Log query method and device, medium and equipment
Through the collaboration of semantic parsing agents and large models, efficient and universal cross-system log queries are achieved, solving the problems of poor universality and long time consumption of log query methods in existing technologies, and improving query efficiency and response rate.
Patent Information
- Application Number
- CN202510621903.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-14
- Publication Date
- 2025-09-19
AI Technical Summary
Existing log query methods have poor versatility and are time-consuming, making them difficult to use across systems. Manual queries are cumbersome and automatic queries are inefficient.
Through semantic parsing agents, user intentions are identified, large models are used to split the target problems into tasks, and query agents corresponding to each sub-service system are matched to perform asynchronous log queries and generate analysis reports.
It improves the generalization and versatility of log queries, realizes efficient cross-system log queries, reduces manual intervention time, and improves response speed.
Smart Images

Figure CN120670385A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of log query technology, and in particular relates to a log query method, device, medium and equipment. Background Art
[0002] Logs are files or collections of information that record events that occur during the operation of systems, applications, network devices, and more. When a system or device malfunctions, technicians can use the detailed information recorded in the logs to locate the problem. With the acceleration of digitalization and the increasing complexity of enterprise systems, cloud services, and distributed architectures, the volume of log data is exploding. Searching for key information within this massive log volume and summarizing task anomalies is a daunting task.
[0003] Currently, there are two main log query methods. One is manual screening one by one, and summarizing the exception report based on the screened content. The other is automatic query, which specifically extracts keywords based on user query information and uses the keywords as an index to search for relevant information in a large number of logs. The queried logs may be relatively messy and irregular. The queried logs are parsed using regular rules, and finally an exception report is generated by manual summary based on the parsing results.
[0004] These query methods have many shortcomings in practical applications. The manual query method is not only cumbersome and time-consuming, but also difficult to respond to business needs in a timely manner. The automatic query method queries from massive data, and the query efficiency is relatively low. At the same time, it has a strong dependence on the log format and structure. Since the log formats in different service systems are different, log queries can only be performed on one service system at a time. The versatility is relatively poor, and it is difficult to achieve cross-system migration. In addition, manual summary and generation of exception reports are required, which is also time-consuming. Summary of the Invention
[0005] In view of this, the present invention provides a log query method, apparatus, medium and device, the main purpose of which is to solve the problem that the existing automatic log query method has poor versatility and is time-consuming.
[0006] According to one aspect of the present application, a log query method is provided, the method comprising:
[0007] Receive the user's data query statement, and use the preset semantic parsing agent to detect the intention of the data query statement to obtain the target question;
[0008] Based on the functions of each sub-service system, the target problem is split into tasks using a preset large model to obtain multiple sub-problem tasks, wherein each sub-problem task is related to at least one sub-service system;
[0009] Matching the sub-problem tasks with the query agent using the large model to obtain matching results, and sending each sub-problem task to a matching target query agent according to the matching results, wherein each target query agent corresponds to a sub-service system;
[0010] Each target query agent analyzes the received sub-question task, and performs a log query in the database of the sub-service system corresponding to the target query agent according to the analysis result to obtain the query data;
[0011] The data queried by each target query agent is aggregated to obtain total query data, and the total query data is input into the large model to obtain a log analysis report.
[0012] Optionally, each of the target query agents parses the received sub-question tasks, and performs a log query in a database of a sub-service system corresponding to the target query agent according to the parsing result, including:
[0013] The target query agent parses the sub-problem task, obtains a first keyword from the parsing result, performs a log query in the database of the sub-service system based on the first keyword to obtain log query data, and organizes the log query data according to a first preset structure to obtain first structured query data.
[0014] Optionally, after parsing the sub-problem task, the log query method further includes:
[0015] If the parsing result also includes an associated SQL table name, the target query agent obtains the task conditions and task operations from the parsing result, generates an SQL query statement based on the task conditions, the task operations, the associated SQL table name and the first keyword, queries the data table in the database based on the SQL query statement, obtains SQL query data, and organizes the SQL query data according to a second preset structure to obtain second structured query data.
[0016] Optionally, after generating the SQL query statement based on the task condition, the task operation, the associated SQL table name, and the first keyword, the log query method further includes:
[0017] If the SQL query statement fails to query the database, the target query agent generates task re-splitting information and sends it to the large model, so that the large model re-splitting the task of the target problem.
