Real-time business abnormity alarm and regulation and control system based on log keyword monitoring
By designing a real-time business exception alarm and control system based on log keyword monitoring, the problems of complex log monitoring, insufficient analysis capabilities, and insufficient data filling and prediction capabilities in the existing technology are solved, real-time monitoring, intelligent analysis and rapid response are achieved, data integrity and response speed are improved, and system flexibility and security are enhanced.
Patent Information
- Application Number
- CN202510284789.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-06-06
AI Technical Summary
The existing technology has problems in log monitoring with complex configuration, high cost, lack of intelligent analysis capabilities, insufficient data filling and prediction capabilities, low processing efficiency, and incomplete audit and backup functions.
A real-time business exception alarm and control system based on log keyword monitoring is designed, including a business control module, a log reading module, a threshold determination module, a warning module, a project identification module, an error processing unit, a local prediction module, an integration module and a data application module. The system realizes real-time monitoring, intelligent analysis and rapid response through dynamic configuration of access and control permissions, feature extraction and similarity analysis, local prediction models and automated data filling, complete audit and backup functions.
It improves the integrity and response speed of log data, reduces the need for manual intervention, enhances the flexibility and security of the system, realizes the rapid identification and processing of abnormal situations, and ensures data traceability and business continuity.
Smart Images

Figure CN120105162A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of log monitoring, and in particular to a real-time business abnormality alarm and regulation system based on log keyword monitoring. Background Art
[0002] With the development of technologies such as cloud computing, big data, and artificial intelligence, enterprises are increasingly relying on information systems to support their daily business and decision-making processes. These systems carry a large amount of business data and operation logs, and are in urgent need of effective monitoring and management. Enterprises usually need to monitor and manage the operation of various resource instances from a business perspective to ensure their efficient operation. These resource instances include but are not limited to hardware devices such as servers, network devices, security devices, and storage devices, as well as software programs such as related applications. Mastering the status of these resources is not only the basis for maintaining IT infrastructure, but also a key link in ensuring business continuity and stable performance.
[0003] In software development and operation and maintenance, logging is a crucial process. It not only helps troubleshooting, but also monitors system performance. Logs have become an indispensable part of systematic operation and maintenance. In the past, we would analyze the corresponding log files after a failure occurred, but the failure had already caused an impact. Real-time log monitoring can detect anomalies or errors in time, and notify the operation and maintenance personnel in time by setting alarm rules, and take corresponding measures;
[0004] Although traditional monitoring tools are powerful, they are often complex to configure and costly. They make it difficult to quickly conduct in-depth data analysis and lack the ability to intelligently analyze historical data, extract features, and perform similarity analysis. They make it difficult to effectively fill in and predict missing data. In traditional log management, audit and backup functions are often not perfect, which makes it difficult to track and recover data errors or security incidents. In the anomaly detection and response process, there are too many processing steps, resulting in low overall processing efficiency and difficulty in real-time response. Summary of the invention
[0005] 1. Technical issues to be solved
[0006] In view of the above-mentioned shortcomings of the prior art, the present invention provides a real-time business abnormality alarm and regulation system based on log keyword monitoring, which can effectively solve the problems of the prior art.
[0007] (II) Technical solution
[0008] To achieve the above objectives, the present invention is implemented through the following technical solutions:
[0009] The present invention discloses a real-time business abnormality alarm and control system based on log keyword monitoring, comprising:
[0010] The business control module is used to obtain the global control authority of each functional module, connect to the business access system, obtain the access authority of the business log file, and dynamically configure the access and control authority of each functional module according to business needs;
[0011] The log reading module is used to monitor a number of specified log files according to a preset period, collect and cache the latest log information, and support normalization and reading of log files in different formats;
[0012] The threshold determination module is used to set filtering conditions and monitoring indicators, preset abnormal determination standards, analyze the log data read by the log reading module, detect abnormal information in the log file, compare it with the set abnormal determination standards, and determine whether it exceeds the preset abnormal determination standards;
[0013] The warning module is used to set several alarm modes, receive the judgment result of the threshold judgment module, and when the judgment result exceeds the preset abnormal judgment standard, adjust the urgency of the alarm mode according to the severity of the abnormality and record the alarm history;
[0014] The project identification module is used to obtain the identification information in the abnormal log and automatically classify it into related business projects based on the identification information in the abnormal log;
[0015] The error processing unit is used to mark the error information of the abnormal part, retrieve the historical data of the business project of the abnormal source for similarity analysis, and extract features from the non-error part and the historical similar data set;
[0016] The local prediction module is used to build a local prediction model, predict the data that can be filled based on the features extracted by the error processing unit and the current error information, generate a number of candidate filling data, score the candidate filling data, and output the filling data with the highest score result;
[0017] The integration module is used to match the context without error according to the content to be filled in the current log file, and integrate and fill the filling data output by the local prediction module with the non-error part of the problem log;
[0018] The data application module is used to enter the data integrated by the integration module into the business system, replace the original log file, and provide auditing and backup of the replacement operation.
