Log query method and device, electronic equipment and storage medium
By using placeholder mapping and decision diagrams in log queries to optimize query conditions, the problem of low rule reuse rate in multi-source heterogeneous log queries is solved, and query efficiency and the speed of abnormal behavior detection are improved.
Patent Information
- Application Number
- CN202510614230.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-10-10
AI Technical Summary
In the existing technology, querying multi-source heterogeneous logs requires customizing log audit rules for each format of data source, resulting in low audit rule reuse rate, increased development costs and low query efficiency.
By using placeholders to represent query fields, log audit rules are mapped to actual values in the log data source, and decision diagrams are used to optimize query conditions and connection conditions. Repeated conditions are executed only once, and frequent query results are cached to improve query efficiency.
It enables the reuse of audit rules across multiple heterogeneous log data sources, reduces development costs, improves log query efficiency, and enables rapid detection of abnormal behavior.
Smart Images

Figure CN120763207A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of log query technology, and in particular to a log query method, device, electronic device and storage medium. Background Art
[0002] For queries on multi-source heterogeneous logs, since the log formats of different data sources are different, traditional query solutions require a customized set of log audit rules for each format of data source, resulting in repeated development of audit rules and a low reuse rate of log audit rules. Summary of the Invention
[0003] The present invention provides a log query method, device, electronic device and storage medium, which are used to solve the technical problem of low reuse rate of log audit rules in the prior art.
[0004] The present invention provides a log query method, comprising: Obtaining a log audit rule, wherein the log audit rule represents a query field by a placeholder; Mapping the placeholder to the actual value of the query field in the log data source; Convert the log audit rules into query conditions; The query condition is executed to query logs from the log data source based on the actual value of the query field.
[0005] According to a log query method provided by the present invention, executing the query condition includes: identifying repeated query conditions through a decision diagram; The query condition is repeated only once.
[0006] According to a log query method provided by the present invention, executing the query condition includes: If the query condition includes multiple screening conditions, the data screening capability of each of the screening conditions is determined through a decision diagram; The screening conditions are executed in descending order of the data screening capabilities.
[0007] According to a log query method provided by the present invention, executing the query condition includes: If the query condition includes a join condition for a multi-table joint query, identifying repeated join conditions through a decision diagram; Only one repetition of the join condition is executed.
[0008] According to a log query method provided by the present invention, executing the query condition includes: If the query condition includes a join condition for a multi-table joint query, the data screening capability of each join condition is determined through a decision diagram; The connection conditions are executed in descending order of the data screening capabilities.
[0009] According to a log query method provided by the present invention, after executing the query condition to query logs from the log data source based on the actual value of the query field, the method further includes: Cache the query results of the current log query; If the query condition of the next log query is the same as that of the current log query, the query result in the cache is directly called.
[0010] The present invention also provides a log query device, comprising: An acquisition module is used to acquire log audit rules, wherein the log audit rules represent query fields through placeholders; A mapping module, configured to map the placeholder to an actual value of the query field in the log data source; A conversion module, used to convert the log audit rules into query conditions; An execution module is used to execute the query condition to query logs from the log data source based on the actual value of the query field.
[0011] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, any of the log query methods described above is implemented.
[0012] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which implements any of the log query methods described above when executed by a processor.
[0013] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements any of the above-mentioned log query methods.
[0014] The log query method, device, electronic device and storage medium provided by the present invention shield the log format differences of different log data sources by mapping the query field placeholders in the log audit rules to the actual values of the query fields in the log data source, so that the log audit rules can be adapted to multiple heterogeneous data sources, thereby improving the reusability of the log audit rules and reducing the development cost of the log audit rules. By improving the efficiency of log queries, abnormal behavior can be discovered quickly and promptly, so as to reduce the harm. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0016] Figure 1 It is a flow chart of the log query method provided by the present invention.
[0017] Figure 2 It is a schematic diagram of the log audit rules provided by the present invention.
[0018] Figure 3 It is a schematic diagram of the configuration file provided by the present invention.
[0019] Figure 4 This is one of the schematic diagrams of the query conditions provided by the present invention.
[0020] Figure 5 This is the second schematic diagram of the query conditions provided by the present invention.
[0021] Figure 6 This is one of the schematic diagrams of the connection conditions provided by the present invention.
