Operation log recording method and device based on database monitoring

Through a database monitoring method, the application buried point log and the monitoring database change information are obtained, and the application operation log is generated in combination with the analysis rules. The impact of operation log recording on the performance of the business system and database in the existing technology is solved, and efficient and low-impact operation log recording is achieved.

CN120196512APending Publication Date: 2025-06-24创优数字科技(广东)有限公司
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510418616.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing operation logging scheme inserts logging statements into the business logic code, resulting in a significant impact on the intrusion of the business system and database performance. An efficient and low-impact method is urgently needed to realize the recording of system operation logs.

Method used

The operation log recording method based on database monitoring is adopted. By obtaining application buried point logs and monitoring database change information, and analyzing database operation events in combination with preset analysis rules, generating application operation logs, real-time monitoring of data changes and recording operation logs.

Benefits of technology

It realizes that the database operation log information is captured and recorded in real time without interfering with the normal operation of the database, reducing the impact on database performance, while ensuring the consistency and integrity of the logs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120196512A_ABST
    Figure CN120196512A_ABST
Patent Text Reader

Abstract

The invention discloses an operation log recording method based on database monitoring, and the method comprises the steps: carrying out the buried point reporting of a log according to a preset configuration rule, caching an application buried point log according to a log buried point identifier, and enabling the application buried point log to record a business logic and a user operation from an application level according to a buried point position sequence. Information such as interface calling, user operation and execution results can be clearly recorded, meanwhile, data change information is obtained through database monitoring, data changes are accurately reflected, and a final application operation log generated by combining the two records application operation behaviors and reflects actual changes of the database at the same time; log recording does not need to be directly carried out on the database level, the influence on database performance is minimized, and meanwhile the consistency and integrity of logs are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to information maintenance technology, and in particular relates to an operation log recording method and device based on database monitoring. Background Art

[0002] In modern software systems, operation log recording is an important function. Monitoring and recording business data is of great significance for ensuring data security, auditing, and troubleshooting for developers and operation and maintenance personnel.

[0003] The existing operation log recording scheme mainly inserts log recording statements into the business logic code. When an operation occurs, the corresponding log recording statement is triggered to execute and the operation information is written into the log file or database. If detailed records are required before and after the data operation, the data needs to be queried before the data is updated. After the database is updated, the modified data needs to be queried again, and then the information of the two data is integrated and saved. This method has a great impact on the intrusion of the business system and the performance of the database. Therefore, there is an urgent need for an efficient and low-impact method to realize the recording of system operation logs. Summary of the invention

[0004] Based on this, the present invention aims to propose an operation log recording method and device based on database monitoring, which can capture and record the operation log information of the database in real time without interfering with the normal operation of the database, so as to realize real-time monitoring of data changes and record operation logs.

[0005] In a first aspect, the present invention provides an operation log recording method based on database monitoring, comprising:

[0006] Obtain application tracking logs, which are cached according to the log tracking identifiers.

[0007] Monitor application database change information and obtain database operation events;

[0008] Analyze database operation events according to preset analysis rules and generate data analysis results;

[0009] Generate application operation logs based on application tracking logs and data analysis results.

[0010] Furthermore, obtaining application tracking logs includes:

[0011] Get the log ID;

[0012] Get application tracking logs based on log identifiers.

[0013] Furthermore, the application database change information is monitored and the database operation events obtained include:

[0014] Monitor the binary log in the application database, and obtain the data table identifier and data snapshot information according to the binary log. The data snapshot information includes the data before and after the change of the data fields.

[0015] Furthermore, parse the database operation events according to the preset parsing rules, and generate data parsing results including:

[0016] Determine the target monitored data fields according to the preset parsing rules and the data table identifier;

[0017] Determine the data before and after the change corresponding to the target monitored data fields in the data snapshot information;

[0018] Generate data parsing information according to the data before and after the change of the target monitored data fields.

