Log data management method and device, equipment and medium

By unifying the collection and storage of logs through a data management platform and controlling access permissions based on user rights, the problem of chaotic log management in enterprises has been solved, and log security and user efficiency have been improved.

CN120408698APending Publication Date: 2025-08-01BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510478245.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

In existing technologies, enterprise log management is chaotic, making it impossible to accurately control user permissions, which leads to the leakage of sensitive information.

Method used

Logs are collected uniformly through a data management platform, standard source identifiers are generated and log characteristics are identified, and the data is stored in a directory-style dataset. Access or processing permissions are granted according to user permissions.

Benefits of technology

It achieves strict control over user permissions, prevents information leakage, and improves log security and user viewing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408698A_ABST
    Figure CN120408698A_ABST
Patent Text Reader

Abstract

The invention discloses a log data management method and device, equipment and a medium. The method is executed by a data management platform, and comprises the following steps: collecting a log to a target file path, and generating a standard source identifier to be correspondingly stored with the log; according to the target file path, the standard source identifier and the log, identifying log features; according to the log features, the logs are stored in corresponding directories in a data set; and when a user accesses the data management platform, opening access or processing permissions of a plurality of target logs to the user according to a directory in the data set and permission information of the user. By the adoption of the technical scheme, various types of logs can be collected and stored in a unified mode, strict control over user permission is achieved, and information leakage is effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular, to a method, device, equipment and medium for log data management. Background Art

[0002] With the development of enterprise business, more and more tools such as network facilities, system facilities, business systems, and container platforms used by enterprises are increasing. In order to realize the monitoring and management of various tools, log collection is required.

[0003] In the prior art, generally, logs from different tools are collected and stored separately according to the tool type, resulting in problems of chaotic management. Moreover, for large enterprises with a large user group, the prior art cannot accurately control user permissions, leading to chaotic permission management and easy leakage of sensitive information. Summary of the Invention

[0004] The present invention provides a method, device, equipment and medium for log data management, which can uniformly collect and store various types of logs and strictly control user permissions, effectively avoiding information leakage.

[0005] According to one aspect of the present invention, there is provided a method for log data management, which is executed by a data management platform and includes:

[0006] Collect logs to a target file path and generate a standard source identifier for corresponding storage with the logs;

[0007] Identify log features according to the target file path, the standard source identifier and the logs;

[0008] Store the logs in a corresponding directory in the dataset according to the log features;

[0009] When a user accesses the data management platform, open the access or processing permissions of multiple target logs to the user according to the directory in the dataset and the user's permission information.

[0010] According to another aspect of the present invention, there is provided a log data management device, which is executed by a data management platform and includes:

[0011] A log collection module, configured to collect logs to a target file path and generate a standard source identifier for corresponding storage with the logs;

[0012] A feature identification module, configured to identify log features according to the target file path, the standard source identifier and the logs;

[0013] A log storage module, configured to store the logs in a corresponding directory in the dataset according to the log features;

[0014] A permission opening module, which is used to open the access or processing permissions of multiple target logs to a user according to the directory in the dataset and the user's permission information when the user accesses the data management platform.

[0015] According to another aspect of the present invention, there is provided an electronic device, which includes:

[0016] At least one processor; and

[0017] A memory communicatively connected to the at least one processor; wherein,

[0018] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the log data management method according to any embodiment of the present invention.

[0019] According to another aspect of the present invention, there is provided a computer-readable storage medium, which stores computer instructions for implementing the log data management method according to any embodiment of the present invention when executed by a processor.

[0020] The technical solution of the embodiment of the present invention can uniformly collect and store logs from various devices and various types in the form of a dataset in the directory by collecting logs to a target file path, generating a standard source identifier corresponding to the log for storage, identifying log features according to the target file path, the standard source identifier, and the log, and storing the log in the corresponding directory in the dataset according to the log features. This solves the problems of separate storage of different types of logs, messy and non-standard data in the prior art. By opening the access or processing permissions of multiple target logs to a user according to the directory in the dataset and the user's permission information when the user accesses the data management platform, strict control of user permissions can be achieved, so that each user can only see the content that he needs and should see, effectively avoiding information leakage, ensuring log security, and improving the viewing efficiency of users.

