Log content visualization updating method and device, equipment and medium

By obtaining log feature values ​​and extracting update content fields, the problem of untimely update log data is solved, realizing instant update and resource optimization.

CN120162215APending Publication Date: 2025-06-17BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510247042.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The prior art has problems such as untimely or invalid updates in the extraction and visual update of log data, resulting in waste of resources.

Method used

By obtaining the current log characteristic value of the candidate audit log, determine the candidate audit log with the content changed as the target audit log, and perform field extraction on it to determine the updated content field. Update the visual view instantly based on the update content field.

Benefits of technology

Realize the content of instant update log visual view, improve the update efficiency of visual view, and avoid resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162215A_ABST
    Figure CN120162215A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a log content visualization updating method and device, equipment and a medium, and the method comprises the steps: obtaining a current log feature value of a candidate audit log, and determining the candidate audit log with changed content as a target audit log according to the current log feature value, the current log feature value is used for representing whether the content of the candidate audit log is changed or not; field extraction is conducted on the target audit log, updated content fields are determined, and the updated content fields comprise content fields of the target audit log in the time period with content changes; and performing content updating on the current visual view according to the updated content field. According to the technical scheme provided by the invention, whether the log content is changed or not can be monitored, and when the log content is changed, the visual view of the log is updated in time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data visualization, and particularly to a method, device, equipment and medium for updating the visualization of log content. Background Art

[0002] Log audit visualization is an important technical means for network security and operation and maintenance management under the background of digital transformation. With the increasing complexity of enterprise information systems, the manual analysis efficiency of massive log data is low, and it is difficult to quickly locate abnormal behaviors in traditional tabular logs. Visualization technology helps the security team to instantly understand the system status and quickly identify risk events such as attack traceability and abnormal logins by converting log data into intuitive forms such as bar charts, heat maps and relationship graphs.

[0003] However, for the extraction of log data currently, the log content is generally extracted regularly. Under the regular extraction rule, it may lead to untimely update of the required visualization data, or it is found that the log content has not changed after extraction, wasting resources. Summary of the Invention

[0004] The present invention provides a method, device, equipment and medium for updating the visualization of log content. Through the technical solution of the present invention, it is possible to monitor whether the log content has changed, and when the log content has changed, immediately update the visualization view of the log.

[0005] In a first aspect, an embodiment of the present invention provides a method for updating the visualization of log content, including:

[0006] Obtain the current log feature value of the candidate audit log, and determine the candidate audit log with content change as the target audit log according to the current log feature value, where the current log feature value is used to represent whether the content of the candidate audit log has changed;

[0007] Extract fields from the target audit log to determine the updated content fields, where the updated content fields include the content fields of the target audit log during the time period with content change;

[0008] Update the content of the current visualization view according to the updated content fields.

[0009] In a second aspect, an embodiment of the present invention provides a device for updating the visualization of log content, including:

[0010] An obtaining module, configured to obtain the current log feature value of the candidate audit log, and determine the candidate audit log with content change as the target audit log according to the current log feature value, where the current log feature value is used to represent whether the content of the candidate audit log has changed;

[0011] An extraction module, configured to extract fields from the target audit log to determine updated content fields, where the updated content fields include the content fields of the target audit log during a time period when content changes occur.

[0012] An update module, configured to update the content of the current visualization view according to the updated content fields.

[0013] In a third aspect, an embodiment of the present invention provides an electronic device, where the electronic device includes:

[0014] At least one processor; and,

[0015] A memory communicatively connected to the at least one processor; where,

[0016] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the update method for visualizing log content according to any one of the embodiments of the present invention.

[0017] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, where the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the update method for visualizing log content according to any one of the embodiments of the present invention when executed by a processor.