[0019] Furthermore, generate data parsing results according to the data before and after the change of the target monitored data fields, including:

[0020] Compare whether the data before and after the change of the target monitored data fields is consistent. If they are consistent, do not record the data of the target monitored data fields, and the data corresponding to the target monitored data fields is not recorded in the data parsing results. Otherwise, record the data change result of the target monitored data fields as the data parsing result.

[0021] Furthermore, generate application operation logs according to the application buried point logs and the data parsing results, including:

[0022] Parse the application buried point logs to obtain the full log information;

[0023] Parse out the data change result of the target monitored data fields from the data parsing results;

[0024] Aggregate the full log information and the data change result into application operation logs.

[0025] Furthermore, the full log information includes business operation descriptions, request parameters, request addresses, operation execution results, operation execution times, and log version identifiers.

[0026] Furthermore, aggregating the full log information and the data change result into application operation logs includes:

[0027] Convert the data change result into a preset log format to obtain the data change result in the target format;

[0028] Aggregate the full log information and the data change result in the target format into application operation logs.

[0029] In a second aspect, the present invention provides an operation log recording device based on database monitoring, including:

[0030] A buried point log acquisition module, configured to acquire application buried point logs, and the application buried point logs are cached according to log buried point identifiers;

[0031] A data monitoring module, configured to monitor application database change information and acquire database operation events;

[0032] A data parsing module, configured to parse database operation events according to preset parsing rules to generate a data parsing result;

[0033] An operation log generation module, configured to generate application operation logs according to application buried point logs and data parsing results.

[0034] In a third aspect, the present invention provides an electronic device, including a memory storing computer-executable instructions and a processor, and when the computer-executable instructions are executed by the processor, the device executes the steps of the operation log recording method based on database monitoring provided in the first aspect.

[0035] In a fourth aspect, the present invention provides a readable storage medium storing a computer-executable program, and when the program is executed, the steps of the operation log recording method based on database monitoring provided in the first aspect can be implemented.

[0036] Compared with the prior art, the present invention has the following beneficial effects:

[0037] The present invention provides an operation log recording method based on database monitoring, which reports buried points for logs according to preset configuration rules, thereby caching application buried point logs according to log buried point identifiers. The application buried point logs record business logic and user operations in sequence according to the buried point positions at the application level, and can clearly record information such as interface calls, user operations, and execution results. At the same time, data change information is obtained through database monitoring to accurately reflect data changes. Combining the two to generate the final application operation log not only records the application operation behavior, but also reflects the actual changes in the database, without directly recording logs at the database level, minimizing the impact on database performance, and at the same time ensuring the consistency and integrity of the logs. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings according to the provided drawings without creative efforts.

[0039] Figure 1 It is a flowchart of an operation log recording method based on database monitoring provided by an embodiment of the present invention;

[0040] Figure 2 It is a structural diagram of an operation log recording device based on database monitoring provided by an embodiment of the present invention.

[0041] Figure 3 It is an architecture diagram of an electronic device provided by an embodiment of the present invention. Specific embodiments

[0042] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0043] Refer to Figure 1 , an embodiment of the present invention provides an operation log recording method based on database monitoring, including:

[0044] Step S110. Obtain application buried point logs, and the application buried point logs are cached according to log buried point identifiers.

[0045] The application buried point logs obtained in this step are to pre-bury log codes in the key business processes of the application program, insert buried point codes at the key nodes of the business logic of the application program (such as user login, order submission, data modification, etc.), generate logs containing business operation contexts, and then use the data monitoring service to obtain the corresponding application buried point logs from the storage module according to the log identifiers.

[0046] Specifically, it can be that the user introduces a log component package according to the log recording requirements, marks a log buried point identifier on the method logic that needs to record operation logs. At this time, the log component package will scan the log buried point identifier through the log buried point interceptor when the program code is executed. The interceptor synchronizes relevant information such as the request parameters of the method and the log version number to the business log database through the interface API or asynchronous MQ. Subsequently, when the program code updates the business database, the log version number will also be updated to the version number field of the business table.

