Classified log management system and method based on JES architecture

Through the classification log management system based on JES architecture, the problem of lack of classification mechanism in the log management system is solved, efficient management and security of log data is realized, and multi-angle analysis and rapid retrieval is supported.

CN120337028APending Publication Date: 2025-07-18SHANDONG ZHIMOU ARTIFICIAL INTELLIGENCE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510367830.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The log management system lacks an effective classification mechanism in the prior art, which makes it difficult to retrieve and analyze log data, affecting the security and stability of the system.

Method used

The classification log management system based on JES architecture is adopted to preprocess and classify the log data through a message queue, identify the operation log, operation log and debug log, store it in the corresponding database, and encrypt the operation log, adjust the debug log level, and perform regular integrity verification.

Benefits of technology

It improves the management efficiency and security of log data, realizes orderly management and rapid retrieval of log data, protects sensitive information, ensures the reliability and accuracy of data, and supports multi-angle log analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337028A_ABST
    Figure CN120337028A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computers, and discloses a classified log management system and method based on a JES architecture, and the method comprises the steps: collecting log data of an application program or service, and transmitting the log data to a message queue; the log data are preprocessed and classified, the log type of each log data is determined, a plurality of log databases are preset, and the types of the log databases correspond to the log types; processing the log data according to the log type, and storing the processed log data in a corresponding log database; if the log is the operation log, encrypting the log data; if the log is the debugging log, performing grade adjustment processing on the log data; and regularly performing integrity verification on the log data in the log database, and determining whether the log data in the log database is safe or not according to an integrity verification result. According to the invention, the management efficiency and security of the log data can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and particularly to a classification log management system and method based on the JES architecture. Background Art

[0002] In a computer system, a log file is an important tool for recording the running state of the system and user operations. With the development of information technology, the amount of log data is increasing day by day. How to effectively manage and utilize this log data has become a challenge. Traditional log management systems often lack an effective classification mechanism, resulting in difficulty in retrieving and analyzing log data, thus affecting the security and stability of the system. Therefore, it is particularly important to develop a system that can effectively classify and manage log data. The classification log management system based on the JES architecture proposed by the present invention aims to solve the problems existing in the prior art and improve the management efficiency and security of log data. Summary of the Invention

[0003] The purpose of the present invention is to provide a classification log management system and method based on the JES architecture, aiming to solve the above problems.

[0004] The present invention provides a classification log management method based on the JES architecture, including:

[0005] Collecting log data of an application program or service and transmitting the log data to a message queue;

[0006] Preprocessing and classifying the log data according to the arrival order of the log data in the message queue, and determining the log type of each log data, where the log type includes operation logs, running logs, and debug logs;

[0007] There are several preset log databases, and the types of the log databases correspond to the log types, and the log databases include an operation log database, a running log database, and a debug log database;

[0008] Processing the log data according to the log type and storing the processed log data in the corresponding log database; if the log type is an operation log, encrypting the log data of the operation log; if the log type is a debug log, performing a level adjustment process on the log data of the debug log;

[0009] Regularly performing an integrity check on the log data in the log database, and determining whether the log data in the log database is secure according to the integrity check result.

[0010] Preferably, preprocessing and classifying the log data according to the arrival order of the log data in the message queue, and determining the log type of each log data, includes:

[0011] Preprocess the log data, where the preprocessing includes removing irrelevant information and extracting key features;

[0012] Determine the elements of the log data according to the extracted key features;

[0013] Classify according to the elements of the log data to determine the log type of each log data.

[0014] Preferably, classifying according to the elements of the log data to determine the log type of each log data includes:

[0015] There is a preset log type element comparison table, the log type element comparison table is provided with several log types, and the log types are provided with corresponding elements;

[0016] Filter the elements in the log type comparison table according to the elements of the log data to determine the log type of the log data;

[0017] The elements of the operation log include: time, user ID, IP address, port number, time description, and result;

[0018] The elements of the running log include: service name / application name, time, time description, and result;

[0019] The elements of the debug log include: time, service name / application name, log level, code file and line number, interface name, event description, and result.