[0018] An embodiment of the present invention provides an update method, apparatus, device, and medium for visualizing log content. The method includes: obtaining a current log feature value of a candidate audit log, and determining, according to the current log feature value, the candidate audit log with content changes as a target audit log, where the current log feature value is used to characterize whether the content of the candidate audit log changes; extracting fields from the target audit log to determine updated content fields, where the updated content fields include the content fields of the target audit log during a time period when content changes occur; and updating the content of the current visualization view according to the updated content fields. Specifically, through the current log feature value of the candidate audit log, the target audit log with content changes can be determined, and then the content of the current visualization view can be updated through the updated content fields of the target audit log. Through the technical solution of the embodiment of the present invention, the log with content changes can be determined immediately, and the content of the visualization view can be updated immediately, improving the update efficiency of the visualization view. Description of the Drawings

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0020] Figure 1 It is a flowchart of a method for updating the visualization of log content provided in the first embodiment of the present invention;

[0021] Figure 2 It is a flowchart of a method for updating the visualization of log content provided in the second embodiment of the present invention;

[0022] Figure 3 It is a schematic structural diagram of a device for updating the visualization of log content provided in the third embodiment of the present invention;

[0023] Figure 4 It is a schematic structural diagram of an electronic device provided in the fourth embodiment of the present invention. Detailed implementation manners

[0024] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0026] It should be noted that in the technical solutions of the present disclosure, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information and other processes all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0027] Embodiment 1

[0028] Figure 1 This is a flowchart of an update method for visualizing log content provided by Embodiment 1 of the present invention. This method can be specifically applicable to the field of visual monitoring of log content, and can also be applicable to the field of monitoring log data of distributed servers. This method can be executed by an update device for visualizing log content, and this device can be composed of software and / or hardware and is configured in a computer or a server.

[0029] As Figure 1 shown, it includes:

[0030] Step 110: Obtain the current log feature value of the candidate audit log, and determine the target audit log from the candidate audit logs with content changes according to the current log feature value, where the current log feature value is used to represent whether the content of the candidate audit log has changed.

[0031] Specifically, the current log feature value is used to represent whether the content of the candidate audit log has changed. The current log feature value can be a hash value. If the current log feature value changes, it indicates that the content of the candidate audit log has changed. Then, the candidate audit log can be determined as the target audit log. By the above method, it is avoided that the obtained audit log is an invalid log with unchanged content. The current log feature value is stored in a pre-established feature value record table. The pre-established feature value record table is a data table for storing log feature values established in advance.

[0032] Step 120: Extract fields from the target audit log to determine the updated content fields, where the updated content fields include the content fields of the target audit log during the time period when content changes occur.

[0033] Specifically, since the purpose of the embodiment of the present application is to update the visual view of the target audit log in real time, therefore, each update only needs to extract the log content during the time period when the content of the target audit log changes, that is, the updated content fields, and use them for updating the visual view. In this way, it is possible to avoid extracting all log content at once to reduce resource consumption.

[0034] Optionally, this step includes:

[0035] Determine the update time period according to the generation time of the current log feature value and the historical log feature value;

[0036] Based on the preset extraction fields, extract fields from the log content within the update time period of the target audit log to determine the updated content fields.

[0037] Among them, the update time period is the time period between the generation time of the historical log feature value and the generation time of the current log feature value. Exemplarily, the generation time of the historical log feature value is 13:00, and the generation time of the current log feature value is 15:00. Therefore, the update time period is 13:00 - 15:00. That is, only the log content generated between 13:00 and 15:00 in the target audit log needs to be extracted.

[0038] Specifically, the time period during which the log content changes can be determined based on the generation times of the current log feature value and the historical log feature value, and then only the log content in this time period is extracted for fields, so as to reduce the resource amount required for field extraction. Among them, the historical log feature value can be obtained through a pre-established feature value record table, which records the log feature values at different times. Optionally, the algorithm for field extraction can be a regular extraction algorithm.

[0039] Step 130: Update the content of the current visualization view according to the updated content fields.

[0040] Optionally, the quantity statistics and quantity analysis can be performed on the updated content fields of each type or each dimension, and then the corresponding update graph is generated, and the current visualization view is updated through the update graph. For example, a pie chart of the ratio of the number of users logging in and logging out between 13:00 and 15:00 is generated. Then the pie chart is updated into the current visualization view.