[0018] Optionally, after performing intent detection on the data query statement using a preset intent detection model, the log query method further includes:
[0019] If the result of the intention detection is irrelevant to the log query, the semantic parsing agent obtains the answer to the data query statement from a preset knowledge base and outputs the answer to the data query statement.
[0020] Optionally, after aggregating the data queried by each target query agent to obtain total query data, and before inputting the total query data into the large model, the log query method further includes:
[0021] The answer recognition agent determines whether the total query data can answer the target question. When the total query data cannot answer the target question, task re-splitting information is generated and sent to the large model so that the large model re-splitting the target question. When the total query data can answer the target question, the total query data is input into the large model.
[0022] Optionally, determining whether the total query data can answer the target question includes:
[0023] If the target query agent queries data, a second keyword in the target question is determined, a correlation between the second keyword and the total query data is calculated, and a query time of each target query agent querying the data is obtained. When the correlation is less than a preset correlation threshold and / or the number of target query agents whose query time is greater than or equal to the time threshold is greater than a quantity threshold, it is determined that the total query data cannot answer the target question;
[0024] If all the target query agents fail to find any data, it is determined that the total query data cannot answer the target question.
[0025] According to another aspect of the present application, a log query device is provided, comprising:
[0026] The target question acquisition module is used to receive the user's data query statement, and use the preset semantic parsing agent to detect the intention of the data query statement to obtain the target question;
[0027] A task splitting module is used to split the target problem into multiple sub-problem tasks based on the function of each sub-service system using a preset large model, wherein each sub-problem task is related to at least one sub-service system;
[0028] A matching module is used to match the sub-question tasks with the query agent using the large model to obtain matching results, and send each sub-question task to a matching target query agent according to the matching results, wherein each target query agent corresponds to a sub-service system;
[0029] A query module, configured for each target query agent to parse the received sub-question task, and perform a log query in the database of the sub-service system corresponding to the target query agent based on the parsing result to obtain the queried data;
[0030] The analysis module is used to summarize the data queried by each target query agent to obtain total query data, input the total query data into the large model, and obtain a log analysis report.
[0031] Optionally, the query module is also used for: the target query agent parses the sub-problem task, obtains a first keyword from the parsing result, performs a log query in the database of the sub-service system based on the first keyword to obtain log query data, and organizes the log query data according to a first preset structure to obtain first structured query data.
[0032] Optionally, the query module is also used for: if the parsing result also includes an associated SQL table name, the target query agent obtains the task conditions and task operations from the parsing result, generates an SQL query statement based on the task conditions, the task operation, the associated SQL table name and the first keyword, queries the data table in the database based on the SQL query statement to obtain SQL query data, and organizes the SQL query data according to a second preset structure to obtain second structured query data.
[0033] Optionally, the query module is also used for: if the SQL query statement fails to query the database, the target query agent generates task re-splitting information and sends it to the big model, so that the big model re-splitting the task of the target problem.
[0034] Optionally, the target question acquisition module is further used to: if the result of the intention detection is irrelevant to the log query, the semantic parsing agent obtains the answer to the data query statement from a preset knowledge base and outputs the answer to the data query statement.
[0035] Optionally, the analysis module is also used for: the answer recognition agent determines whether the total query data can answer the target question; when the total query data cannot answer the target question, task re-splitting information is generated and sent to the large model, so that the large model re-splitting the target question; when the total query data can answer the target question, the total query data is input into the large model.
[0036] Optionally, the analysis module is also used to: if the target query agent queries data, determine the second keyword in the target question, calculate the correlation between the second keyword and the total query data, and obtain the query time when each target query agent queries the data; when the correlation is less than a preset correlation threshold and / or the number of target query agents whose query time is greater than or equal to the time threshold is greater than the quantity threshold, determine that the total query data cannot answer the target question; if all target query agents do not query data, determine that the total query data cannot answer the target question.
[0037] According to another aspect of the present application, a storage medium is provided, in which at least one executable instruction is stored. The executable instruction enables a processor to execute operations corresponding to the log query method described above.
[0038] According to another aspect of the present application, a computer device is provided, comprising: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other via the communication bus;
[0039] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute operations corresponding to the log query method as described above.