[0019] Furthermore, the threshold determination module is interactively connected to a tolerance module via a wireless network. The tolerance module dynamically sets the threshold of the abnormal determination standard of the threshold determination module, supports setting custom tolerances under different business scenarios and requirements, continuously monitors the abnormal fluctuation of the threshold determination module, and automatically adjusts the threshold of the abnormal determination standard based on the custom tolerance when the abnormal fluctuation increases or decreases.
[0020] Furthermore, during the judgment operation stage, the threshold judgment module triggers a jump based on the judgment result of the preset abnormal judgment standard. When the judgment result is a threshold that does not meet the abnormal judgment standard, it is deemed that there is no abnormality, and the module jumps to the log reading module for further operation. When the judgment result is a threshold that meets the abnormal judgment standard, it is deemed that there is an abnormality, and the module jumps to the warning module and the project identification module for further operation.
[0021] Furthermore, the alarm mode of the alarm module includes: SMS notification, email notification and system notification with preset content to the authenticated user.
[0022] Furthermore, the error processing unit is deployed with submodules at the lower level, and the submodules include: an error interception module, a history retrieval module and a comprehensive extraction module, the error interception module and the history retrieval module are interactively connected through a wireless network, and the history retrieval module and the comprehensive extraction module are interactively connected through a wireless network, wherein:
[0023] The error interception module is used to locate the line and context information where the exception occurs in the current log file, extract the error paragraph, and save the interception information;
[0024] The historical retrieval module is used to search for historical log data under the business items related to the current error section, classify and filter, match historical log data of similar types to the error information, and form a historical similar data set;
[0025] The comprehensive extraction module is used to form a feature matrix from the error-free part of the current log file and the historical similar data set for feature extraction.
[0026] Furthermore, the calculation formula for predicting the data that can be filled by the local prediction model in the local prediction module is:
[0027]
[0028] In the formula, Y represents the predicted output, β 0 represents the bias term of the model, n represents the number of features extracted from the feature vector of the error-free part, m represents the number of features extracted from the feature vector of the historical similar data set, and w represents the number of features extracted from the feature vector of the current error information. Represents the feature X with no error reporting i The relevant weight parameter, X i represents the i-th non-error partial feature, Represents similar characteristics to history j The relevant weight parameter, h j represents the jth historical similarity feature, Represents the current error feature y kThe relevant weight parameter, y k Represents the kth current error feature.
[0029] Furthermore, the local prediction model divides the data set into a training set and a test set based on the existing historical data, passes the training set features, actual error information and repair information into the local prediction model for training, learns the optimal model parameter weights, uses the test set to evaluate the trained local prediction model, and calculates the prediction error as a reference for adjusting the model parameters.
[0030] Furthermore, the integration module is interactively connected to a calling module via a wireless network, and the calling module is used to obtain the original text of the content to be filled in the current log file of the integration module, and provide guidance on the area to be filled in the original error part.
[0031] Furthermore, the data application module is interactively connected to a response module via a wireless network. The response module is used to receive data application results from the data application module, take the business control module as the transmission target, and feed back the data application results to the business control module. The user logs in to the business control module to read the application results in the log file.
[0032] Furthermore, the business control module is interactively connected to the log reading module through a wireless network, the log reading module is interactively connected to the threshold determination module through a wireless network, the threshold determination module is interactively connected to the warning module and the project identification module through a wireless network, the error processing unit is interactively connected to the project identification module and the local prediction module through a wireless network, the local prediction module is interactively connected to the integration module through a wireless network, and the integration module is interactively connected to the data application module through a wireless network.
[0033] (III) Beneficial effects
[0034] Compared with the known prior art, the technical solution provided by the present invention has the following beneficial effects:
[0035] 1. Through feature extraction and similarity analysis, the system can automatically extract key features from historical data and perform intelligent analysis on anomalies, enabling users to deeply understand the changing trends of log data and effectively support decision-making. It introduces local prediction models, intelligently fills in missing data, and generates candidate filling data. The automated filling method not only improves data integrity, but also reduces the need for manual intervention and improves response time.