[0021] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0023] Figure 1 is a flowchart of a log data management method provided in Embodiment 1 of the present invention;

[0024] Figure 2 is a flowchart of another log data management method provided in Embodiment 2 of the present invention;

[0025] Figure 3 is a schematic structural diagram of a log data management system provided in the embodiments of the present invention;

[0026] Figure 4 is a schematic structural diagram of a log data management device provided in Embodiment 3 of the present invention;

[0027] Figure 5 is a schematic structural diagram of an electronic device for implementing the log data management method of the embodiments of the present invention. Detailed Embodiments

[0028] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0030] Embodiment 1

[0031] Figure 1 The flowchart of a log data management method provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of unified collection and management of various types of logs in an enterprise. This method can be executed by a log data management device, which can be implemented in the form of hardware and / or software and can be configured in a data management platform. The data management platform can be installed in a computer or processor with data processing capabilities. As Figure 1 shown, the method includes:

[0032] S110. Collect the logs to the target file path and generate a standard source identifier corresponding to the logs for storage.

[0033] Optionally, the data management platform can be a big data collection platform. By pre-configuring the file paths in various log sources such as network facilities, system facilities, business systems, and container platforms, when logs are generated in each log source, the logs can be directly collected to the target file path configured for that log source, but it is not limited to the various log sources exemplified above.

[0034] Optionally, for different log sources used in an enterprise, the types of logs generated are also different. The log types mainly can include network logs, security logs, Docker running logs, Linux & Windows system logs, transaction logs of business systems, and metric data of monitoring systems.

[0035] Optionally, the file path can correspond to the log collection method. The file paths configured for each log source correspond to the log types generated by them. The log collection methods can include the log record protocol method, the file method, and the message queue system method. For example, the log record protocol can be the SYSLOG protocol. When the log source generates network logs or security logs, the file path configured for the log source corresponds to the log record protocol method; when the log source generates Docker running logs or metric data of the monitoring system, the file path configured for the log source corresponds to the message queue system method; when the log source generates Linux & Windows system logs or transaction logs of business systems, the file path configured for the log source corresponds to the file method.

[0036] The advantage of such a setting is that: through various log collection methods, the method of collecting various types of logs to the specified target file path can realize the collection of all types of logs through the data management platform, and achieve the unified collection and storage of the data generated by each log source in the enterprise.

[0037] Optionally, the standard source identifier may include, but is not limited to, the IP (Internet Protocol) address of the log source, the target file path, the IP address of the network facility, the log source identifier, etc. When the log is the Docker running log or the metric data of the monitoring system, since the collection method of these two types of logs is the message queue system method, therefore, the standard source representation may also include a topic, which can be used to further classify the logs collected in the message queue system method.

[0038] S120. Identify log features according to the target file path, the standard source identifier, and the log.

[0039] Among them, identifying log features according to the target file path, the standard source identifier, and the log may include:

[0040] Determine the collection method of the log according to the target file path;

[0041] Parse the log and determine the log type and device type according to the key fields in the log;

[0042] Determine the distribution area according to the IP network segment in the standard source identifier.

[0043] Optionally, the log features may include the collection method of the log, the log type, the device type, and the distribution area.

[0044] Optionally, different file paths may correspond to different cache areas. When it is determined that the log is stored under the target file path, the target collection method corresponding to the target file path may be determined as the collection method of the log.

[0045] Optionally, for the same collection method, it may collect multiple different types of logs. For example, through the log record protocol method, network logs and security logs can be stored in the same target file path. Therefore, it is necessary to further classify the logs under the target file path by log type.

[0046] It can be understood that different types of logs are used to record different data contents. Furthermore, in different types of logs, there are different key fields or different log descriptions. By analyzing the key fields or log descriptions, the log type can be determined.

[0047] In an optional example, when fields such as the alarm level and alarm description are identified in the log, these fields may be pre-specified as the key fields of the metric data of the monitoring system, thereby determining that the log type is the metric data of the monitoring system.

[0048] Optionally, based on the key fields in the log, the log type and the device type can be determined, which can specifically include: obtaining the first key field and the second key field respectively corresponding to each pre-determined log type; when the first key field is recognized in the log, determining the log type as the target log type corresponding to the first key field, and recognizing the second key field in the log, and determining the device type according to the value of the second key field.

[0049] Optionally, the device type can refer to the device type that generates the log, that is, the device type of the log source device. For example, when the log type is a network log, the corresponding device type can be any one of a firewall, a switch, and a router. This is only an exemplary illustration here.