[0041] Optionally, the method for updating the content of the current visualization view includes:

[0042] Determine the visualization data corresponding to the current visualization view; update the visualization data according to the updated content fields, and generate a visualization view based on the updated visualization data.

[0043] Among them, the visualization data is the graph data corresponding to the visualization view.

[0044] Specifically, the visualization view displays the log data of a preset time period (such as 5 days) in real time. When the updated content fields (such as the data of the current day) are determined, the earliest day's visualization data within the time window is automatically replaced to ensure that the visualization view always presents the complete data set of the latest time period and maintains the real-time monitoring.

[0045] An embodiment of the present invention provides a method for updating the visualization of log content. The method includes: obtaining the current log feature value of a candidate audit log, and determining the candidate audit log with content changes as the target audit log according to the current log feature value, where the current log feature value is used to characterize whether the content of the candidate audit log has changed; extracting fields from the target audit log to determine the updated content fields, where the updated content fields include the content fields of the target audit log during the time period when content changes occur; and updating the content of the current visualization view according to the updated content fields. Specifically, through the current log feature value of the candidate audit log, the target audit log with content changes can be determined, and then the content of the current visualization view can be updated through the updated content fields of the target audit log. Through the technical solution of the embodiment of the present invention, the log with content changes can be determined immediately, and the content of the visualization view can be updated immediately, improving the update efficiency of the visualization view.

[0046] Embodiment 2

[0047] Figure 2 It is a flowchart of the method for updating the visualization of log content provided by Embodiment 2 of the present invention. Based on the above embodiment, the method for determining the target audit log and the specific method for updating the content of the current visualization view according to the updated content fields are further defined.

[0048] As Figure 2 shown, it includes:

[0049] Step 210, obtain the historical log feature value of the candidate audit log from a pre-established feature value record table.

[0050] Among them, the feature value record table records the historical log feature values of candidate audit logs at each time point.

[0051] Step 220, if the difference between the current log feature value and the historical log feature value exceeds a preset threshold, determine the candidate audit log as the target audit log.

[0052] Among them, the preset threshold is used to characterize the degree of content change of the candidate audit log. It should be noted that if only one punctuation mark is added to the candidate audit log, its log feature value will still change, but at this time, there is no increase in key data in the log content. Therefore, the establishment of the preset threshold can avoid frequent log extraction operations and avoid invalid extraction.

[0053] Specifically, the difference result can be determined by comparing the current log feature value with the historical log feature value. If the difference result is greater than the preset threshold, it means that a large number of changes have occurred in the candidate audit log, and it needs to be determined as the target audit log.

[0054] Step 230: Extract fields from the target audit log to determine the updated content fields.

[0055] Step 240: Determine each target sub-view associated with each field type in the visual view according to the field types covered by the updated content fields.

[0056] Among them, each sub-view of the visual view is generated by fields of different field types. Exemplarily, for example, the field corresponding to the sub-view reflecting the alarm frequency is the field of the alarm type, and the field corresponding to the sub-view reflecting the login frequency is the field of the login type. It should be noted that the corresponding relationship between different types of fields and sub-views is preset and will not be limited here. Further, each sub-view corresponds to different preset metrics and business scenarios. Among them, the preset metrics represent objects in different dimensions of log auditing, such as user metrics and hardware resource metrics, etc. The business scenario represents different dimensions of business scenarios under any preset metric. For example, for user metrics, the associated business scenarios may include log collection and analysis, user login analysis, function access analysis, monitoring and alarm analysis, field extraction analysis, search and statistics analysis, and system status analysis.

[0057] Specifically, the same log data can be analyzed for different business scenarios and different preset metrics, and then sub-views reflecting different information are generated. Further, since the field content included in the updated content fields may only be able to update a specific number of sub-views, it is necessary to determine the sub-views to be updated this time according to the field types covered by the updated content fields. Exemplarily, if the field types covered by the updated content fields include alarm fields and login fields, it can be explained that the target sub-views to be updated this time may include the alarm sub-view and the login sub-view.