[0022] Figure 7 This is the second schematic diagram of the connection conditions provided by the present invention.
[0023] Figure 8 It is a schematic diagram of the algorithm flow for optimizing query conditions and connection conditions provided by the present invention.
[0024] Figure 9 It is a schematic diagram of the principle of the cache algorithm provided by the present invention.
[0025] Figure 10 It is a structural diagram of the log query device provided by the present invention.
[0026] Figure 11 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0027] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0028] It should be noted that, in the description of the present invention, the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, the phrase "comprises a..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising the elements. Terms such as "upper" and "lower" indicate positions or relationships based on those shown in the accompanying drawings and are intended solely to facilitate the description of the present invention and simplify the description. They are not intended to indicate or imply that the devices or elements referred to must have a specific orientation, be constructed, or operate in a specific orientation, and are therefore not to be construed as limitations on the present invention. Unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be broadly construed, for example, to mean fixed, removable, or integral; mechanical or electrical; direct or indirect through an intermediary; or internal communication between two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0029] The terms "first," "second," and so forth, used herein are used to distinguish similar objects, not to describe a specific order or precedence. It should be understood that such terms are interchangeable where appropriate, allowing embodiments of the present invention to be implemented in an order other than that illustrated or described herein. Furthermore, the terms "first," "second," and so forth generally distinguish objects of a single type, and do not limit the number of objects. For example, the first object may be one or more. Furthermore, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the connected objects.
[0030] The following combination Figures 1-11 The present invention describes a log query method, device, electronic device, and storage medium.
[0031] like Figure 1 As shown, the log query method provided by the present invention includes steps S1 to S4.
[0032] Step S1: Obtain log audit rules, where the log audit rules represent query fields through placeholders.
[0033] Log audit rules are used to define filter criteria for user behaviors or events. For example, if a user logs in without clocking in, the log audit rule might include $login_time<$clock_in_time, indicating that the login time $login_time is earlier than the clock-in time $clock_in_time. This expression can be used to filter logs for "users logging in without clocking in."
[0034] The log audit rules of the present invention support multiple data types and multiple operations, including string, integer, floating point number, Boolean, set, date / time and null. The log audit rules can be in the form of Figure 2 As shown, the expression ( <expression>) is the core part, which represents the combination of various conditions. Figure 2 There are five types of expressions supported: (1) Logical Expression (LogicalExpr): <𝐿𝑜𝑔𝑖𝑐𝑎l𝐸𝑥𝑝𝑟>∷=<𝐸𝑥𝑝𝑟𝑒𝑠𝑠𝑖𝑜𝑛>(𝑁𝐷| 𝑂𝑅| 𝑁𝑂𝑇)<𝐸𝑥𝑝𝑟𝑒𝑠𝑠𝑖𝑜𝑛>, which means logical operation and supports common Boolean operations such as AND, OR, and NOT to represent the combination of multiple conditions; for example, the expression $user_id = 1 AND $role = 'admin' Indicates that the user ID is 1 and the role is administrator. $user_id is a placeholder for the query field representing the user ID, and $role is a placeholder for the query field representing the role. (2) Comparison Expression (ComparisonExpr): <comparisonexpr> ::= <variable> ( <op> ) <variable>, used to compare the relationship between two variables or constants, supporting common comparison operators (such as =, >, <, >=, <=); for example, the expression $age>18 means to check whether the age is greater than 18, and $age is a placeholder for the age query field; (3) Set Expression (SetExpr): <setexpr> ::= <variable>IN <set>, used to determine whether a variable belongs to a certain set, supports the IN operator; for example, the expression $role IN {'admin', 'manager'} means to determine whether the role is an administrator or a manager, and $role is a placeholder for the role query field; (4) Arithmetic expression (ArithExpr): <arithexpr> ::= <variable> (+ | - | * | / ) <variable>, used for arithmetic operations between variables, supporting addition, subtraction, multiplication, and division. For example, the expression $salary+ 1000 means salary plus 1000, where $salary is a placeholder for the query field salary. (5) Pattern matching expression (PatternExpr): <patternexpr> ::= <variable>MATCHES <pattern>, used to match string data using regular expressions; for example, the expression $user_idMATCHES / [A-Za-z0-9_]+ / determines whether the user ID matches the regular expression, and $user_id is a placeholder for the user ID query field.