[0040] By means of the above technical solution, the present application provides a log query method, device, medium and equipment, which recognizes the intention of the data query statement input by the user based on the semantic parsing agent to obtain the target problem, and decomposes the target problem into multiple sub-problem tasks based on the big model. The big model matches the sub-problem tasks with the query agent, and sends each sub-problem task to at least one target query agent corresponding to it according to the matching results. Each target query agent performs log query according to the corresponding sub-problem task, and the data queried by each target agent is integrated together to obtain the total query data, and the total query data is sent to the big model. The big model generates an analysis report based on the total query data. Through the cooperation between the big model and multiple agents, multiple target query agents perform data query at the same time to realize asynchronous query, thereby improving query efficiency. Since the sub-service system corresponding to each query agent may use different environments or code languages, it is only necessary to modify the query agent to query the new sub-service system, which greatly improves the generalization and versatility of log queries.
[0041] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0043] Figure 1 A flow chart of a log query method provided by an embodiment of the present application is shown;
[0044] Figure 2 Another flow chart of a log query method provided by an embodiment of the present application is shown;
[0045] Figure 3 Another flow chart of a log query method provided by an embodiment of the present application is shown;
[0046] Figure 4 A block diagram of a log query device provided by an embodiment of the present application is shown;
[0047] Figure 5 A structural diagram of a computer device provided in an embodiment of the present application is shown.
[0048] In the figure: 402 - target problem acquisition module; 404 - task splitting module; 406 - matching module; 408 - query module; 410 - analysis module; 502 - processor; 504 - communication interface; 506 - memory; 508 - communication bus; 510 - program. DETAILED DESCRIPTION
[0049] The present invention will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, in the absence of conflict, the embodiments and features of the embodiments of the present invention can be combined with each other.
[0050] To further illustrate the technical means and effects employed by the present invention to achieve its intended objectives, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention is provided in conjunction with the accompanying drawings and preferred embodiments. In the following description, different references to "one embodiment" or "embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics of one or more embodiments may be combined in any suitable manner.
[0051] In order to solve the problem that the existing automatic log query method has poor versatility and is time-consuming, the embodiment of the present application provides a log query method, such as Figure 1 As shown, the method includes:
[0052] 102: Receive the user's data query statement, and use the preset semantic parsing agent to detect the intent of the data query statement to obtain the target question;
[0053] 104: Based on the functions of each sub-service system, the target problem is split into tasks using a preset large model to obtain multiple sub-problem tasks, wherein each sub-problem task is related to at least one sub-service system;
[0054] 106: Match the sub-problem tasks with the query agent through the large model to obtain matching results, and send each sub-problem task to the matching target query agent according to the matching results, where each target query agent corresponds to a sub-service system;
[0055] 108: Each target query agent parses the received sub-question task, and performs a log query in the database of the sub-service system corresponding to the target query agent based on the parsing result to obtain the queried data;
[0056] 110: Summarize the data queried by each target query agent to obtain total query data, input the total query data into the large model, and obtain a log analysis report.
[0057] Specifically, when users use an application service, system failures or abnormalities may occur. Logs record various events and operation information of the system before and after the failure. By querying the logs, operation and maintenance personnel can quickly locate the problem, understand what operations the system performed and what errors occurred, thereby speeding up the diagnosis and repair of the failure.
[0058] The execution subject of the present application is a processor or controller that can execute the log query method. The agent and the big model are modules in the processor that perform a certain function. When a system failure or abnormality occurs, the user inputs a data query statement about the failure or abnormality. The semantic parsing agent detects the intention of the data query statement and determines the target question that the user wants to query through multiple exchanges with the user. If the user's query is related to the log query, the semantic parsing agent sends the target question to the big model. The big model analyzes the question and outputs the analysis results. Based on the analysis results and the functional descriptions of multiple sub-service systems, a prompt word is generated and the prompt word is input into the big model again. The big model analyzes the sub-service system that may correspond to the system when a failure or abnormality occurs. Based on the prompt word, the target problem is split into tasks to obtain multiple sub-problem tasks. Each sub-problem task corresponds to at least one sub-service system. Different sub-service systems may use different environments or code languages. Each query agent corresponds to a sub-service system. If a new sub-service system is added, it is only necessary to add or modify the query agent.