[0050] Optionally, the distribution area can refer to the computer room region where the log source device is located. For example, it comes from the Jiangsu computer room, the Shanghai computer room, etc.

[0051] Optionally, after identifying the log features based on the target file path, the standard source identifier, and the log, it can further include:

[0052] Determining the log type according to the log features, and determining the management method of the log according to the log type; where the management method includes the storage time and the number of copies.

[0053] Optionally, for different log types, the management method can be preset, and the storage time and the number of copies of the log can be managed according to the management method corresponding to the log type.

[0054] In an optional example, the management method of network logs can be to store them for 180 days and have two copies; the management method of security logs can be to store them for 180 days and have two copies; the management method of Docker running logs can be to store them for 60 days and have two copies; the management method of Linux&Windows system logs can be to store them for 180 days and have two copies; the management method of transaction logs of the business system can be to store them for 90 days and have two copies; the management method of metric data of the monitoring system can be to store them for 30 days and have two copies. This is only an exemplary illustration here. The specific storage time and the number of copies can be set according to user requirements.

[0055] S130. Store the log in the corresponding directory in the dataset according to the log features.

[0056] Optionally, in the data management platform, logs can be maintained through a dataset in the form of a directory. The directory of the dataset can be divided into multiple levels, and each directory level corresponds to the log collection method, log type, device type, and distribution area of the logs. For example, the first-level directory is the log collection method, and the logs belonging to the same collection method are divided under the same first-level directory; the second-level directory is the log type, and the second-level directories under each first-level directory include all the log types corresponding to the log collection method of the first-level directory; the third-level directory is the device type, and the third-level directories under each second-level directory include the device types of all the log source devices corresponding to the log type of the second-level directory; the fourth-level directory is the distribution area, and the fourth-level directories under each third-level directory include all the distribution areas where the device types of the third-level directory are located.

[0057] Table 1 shows an optional directory table. Taking the log record protocol method as an example, Table 1 shows the directory situation at all levels under a first-level directory, which is only for illustrative purposes and does not limit the specific directory form and content.

[0058] As shown in Table 1, when the first-level directory is the log record protocol method, the log types of its second-level directory can include network logs and security logs. Under the third-level directory of network logs, it can include firewalls and switches. Under the third-level directory of security logs, it can include Web application firewalls. When firewalls, switches, and Web application firewalls are all deployed in the Shanghai computer room and the Jiangsu computer room, the fourth-level directories of each third-level directory include the Shanghai computer room and the Jiangsu computer room. This is only for illustrative purposes and aims to clarify the division method of each level of directory.

[0059] Table 1

[0060]

[0061] Optionally, after determining the log features, according to each log feature, determine the levels of directories to which the log belongs, and then store the log in the corresponding directory.

[0062] S140. When the user accesses the data management platform, open the access or processing permissions of multiple target logs to the user according to the directory in the dataset and the user's permission information.

[0063] Optionally, to ensure the data security of an enterprise, different business teams in the enterprise generally can only view the logs associated with their work content. For example, the network operation and maintenance team has the access or processing permission for network logs, the security management team has the access or processing permission for security logs, the big data development team has the access or processing permission for Docker running logs, the system management team has the access or processing permission for Linux & Windows system logs, the business development team has the access or processing permission for transaction logs of business systems, and the operation and maintenance monitoring team has the access or processing permission for metric data of monitoring systems. However, since the enterprise architecture of each enterprise is different, it is not limited to the above business teams, and the log types corresponding to specific business teams can be allocated and managed by the enterprise.

[0064] Furthermore, an enterprise can also divide business teams by region. For example, for the network operation and maintenance teams, the network operation and maintenance team in Jiangsu can only access the logs from the Jiangsu computer room in the network logs, and the network operation team in Shanghai can only access the logs from the Shanghai computer room in the network logs. This is only for illustrative purposes.

[0065] Among them, when a user accesses the data management platform, according to the directory in the dataset and the user's permission information, the access or processing permission for multiple target logs is opened to the user, which may include:

[0066] Determine the user's group, account level, and personal permissions according to the account identifier currently accessing the data management platform;

[0067] Determine multiple target logs in the dataset according to the user's group and personal permissions, and determine the user's access permission or processing permission according to the user's account level;

[0068] Adjust the user's access page according to the target logs and the user's access permission or processing permission.