[0020] Preferably, if the log type is an operation log, encrypt the log data of the operation log, including:

[0021] Determine whether the elements of the log data are sensitive elements. If they are sensitive elements, encrypt the log data corresponding to the sensitive elements. The sensitive elements include user ID and IP address;

[0022] Generate a symmetric key using a random number generator;

[0023] Encrypt the log data using the symmetric key and store the encrypted log data and the symmetric key in the log database.

[0024] Preferably, if the log type is a debug log, perform a level adjustment process on the log data of the debug log, including:

[0025] There is a preset log level debug table, the log level debug table includes several service names / application names, and the service names / application names are provided with corresponding debug levels;

[0026] Determine the service name / application name of the debug log, compare the service name / application name of the debug log with the service name / application name in the log level debug table, and determine the corresponding debug level;

[0027] Determine the log level of the debug log. If the log level is the same as the debug level, no level adjustment is made to the log data of the debug log;

[0028] If the log level is different from the debug level, adjust the log level according to the debug level and adjust the log level to the debug level.

[0029] Preferably, when performing level adjustment processing on the log data of the debug log, use the jlogset command-line tool to dynamically modify the log level of the debug log.

[0030] Preferably, regularly perform integrity verification on the log data in the log database, and determine whether the log data in the log database is secure according to the integrity verification result, including:

[0031] Use the hash algorithm to calculate the hash value of the preprocessed log data to determine the original hash value of the preprocessed log data;

[0032] Use the hash algorithm to calculate the hash value of the same log data in the log database to determine the verification hash value of the same log data in the log database;

[0033] Compare the original hash value with the verification hash value. If the original hash value is the same as the verification hash value, it is determined that the integrity verification is passed, and the log data in the log database is secure data;

[0034] If the original hash value is different from the verification hash value, it is determined that the integrity verification fails, and the log data in the log database is tampered data.

[0035] Preferably, the method further includes: a log query interface is provided, and the log query interface includes log query and log download. The log query is used to query the log data in the log database according to the time range; the log download is used to download the log data in the log database according to the user's selection;

[0036] Among them, the download formats of the operation log and the running log are CSV or TXT;

[0037] The download format of the debug log is TXT or LOG.

[0038] The present invention also discloses a classified log management system based on the JES architecture, which is used to apply the above-mentioned classified log management method based on the JES architecture, including:

[0039] A collection and transmission module, configured to collect log data of an application or service and transmit the log data to a message queue;

[0040] A log classification module, configured to classify the log data according to the arrival order of the log data in the message queue, and determine the log type of each piece of log data, where the log types include operation logs, running logs, and debug logs;

[0041] A log storage module, in which a number of log databases are preset. The types of the log databases correspond to the log types, and the log databases include an operation log database, a running log database, and a debug log database. The log storage module is configured to process the log data according to the log type and store the processed log data in the corresponding log database. If the log type is an operation log, the log data is encrypted. If the log type is a debug log, the log data is subjected to a level adjustment process;

[0042] A log verification module, configured to periodically verify the integrity of the log data in the log database and determine whether the log data in the log database is secure according to the integrity verification result.

[0043] Preferably, the system further includes: a log query and download module, in which a log query interface is set. The log query interface includes log query and log download. The log query is used to query the log data in the log database according to a time range. The log download is used to download the log data in the log database according to the user's selection.