[0035] Step S2: Map the placeholder to the actual value of the query field in the log data source.
[0036] The log data source of the present invention may include a relational database (such as MySQL, PostgreSQL) and a file data source (such as a CSV file, an Excel spreadsheet).
[0037] The present invention pre-establishes a configuration file that records the placeholder for each query field in the log audit rule and the actual value of the query field in each corresponding log data source. For example, for the query field "login time," its placeholder can be $login_time. If login_time is used to represent login time in log data source A and timestamp is used to represent login time in log data source B, the configuration file will record the actual value login_time of the query field "login time" in log data source A and the actual value timestamp of the query field "login time" in log data source B corresponding to the placeholder $login_time. By using the expression $login_time<8:00 in the log audit rule, log information with a login time earlier than 8:00 can be queried in log data sources A and B, thereby achieving the purpose of the log audit rule being applicable to both log data sources A and B.
[0038] The configuration file can be Figure 3 As shown, Figure 3 Indicates that the placeholder $user_id in the log audit rule is mapped to the USER_ID column in the log data source logs / access.csv file, and the placeholder $role_set is mapped to the ROLE_ID column in the log data source logs / role_table.csv file.
[0039] Step S3: convert the log audit rules into query conditions.
[0040] Logical judgments in log audit rules will be converted into SQL query conditions. For example, if you want to query the log information of the event "user logged into the system without punching in" in log data source A, the expression in the log audit rule is login_time <clock_in_time,转化得到的查询条件为: sql CopyEdit WHERE login_time <clock_in_time; By executing this query condition, you can obtain the log information of the event "User logged into the system without clocking in".
[0041] In addition, SQL query conditions can enable log audit rules to flexibly handle complex audit requirements, avoid manually writing tedious judgment conditions, and enhance the efficiency and scalability of rule execution.
[0042] Step S4: executing the query condition to query logs from the log data source based on the actual value of the query field.
[0043] For example, by executing the query condition in step S3, the log information of the event "user logged into the system without clocking in" can be queried from log data source A based on the actual value login_time of the query field "login time" and the actual value clock_in_time of the query field "clock-in time".
[0044] As can be seen from the above, the present invention shields the differences in log formats between different log data sources by mapping the query field placeholders in the log audit rules to the actual values of the query fields in the log data source. This allows the log audit rules to be adapted to multiple heterogeneous data sources, improves the reusability of the log audit rules, and reduces the development cost of the log audit rules. Furthermore, since there is no need to repeatedly develop log audit rules, the efficiency of log queries can be improved, enabling abnormal behavior to be discovered quickly and promptly, thereby reducing the harm.
[0045] Generally, when processing large-scale log data, multiple query conditions may include the same fields, resulting in duplicate query conditions. All duplicate query conditions will be executed, greatly reducing the efficiency of log query. For example, suppose there are two queries such as Figure 4 As shown in the figure, in the traditional query method, the two query conditions user_id = 'abc' and status = 'active' will be executed twice in two queries respectively, resulting in repeated execution.
[0046] In order to improve the efficiency of log query, in some embodiments, in step S4, executing the query condition may further include: identifying repeated query conditions through a decision diagram; The query condition is repeated only once.
[0047] Decision graphs graphically represent the decision-making process of Boolean functions or complex conditions. In log queries, decision graphs can optimize query paths by converting query conditions into a graph structure, merge multiple query conditions, reduce redundant calculations, and share condition calculations, thereby improving query efficiency. The basic structure of a decision graph in log queries is as follows: (1) Decision nodes: Each node represents a conditional judgment; for example, whether a field value is equal to a certain value, or whether the join condition between two tables in a multi-table join query (for example, Where l.user_id = u.user_id) is true; (2) Branch: The branch of each decision node represents the result of the judgment (TRUE or FALSE), and the conditional judgment result is passed down; (3) Path: The path represents the order of judgment. The execution order of each query condition is clearly represented in the decision diagram. Multiple paths represent different query execution processes.
[0048] for Figure 4 The decision graph shows that user_id = 'abc' and status = 'active' are duplicate query conditions and will be merged into a shared decision node. The query will only execute user_id = 'abc' and status = 'active' once.
[0049] In this way, repeated query conditions can be merged into shared decision nodes through the decision graph, and repeated query conditions are only executed once, which can improve query efficiency.