[0047] Furthermore, the application buried point logs can be written manually by developers by inserting logs at specific business logics, or can be automatically collected for all user behaviors including page clicks, swipes, inputs, etc. without specific buried points. A more preferred implementation manner can also be to configure buried points through a visualization tool without modifying the original application business logic code.

[0048] Preferably, the core fields included in the application buried point log are:

[0049] Event timestamp, user identification, event name, page name, device information, operation content, IP address.

[0050] The application buried point log can be temporarily stored in an in-memory database (such as Redis) or a distributed message queue (such as Kafka) to avoid performance bottlenecks caused by direct writing to persistent storage; it can also be to asynchronously transmit the buried point log through a message queue (such as RabbitMQ) to achieve peak shaving and valley filling; it can also be to slice and store the log according to business modules or time ranges to improve query efficiency.

[0051] Furthermore, the log buried point identifier can be generated as a unique identifier through a globally unique algorithm to ensure the uniqueness of each log.

[0052] Step S120. Monitor the application database change information and obtain database operation events.

[0053] In this step, the system needs to monitor the changes (such as data insertion, update, deletion, etc.) that occur in the database used by the application in real time and capture all database operation events. By monitoring the database changes, the dynamic changes of business data and the operation sources can be traced.

[0054] Specifically, monitor the binary log in the application database, and obtain the data table identifier and data snapshot information according to the binary log. The data snapshot information includes the data before and after the change of the data fields. More preferably, the binary log of the database usually includes the data snapshot information of the data fields before and after the data change, and the data monitoring service obtains the data table identifier, data snapshot information, and log version number through the parsing module.

[0055] Furthermore, a trigger can be configured in the database to automatically record the operation events in the auxiliary log table when the data changes; or, deploy a database proxy server to proxy and monitor all requests, so as to capture the database operation log at the middle layer.

[0056] Step S130. Parse the database operation events according to the preset parsing rules to generate a data parsing result.

[0057] Specifically, step S130 includes the following process:

[0058] Step S131. Determine the target monitored data fields according to the preset parsing rules and the data table identifier.

[0059] Specifically, the preset parsing rules may include defining the correspondence between database table fields and business fields, filtering rules, and sensitive data desensitization. That is, during the system initialization or configuration phase, a set of parsing rules are predefined through configuration files, database metadata, or a dedicated rule management platform. These rules clarify which fields need to be monitored during the data change process. For example, which fields can be configured as sensitive data, key business data, or fields that need to be recorded with emphasis. The configuration file usually contains information such as field names, data types, business meanings, and monitoring strategies to ensure that the target data fields can be accurately identified during subsequent parsing. More preferably, a dedicated rule engine can be used to define and execute the parsing rules, enabling the parsing rules to be dynamically configured and extended.

[0060] The data table identifier (such as table name, logical identifier) is used to distinguish different data tables and their corresponding business scenarios. The system determines the data table to which the current change event belongs through this identifier and searches for the corresponding field monitoring rules accordingly. In addition, the data table identifier may also include partition information, database instance identifier, etc., to achieve multi-dimensional field positioning in a distributed environment.

[0061] When specifically determining the target listening data fields, the preset parsing rules are loaded and associated with the data table identifier. According to the data table identifier in the database operation event, it is matched with the table identifier configured in the parsing rules to confirm the field range that should be concerned about in the current event, and all target fields related to the current data table are extracted to form a set of fields to be listened to for subsequent data snapshot information processing.

[0062] Step S132. Determine the data before the change and the data after the change corresponding to the target listening data fields in the data snapshot information.

[0063] In this step, a complete row-level change snapshot (before_image and after_image) is extracted from the database binary log, and the data snapshots before and after the change are recorded in a temporary table through a database trigger. The target listening field list is traversed, and the values of the corresponding fields are extracted from the fields before_image and after_image. If a field does not exist in the data before the change but exists in the data after the change, it can be marked as null to indicate an insert operation. Conversely, if a field exists in the data before the change but does not exist in the data after the change, it can be marked as deleted to indicate a delete operation.