[0058] Step 250: For any target sub-view, determine the preset metric and business scenario corresponding to the target sub-view.

[0059] Step 260: Determine the target content fields from the updated content fields according to the preset metric, business scenario of the target sub-view, and the field type corresponding to the target sub-view.

[0060] Specifically, the updated content fields may include fields of multiple field types. Therefore, it is necessary to determine the target content fields for updating the target sub-view from the updated content fields according to the preset metric, business scenario of the target sub-view, and the field type corresponding to the target sub-view.

[0061] For example, for the analysis of the user login scenario under user metrics, the target content fields required are the online and offline records of the user and the online time, etc.

[0062] In this way, the target content fields required for updating each target sub-view can be determined to improve the update efficiency of the sub-view.

[0063] Step 270: Cluster the target content fields according to the clustering rules corresponding to the business scenario to obtain multiple clustering clusters corresponding to the business scenario.

[0064] Among them, the clustering rule is the classification rule for the target content fields based on the business scenario. If the target content field is a user behavior field, the clustering rule can be a specific user behavior, such as addition, deletion, modification, and query. Furthermore, different user behaviors can be clustered to generate multiple clustering clusters corresponding to the business scenario. For example, clustering clusters corresponding to addition, deletion, modification, and query behaviors are generated.

[0065] Step 280: Generate an update graph according to the number of target content fields in the clustering cluster, and update the target sub-view according to the update graph.

[0066] Specifically, the information ratio of the data information represented by the clustering cluster can be determined according to the target content field of the clustering cluster, and then the update graph is generated. Further, the update operation can be to connect the update graph behind the target sub-view, or to replace the target sub-view with the update graph.

[0067] Exemplarily, if the target content field of the clustering cluster represents the addition operation of users, the ratio of the addition operation can be determined according to the total number of user operation behaviors and the number of addition operations, and then a ratio graph is generated.

[0068] It should be noted that the update operation may further include:

[0069] Performing aggregation analysis on the log data associated with the sub-view and the newly added content fields, and dynamically updating the view content according to the analysis results. For example, the current sub-view shows the user login frequency in the recent 5 days, and the newly added field is the data of the current day. The system automatically eliminates the record of the oldest first day, aggregates the data of the recent 4 days and the data of the current day to generate a new 5-day data set, and then updates the original sub-view according to the sub-view corresponding to the new 5-day data set.

[0070] Furthermore, due to the numerous dimensions of log data analysis, a large number of different visual views will be generated, and the required data volume is extremely large. However, in actual use, users usually only view some sub-views, resulting in waste of resources due to a large number of idle views. For this reason, the present solution adopts an on-demand loading mechanism, and the specific implementation is as follows.

[0071] Optionally, the update method for visualizing the log content in the embodiments of the present invention further includes:

[0072] In response to an interaction operation on the hardware identification field, according to the target audit log corresponding to the hardware identification field, extract the hardware information field of the target audit log, where the visualization view includes a hardware device set, and the hardware device set includes a hardware identification field;

[0073] Generate a hardware sub-view according to the hardware information field and the hardware identification.

[0074] Among them, the hardware identification field is the device MAC address or the unique serial number, which is used to identify different devices in the visualization view; the interaction operation can be a click operation.

[0075] Specifically, the visualization view displays the identification fields of the hardware device set. When the user clicks on a certain identification field, the system dynamically extracts the corresponding hardware information field from the associated target audit log through a pre-built field-log mapping table, and then generates a hardware sub-view in real time based on these fields. This post-extraction mechanism (on-demand loading mechanism) is only triggered when the user requests to obtain specific data, avoiding resource waste caused by loading all data at once.

[0076] Optionally, determine the hardware identification field as the title of the hardware sub-view, and fill the corresponding area of the hardware sub-view with the hardware information field, where the types of the hardware information fields corresponding to different areas of the hardware sub-view are different.