[0050] If the query conditions include multiple filter conditions, each filter condition has different data filtering capabilities. If the execution order of each filter condition is not designed properly, some filter conditions may filter a large amount of data, resulting in low log query efficiency. For example, Figure 5 As shown in the figure, assume that a query condition includes two filter conditions: user_id = 'abc' and status = 'active'. If status = 'active' is executed first and 50,000 logs satisfying status = 'active' are obtained, then the query condition for user_id = 'abc' needs to be executed 50,000 times.
[0051] In order to improve the efficiency of log query, in some embodiments, in step S4, executing the query condition may further include: If the query condition includes multiple screening conditions, the data screening capability of each of the screening conditions is determined through a decision diagram; The screening conditions are executed in descending order of the data screening capabilities.
[0052] The data filtering capability can be reflected by the amount of remaining log data after the filtering conditions are executed. The smaller the amount of remaining log data, the stronger the data filtering capability. Figure 5 In the example, user_id = 'abc' is executed first. If 10 logs satisfying the condition are obtained, the data filtering capability of the filtering condition user_id = 'abc' is greater than that of status = 'active'. Therefore, user_id = 'abc' is executed first, followed by status = 'active'. The execution only needs to be executed 10 times when status = 'active' is satisfied.
[0053] In this way, the data screening capability of each of the screening conditions can be determined through the decision diagram, and the screening conditions with strong data screening capability can be executed first, which can improve the query efficiency.
[0054] For multi-table joint queries, the join operations between tables (such as JOIN) are usually evaluated one by one according to the join conditions. Traditional query methods need to execute the join conditions between each table each time a join operation is performed, which not only reduces the query efficiency but also may cause unnecessary repeated operations. For example, if there is a query such as Figure 6 As shown, in a traditional multi-table union query, each JOIN operation will execute the connection condition l.user_id = u.user_id once.
[0055] In order to improve the efficiency of multi-table joint query, in some embodiments, in step S4, executing the query condition may further include: If the query condition includes a join condition for a multi-table joint query, identifying repeated join conditions through a decision diagram; Only one repetition of the join condition is executed.
[0056] The decision diagram in the present invention will Figure 6 The same join conditions (such as user_id) in the query are merged into shared judgment nodes. If other queries also use the same JOIN operation, these join conditions are only executed once, improving the efficiency of multi-table joint queries.
[0057] In multi-table joint queries, the order in which join conditions are executed directly affects query efficiency. Some table join conditions have strong data filtering capabilities, effectively filtering large amounts of data, while other table join conditions have weaker data filtering capabilities. Improper execution of join conditions can reduce the efficiency of multi-table joint queries.
[0058] To improve the efficiency of multi-table joint query, in some embodiments, the step S4 of executing the query condition can further include: If the query condition includes the connection condition of multi-table joint query, the data filtering capability of each connection condition is determined by decision diagram; The connection conditions are executed in the order of the data filtering capability from large to small.
[0059] The data filtering capability can be reflected by the remaining log data volume after the execution of the connection condition, and the smaller the remaining log data volume is, the stronger the data filtering capability is. For example, assume that the query is as shown in Figure 7 The query condition includes the connection condition of the users table and the products table, and if the data filtering capability of the connection condition of the users table is strong, the connection condition of the users table is executed first, and then the connection condition of the products table is executed, thereby improving the efficiency of multi-table joint query.
[0060] The above can obtain the algorithm flowchart for optimizing the query condition and the connection condition as shown in Figure 8 The algorithm flowchart includes: Step 1: initialize the shared condition set, create an empty set shared_conditions, and store all conditions that need to be optimized in the set, so as to avoid repeated calculation of the same condition in multiple queries.
[0061] Step 2: optimize the query condition, traverse the condition condition in each query query, and if the condition condition is not in the shared_conditions set, add the condition to the shared_conditions set. Set the optimized condition of the query query as shared_conditions, that is, apply the shared condition to the query. Add the optimized query query to the optimized query list optimized_queries.
[0062] Step 3: initialize the shared connection condition set, create an empty set shared_joins, and store the shared connection condition in multiple queries, so as to avoid redundant calculation.
[0063] Step 4: Optimize the join conditions. Iterate through the join conditions in each query. If the join condition is not in the shared_joins set, add it to the shared_joins set. Set the query's optimized join condition to shared_joins, applying the shared join condition to the query. Add the optimized query to the optimized_queries list.