[0044] Compared with the prior art, the beneficial effects of the present invention are as follows: By preprocessing and classifying the log data of the message queue, the present invention can effectively improve the efficiency of log processing. The use of the message queue can also achieve asynchronous processing of log data, avoiding performance degradation of the application or service caused by log processing. Storing the log data in the corresponding log database according to the log type can achieve orderly management and fast retrieval of log data. Different types of log databases can be optimized according to their characteristics. For example, operation logs may require stronger security and privacy protection, while running logs may pay more attention to real-time performance and query efficiency. Encrypting the operation logs can protect sensitive information from unauthorized access. Adjusting the level of debug logs can adjust their visibility and accessibility according to the importance and sensitivity of the logs, thereby protecting the security of the system while ensuring the transparency of the system. Regularly performing integrity verification on the log data in the log database can promptly detect and repair problems of data corruption or loss, ensuring the reliability and accuracy of log data. This is very important for subsequent data analysis, fault troubleshooting, and compliance auditing. Since the log data is stored separately by type, when it is necessary to process or analyze a certain type of log, operations can be directly performed on the corresponding log database, simplifying the maintenance work. At the same time, this architecture is also convenient for future expansion, such as adding new log types or log databases. Since the log data is classified and stored by type, it makes it possible to analyze the log data from multiple perspectives. For example, user behavior patterns can be analyzed from operation logs, system performance metrics can be monitored from running logs, and software defects can be traced from debug logs. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0046] Figure 1 It is a schematic flowchart of the classification log management method based on the JES architecture of the present invention;

[0047] Figure 2 It is a functional block diagram of the classification log management system based on the JES architecture of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0049] As Figure 1 shown, the present invention provides a classification log management method based on the JES architecture, including:

[0050] Collect the log data of the application program or service and transmit the log data to the message queue;

[0051] Preprocess and classify the log data according to the arrival order of the log data in the message queue, and determine the log type of each log data. The log type includes operation logs, running logs, and debug logs;

[0052] There are several preset log databases, and the types of the log databases correspond to the log types. The log databases include an operation log database, a running log database, and a debug log database;

[0053] Process the log data according to the log type and store the processed log data in the corresponding log database; if the log type is an operation log, encrypt the log data of the operation log; if the log type is a debug log, perform a level adjustment process on the log data of the debug log;

[0054] Regularly perform integrity verification on the log data in the log database, and determine whether the log data in the log database is secure according to the integrity verification result.

[0055] In some embodiments of the present application, preprocessing and classifying the log data according to the arrival order of the log data in the message queue to determine the log type of each log data includes: preprocessing the log data, and the preprocessing includes removing irrelevant information and extracting key features; determining the elements of the log data according to the extracted key features; classifying according to the elements of the log data to determine the log type of each log data.

[0056] When processing log data in a message queue, it is first necessary to preprocess this log data to ensure the accuracy and efficiency of subsequent processing. The preprocessing steps include removing irrelevant information and extracting key features. Removing irrelevant information is mainly to exclude data that has no impact on log analysis, such as some fixed header information, timestamps, etc., which can reduce the complexity of data processing and improve the processing speed. Extracting key features is to extract information from the log data that is helpful for judging the log type, such as exception information, specific keywords, etc. After preprocessing, the next step is to determine the elements of the log data based on the extracted key features. These elements may include the source of the log, the log level, the occurrence time, the modules or services involved, etc. By analyzing these elements, the log data can be preliminarily classified. Finally, classify according to the elements of the log data to determine the log type of each log data. Through such classification, the log data can be managed and analyzed more effectively, providing support for subsequent monitoring, alarm, problem location, etc.

[0057] In some embodiments of the present application, classifying according to the elements of the log data to determine the log type of each log data includes: presetting a log type element comparison table, the log type element comparison table is provided with several log types, and each log type is provided with corresponding elements; screening the elements in the log type comparison table according to the elements of the log data to determine the log type of the log data.

[0058] The elements of the operation log include: time, user ID, IP address, port number, time description, and result; the elements of the running log include: service name / application name, time, time description, and result; the elements of the debug log include: time, service name / application name, log level, code file and line number, interface name, event description, and result.

[0059] To effectively manage and analyze log data, it is first necessary to classify the logs according to the elements of the log data to determine their log types. This can be achieved by using a preset log type element comparison table. This comparison table lists multiple log types and assigns corresponding elements to each log type.

[0060] The specific steps are as follows:

[0061] Prepare a log type element comparison table, which contains multiple log types, such as operation logs, running logs, and debug logs, etc.

[0062] For each type of log, list in detail its unique elements. For example: The elements of operation logs include: time, user ID, IP address, port number, time description, and result. The elements of running logs include: service name / application name, time, time description, and result. The elements of debug logs include: time, service name / application name, log level, code file and line number, interface name, event description, and result.