[0064] Specifically, parse the data snapshot information, convert the data into a structured format (such as JSON, XML, or key-value pairs) to facilitate subsequent field lookup; use the determined target monitoring data fields to perform field mapping on the data records in the snapshot, find the entries that are the same as the target field name or identifier, and extract the specific values of the target fields from the data before and after the change respectively.

[0065] Furthermore, during the extraction process, verify the target fields to ensure that the data before and after the change are correctly captured.

[0066] More preferably, for critical data fields, a redundant verification mechanism can be set up, such as data integrity verification and data type matching, to prevent parsing errors or data omission.

[0067] Step S133. Generate data parsing information based on the data before and after the change of the target monitoring data fields.

[0068] The data parsing information generated in this step refers to the difference information, the amount of change, and the possible business impact assessment extracted after comparing the state of the target monitoring data fields before and after the change. This information is used for subsequent log recording, auditing, data monitoring, and anomaly detection to help the system clarify the details and scope of data changes.

[0069] Specifically, compare whether the data before and after the change of the target monitoring data fields are the same. If they are the same, do not record the data of the target monitoring data fields, and the data parsing result does not record the data corresponding to the target monitoring data fields. Otherwise, record the data change result of the target monitoring data fields as the data parsing result.

[0070] If the field data is numerical, the difference value or increment can be calculated; if it is a string or enumeration type, record the differences in the states before and after, and mark the specific change content. Package the comparison result in the form of structured data.

[0071] Exemplarily, for the B field in tableA defined in the preset parsing rules that needs to be monitored, determine whether the field value of the B field has changed according to the data snapshot information obtained from the binary log. If there is no change, discard the field, and the B field is not recorded in the final data parsing result. If there is a change, record it.

[0072] Step S140. Generate application operation logs based on the application buried point logs and the data parsing results.

[0073] This step performs correlation matching using common identifiers included in the logs (such as log version number, user ID, session ID, timestamp, transaction ID). If the buried-point logs and database operation events each contain independent identifiers, they are correlated through time-window matching to ensure the consistency of records. The operation descriptions and context information in the buried-point logs are merged with the specific change data and execution results in the database operation events to generate structured records, such as JSON objects or database records, which contain a comprehensive description of user operation behaviors and system responses.

[0074] Specifically, step S140 includes the following processes:

[0075] Step S141. Parse the application buried-point logs to obtain the full log information.

[0076] The full log information parsed from the application buried-point logs in this step includes business operation descriptions, request parameters, request addresses, operation execution results, operation execution times, and log version identifiers. Obtain the original log data from the buried-point logs generated by the application. The data source can be memory cache, message queue, log file, or third-party log platform.

[0077] Step S142. Parse the data change results of the target monitoring data fields from the data parsing results.

[0078] The data parsing results usually contain detailed information such as the data before and after the change, change type, and change range of each target field during the database change process. This result reflects the changes in business data during the operation process. According to the preset list of target monitoring data fields, filter out the records related to the target fields from the overall data parsing results. Use field name matching, data table identifiers, and preset rules to filter the records to ensure that only the change data of key business fields are retained. Compare the filtered data records to extract the data before and after the change for each target field.

[0079] Step S143. Aggregate the full log information and data change results into application operation logs.

[0080] The goal of this step's aggregation process is to correlate and integrate the user operation behaviors at the application layer with the data changes at the database layer to form complete application operation logs. These logs record the full process information from user operation triggers, log buried-point records, to actual database data changes, facilitating subsequent auditing, monitoring, and business analysis.

[0081] Furthermore, convert the data change results into a preset log format to obtain the data change results in the target format, and aggregate the full log information and the data change results in the target format into application operation logs.

[0082] The above embodiments provide a method for recording operation logs based on database monitoring. According to preset configuration rules, logs are reported with buried points, so as to cache application buried point logs according to log buried point identifiers. The application buried point logs record business logics and user operations in the order of buried point positions at the application level, and can clearly record information such as interface calls, user operations, and execution results. At the same time, data change information is obtained through database monitoring to accurately reflect data changes. Combining the two generates the final application operation logs, which not only record application operation behaviors but also reflect the actual changes in the database, without directly recording logs at the database level, minimizing the impact on database performance while ensuring the consistency and integrity of the logs.