[0036] 2. Through dynamic configuration of access and control permissions, it supports seamless integration and automated configuration, reducing the need for complex manual settings. The system flexibility enables users to quickly adjust to specific needs, reducing implementation costs, and provides comprehensive audit and backup functions. It automates the process of replacing and storing original logs, ensuring that any data operations are traceable, helping users to quickly track and recover when data errors or security incidents occur.
[0037] 3. By introducing an automated anomaly detection process, combined with dynamic threshold adjustment and multiple alarm methods to reduce steps, the response time is optimized. When encountering anomalies, the system can quickly identify and take graded responses to ensure timely problem resolution and rapid transmission of information between modules, ensuring that the system can monitor and respond quickly to abnormal situations in real time, avoiding delays caused by too many processing steps. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0039] Figure 1 It is a schematic diagram of the framework of the present invention;
[0040] Figure 2 It is a schematic diagram of the framework of the error processing unit in the present invention.
[0041] The numbers in the figure represent, respectively, 1. Business control module; 2. Log reading module; 3. Threshold determination module; 4. Warning module; 5. Project identification module; 6. Error processing unit; 61. Error interception module; 62. History retrieval module; 63. Comprehensive extraction module; 7. Local prediction module; 8. Integration module; 9. Data application module; 10. Response module; 11. Tolerance module; 12. Call module. DETAILED DESCRIPTION
[0042] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0043] The present invention will be further described below in conjunction with the embodiments.
[0044] Example 1
[0045] A real-time business abnormality alarm and control system based on log keyword monitoring in this embodiment, such as Figure 1 As shown, including:
[0046] Business control module 1 is used to obtain the global control authority of each functional module, connect to the business access system, obtain the access authority of the business log file, and dynamically configure the access and control authority of each functional module according to business needs; it provides centralized management of each functional module, ensures system security and flexibility, and supports dynamic configuration of access rights to adapt to different business needs;
[0047] Log reading module 2 is used to monitor a number of specified log files according to a preset period, collect and cache the latest log information, and support normalization and reading of log files of different formats; by regularly monitoring multiple log files and normalizing log files of different formats, the consistency of data processing and analysis efficiency are improved, and real-time data collection is supported;
[0048] The threshold determination module 3 is used to set filtering conditions and monitoring indicators, preset abnormality determination standards, analyze the log data read by the log reading module 2, detect abnormal information in the log file, compare it with the set abnormality determination standards, and determine whether it exceeds the preset abnormality determination standards; perform abnormality detection according to specific business needs, and allow dynamic adjustment of thresholds through wireless networks to adapt to changes in different scenarios;
[0049] The threshold determination module 3 is interactively connected to the tolerance module 11 through a wireless network. The tolerance module 11 dynamically sets the threshold of the abnormal determination standard of the threshold determination module 3, supports setting custom tolerances under different business scenarios and requirements, continuously monitors the abnormal fluctuation of the threshold determination module 3, and automatically adjusts the threshold of the abnormal determination standard when the abnormal fluctuation increases or decreases based on the custom tolerance; in the determination operation stage, the threshold determination module 3 triggers a jump based on the determination result of the preset abnormal determination standard. When the determination result is a threshold value that does not meet the abnormal determination standard, it is deemed that there is no abnormality, and jumps to the log reading module 2 for further operation. When the determination result is a threshold value that meets the abnormal determination standard, it is deemed that there is an abnormality, and synchronously jumps to the warning module 4 and the project identification module 5 for further operation; the alarm strategy is automatically adjusted according to the severity of the abnormality, which enhances the timeliness and effectiveness of the response, and the alarm history can be recorded for auditing;
[0050] The warning module 4 is used to set several alarm modes, receive the judgment result of the threshold judgment module 3, and when the judgment result exceeds the preset abnormal judgment standard, adjust the urgency of the alarm mode according to the severity of the abnormality and record the alarm history; the alarm mode includes: SMS notification, email notification and system notification of preset content to the authenticated user;
[0051] The project identification module 5 is used to obtain identification information in the abnormal log, and automatically classify it into relevant business projects based on the identification information in the abnormal log; automatically classifying the abnormal log using the identification information helps to reduce manual intervention, improve processing efficiency, and facilitate users to quickly locate and solve problems;
[0052] The error processing unit 6 is used to mark the error information of the abnormal part, retrieve the historical data of the business project of the abnormal source for similarity analysis, and extract features from the non-error part and the historical similar data set; marking and analyzing the error information and extracting features from the non-error part are helpful to discover potential system problems and improvement points, and improve the reliability of the system;