[0069] Optionally, each user of the enterprise can be managed in the form of groups in the data management platform. According to the business team and region where each user is located in the enterprise, determine the group corresponding to each user, allocate the user identifier to the group, and store the account level and personal permissions corresponding to the user identifier. Among them, when establishing groups and dividing users, both the business team and region are considered, and the group identifier includes both business team information and the region information where the business team is located.

[0070] Optionally, according to the account level, it can be determined whether the user has access or processing permissions. When the account level belongs to the first level, it is determined that the user has access permissions and can only view the logs. When the account level belongs to the second level, it is determined that the user has processing permissions and can not only view the logs, but also perform operations such as modifying, transferring, and revoking and delegating permissions on the logs. For example, for ordinary employees, their account level can be the first level, and for team or regional leaders, their account level can be the second level. The senior leaders of the enterprise can also be set to the third level, which is not limited here.

[0071] It can be understood that according to the user's affiliated team and location, the directory range of the user's permissions can be determined. When the user needs to view additional logs, a permission application can be made. For example, when the user belongs to the network operation and maintenance team in Jiangsu, generally, they can only access the logs from the Jiangsu computer room in the network logs. However, if they apply to access the network logs from the Shanghai computer room and the approval is passed, the network logs from the Shanghai computer room will be associated and stored with their account identifier as their personal permissions.

[0072] Optionally, according to the user's group and personal permissions, multiple target logs are determined in the dataset, and according to the user's account level, it is determined whether the user has access or processing permissions, which may include: determining the user's affiliated business team and location according to the user's group; determining at least one set of directories matching the user's permissions according to the user's affiliated business team and location; where each set of directories includes the directory identifiers of each level of directories, and the directory identifiers of at least one level of directories are different between each set of directories; determining multiple target logs according to each set of directories matching the user's permissions and the user's personal permissions; determining whether the user's account level is the first level; if so, determining that the user has access permissions to the target logs, if not, determining that the user has processing permissions to the target logs.

[0073] Optionally, according to the target logs and the user's access or processing permissions, the user's access page can be adjusted, which may include: displaying each target log on the user's access page; if the user has processing permissions, operation components for each target log are also displayed on the user's access page.

[0074] The technical solution of the embodiment of the present invention can uniformly collect and store logs from various devices and various types of logs through a dataset in the form of a directory by collecting logs to the target file path, generating a standard source identifier corresponding to the logs for storage, identifying log features based on the target file path, the standard source identifier, and the logs, and storing the logs in the corresponding directory in the dataset according to the log features. This solves the problems of separate storage of different types of logs, messy and non-standard data in the prior art. By opening the access or processing permissions of multiple target logs to the user according to the directory in the dataset and the user's permission information when the user accesses the data management platform, strict control of user permissions can be achieved, enabling each user to only see the content they need and should see, effectively avoiding information leakage, ensuring log security, and improving the user's viewing efficiency.

[0075] Embodiment 2

[0076] Figure 2 FIG. is a flowchart of a log data management method provided by Embodiment 2 of the present invention. Based on the above embodiment, this embodiment specifically illustrates the management method of the data management platform for users. As Figure 2 shown, the method includes:

[0077] S210. Collect logs to the target file path and generate a standard source identifier corresponding to the logs for storage.

[0078] S220. Determine the log collection method according to the target file path.

[0079] S230. Analyze the logs and determine the log type and device type according to the key fields in the logs.

[0080] S240. Determine the distribution area according to the IP network segment in the standard source identifier.

[0081] S250. Determine the log type according to the log features, and determine the log management method according to the log type.

[0082] Among them, the management method includes storage time and the number of copies.

[0083] The advantage of this setting is that on the basis of realizing the unified collection and management of log data, different management methods are assigned to various types of logs, enabling personalized and flexible management of various types of logs, so that the storage time and the number of copies can be set separately according to the importance of the data, ensuring that key data will not be lost, and at the same time, reasonably allocating the storage space to prevent unimportant data from occupying the storage space for a long time.

[0084] S260. Store the logs in the corresponding directory in the dataset according to the log features.

[0085] Optionally, the log features include the log collection method, log type, device type, and distribution area, and each log feature corresponds to each hierarchical directory in the dataset.

[0086] S270. Determine the user's group, account level, and personal permissions based on the account identifier of the currently accessing the data management platform.