[0059] According to the preset query agent mapping table, the large model matches the sub-service system corresponding to the sub-problem task with the sub-service system corresponding to the query agent, and obtains at least one target query agent corresponding to the sub-problem task. Each target query agent corresponds to a sub-service system. The large model then sends the sub-problem task to at least one target query agent corresponding to it, breaks down the user's question into different sub-problems, and assigns the sub-problem task to the target query agent. Subsequently, each target query agent simultaneously performs data queries based on the sub-problem task, completes asynchronous queries, collaboratively extracts valid log information from different subsystems, and completes the structured output of the information, which is convenient for the large model to parse. The information queried by all target query agents is aggregated to obtain the total query data, and the aggregated total query data is sent to the large model. The large model analyzes the aggregated total query data, analyzes the abnormal information in the log, gives suggestions for solutions, and generates a log analysis report for the final response, which is convenient for developers to make code corrections and improve the response rate to production problems.
[0060] For example, when the data query statement entered by the user is to purchase something through the ** application at ** time, and the transaction fails, the target problem determined by the semantic parsing agent is the failure of the ** application transaction and the corresponding time when it fails. The large model combines the functions of the sub-service system to analyze and split the target problem, and obtains multiple sub-problem tasks, namely: inconsistent data in the database, authentication failure, server failure, network failure, etc. Therefore, the sub-service system corresponding to each sub-problem is determined, and then the target query agent corresponding to each sub-service system is determined, and the sub-problem task is sent to each target query agent. Each target query agent performs log query according to the sub-problem task.
[0061] Compared with the existing technology, the log query method provided by the present application is based on semantic parsing agents to identify the intention of data query statements input by users to obtain a target problem, and based on the big model, the target problem is decomposed into tasks to obtain multiple sub-problem tasks. The big model matches the sub-problem tasks with the query agents, and sends each sub-problem task to at least one target query agent corresponding to it according to the matching results. Each target query agent performs log query according to the corresponding sub-problem task, and the data queried by each target agent is combined to obtain total query data, and the total query data is sent to the big model. The big model generates an analysis report based on the total query data. Through the cooperation between the big model and multiple agents, multiple target query agents perform data query at the same time to realize asynchronous query, thereby improving query efficiency. Since the sub-service system corresponding to each query agent may adopt different environments or code languages, it is only necessary to modify the query agent to query the new sub-service system, which greatly improves the generalization and versatility of log queries.
[0062] In one embodiment, if the result of the intention detection is irrelevant to the log query, the semantic parsing agent obtains the answer to the data query statement in the preset knowledge base and outputs the answer to the data query statement, such as Figure 2 As shown in the figure, if the result of intention detection is that no log query is required or is irrelevant to the log query and can be answered directly, the semantic parsing agent directly outputs the answer. If log query is required, subsequent task decomposition is performed.
[0063] In one embodiment, after the data queried by each target query agent is summarized to obtain the total query data, before the total query data is input into the big model, the log query method also includes: the answer recognition agent determines whether the total query data can answer the target question. When the total query data cannot answer the target question, task re-splitting information is generated and sent to the big model, so that the big model re-splits the target question into tasks. When the total query data can answer the target question, the total query data is input into the big model.
[0064] Specifically, after the total query data is sent to the answer recognition agent, the answer recognition agent needs to determine whether the content in the log is sufficient to answer the user's question. If the log information is not sufficient to solve the problem, the answer recognition agent will flow to the task decomposition step, that is, the answer recognition agent sends the task re-splitting information to the large model. After receiving the task re-splitting information, the large model will summarize the experience from the historical information, re-plan the subtasks, re-match the target query agent, and collect relevant logs again, such as Figure 2 Here, the number of rotations needs to be controlled. If the problem cannot be solved after exceeding the number threshold or no abnormal information is found, the user will be reminded that the system is running normally for this task and asks for manual intervention.
[0065] Specifically, if the target query agent queries data, the second keyword in the target question is determined, the correlation between the second keyword and the total query data is calculated, and the query time when each target query agent queries the data is obtained. When the correlation is less than the preset correlation threshold and / or the number of target query agents whose query time is greater than or equal to the time threshold is greater than the quantity threshold, it is determined that the total query data cannot answer the target question; if all target query agents do not query data, it is determined that the total query data cannot answer the target question.