[0077] The embodiment of the present invention provides a method for updating the visualization of log content. This method effectively filters out non-critical content changes and reduces the ineffective extraction of log content by comparing the differences in log feature values and combining with a preset threshold. Further, this method combines the on-demand loading mechanism to dynamically update the sub-view, which can significantly reduce the system resource consumption while ensuring the real-time performance of the audit log visualization.

[0078] Embodiment III

[0079] Figure 3 It is a schematic structural diagram of a device for visualizing log content provided by Embodiment III of the present invention. This device is used to execute any one of the methods for visualizing log content in the embodiments of the present invention. As Figure 3 shown, the device includes:

[0080] An acquisition module 310, configured to acquire the current log feature value of the candidate audit log, and determine the candidate audit log with content changes as the target audit log according to the current log feature value, where the current log feature value is used to characterize whether the content of the candidate audit log has changed.

[0081] An extraction module 320 is configured to extract fields from the target audit log to determine updated content fields, where the updated content fields include the content fields of the target audit log during a time period when content changes occur.

[0082] An update module 330 is configured to update the content of the current visualization view according to the updated content fields.

[0083] An embodiment of the present invention provides an update device for visualizing log content. The device includes: obtaining a current log feature value of a candidate audit log, and determining, according to the current log feature value, the candidate audit log with content changes as the target audit log, where the current log feature value is used to characterize whether the content of the candidate audit log changes. Extracting fields from the target audit log to determine updated content fields, where the updated content fields include the content fields of the target audit log during a time period when content changes occur. Updating the content of the current visualization view according to the updated content fields. Specifically, through the current log feature value of the candidate audit log, the target audit log with content changes can be determined, and then the content of the current visualization view can be updated through the updated content fields of the target audit log. Through the technical solution of the embodiment of the present invention, the log with content changes can be determined immediately, and the content of the visualization view can be updated immediately, improving the update efficiency of the visualization view.

[0084] Optionally, the obtaining module 310 includes:

[0085] A determination unit is configured to determine the current log feature value of the candidate audit log according to the log content of the candidate audit log.

[0086] A query unit is configured to obtain the historical log feature value of the candidate audit log from a pre-established feature value record table.

[0087] A comparison unit is configured to determine the candidate audit log as the target audit log if the difference between the current log feature value and the historical log feature value exceeds a preset threshold.

[0088] Optionally, the determination unit specifically includes:

[0089] A conversion subunit is configured to convert the log content of the candidate audit log into binary data.

[0090] A calculation subunit is configured to calculate a feature value for the binary data through a preset hash function to determine the current log feature value.

[0091] Optionally, the extraction module 320 specifically includes:

[0092] An update time period determination unit for determining an update time period according to the generation times of the current log feature value and the historical log feature value.

[0093] An update content field determination unit for performing field extraction on the log content within the update time period of the target audit log based on preset extraction fields to determine update content fields.

[0094] Optionally, each sub-view of the visualization view is generated by fields of different field types, and the sub-views correspond to different preset metrics and business scenarios.

[0095] The update module 330 includes:

[0096] An association unit for determining each target sub-view associated with each field type in the visualization view according to each field type covered by the update content fields.

[0097] A determination unit for determining, for any target sub-view, the preset metric and business scenario corresponding to the target sub-view.

[0098] A target content field determination unit for determining target content fields from the update content fields according to the preset metric, business scenario of the target sub-view, and the field type corresponding to the target sub-view.

[0099] A clustering unit for clustering the target content fields according to the clustering rules corresponding to the business scenario to obtain multiple clustering clusters corresponding to the business scenario.

[0100] An update unit for generating an update graph according to the number of target content fields in the clustering cluster and updating the target sub-view according to the update graph.

[0101] Optionally, the update device for visualizing log content further includes a post-extraction module, and the post-extraction module includes:

[0102] A receiving unit for, in response to an interaction operation on the hardware identification field, extracting the hardware information field of the target audit log according to the target audit log corresponding to the hardware identification field.

[0103] A generation unit for generating a hardware sub-view according to the hardware information field and the hardware identification.