[0063] When new log data is received, analyze the elements it contains. Based on the elements contained in the log data, match and filter them against the elements in the log type element comparison table. Determine which log type's elements in the comparison table match the elements contained in the log data, thereby determining the log type of the log data. Through the above steps, the log data can be classified quickly and accurately, facilitating subsequent log management and analysis work.

[0064] In some embodiments of the present application, if the log type is an operation log, encrypt the log data of the operation log, including: determining whether the elements of the log data are sensitive elements. If they are sensitive elements, encrypt the log data corresponding to the sensitive elements. The sensitive elements include user ID and IP address; generate a symmetric key using a random number generator; encrypt the log data using the symmetric key, and store the encrypted log data and the symmetric key in the log database.

[0065] When processing operation logs, it is first necessary to analyze the log data to determine whether it contains sensitive information. Sensitive information generally refers to data that can directly or indirectly identify personal identity or location. In our scenario, the sensitive elements specifically refer to user ID and IP address because these information can be associated with a specific user or the user's location information.

[0066] Once it is confirmed that the log data contains sensitive elements, encryption measures will be taken to protect this data. The encryption process first involves generating a symmetric key, which will be used to encrypt the log data. The generation of the symmetric key relies on a random number generator to ensure that each generated key is unique and unpredictable, thereby enhancing the security of encryption.

[0067] Next, use this symmetric key to encrypt the log data containing sensitive elements. The selection of the encryption algorithm should ensure the confidentiality and integrity of the data. Common symmetric encryption algorithms include AES (Advanced Encryption Standard), etc. After encryption, the obtained ciphertext together with the symmetric key is stored in the log database. In this way, even if the log data is obtained by an unauthorized third party, the original sensitive information cannot be decrypted without the symmetric key.

[0068] When storing the encrypted log data and the symmetric key, it is necessary to ensure their security. The storage of the symmetric key is particularly important because if the key is lost or leaked, the encrypted data may be decrypted. Therefore, additional security measures should be taken for the storage of the symmetric key, such as using a key management system for management to ensure that only authorized systems or personnel can access it.

[0069] Through the above steps, the security of sensitive data in the operation log is ensured, while meeting the requirements of data protection regulations and company policies for the processing of sensitive information.

[0070] In some embodiments of the present application, if the log type is a debug log, the log data of the debug log is subjected to a level adjustment process, including: presetting a debug log level table, the debug log level table including several service names / application names, and corresponding debug levels being set for the service names / application names; determining the service name / application name of the debug log, comparing the service name / application name of the debug log with the service names / application names in the debug log level table to determine the corresponding debug level; determining the log level of the debug log, if the log level is consistent with the debug level, no level adjustment is made to the log data of the debug log; if the log level is inconsistent with the debug level, the log level is adjusted according to the debug level, and the log level is adjusted to the debug level.

[0071] When processing log data, if the log type is identified as a debug log, a preset debug log level table will be referred to first. This debug table details different service names or application names and assigns a specific debug level to each name. These debug levels are important parameters for guiding the processing of log data.

[0072] Next, analyze the debug log to be processed and extract the service name or application name from it. With this information, it is matched with the service names or application names listed in the debug log level table to determine the corresponding debug level of the debug log.

[0073] Once the current log level of the debug log is determined, a comparison is made to see if it is consistent with the previously determined debug level. If the current log level is the same as the debug level, then no level adjustment needs to be made to the log data. However, if the current log level does not match the debug level, the log level will be adjusted according to the debug level to ensure that the final log level is consistent with the debug level specified in the debug table.

[0074] In this way, it can be ensured that the processing of debug logs is carried out according to the established debug strategy, which helps developers or system administrators diagnose and solve problems more effectively.

[0075] In some embodiments of the present application, when performing level adjustment processing on the log data of the debug log, the jlogset command-line tool is used to dynamically modify the log level of the debug log.