[0087] Among them, the method further includes:

[0088] Obtain the data synchronization permission of the first system, and synchronize the user information of each user in the first system to the data management platform; where the user information includes the account identifier, the affiliated organizational structure, the account level, and the personal permissions;

[0089] Create multiple groups according to the affiliated organizational structures of each user;

[0090] Allocate each account identifier to each group, and associate and store the user's account level and personal permissions with the user's account identifier.

[0091] Optionally, the first system may refer to a system used in an enterprise for unified management of the accounts of enterprise internal personnel. The first system can manage information such as the organizational structures where each user in the enterprise is located, user accounts, and user names.

[0092] Optionally, obtaining the data synchronization permission of the first system may include:

[0093] Establish a data synchronization connection with the first system according to the access information of the first system; where the access information includes the access address, user name, password, and organizational unit (OU) of the first system;

[0094] When establishing the connection for the first time, synchronize the user information of all users in the first system to the data management platform.

[0095] Optionally, the user's affiliated organizational structure may include the business team where the user is located and the region where the business team is located. The account identifier may include the user account and / or user name. The account level may refer to the account level of the user in the enterprise, such as first level, second level, third level, etc. The personal permissions may refer to the permissions other than the permissions limited by the team and region of the user.

[0096] Optionally, based on the organizational structure to which the user belongs, all business teams of the enterprise and the regions where each business team is located can be determined, and then each group can be generated; the groups can be in a parallel relationship, and each group is different in at least one of the business team and the region. For example, the safety management team in Jiangsu is a group, the safety management team in Shanghai is a group, the network operation and maintenance team in Shanghai is a group, and so on; there can also be a certain organizational structure relationship between the groups. The business team is the first-level organizational structure, and the region is the second-level organizational structure. For example, the safety management team can be a large group of the first-level organizational structure. Under each large group, there are also small groups located in Jiangsu and Shanghai respectively. This is only for illustrative purposes.

[0097] Wherein, the method further includes:

[0098] After the user information of the first user in the first system is changed, synchronize the changed user information to the data management platform, and maintain the account identifier of the first user in the group according to the changed user information.

[0099] Optionally, the change of user information can include adding a user, deleting a user, changing the user account level, and changing the organizational structure to which the user belongs, etc. Maintaining the account identifier of the first user in the group can include adding an account identifier, deleting an account identifier, updating the account level associated with the account identifier, and updating the group where the account identifier is located, etc. The first user can refer to the user whose user information is changed in the first system.

[0100] Optionally, after the connection with the first system is established for the first time, the change situation of the user information in the first system can be synchronized in real time. When a new user is added in the first system, the information of the new user can be synchronized to the data management platform, and the new user can be added to the corresponding group; when a user is deleted in the first system, the user can be correspondingly deleted in the group; when the account level of the user is changed, the account level of the user is modified in the group; when the organizational structure to which the user belongs is changed, the user is changed to a different group.

[0101] Wherein, the method further includes:

[0102] When a newly approved application work order is detected in the second system, parse the application work order to obtain the account identifier, the organizational structure to which the second user belongs, and the application data scope of the second user;

[0103] Judge whether the account identifier of the second user exists in the group;

[0104] If so, update the personal permissions of the second user in the group according to the application data scope;

[0105] If not, according to the organizational structure to which the second user belongs, assign the account identifier of the second user to the corresponding group, and generate the personal permissions of the second user according to the scope of the application data.

[0106] Optionally, the second system can be a system that supports automated work order processing. The data management platform can interface with the second system through the inherent API (Application Programming Interface) permission configuration interface to actively detect the approval work order tool in the second system.

[0107] Optionally, when a user needs to apply for additional personal permissions, they can fill out a work order in the approval work order tool in the second system and upload it to the management for approval. The scope of the application data can refer to the scope of the additional access logs applied for by the user by filling out the work order. The scope of the additional access logs refers to the log scope outside the log scope defined by their own business team and region. The second user can refer to the user who fills out the work order.

[0108] Figure 3 It is a schematic diagram of the structure of an optional log data management system. As Figure 3 shown, the data management platform, the first system, and the second system can jointly form a log data management system. The data management platform can synchronize the user information in the first system and the work order information in the second system. Moreover, the data management platform supports collecting various types of logs in multiple collection methods.

[0109] S280. Determine multiple target logs in the dataset according to the group where the user is located and the personal permissions, and determine whether the user has access rights or processing rights according to the user's account level.