[0066] In this embodiment, the method by which the answer recognition agent determines whether the content in the log is sufficient to answer the user's question is that as long as any of the following situations occurs, it is determined that the queried log content cannot answer the user's question: (1) If all target query agents fail to query data, it is determined that the user's question cannot be answered; (2) the query time of the target query agent is measured, and when the number of target query agents whose query time is greater than or equal to the time threshold exceeds half of the number of target query agents, it is determined that the content in the log cannot answer the user's question; (3) the correlation between the target question and the log is calculated based on the keywords in the target question, and when the correlation exceeds the correlation threshold, it is determined that the content in the log cannot answer the user's question.
[0067] In another embodiment of the present invention, the log query method further includes:
[0068] The target query agent parses the sub-problem task, obtains the first keyword from the parsed result, performs a log query in the database of the sub-service system based on the first keyword, obtains log query data, and organizes the log query data according to the first preset structure to obtain first structured query data:
[0069] If the parsing result also includes the associated SQL table name, the target query agent obtains the task conditions and task operations from the parsing result, generates an SQL query statement based on the task conditions, task operations, associated SQL table names and the first keyword, queries the data table in the database based on the SQL query statement, obtains SQL query data, and organizes the SQL query data according to a second preset structure to obtain second structured query data.
[0070] Specifically, the target query agent parses the sub-problem tasks from the large model, extracting relevant parameters such as time period and task ID. If a SQL table query is required, the associated SQL table name must be extracted. Subsequently, a two-way query is performed on the log and SQL data. In the log query, the time period and task ID are used as keywords for keyword-based queries, sequentially retrieving exception and error information. Alternatively, an embedding model can be trained, using time period and task ID as vectors for vector-based retrieval. The target query agent organizes the log query data according to a first preset structure, generating first structured query data. In the SQL query, the target query agent constructs an SQL query statement based on the time period, task ID, and associated SQL table name. Based on the SQL query statement, it queries the SQL table in the corresponding self-service system database, generating SQL query data. The target query agent then organizes the retrieved SQL data into structured information according to a second preset structure, generating second structured query data. Finally, each target query agent integrates the first and second structured query data and outputs them, completing the query for each sub-problem task.
[0071] In this embodiment, if the SQL query statement fails to query the database, the target query agent generates task re-splitting information and sends it to the large model so that the large model can re-splitting the target problem, such as Figure 3 shown.
[0072] Furthermore, as a response to the above Figure 1 The implementation of the method shown, such as Figure 4 As shown, an embodiment of the present invention provides a log query device, including:
[0073] The target question obtaining module 402 is used to receive the user's data query statement, and to detect the intent of the data query statement through a preset semantic parsing agent to obtain the target question;
[0074] The task splitting module 404 is configured to split the target problem into multiple sub-tasks based on the functions of each sub-service system using a preset macro model, wherein each sub-task is associated with at least one sub-service system.
[0075] Matching module 406 is used to match sub-question tasks with query agents using the large model to obtain matching results, and send each sub-question task to a matching target query agent based on the matching results, where each target query agent corresponds to a sub-service system;
[0076] Query module 408, for each target query agent to parse the received sub-question task, and perform log query in the database of the sub-service system corresponding to the target query agent based on the parsing result to obtain the queried data;
[0077] The analysis module 410 is used to summarize the data queried by each target query agent to obtain total query data, input the total query data into the big model, and obtain a log analysis report.
[0078] Compared with the prior art, the log query device provided by the present application recognizes the intention of the data query statement input by the user based on the semantic parsing agent to obtain the target problem, decomposes the target problem into multiple sub-problem tasks based on the large model, and matches the sub-problem tasks with the query agent. According to the matching results, each sub-problem task is sent to at least one target query agent corresponding to it. Each target query agent performs log query according to the corresponding sub-problem task, and the data queried by each target agent is integrated to obtain the total query data, and the total query data is sent to the large model. The large model generates an analysis report based on the total query data. Through the cooperation between the large model and multiple agents, multiple target query agents perform data query at the same time to realize asynchronous query and improve query efficiency. Since the sub-service system corresponding to each query agent may adopt different environments or code languages, it is only necessary to modify the query agent to query the new sub-service system, which greatly improves the generalization and versatility of log queries.