[0076] When processing debug log data, if it is necessary to dynamically adjust the log level, the jlogset command-line tool can be used. This tool allows users to modify the output level of the log in real time without interrupting the service. The specific operations are as follows:

[0077] Open the command-line interface.

[0078] Enter the jlogset command, followed by the corresponding parameters to set the log level.

[0079] According to the prompt or the help document of the command-line tool, specify the log component to be adjusted and the new log level.

[0080] Execute the command to complete the adjustment of the log level.

[0081] The command can be:

[0082] jlogset--level <level>:Modify the global log level.

[0083] jlogset --app <app_name> --level <level>: Modify the log level for a specific application.

[0084] jlogset--save <path>: Set the save path of the debug log.

[0085] jlogset--app<app_name>--save <path>: Set the saving path of the debug logs for a specific application.

[0086] In some embodiments of the present application, the integrity of the log data in the log database is periodically verified, and it is determined whether the log data in the log database is secure according to the integrity verification result, including: calculating the hash value of the preprocessed log data by using a hash algorithm to determine the original hash value of the preprocessed log data; calculating the hash value of the same log data in the log database by using a hash algorithm to determine the verification hash value of the same log data in the log database; comparing the original hash value with the verification hash value, if the original hash value is the same as the verification hash value, it is determined that the integrity verification is passed and the log data in the log database is secure data; if the original hash value is different from the verification hash value, it is determined that the integrity verification is not passed and the log data in the log database is tampered data.

[0087] To ensure the security and integrity of the data in the log database, a strict verification process is adopted. First, the log data is preprocessed, and this step includes clearing irrelevant information, formatting the data, and possible encryption processing to ensure the accuracy and consistency of the data. After the preprocessing is completed, a hash algorithm is used to calculate the hash value of these data to obtain an original hash value. This hash value is a unique fingerprint of the data, and any small change in the data will result in a huge difference in the hash value.

[0088] Next, the same hash algorithm is executed on the corresponding log data stored in the log database to obtain the verification hash value. By comparing the original hash value of the preprocessed log data with the verification hash value of the corresponding data in the log database, the integrity of the data can be verified.

[0089] If the original hash value is exactly the same as the verification hash value, this indicates that the log data has not been tampered with since the preprocessing, and it can be determined that the data has passed the integrity verification and is secure. However, if the two do not match, that is, there is a difference between the original hash value and the verification hash value, this indicates that the log data may have been modified or damaged without authorization during storage or processing. Therefore, it is determined that the data has not passed the integrity verification and there is a risk of tampering.

[0090] In some embodiments of the present application, the method further includes: a log query interface is provided, and the log query interface includes log query and log download. The log query is used to query the log data in the log database according to the time range; the log download is used to download the log data in the log database according to the user's selection; wherein, the download formats of the operation logs and the running logs are CSV or TXT; the download format of the debug logs is TXT or LOG.

[0091] It also includes: a log query interface is provided, which includes two main functional areas: log query and log download. The log query function allows users to retrieve log data stored in the log database according to a specified time range, so as to quickly find the required information. Users can input the start time and end time, and the system will return all relevant log records during this period.

[0092] The log download function allows users to select specific log data for download according to their own needs. Users can locate specific log entries through the filtering conditions of the log query interface and then select to download these entries. The download formats of operation logs and running logs support CSV (Comma-Separated Values) or TXT (text file). These two formats are widely used for data exchange and text reading. Users can choose the appropriate format for data processing or analysis according to their own needs.

[0093] For debug logs, considering that they may contain more detailed system operation information, the download formats support TXT or LOG. The TXT format is convenient for users to read and perform basic text processing, while the LOG format may retain more log metadata and structure information, which is suitable for further debugging and analysis work. Users can choose the appropriate download format according to their specific needs and the convenience of subsequent processing.

[0094] As Figure 2 shown, the present invention also discloses a classified log management system based on the JES architecture for applying the above-mentioned classified log management method based on the JES architecture, including:

[0095] A collection and transmission module, which is used to collect log data of an application program or service and transmit the log data to a message queue.

[0096] A log classification module, which is used to classify the log data according to the arrival order of the log data in the message queue, and determine the log type of each log data. The log types include operation logs, running logs, and debug logs.