[0083] The above-disclosed method can be implemented by devices in various forms. Therefore, the present invention also discloses an operation log recording device corresponding to the above method, and specific embodiments are given below for detailed description.

[0084] As Figure 2 shown, an embodiment of the present invention provides an operation log recording device based on database monitoring, including:

[0085] A buried point log acquisition module 202, configured to acquire application buried point logs, and the application buried point logs are cached according to log buried point identifiers;

[0086] A data monitoring module 204, configured to monitor application database change information and obtain database operation events;

[0087] A data parsing module 206, configured to parse database operation events according to preset parsing rules to generate data parsing results;

[0088] An operation log generation module 208, configured to generate application operation logs according to application buried point logs and data parsing results.

[0089] The device provided by the embodiments of the present application has the same implementation principle and the same technical effects as those of the foregoing method embodiments. For a brief description, for the parts not mentioned in the device embodiments, reference may be made to the corresponding content in the foregoing method embodiments.

[0090] The methods and related devices mentioned in the above embodiments are described with reference to the method flowcharts and / or structural schematic diagrams provided by the embodiments of the present application. Specifically, each process and / or block of the method flowchart and / or structural schematic diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementation in the process Figure 1Schematic of one or more processes and / or structures Figure 1 a device for the functions specified in one or more boxes. These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device, and the instruction device implements the process Figure 1 Schematic of one or more processes and / or structures Figure 1 a device for the functions specified in one or more boxes. These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more boxes in one or more processes Figure 1 Schematic of one or more processes and / or structures, steps for the functions specified in one or more boxes

[0091] In the following embodiments, the method is described by taking its application to a computer device as an example. It can be understood that the computer device can be any device with computing and processing functions, and can be, but is not limited to, a server or a personal laptop computer, etc. In one embodiment, the computer device can be an application server, and the application server can be a server for running an application under test.

[0092] Refer to Figure 3 , which shows a hardware structure block diagram of an electronic device. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present application described and / or claimed herein.

[0093] As Figure 3 shown, the electronic device includes: at least one processor 1, at least one communication interface 2, at least one memory 3, and at least one communication bus 4;

[0094] In the embodiments of the present application, the number of the processor 1, the communication interface 2, the memory 3, and the communication bus 4 is at least one, and the processor 1, the communication interface 2, and the memory 3 communicate with each other through the communication bus 4;

[0095] The processor 1 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention, etc.;

[0096] The memory 3 may include high-speed RAM memory, and may also include non-volatile memory, etc., such as at least one disk memory;

[0097] Among them, the memory stores a program, and the processor can call the program stored in the memory. The program is used to: implement each processing flow of the foregoing operation log recording based on database monitoring.

[0098] The embodiments of the present invention also provide a readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements each processing flow of the operation log recording solution based on database monitoring provided by any possible implementation manner of the foregoing embodiments and / or combined embodiments.

[0099] The above embodiments have described the present invention in particular detail with respect to possible scenarios. Those skilled in the art will recognize that the present invention can be practiced through other embodiments. The specific naming of components, the case of terms, attributes, data structures, or any other programming or structural aspects are not mandatory or important. The mechanisms or features for implementing the present invention can have different names, forms, or procedures. The system can be implemented through a combination of hardware and software (as described), entirely through hardware elements, or entirely through software elements. The specific division of functions between the various system components described in the text is exemplary, not mandatory; on the contrary, the functions performed by a single system component can be performed by multiple components, or the functions performed by multiple components can be performed by a single component.

[0100] Those skilled in the art should understand that each step of the above disclosed method can be implemented by a general-purpose computing device. They can be concentrated on a single computing device, or distributed over a network composed of multiple computing devices. Optionally, they can be implemented with program code executable by the computing device, so that they can be stored in a storage device and executed by the computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. Thus, the disclosure of the embodiments of the present invention is not limited to any specific combination of hardware and software.