[0079] In one embodiment, the query module is also used for: the target query agent parses the sub-problem task, obtains the first keyword from the parsing result, performs a log query in the database of the sub-service system based on the first keyword to obtain log query data, and organizes the log query data according to a first preset structure to obtain first structured query data.
[0080] In one embodiment, the query module is also used for: if the parsing result also includes the associated SQL table name, the target query agent obtains the task conditions and task operations from the parsing result, generates an SQL query statement based on the task conditions, task operations, the associated SQL table name and the first keyword, queries the data table in the database based on the SQL query statement, obtains SQL query data, and organizes the SQL query data according to a second preset structure to obtain second structured query data.
[0081] In one embodiment, the query module is also used for: if the SQL query statement fails to query in the database, the target query agent generates task re-splitting information and sends it to the big model, so that the big model re-splitting the task of the target problem.
[0082] In one embodiment, the target question acquisition module is further used to: if the result of the intention detection is irrelevant to the log query, the semantic parsing agent obtains the answer to the data query statement in a preset knowledge base and outputs the answer to the data query statement.
[0083] In one embodiment, the analysis module is also used for: the answer recognition agent determines whether the total query data can answer the target question. When the total query data cannot answer the target question, task re-splitting information is generated and sent to the big model so that the big model can re-split the target question into tasks. When the total query data can answer the target question, the total query data is input into the big model.
[0084] In one embodiment, the analysis module is also used to: if the target query agent queries data, determine the second keyword in the target question, calculate the correlation between the second keyword and the total query data, and obtain the query time when each target query agent queries the data; when the correlation is less than a preset correlation threshold and / or the number of target query agents whose query time is greater than or equal to the time threshold is greater than the quantity threshold, determine that the total query data cannot answer the target question; if all target query agents do not query data, determine that the total query data cannot answer the target question.
[0085] According to another aspect of the present application, a storage medium is provided, in which at least one executable instruction is stored. The executable instruction enables a processor to execute operations corresponding to the above-mentioned log query method.
[0086] According to one embodiment of the present invention, a storage medium is provided. The storage medium stores at least one executable instruction. The computer-executable instruction can execute the log query method in any of the above method embodiments.
[0087] Figure 5 A schematic structural diagram of a computer device provided according to an embodiment of the present invention is shown. The specific embodiment of the present invention does not limit the specific implementation of the computer device.
[0088] like Figure 5 As shown, the computer device may include: a processor (processor) 502 , a communication interface (Communications Interface) 504 , a memory (memory) 506 , and a communication bus 508 .
[0089] The processor 502 , the communication interface 504 , and the memory 506 communicate with each other via a communication bus 508 .
[0090] The communication interface 504 is used to communicate with other devices such as clients or other servers.
[0091] The processor 502 is configured to execute the program 510 , and specifically to execute the relevant steps in the above-mentioned log query method embodiment.
[0092] Specifically, the program 510 may include program codes, which include computer operation instructions.
[0093] Processor 502 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention. The one or more processors included in a computer device may be of the same type, such as one or more CPUs, or may be of different types, such as one or more CPUs and one or more ASICs.
[0094] The memory 506 is used to store the program 510. The memory 506 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
[0095] The program 510 may be specifically configured to enable the processor 502 to perform the following operations:
[0096] Receive the user's data query statement, and use the preset semantic parsing agent to detect the intent of the data query statement to obtain the target question;
[0097] Based on the functions of each sub-service system, the target problem is split into tasks using a preset large model to obtain multiple sub-problem tasks, where each sub-problem task is related to at least one sub-service system;
[0098] The large model is used to match sub-problem tasks with query agents to obtain matching results. Based on the matching results, each sub-problem task is sent to the matching target query agent, where each target query agent corresponds to a sub-service system.
[0099] Each target query agent parses the received sub-question task and performs log query in the database of the sub-service system corresponding to the target query agent based on the parsing result to obtain the queried data;
[0100] The data queried by each target query agent is summarized to obtain the total query data, and the total query data is input into the large model to obtain a log analysis report.
[0101] The above embodiments are merely exemplary embodiments of the present application and are not intended to limit the scope of the present application. The scope of protection of the present application is defined by the claims. Those skilled in the art may make various modifications or equivalent substitutions to the present application within the essence and scope of protection of the present application, and such modifications or equivalent substitutions shall also be deemed to fall within the scope of protection of the present application.