[0097] A log storage module, in which several log databases are preset. The types of the log databases correspond to the log types. The log databases include an operation log database, a running log database, and a debug log database. The log storage module is used to process the log data according to the log type and store the processed log data in the corresponding log database. If the log type is an operation log, the log data is encrypted. If the log type is a debug log, the log data is subjected to a level adjustment process.

[0098] The log verification module is used to periodically verify the integrity of the log data in the log database and determine whether the log data in the log database is secure based on the integrity verification results.

[0099] The log query and download module is provided with a log query interface. The log query interface includes log query and log download. The log query is used to query the log data in the log database according to a time range; the log download is used to download the log data in the log database according to user selection.

[0100] Through the collection and transmission module, the log data of the application program or service can be monitored and collected in real time and quickly transmitted to the message queue. This mechanism ensures the timeliness and integrity of the log data and avoids data loss or delay.

[0101] The log classification module automatically classifies according to the arrival order of the log data in the message queue and identifies different types such as operation logs, running logs, and debug logs. This helps with subsequent specialized processing and analysis of the log data, improving the efficiency and accuracy of log management.

[0102] The log storage module is preset with a database corresponding to the log type, and corresponding storage strategies can be adopted according to different log characteristics. For example, encrypt the operation logs to enhance security and adjust the levels of the debug logs to optimize the storage space.

[0103] By periodically verifying the integrity of the log data in the log database through the log verification module, potential data problems can be discovered and fixed in a timely manner, ensuring the reliability and accuracy of the log data. This is crucial for compliance audits and troubleshooting.

[0104] The log query and download module provides a user-friendly interface that allows users to query specific log data according to a time range and download relevant logs as needed. This greatly facilitates users' access to and use of the log data and improves work efficiency.

[0105] Since the system adopts a modular design, each module is independent but works in coordination with each other, which makes the system easy to maintain and upgrade. At the same time, the modular design also facilitates adding new functions or expanding existing functions according to future requirements.

[0106] By specially processing and storing different types of log data, the system supports analyzing the log data from multiple perspectives. This helps enterprises better understand the system operation status, user behavior patterns, and potential security issues.

[0107] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions of the present invention or make equivalent replacements, and these modifications or equivalent replacements cannot make the modified technical solutions deviate from the spirit and scope of the technical solutions of the present invention.

[0108] For the system provided by the above embodiments, only the division of the above functional modules is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the modules or steps in the embodiments of the present invention can be further decomposed or combined. For example, the modules in the above embodiments can be combined into one module, or further split into multiple sub-modules to complete all or part of the functions described above. The names of the modules and steps involved in the embodiments of the present invention are only used to distinguish each module or step, and are not considered as an improper limitation of the present invention.

[0109] Those skilled in the art should be able to realize that the modules and method steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. The programs corresponding to the software modules and method steps can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well known in the technical field. To clearly illustrate the interchangeability of electronic hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in the form of electronic hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.< / path> < / path> < / level> < / level>

Claims

1. A classification log management method based on the JES architecture, characterized in that, Including: Collecting log data of an application or service and transmitting the log data to a message queue; Preprocessing and classifying the log data according to the arrival order of the log data in the message queue, and determining the log type of each piece of log data, where the log type includes operation logs, running logs, and debug logs; There are several preset log databases, and the type of the log database corresponds to the log type, and the log database includes an operation log database, a running log database, and a debug log database; Processing the log data according to the log type and storing the processed log data in the corresponding log database; if the log type is an operation log, encrypting the log data of the operation log; If the log type is a debug log, performing a level adjustment process on the log data of the debug log; Regularly performing an integrity check on the log data in the log database, and determining whether the log data in the log database is secure according to the integrity check result.

2. The classification log management method based on the JES architecture according to claim 1, wherein Preprocessing and classifying the log data according to the arrival order of the log data in the message queue, and determining the log type of each piece of log data, including: Preprocessing the log data, where the preprocessing includes removing irrelevant information and extracting key features; Determining the elements of the log data according to the extracted key features; Classifying according to the elements of the log data to determine the log type of each piece of log data.