[0110] S290. Adjust the user's access page according to the target logs and the user's access rights or processing rights.

[0111] The technical solution of the embodiment of the present invention collects logs to the target file path, generates a standard source identifier and stores it corresponding to the logs, identifies log features according to the target file path, the standard source identifier and the logs, and stores the logs in the corresponding directory in the data set according to the log features. In this way, it can uniformly collect and store logs from various devices and various types in the form of a data set in the directory, solving the problems of separate storage of different types of logs, messy and non-standard data in the prior art. When a user accesses the data management platform, according to the directory in the data set and the user's permission information, the access or processing permissions of multiple target logs are opened to the user, realizing strict control of user permissions, and each user can only see the content he needs and should see, effectively avoiding information leakage, ensuring log security, and improving the viewing efficiency of users. By synchronizing the data of the first system and the second system and maintaining the user's account identifier and updating the personal permissions in the data management platform, it can realize automated user information management, solve the problem of high difficulty in personnel review and configuration, accurately manage user permissions, and avoid the problem of chaotic user permission management.

[0112] Embodiment III

[0113] Figure 4 It is a schematic structural diagram of a log data management device provided in Embodiment III of the present invention. As Figure 4 shown, the device includes: a log collection module 310, a feature recognition module 320, a log storage module 330, and a permission opening module 340.

[0114] The log collection module 310 is used to collect logs to the target file path and generate a standard source identifier and store it corresponding to the logs.

[0115] The feature recognition module 320 is used to identify log features according to the target file path, the standard source identifier, and the logs.

[0116] The log storage module 330 is used to store the logs in the corresponding directory in the data set according to the log features.

[0117] The permission opening module 340 is used to, when a user accesses the data management platform, open the access or processing permissions of multiple target logs to the user according to the directory in the data set and the user's permission information.

[0118] The technical solution of the embodiment of the present invention can uniformly collect and store logs from various devices and various types of logs through a dataset in the form of a directory by collecting logs to a target file path, generating a standard source identifier corresponding to the logs for storage, identifying log features according to the target file path, the standard source identifier, and the logs, and storing the logs in the corresponding directory in the dataset. This solves the problems of separate storage of different types of logs, messy and non-standard data in the prior art. By opening the access or processing permissions of multiple target logs to the user according to the directory in the dataset and the user's permission information when the user accesses the data management platform, strict control over user permissions can be achieved, enabling each user to only see the content that they need and should see, effectively avoiding information leakage, ensuring log security, and improving the user's viewing efficiency.

[0119] Based on the above embodiments, a log management module may further be included for:

[0120] Determine the log type according to the log features, and determine the management method of the logs according to the log type; wherein, the management method includes storage time and the number of copies.

[0121] Based on the above embodiments, a group creation module may further be included for:

[0122] Obtain the data synchronization permission of the first system, and synchronize the user information of each user in the first system to the data management platform; wherein, the user information includes account identifier, affiliated organizational structure, account level, and personal permissions;

[0123] Create multiple groups according to the affiliated organizational structures of each user;

[0124] Allocate each account identifier to each group, and store the account level and personal permissions of the user in association with the account identifier of the user.

[0125] Based on the above embodiments, a user information change module may further be included for:

[0126] After the user information of the first user in the first system is changed, synchronize the changed user information to the data management platform, and maintain the account identifier of the first user in the group according to the changed user information.

[0127] Based on the above embodiments, a permission application module may further be included for:

[0128] When a newly approved application work order is detected in the second system, parse the application work order to obtain the account identifier, affiliated organizational structure, and application data scope of the second user;

[0129] Determine whether there is an account identifier of the second user in the group;

[0130] If so, update the personal permissions of the second user in the group according to the application data range;

[0131] If not, allocate the account identifier of the second user to the corresponding group according to the organizational structure to which the second user belongs, and generate the personal permissions of the second user according to the application data range.

[0132] Based on the above embodiments, the feature recognition module 320 can be specifically configured to:

[0133] Determine the log collection method according to the target file path;

[0134] Parse the log, and determine the log type and device type according to the key fields in the log;

[0135] Determine the distribution area according to the IP network segment in the standard source identifier.