[0104] Optionally, the generation unit is specifically configured to determine the hardware identification field as the title of the hardware sub-view and fill the corresponding area of the hardware sub-view with the hardware information field, where the types of the hardware information fields corresponding to different areas of the hardware sub-view are different.

[0105] The update device for visualizing log content provided by the embodiments of the present invention can execute the update method for visualizing log content provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0106] Embodiment 4

[0107] Figure 4 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0108] As Figure 4 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor, and the processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0109] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0110] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the method for updating the visualization of log content.

[0111] In some embodiments, the method for updating the visualization of log content can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method for updating the visualization of log content described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the method for updating the visualization of log content by any other suitable means (e.g., by means of firmware).

[0112] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor, that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0113] The computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0114] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0115] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0116] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0117] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0118] It should be understood that various forms of processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0119] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A log content visualization updating method, characterized in that: include: Obtaining a current log feature value of the candidate audit log, and determining the candidate audit log with changed content as the target audit log according to the current log feature value, wherein the current log feature value is used to indicate whether the content of the candidate audit log has changed; Performing field extraction on the target audit log to determine an updated content field, wherein the updated content field includes a content field of the target audit log within a time period in which content changes occur; Update the content of the current visualization view according to the update content field.

2. The method according to claim 1, characterized in that The step of determining, according to the current log feature value, a candidate audit log with content change as a target audit log includes: Acquire the historical log characteristic value of the candidate audit log from a pre-established characteristic value record table; If the difference between the current log feature value and the historical log feature value exceeds a preset threshold, the candidate audit log is determined as a target audit log.

3. The method according to claim 2, characterized in that The extracting fields from the target audit log to determine the update content fields includes: Determine the update time period according to the generation time of the current log characteristic value and the historical log characteristic value; Based on the preset extraction fields, field extraction is performed on the log content within the target audit log update time period to determine the update content field.

4. The method according to claim 1, characterized in that Each sub-view of the visualization view is generated by fields of different field types, and each sub-view corresponds to a different preset indicator and business scenario; The updating of the content of the current visualization view according to the update content field includes: According to the field types covered by the update content field, determine the target sub-views associated with the field types in the visualization view; For any target sub-view, determine the preset indicators and business scenarios corresponding to the target sub-view; Determining a target content field from the update content field according to preset indicators of the target subview, business scenarios, and field types corresponding to the target subview; Clustering the target content fields according to the clustering rules corresponding to the business scenarios to obtain a plurality of clustering clusters corresponding to the business scenarios; An update graph is generated according to the number of target content fields of the clusters, and the target sub-view is updated according to the update graph.

5. The method according to claim 1, characterized in that: The updating of the content of the current visualization view according to the update content field includes: Determine visualization data corresponding to the current visualization view; The visualization data is updated according to the update content field, and a visualization view is generated according to the updated visualization data.

6. The method according to claim 1, characterized in that Also includes: The visualization view includes a hardware device set, and the hardware device set includes a hardware identification field; In response to the interactive operation on the hardware identification field, extracting the hardware information field of the target audit log according to the target audit log corresponding to the hardware identification field; A hardware subview is generated according to the hardware information field and the hardware identifier.

7. The method according to claim 6, characterized in that The generating of the hardware subview according to the hardware information field and the hardware identifier includes: The hardware identification field is determined as the title of the hardware sub-view, and the corresponding area of ​​the hardware sub-view is filled with the hardware information field, wherein different areas of the hardware sub-view correspond to different types of hardware information fields.

8. A log content visualization updating device, characterized in that: include: An acquisition module, used to acquire a current log feature value of a candidate audit log, and determine the candidate audit log with changed content as a target audit log according to the current log feature value, wherein the current log feature value is used to indicate whether the content of the candidate audit log has changed; An extraction module, configured to extract fields from the target audit log and determine an updated content field, wherein the updated content field includes a content field of the target audit log within a time period in which content changes occur; The update module is used to update the content of the current visualization view according to the update content field.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the log content visualization updating method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the log content visualization updating method according to any one of claims 1 to 7 when executed.