3. The classification log management method based on the JES architecture according to claim 2, wherein, Classifying according to the elements of the log data to determine the log type of each piece of log data, including: There is a preset log type element comparison table, and several log types are set in the log type element comparison table, and corresponding elements are set for the log types; Filtering the elements in the log type comparison table according to the elements of the log data to determine the log type of the log data; The elements of the operation log include: time, user ID, IP address, port number, time description, and result; The elements of the running log include: service name / application name, time, time description, and result; The elements of the debug log include: time, service name / application name, log level, code file and line number, interface name, event description, and result.

4. The classification log management method based on the JES architecture according to claim 3, characterized in that If the log type is an operation log, encrypting the log data of the operation log, including: Determining whether the elements of the log data are sensitive elements, and if they are sensitive elements, encrypting the log data corresponding to the sensitive elements, where the sensitive elements include user ID and IP address; Generating a symmetric key using a random number generator; Encrypting the log data using the symmetric key and storing the encrypted log data and the symmetric key in the log database.

5. The classification log management method based on the JES architecture according to claim 4, characterized in that If the log type is a debug log, performing a level adjustment process on the log data of the debug log, including: There is a preset log level debug table, and the log level debug table includes several service names / application names, and corresponding debug levels are set for the service names / application names; Determine the service name / application name of the debug log, compare the service name / application name of the debug log with the service name / application name in the log level debug table, and determine the corresponding debug level; Determine the log level of the debug log. If the log level is the same as the debug level, no level adjustment is made to the log data of the debug log; If the log level is different from the debug level, adjust the log level according to the debug level and adjust the log level to the debug level.

6. The classification log management method based on the JES architecture according to claim 5, characterized in that When performing level adjustment processing on the log data of the debug log, use the jlogset command-line tool to dynamically modify the log level of the debug log.

7. The classification log management method based on the JES architecture according to claim 6, characterized in that Periodically perform integrity verification on the log data in the log database, and determine whether the log data in the log database is secure according to the integrity verification result, including: Use the hash algorithm to calculate the hash value of the preprocessed log data to determine the original hash value of the preprocessed log data; Use the hash algorithm to calculate the hash value of the same log data in the log database to determine the verification hash value of the same log data in the log database; Compare the original hash value with the verification hash value. If the original hash value is the same as the verification hash value, it is determined that the integrity verification is passed, and the log data in the log database is secure data; If the original hash value is different from the verification hash value, it is determined that the integrity verification fails, and the log data in the log database is tampered data.

8. The classification log management method based on the JES architecture according to claim 7, wherein, The method further includes: There is a log query interface, which includes log query and log download. The log query is used to query the log data in the log database according to the time range; the log download is used to download the log data in the log database according to the user's selection; Among them, the download formats of the operation log and the running log are CSV or TXT; The download format of the debug log is TXT or LOG.

9. A classification log management system based on the JES architecture, which is used to apply the classification log management method based on the JES architecture according to any one of claims 1-8, and is characterized in that, It includes: A collection and transmission module, which is used to collect the log data of the application program or service and transmit the log data to the message queue; A log classification module, which is used to classify the log data according to the arrival order of the log data in the message queue, determine the log type of each log data, and the log type includes operation log, running log and debug log; A log storage module, in which several log databases are preset. The type of the log database corresponds to the log type. The log database includes an operation log database, a running log database and a debug log database; the log storage module is used to process the log data according to the log type and store the processed log data in the corresponding log database; if the log type is an operation log, the log data is encrypted; If the log type is a debug log, level adjustment processing is performed on the log data; A log verification module, which is used to periodically perform integrity verification on the log data in the log database, and determine whether the log data in the log database is secure according to the integrity verification result.

10. The classification log management system based on the JES architecture according to claim 9, characterized in that, The system further includes: Log query and download module, within which a log query interface is set up. The log query interface includes log query and log download. The log query is used to query log data in the log database according to a time range; the log download is used to download log data in the log database according to user selection.