[0101] Programs (also referred to as programs, software, software applications, or code) executable by these computing devices include machine instructions for a programmable processor and can implement these computing programs using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.

[0102] Certain aspects of the present invention include the process steps and instructions described herein in the form of an algorithm. It should be noted that the process steps and instructions of the present invention can be implemented in software, firmware, and / or hardware. When implemented by software, it can be downloaded and thus saved and operated on different platforms used by various operating systems.

[0103] Those skilled in the art can understand that the structures shown in the drawings are only block diagrams of some of the structures related to the solution of the present application and do not constitute a limitation on the terminal devices to which the solution of the present application is applied. The specific terminal devices may include more or fewer components than those shown in the drawings, or combine some components, or have different component arrangements.

[0104] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "possible design", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0105] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An operation log recording method based on database monitoring, characterized in that: include: Obtaining application tracking logs, wherein the application tracking logs are cached according to the log tracking identifiers; Monitor application database change information and obtain database operation events; Analyze the database operation event according to preset analysis rules to generate data analysis results; Generate application operation logs based on the application tracking logs and data analysis results.

2. The method according to claim 1, characterized in that: The monitoring of application database change information and obtaining database operation events includes: The binary log in the application database is monitored, and a data table identifier and data snapshot information are obtained according to the binary log, wherein the data snapshot information includes data before and after the change of the data field.

3. The method according to claim 2, characterized in that The parsing of the database operation event according to the preset parsing rules to generate data parsing results includes: Determine the target monitoring data field according to the preset parsing rules and data table identifier; Determining the pre-change data and the post-change data corresponding to the target monitoring data field in the data snapshot information; Data parsing information is generated according to the pre-change data and the post-change data of the target monitoring data field.

4. The method according to claim 3, characterized in that Generating a data analysis result according to the pre-change data and the post-change data of the target monitoring data field includes: Compare the data before and after the change of the target monitoring data field to see if they are consistent. If they are consistent, the data of the target monitoring data field is not recorded, and the data corresponding to the target monitoring data field is not recorded in the data analysis result. Otherwise, the data change result of the target monitoring data field is recorded as the data analysis result.

5. The method according to claim 1, characterized in that Generating the application operation log according to the application tracking log and the data analysis result includes: Analyze the application tracking log to obtain full log information; Parsing the data change result of the target monitoring data field from the data parsing result; Aggregate the full amount of log information and data change results into an application operation log.

6. The method according to claim 5, characterized in that The full log information includes business operation description, request parameters, request address, operation execution result, operation execution time, and log version identifier.

7. The method according to claim 5, characterized in that Aggregating the full amount of log information and data change results into an application operation log includes: Convert the data change results into a preset log format to obtain the data change results in the target format; Aggregate the full amount of log information and data change results in the target format into application operation logs.

8. An operation log recording device based on database monitoring, characterized in that: include: A tracking point log acquisition module is used to obtain application tracking point logs, and the application tracking point logs are cached according to the log tracking point identifiers; The data monitoring module is used to monitor the application database change information and obtain database operation events; The data analysis module is used to analyze the database operation events according to the preset analysis rules and generate data analysis results; The operation log generation module is used to generate application operation logs based on application tracking logs and data analysis results.

9. An electronic device, characterized in that: The device comprises a memory storing computer executable instructions and a processor. When the computer executable instructions are executed by the processor, the device executes the operation log recording method based on database monitoring as described in any one of claims 1 to 7.

10. A readable storage medium, characterized in that: A computer executable program is stored, and when the program is executed, the operation log recording method based on database monitoring as described in any one of claims 1 to 7 can be implemented.

Citation Information

Cited By

  • Log processing method and device, electronic equipment and computer readable medium

    CN121255742A

  • Data synchronization method, device and equipment among multiple server nodes in isolation environment

    CN121542357A