[0053] The local prediction module 7 is used to construct a local prediction model, predict the data that can be filled based on the features extracted by the error processing unit 6 and the current error information, generate a number of candidate filling data, and score the candidate filling data, and output the filling data with the highest score result; providing a more intelligent data filling method, which can effectively alleviate the problem of missing data and improve data integrity;
[0054] The integration module 8 is used to match the error-free context according to the content to be filled in the current log file, and integrate the filling data output by the local prediction module 7 with the error-free part of the problem log to fill in; the integration module 8 is interactively connected to the calling module 12 through a wireless network, and the calling module 12 is used to obtain the original text of the content to be filled in the current log file of the integration module 8, and provide guidance on the area to be filled in the original error part; the filling data is integrated with the error-free context to ensure that the filled data is consistent with the actual situation, thereby enhancing the consistency and accuracy of the data;
[0055] The data application module 9 is used to enter the data integrated by the integration module 8 into the business system, replace the original log file, and provide audit and backup of the replacement operation. The data application module 9 is interactively connected to the response module 10 via a wireless network. The response module 10 is used to receive the data application results of the data application module 9, take the business control module 1 as the transmission target, and feed back the data application results to the business control module 1. The user logs in to the business control module 1 to read the application results in the log file. While replacing the original log, it provides audit and backup functions to ensure the security and traceability of the data and provide support for subsequent audit and analysis.
[0056] As an implementation method in this embodiment, Figure 1 As shown, the business control module 1 is interactively connected to the log reading module 2 through a wireless network, the log reading module 2 is interactively connected to the threshold determination module 3 through a wireless network, the threshold determination module 3 is interactively connected to the warning module 4 and the project identification module 5 through a wireless network, the error processing unit 6 is interactively connected to the project identification module 5 and the local prediction module 7 through a wireless network, the local prediction module 7 is interactively connected to the integration module 8 through a wireless network, and the integration module 8 is interactively connected to the data application module 9 through a wireless network.
[0057] Compared with the existing technology, it can automatically adjust the threshold according to abnormal fluctuations, which is more flexible and accurate than the traditional static setting mechanism. It realizes the automation of multiple links such as log monitoring, anomaly detection, and data filling, reduces the need for manual intervention, and improves the processing speed. It introduces the concepts of feature extraction and local prediction models, so that the system can make more accurate judgments and warnings when facing complex data, flexibly adjust the alarm method according to the degree of abnormality, enhance the timeliness of response, and improve the security of the business.
[0058] Example 2
[0059] At other levels, this embodiment also provides an error processing unit 6, and the error processing unit 6 has submodules deployed at the lower level, such as Figure 2 As shown, the error processing unit 6 is deployed with submodules at the lower level, and the submodules include: an error interception module 61, a history retrieval module 62 and a comprehensive extraction module 63. The error interception module 61 is interactively connected with the history retrieval module 62 through a wireless network, and the history retrieval module 62 is interactively connected with the comprehensive extraction module 63 through a wireless network, wherein:
[0060] The error interception module 61 is used to locate the line and context information of the abnormality in the current log file, extract the error paragraph, and save the intercepted information; by effectively locating the line and context information of the abnormality, the system can quickly identify the specific problem, reducing the time and cost of manual retrieval, extracting the error paragraph and saving the intercepted information, providing rich context data, which is helpful for subsequent analysis and positioning;
[0061] The history retrieval module 62 is used to search for historical log data under the business items related to the current error section, classify and filter, match historical log data of similar types to the error information, and form a historical similar data set; by classifying and filtering the historical log data under the business items related to the current error section, the system can effectively use historical data, improve the accuracy of exception processing, match historical logs similar to the error information, and construct a historical similar data set, which provides a rich data foundation for subsequent feature extraction and pattern recognition;
[0062] The comprehensive extraction module 63 is used to form a feature matrix with the error-free part of the current log file and the historical similar data set to perform feature extraction. The error-free part and the historical similar data set are combined to form a feature matrix. This process can improve the efficiency and accuracy of feature extraction, thereby enhancing the scientific nature of subsequent analysis and decision-making. Through the analysis of the feature matrix, the system can discover potential business rules and associations, and assist in the prediction and forecasting of anomalies.
[0063] Compared with existing technologies, it integrates the location of abnormal logs, historical data matching and feature extraction to form an efficient workflow, reduce processing steps, and improve the overall response speed. Through intelligent analysis and feature extraction of historical data, it can more accurately support business decisions and reduce decision-making risks.