[0064] Step 5: Initialize the join selectivity metric list. Create an empty list join_selection_factors to store the selectivity metric for each join condition.
[0065] Step 6: Optimize the join order. Traverse each join condition in the query. Calculate the selectivity factor for each join condition, which represents the join condition's ability to filter data. Add the join condition and its selectivity factor to the join_selection_factors list. Sort the join conditions in descending order based on the selectivity factor, with the most selective conditions executed first. Apply the sorted join conditions to the query to optimize the query execution order.
[0066] Step 7: Returns a list of all optimized queries, optimized_queries.
[0067] The decision graph-based log query method effectively reduces redundant computations and improves query efficiency by transforming query conditions and multi-table association logic into a decision graph. Specifically, the decision graph transforms shared query conditions into unified decision nodes, enabling multiple queries to share computation results, significantly reducing the time overhead of repeated computations. When performing joint queries involving multiple tables, the decision graph dynamically optimizes the table join order, reducing unnecessary redundant join calculations. It also optimizes the join order through selectivity metrics, prioritizing join conditions that effectively filter data and improving query efficiency.
[0068] In large-scale log data retrieval, as the amount of data increases, the complexity of query operations also gradually increases. Especially for frequently executed repeated queries, traditional query methods not only consume a lot of computing resources, but also have a long response time, affecting the overall performance of the system.
[0069] In order to improve the efficiency of log query, in some embodiments, after step S4, the log query method of the present invention may further include: Cache the query results of the current log query; If the query condition of the next log query is the same as that of the current log query, the query result in the cache is directly called.
[0070] The cached query results may include static data or frequently used query results.
[0071] Static data includes user information, role permissions, and user attributes. Generally, static data is updated less frequently, so a more persistent caching strategy can be designed for static data to reduce frequent access to the database. Role permissions and user information do not change frequently in most cases, so a static caching strategy is suitable. Role permissions and user information can avoid the need to load the same user information or role permissions from the database every time a query is made, thereby improving query performance. Similar to role permissions, user attributes (such as age, department, etc.) are generally stable, and unless the user attributes change, there is no need to frequently query the database. To improve performance, these user attributes can be cached for a long time to avoid reloading on each access.
[0072] For static data, you can use a longer-term caching strategy. The cached data is valid for a certain period of time. The cached content is updated only when the data changes (such as changes in role permissions or updates to user attributes). The caching strategies used include: Time-driven cache: Set the expiration time of the cache, and the data will be automatically refreshed after the expiration.
[0073] Event-driven caching: When data in the system is updated, a cache update is triggered; for example, when user role permissions change, the relevant role data in the cache is updated.
[0074] Frequently used query results include those of repeated query conditions and those of repeated join conditions in multi-table joint queries. By optimizing the decision graph, the query results of query conditions that appear multiple times can be cached to avoid performing the same condition calculation in each query. The decision graph can convert the same condition judgments in multiple queries into shared decision nodes, so that multiple queries can share the same calculation results. Caching algorithms such as Figure 9 In multi-table join queries, join conditions are often repeated, especially when it comes to foreign key and primary key relationships. Decision graph optimization allows you to cache the query results for shared join conditions across multiple queries, avoiding recalculation of these join conditions each time the query is executed.
[0075] By combining decision graph optimization query conditions and cache connection conditions, the redundant calculation in the query can be significantly reduced, and the query efficiency can be improved. Especially in the multi-table joint query and condition repetition scene, the decision graph can intelligently identify the shared conditions and cache them, avoiding repeated execution of the same calculation for each query. This optimization not only reduces the computing overhead, but also improves the response speed of the system.
[0076] As Figure 10 indicated, the log query device provided by the application comprises: The acquisition module is configured to acquire a log audit rule, wherein the log audit rule represents a query field through a placeholder; The mapping module is configured to map the placeholder to an actual value of the query field in a log data source; The conversion module is configured to convert the log audit rule into a query condition; The execution module is configured to execute the query condition to query logs from the log data source based on the actual value of the query field.
[0077] It should be noted that the log query device provided by the application can execute the log query method described in any of the above embodiments when it is actually run, and the present embodiment will not be repeated.
[0078] In some embodiments, the execution module can be specifically configured to: identify repeated query conditions through a decision graph; execute the repeated query conditions only once.