[0136] Based on the above embodiments, the permission opening module 340 can be specifically configured to:

[0137] Determine the group where the user is located, the account level, and the personal permissions according to the account identifier of the currently accessing the data management platform;

[0138] Determine multiple target logs in the dataset according to the group where the user is located and the personal permissions, and determine the access permission or processing permission of the user according to the user's account level;

[0139] Adjust the user's access page according to the target log and the user's access permission or processing permission.

[0140] The log data management device provided by the embodiments of the present invention can execute the log data management method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0141] Embodiment 4

[0142] Figure 5The structural schematic diagram of the electronic device 10 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0143] As Figure 5 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0144] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0145] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the log data management method described in the embodiments of the present invention. That is:

[0146] Collect the logs into the target file path and generate the corresponding storage of the standard source identifier and the logs;

[0147] Identify log features based on the target file path, standard source identifier, and log.

[0148] Store the log in the corresponding directory in the dataset according to the log features.

[0149] When a user accesses the data management platform, open the access or processing permissions of multiple target logs to the user according to the directory in the dataset and the user's permission information.

[0150] In some embodiments, the log data management method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by the processor 11, one or more steps of the log data management method described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute the log data management method by any other suitable means (e.g., by means of firmware).

[0151] The various embodiments of the systems and techniques described above in this document may be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: implemented in one or more computer programs, which may be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, and may receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0152] The computer program for implementing the method of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to the processor of a general-purpose computer, a dedicated computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0153] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0154] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0155] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0156] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0157] It should be understood that various forms of processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0158] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for managing log data, characterized in that, Executed by the data management platform, including: Collect the logs to the target file path and generate the corresponding storage of the standard source identifier and the logs; Identify the log features according to the target file path, the standard source identifier and the logs; Store the logs in the corresponding directory in the dataset according to the log features; When the user accesses the data management platform, open the access or processing permissions of multiple target logs to the user according to the directory in the dataset and the user's permission information.

2. The method according to claim 1, characterized in that, After identifying the log features according to the target file path, the standard source identifier and the logs, it further includes: Determine the log type according to the log features, and determine the management method of the logs according to the log type; wherein, the management method includes the storage time and the number of copies.

3. The method according to claim 1, characterized in that, It also includes: Obtain the data synchronization permission of the first system and synchronize the user information of each user in the first system to the data management platform; wherein, the user information includes the account identifier, the affiliated organizational structure, the account level and the personal permissions; Create multiple groups according to the affiliated organizational structures of each user; Assign each account identifier to each group and associate and store the user's account level and personal permissions with the user's account identifier.

4. The method according to claim 3, characterized in that It also includes: After the user information of the first user in the first system is changed, synchronize the changed user information to the data management platform, and maintain the account identifier of the first user in the group according to the changed user information.

5. The method according to claim 3, wherein It also includes: When a newly approved application work order is detected in the second system, parse the application work order to obtain the account identifier, the affiliated organizational structure and the application data scope of the second user; Judge whether the account identifier of the second user exists in the group; If so, update the personal permissions of the second user in the group according to the application data scope; If not, assign the account identifier of the second user to the corresponding group according to the affiliated organizational structure of the second user, and generate the personal permissions of the second user according to the application data scope.

6. The method according to claim 1, wherein Identifying the log features according to the target file path, the standard source identifier and the logs includes: Determine the log collection method according to the target file path; Parse the logs and determine the log type and the device type according to the key fields in the logs; Determine the distribution area according to the Internet Protocol (IP) network segment in the standard source identifier.

7. The method according to claim 3, characterized in that, When the user accesses the data management platform, opening the access or processing permissions of multiple target logs to the user according to the directory in the dataset and the user's permission information includes: Determine the user's group, account level and personal permissions according to the account identifier currently accessing the data management platform; Determine multiple target logs in the dataset according to the user's group and personal permissions, and determine the user's access permission or processing permission according to the user's account level; Adjust the user's access page according to the target logs and the user's access permission or processing permission.

8. A log data management device, characterized in that, Executed by the data management platform, including: A log collection module for collecting the logs to the target file path and generating the corresponding storage of the standard source identifier and the logs; A feature recognition module, configured to recognize log features according to a target file path, a standard source identifier, and a log; A log storage module, configured to store the log in a corresponding directory in a dataset according to the log features; A permission opening module, configured to, when a user accesses a data management platform, open access or processing permissions for multiple target logs to the user according to the directories in the dataset and the user's permission information.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the log data management method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a processor to implement the log data management method according to any one of claims 1-7 when executed.