[0064] Example 3
[0065] In this embodiment, a calculation formula for predicting the data that can be filled by a local prediction model is provided, which is specifically:
[0066]
[0067] In the formula, Y represents the predicted output, which means the fillable data inferred by the model, β 0 represents the bias term of the model, indicating the predicted value when all input features are zero. n represents the number of features extracted from the feature vector of the error-free part, including the mean, standard deviation, maximum value, minimum value, and request processing time. m represents the number of features extracted from the feature vector of the historical similar data set, including the frequency, time distribution, and features of similar calls of historical errors. w represents the number of features extracted from the feature vector of the current error information, including the error code, specific error description, and occurrence time. Represents the feature X with no error reporting i The relevant weight parameter indicates the influence of the i-th feature on the final prediction, X i represents the i-th non-error partial feature, Represents similar characteristics to history j The relevant weight parameter represents the influence of the jth feature on the output, h j represents the jth historical similarity feature, Represents the current error feature y k The relevant weight parameter represents the influence of the kth feature on the output, y k Represents the kth current error feature;
[0068] Based on the existing historical data, the local prediction model divides the data set into a training set and a test set. The training set features, actual error information, and repair information are passed into the local prediction model for training, and the optimal model parameter weights are learned. The trained local prediction model is evaluated using the test set, and the prediction error is calculated as a reference for adjusting the model parameters.
[0069] Compared with the existing technology, the local prediction model can flexibly adjust the input according to different log features, such as non-error data, historical similar data and current error information, so that the model can adapt to a variety of data sources and data structures, focusing on local features rather than global features, thereby reducing the sensitivity to noise data. By focusing on the current error information and similar historical data, the accuracy of the prediction can be improved;
[0070] By effectively utilizing similar data from the past and extracting features from similar historical data sets, the model’s learning and prediction capabilities are enhanced, making it possible to identify and respond to repeated problems. Based on feature weighting and model structure, the impact of each feature on the final prediction can be explained more clearly. By combining current errors with historical data, the model can improve its ability to detect potential faults, thereby achieving faster problem response and fault recovery.
[0071] Working principle: When the system of the present invention is installed, the business control module 1 obtains the control authority and log access authority of the global function module, the log reading module 2 reads the target log file, the threshold determination module 3 detects the abnormal information in the log file, determines whether it exceeds the preset threshold, and sets its dynamic threshold through the tolerance module 11, and triggers it as needed;
[0072] When the threshold determination module 3 determines that there is an abnormality in the log file, the warning module 4 will give an alarm information feedback, and the project identification module 5 will determine the business project of the log abnormality source, and mark the local error part of the abnormality through the error interception module 61, and perform similarity analysis on the business project information of the abnormality source through the history retrieval module 62, and retrieve several data of the same type at the intercepted error to form a reference data set, and perform feature extraction on the non-error part of the problem log and the reference data set of its historical similar data through the comprehensive extraction module 63;
[0073] Through the local prediction module 7, a local prediction model is constructed, and the error part of the problem log is predicted and filled based on the features extracted from the non-error part of the log file and the reference data set of its historical similar data, and the filled data is output. The filled data and the non-error part of the problem log are filled in correspondence through the integration module 8, and the integrated data is output. The delivery path of the integrated data is provided by the calling module 12, and the integrated data is entered into the business system through the data application module 9 to replace the original log file. The data application status feedback is provided through the response module 10.
[0074] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A real-time business abnormality alarm and control system based on log keyword monitoring, characterized in that: include: The business control module (1) is used to obtain the global control authority of each functional module, connect to the business access system, obtain the business log file access authority, and dynamically configure the access and control authority of each functional module according to business needs; A log reading module (2) is used to monitor a number of designated log files according to a preset period, collect and cache the latest log information, and support reading after normalization of log files in different formats; A threshold determination module (3) is used to set filtering conditions and monitoring indicators, preset abnormality determination standards, analyze the log data read by the log reading module (2), detect abnormal information in the log file, compare it with the set abnormality determination standards, and determine whether it exceeds the preset abnormality determination standards; The warning module (4) is used to set a plurality of alarm modes, receive the determination result of the threshold determination module (3), and when the determination result exceeds the preset abnormal determination standard, adjust the urgency of the alarm mode according to the severity of the abnormality, and record the alarm history; A project identification module (5) is used to obtain identification information in the abnormal log and automatically classify it into relevant business projects based on the identification information in the abnormal log; An error processing unit (6) is used to mark the error information of the abnormal part, retrieve the historical data of the business project of the abnormal source for similarity analysis, and extract features from the non-error part and the historical similar data set; A local prediction module (7) is used to construct a local prediction model, predict the data that can be filled based on the features extracted by the error processing unit (6) and the current error information, generate a number of candidate filling data, and score the candidate filling data, and output the filling data with the highest score result; An integration module (8) is used to match the context without error according to the content to be filled in the current log file, and integrate and fill the filling data output by the local prediction module (7) with the non-error part of the problem log; The data application module (9) is used to input the data integrated by the integration module (8) into the business system, replace the original log file, and provide audit and backup of the replacement operation.
2. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The threshold determination module (3) is interactively connected to a tolerance module (11) via a wireless network. The tolerance module (11) dynamically sets a threshold value of an abnormal determination standard of the threshold determination module (3), supports setting a custom tolerance under different business scenarios and requirements, continuously monitors the abnormal fluctuation status of the threshold determination module (3), and automatically adjusts the threshold value of the abnormal determination standard based on the custom tolerance when the abnormal fluctuation increases or decreases.
3. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The threshold determination module (3) triggers a jump based on the determination result of the preset abnormal determination standard during the determination operation stage. When the determination result is a threshold value that does not meet the abnormal determination standard, it is deemed that there is no abnormality and the module jumps to the log reading module (2) for further operation. When the determination result is a threshold value that meets the abnormal determination standard, it is deemed that there is an abnormality and the module jumps to the warning module (4) and the project identification module (5) for further operation.
4. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The alarm mode of the alarm module (4) includes: SMS notification, email notification and system notification with preset content to the authenticated user.
5. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The error processing unit (6) is provided with submodules at a lower level, and the submodules include: an error interception module (61), a history retrieval module (62) and a comprehensive extraction module (63). The error interception module (61) and the history retrieval module (62) are interactively connected via a wireless network, and the history retrieval module (62) and the comprehensive extraction module (63) are interactively connected via a wireless network, wherein: An error interception module (61) is used to locate the line where the exception occurs and context information in the current log file, extract the error paragraph, and save the interception information; A history retrieval module (62) is used to search for historical log data under business items related to the current error reporting section, classify and filter, match historical log data of similar types to the error reporting information, and form a historical similar data set; The comprehensive extraction module (63) is used to form a feature matrix from the error-free part of the current log file and the historical similar data set to perform feature extraction.
6. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The calculation formula for predicting the data that can be filled by the local prediction model in the local prediction module (7) is: In the formula, Y represents the predicted output, β0 represents the bias term of the model, n represents the number of features extracted from the feature vector of the error-free part, m represents the number of features extracted from the feature vector of the historical similar data set, and w represents the number of features extracted from the feature vector of the current error information. Represents the feature X with no error reporting i The relevant weight parameter, X i represents the i-th non-error partial feature, Represents similar characteristics to history j The relevant weight parameter, h j represents the jth historical similarity feature, Represents the current error feature y k The relevant weight parameter, y k Represents the kth current error feature.
7. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The local prediction model divides the data set into a training set and a test set based on the existing historical data, passes the training set features, actual error information and repair information into the local prediction model for training, learns the optimal model parameter weights, uses the test set to evaluate the trained local prediction model, and calculates the prediction error as a reference for model parameter adjustment.
8. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The integration module (8) is interactively connected to a calling module (12) via a wireless network. The calling module (12) is used to obtain the original text of the content to be filled in the current log file of the integration module (8) and provide guidance on the area to be filled in the original error part.
9. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The data application module (9) is interactively connected to a response module (10) via a wireless network. The response module (10) is used to receive the data application result of the data application module (9), take the business control module (1) as the transmission target, and feed back the data application result to the business control module (1). The user logs in to the business control module (1) to read the application result in the log file.
10. A real-time business abnormality alarm and control system based on log keyword monitoring according to claim 1, characterized in that: The business control module (1) is interactively connected to the log reading module (2) via a wireless network, the log reading module (2) is interactively connected to the threshold determination module (3) via a wireless network, the threshold determination module (3) is interactively connected to the warning module (4) and the project identification module (5) via a wireless network, the error processing unit (6) is interactively connected to the project identification module (5) and the local prediction module (7) via a wireless network, the local prediction module (7) is interactively connected to the integration module (8) via a wireless network, and the integration module (8) is interactively connected to the data application module (9) via a wireless network.