Claims
1. A log query method, characterized in that: include: Receive the user's data query statement, and use the preset semantic parsing agent to detect the intention of the data query statement to obtain the target question; Based on the functions of each sub-service system, the target problem is split into tasks using a preset large model to obtain multiple sub-problem tasks, wherein each sub-problem task is related to at least one sub-service system; Matching the sub-problem tasks with the query agent using the large model to obtain matching results, and sending each sub-problem task to a matching target query agent according to the matching results, wherein each target query agent corresponds to a sub-service system; Each target query agent analyzes the received sub-question task, and performs a log query in the database of the sub-service system corresponding to the target query agent according to the analysis result to obtain the query data; The data queried by each target query agent is aggregated to obtain total query data, and the total query data is input into the large model to obtain a log analysis report.
2. The log query method according to claim 1, wherein: Each of the target query agents parses the received sub-question tasks, and performs log query in the database of the sub-service system corresponding to the target query agent according to the parsing result, including: The target query agent parses the sub-problem task, obtains a first keyword from the parsing result, performs a log query in the database of the sub-service system based on the first keyword to obtain log query data, and organizes the log query data according to a first preset structure to obtain first structured query data.
3. The log query method according to claim 2, wherein: After parsing the sub-problem task, the log query method further includes: If the parsing result also includes an associated SQL table name, the target query agent obtains the task conditions and task operations from the parsing result, generates an SQL query statement based on the task conditions, the task operations, the associated SQL table name and the first keyword, queries the data table in the database based on the SQL query statement, obtains SQL query data, and organizes the SQL query data according to a second preset structure to obtain second structured query data.
4. The log query method according to claim 3, wherein: After generating the SQL query statement based on the task condition, the task operation, the associated SQL table name, and the first keyword, the log query method further includes: If the SQL query statement fails to query the database, the target query agent generates task re-splitting information and sends it to the large model, so that the large model re-splitting the task of the target problem.
5. The log query method according to any one of claims 1 to 4, characterized in that: After detecting the intent of the data query statement using a preset intent detection model, the log query method further includes: If the result of the intention detection is irrelevant to the log query, the semantic parsing agent obtains the answer to the data query statement from a preset knowledge base and outputs the answer to the data query statement.
6. The log query method according to any one of claims 1 to 4, characterized in that: After aggregating the data queried by each target query agent to obtain total query data, and before inputting the total query data into the large model, the log query method further includes: The answer recognition agent determines whether the total query data can answer the target question. When the total query data cannot answer the target question, task re-splitting information is generated and sent to the large model so that the large model re-splitting the target question. When the total query data can answer the target question, the total query data is input into the large model.
7. The log query method according to claim 6, wherein: Determining whether the total query data can answer the target question includes: If the target query agent queries data, a second keyword in the target question is determined, a correlation between the second keyword and the total query data is calculated, and a query time of each target query agent querying the data is obtained. When the correlation is less than a preset correlation threshold and / or the number of target query agents whose query time is greater than or equal to the time threshold is greater than a quantity threshold, it is determined that the total query data cannot answer the target question; If all the target query agents fail to find any data, it is determined that the total query data cannot answer the target question.
8. A log query device, characterized in that: include: The target question acquisition module is used to receive the user's data query statement, and use the preset semantic parsing agent to detect the intention of the data query statement to obtain the target question; A task splitting module is used to split the target problem into multiple sub-problem tasks based on the function of each sub-service system using a preset large model, wherein each sub-problem task is related to at least one sub-service system; A matching module is used to match the sub-question tasks with the query agent using the large model to obtain matching results, and send each sub-question task to a matching target query agent according to the matching results, wherein each target query agent corresponds to a sub-service system; A query module, configured for each target query agent to parse the received sub-question task, and perform a log query in the database of the sub-service system corresponding to the target query agent based on the parsing result to obtain the queried data; The analysis module is used to summarize the data queried by each target query agent to obtain total query data, input the total query data into the large model, and obtain a log analysis report.
9. A storage medium storing at least one executable instruction, characterized in that: The executable instructions enable the processor to perform operations corresponding to the log query method according to any one of claims 1 to 7.
10. A computer device comprising: A processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, wherein the executable instruction enables the processor to execute an operation corresponding to the log query method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Multi-agent-based equipment analysis method and system, equipment and storage medium
CN119226078A