatenation task matching the second level is determined to perform structured processing on the log to be processed in the second system to extract the log template and log variables; Filter the log template and the log variable according to the first filtering condition, and determine the serial number of the to-be-processed log representing the same transaction in a single second system from the log variable; According to the serial number, the to-be-processed logs belonging to the same transaction in a single second system are connected in series; determining a log sequence pattern of pending logs belonging to the same transaction in the second system; Filter the log sequence pattern and the log variable according to the second filtering condition, and determine the matching relationship between the serial numbers of the to-be-processed logs representing the same transaction between the second systems from the log sequence pattern; Determining the connection relationship between the second systems according to the matching relationship of the serial numbers of the logs to be processed; According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction between the second systems are connected.

5. The method according to claim 2, characterized in that: Determining, according to the log information, a log concatenation task matching the log level, further comprising: If the log information of the log to be processed includes the serial number and the serial number position information and does not include the upstream and downstream connection relationship, the log concatenation task matching the third level is determined to be determining the serial numbers of the logs to be processed belonging to the same transaction between the second systems; Determine the connection relationship between the second systems according to the serial number; According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction in the first system are connected.

6. The method according to claim 2, characterized in that Determining, according to the log information, a log concatenation task matching the log level, further comprising: If the log information of the log to be processed includes a serial number, serial number position information, and upstream and downstream connection relationships, the log concatenation task matching the fourth level is determined as: determining the logs to be processed belonging to the same transaction in a single second system according to the serial number, and concatenating the logs to be processed belonging to the same transaction in each second system; According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction in the first system are connected in series.

7. The method according to claims 3-5, characterized in that: According to the connection relationship between the second systems, the to-be-processed logs belonging to the same transaction in the first system are connected, including: According to the connection relationship between the second systems, determine the upstream and downstream connection relationship and upstream and downstream connection positions of the to-be-processed logs belonging to the same transaction between the second systems; According to the upstream and downstream connection relationship and the upstream and downstream connection positions, the to-be-processed logs belonging to the same transaction in the first system are connected.

8. The method according to claim 7, characterized in that Determining the upstream and downstream connection relationships and upstream and downstream connection positions between the second systems according to the connection relationships between the second systems includes: Determine the time span of the logs to be processed belonging to the same transaction in the third system, and determine the time interval of the logs to be processed belonging to the same transaction in the fourth system; the time span is the difference between the log generation time of the first log to be processed and the last log to be processed belonging to the same transaction in the third system, and the time interval is the difference between the log generation time of two adjacent and continuous logs to be processed belonging to the same transaction in the fourth system; the third system and the fourth system belong to the second system; the third system and the fourth system have a connection relationship; According to the time span and time interval, the upstream and downstream connection relationship and upstream and downstream connection positions of the logs to be processed between the third system and the fourth system having a connection relationship are determined.

9. The method according to claim 8, characterized in that Determining the upstream and downstream connection relationship and upstream and downstream connection positions of the logs to be processed between the third system and the fourth system having a connection relationship according to the time span and the time interval includes: If the time span of the to-be-processed logs of the third system is smaller than the time interval of the to-be-processed logs of the fourth system, it is determined that the to-be-processed logs belonging to the same transaction in the third system are downstream of the to-be-processed logs belonging to the same transaction in the fourth system, and the position between two adjacent and continuous to-be-processed logs belonging to the same transaction in the fourth system is the upstream and downstream connection position of the to-be-processed logs belonging to the same transaction in the third system; Otherwise, it is determined that the pending log belonging to the same transaction in the third system is upstream of the pending log belonging to the same transaction in the fourth system, and the position between two adjacent and continuous pending logs belonging to the same transaction in the third system is the upstream and downstream connection position of the pending log belonging to the same transaction in the fourth system.

10. A log series connection device, characterized in that: include: A log information determination module is used to determine the log information of the to-be-processed log of the first system, wherein the log information includes a serial number, serial number position information, and an upstream and downstream connection relationship, wherein the serial number is an identifier representing a transaction, the serial number position information is the position of the serial number in each to-be-processed log, and the upstream and downstream connection relationship is the connection relationship between the second systems recording the logs; the first system includes at least one second system; and the second systems have an upstream and downstream relationship; A log level determination module, used to determine the log level of the log to be processed according to the log information of the log to be processed of the first system, wherein the log level is used to indicate the degree of perfection of the log information of the log to be processed; A log series task determination module is used to determine a log series task that matches the log level according to the log information; wherein different log levels match different log series tasks; the log series task is used to series the to-be-processed logs belonging to the same transaction in the first system according to the upstream and downstream connection relationship and the order of log generation; the log generation time is used to indicate the time when the log is recorded in the first system; The log concatenation module is used to concatenate the to-be-processed logs of the first system according to the log concatenation task.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the log concatenation method as described in any one of claims 1 to 9 is implemented.

12. A storage medium storing computer executable instructions, characterized in that: When the computer executable instructions are executed by a computer processor, they are used to perform the log concatenation method according to any one of claims 1 to 9.