[0079] In some embodiments, the execution module can be specifically configured to: If the query condition includes multiple filtering conditions, determine the data filtering capabilities of each filtering condition through a decision graph; execute the filtering conditions in order from large to small according to the data filtering capabilities.
[0080] In some embodiments, the execution module can be specifically configured to: If the query condition includes connection conditions of multi-table joint queries, identify repeated connection conditions through a decision graph; execute the repeated connection conditions only once.
[0081] In some embodiments, the execution module can be specifically configured to: If the query condition includes connection conditions of multi-table joint queries, determine the data filtering capabilities of each connection condition through a decision graph; execute the connection conditions in order from large to small according to the data filtering capabilities.
[0082] In some implementations, the log query device may further include: The cache module is used to cache the query results of the current log query; The calling module is configured to directly call the query result in the cache if the query condition of the next log query is the same as that of the current log query.
[0083] Figure 11 Schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 11 As shown, the electronic device may include: a processor, a communications interface, a memory, and a communications bus, wherein the processor, the communications interface, and the memory communicate with each other via the communications bus. The processor may invoke logic instructions in the memory to execute a log query method, which includes: obtaining a log audit rule, wherein the log audit rule represents a query field using a placeholder; mapping the placeholder to the actual value of the query field in the log data source; converting the log audit rule into a query condition; and executing the query condition to query logs from the log data source based on the actual value of the query field.
[0084] Furthermore, the logical instructions in the aforementioned memory can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media capable of storing program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.
[0085] On the other hand, the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the log query method provided by the above-mentioned embodiments, the method including: obtaining log audit rules, the log audit rules representing query fields through placeholders; mapping the placeholders to the actual values of the query fields in the log data source; converting the log audit rules into query conditions; and executing the query conditions to query logs from the log data source based on the actual values of the query fields.
[0086] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it is implemented to execute the log query method provided by the above-mentioned embodiments, the method including: obtaining log audit rules, the log audit rules representing the query field through a placeholder; mapping the placeholder to the actual value of the query field in the log data source; converting the log audit rules into query conditions; executing the query conditions to query logs from the log data source based on the actual value of the query field.
[0087] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0088] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0089] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.< / pattern> < / variable> < / patternexpr> < / variable> < / variable> < / arithexpr> < / set> < / variable> < / setexpr> < / variable> < / op> < / variable> < / comparisonexpr> < / expression>
Claims
1. A log query method, characterized in that: include: Obtaining a log audit rule, wherein the log audit rule represents a query field using a placeholder; Mapping the placeholder to the actual value of the query field in the log data source; Convert the log audit rules into query conditions; The query condition is executed to query logs from the log data source based on the actual value of the query field.
2. The log query method according to claim 1, characterized in that: The executing the query condition includes: identifying repeated query conditions through a decision diagram; The query condition is repeated only once.
3. The log query method according to claim 1, characterized in that: The executing the query condition includes: If the query condition includes multiple screening conditions, the data screening capability of each of the screening conditions is determined through a decision diagram; The screening conditions are executed in descending order of the data screening capabilities.
4. The log query method according to claim 1, characterized in that: The executing the query condition includes: If the query condition includes a join condition for a multi-table joint query, identifying repeated join conditions through a decision diagram; Only one repetition of the join condition is executed.
5. The log query method according to claim 1, characterized in that: The executing the query condition includes: If the query condition includes a join condition for a multi-table joint query, the data screening capability of each join condition is determined through a decision diagram; The connection conditions are executed in descending order of the data screening capabilities.
6. The log query method according to claim 1, characterized in that: After executing the query condition to query logs from the log data source based on the actual value of the query field, the method further includes: Cache the query results of the current log query; If the query condition of the next log query is the same as that of the current log query, the query result in the cache is directly called.
7. A log query device, characterized in that: include: An acquisition module is used to acquire log audit rules, wherein the log audit rules represent query fields through placeholders; A mapping module, configured to map the placeholder to an actual value of the query field in the log data source; A conversion module, used to convert the log audit rules into query conditions; An execution module is used to execute the query condition to query logs from the log data source based on the actual value of the query field.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the log query method according to any one of claims 1 to 6 is implemented.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the log query method according to any one of claims 1 to 6 is implemented.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the log query method according to any one of claims 1 to 6 is implemented.