Log analysis method and device, electronic equipment, storage medium and program product

By introducing a location attribution model to automatically analyze test logs, identify faulty modules, and determine responsibility, the problems of low efficiency and low accuracy in log analysis in existing technologies are solved, and efficient automated log analysis is achieved.

CN120909829APending Publication Date: 2025-11-07GUOGUANG ELECTRIC COMPANY LIMITED
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511051140.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-29
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In existing technologies, test log analysis is inefficient, prone to misjudgments, has unclear attribution of responsibility, and lacks standardized knowledge accumulation, resulting in time-consuming and inaccurate manual analysis.

Method used

By introducing a location attribution model, the system automatically identifies faulty modules and outputs responsibility attribution results, generating processing suggestions, by determining the logs and vectors to be analyzed.

Benefits of technology

It automates log analysis, improves analysis accuracy and depth, reduces complexity, and minimizes the time and errors associated with manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120909829A_ABST
    Figure CN120909829A_ABST
Patent Text Reader

Abstract

The invention discloses a log analysis method and device, electronic equipment, a storage medium and a program product. According to the specific implementation scheme, the method comprises the steps of determining a to-be-analyzed log and a to-be-analyzed vector corresponding to the to-be-analyzed log; inputting the to-be-analyzed vector into a positioning attribution model, and outputting an error module in the to-be-analyzed log; according to the error module, outputting a responsibility affiliation result corresponding to the error module by the positioning affiliation model; and generating a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result. The positioning attribution model is introduced to analyze the to-be-analyzed log, so that the precision and depth of log analysis are improved, automatic analysis of the to-be-analyzed log is realized, manual participation is not needed, the analysis complexity is reduced, and the problems of long time consumption and low analysis accuracy caused by manual log analysis are solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of testing, in particular to a log analysis method and device, electronic equipment, storage medium and program product. BACKGROUND

[0002] In the current electronic manufacturing, communication equipment, consumer electronics and other industries, products need to be detected by multiple test stations. If there is a failure, a test log will be generated. The operator or engineer needs to manually check these logs and manually analyze the problem module, the responsible department and the possible processing method.

[0003] The existing test log analysis process often has the following problems: low efficiency: complex logs require a lot of manual review; frequent misjudgment: non-standard error description affects judgment accuracy; confusion of attribution: responsibility division depends on interpersonal communication; suggestion missing: no standard knowledge sedimentation, repeated errors repeatedly occur. Therefore, the existing test log analysis method needs to rely on manual analysis, which is time-consuming and has low analysis accuracy. SUMMARY

[0004] The present application provides a log analysis method, device, electronic equipment, storage medium and program product to solve the problem of time-consuming and low analysis accuracy caused by manual analysis of logs, and to realize automatic analysis of logs.

[0005] According to an aspect of the present application, a log analysis method is provided, comprising:

[0006] determining a log to be analyzed and a to-be-analyzed vector corresponding to the log to be analyzed, the log to be analyzed including unanalyzed test logs generated when a detection failure problem occurs, the detection failure problem including a problem that occurs when a product is detected;

[0007] inputting the to-be-analyzed vector into a positioning and attribution model to output an error module in the log to be analyzed, the error module indicating a position on the product where the detection failure problem occurs;

[0008] According to the error module, the positioning and attribution model outputs a responsibility attribution result corresponding to the error module;

[0009] According to the error module and the responsibility attribution result, a processing suggestion for solving the detection failure problem is generated.

[0010] According to another aspect of the present application, a log analysis device is provided, comprising:

[0011] The determining module is configured to determine a log to be analyzed and a vector corresponding to the log to be analyzed, the log to be analyzed including a test log that is not analyzed and is generated when a detection failure problem occurs, the detection failure problem including a problem that occurs when a product is detected;

[0012] The input module is configured to input the vector to be analyzed into a positioning attribution model, and output an error module in the log to be analyzed, the error module indicating a position at which the detection failure problem occurs on the product;

[0013] The output module is configured to output, according to the error module, a responsibility attribution result corresponding to the error module from the positioning attribution model.

[0014] The generating module is configured to generate, according to the error module and the responsibility attribution result, a processing suggestion for solving the detection failure problem.

[0015] According to another aspect of the present application, an electronic device is provided, which includes:

[0016] at least one processor; and

[0017] a memory connected to the at least one processor in communication; wherein

[0018] the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the log analysis method according to any one of the embodiments of the present application.

[0019] According to another aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for enabling a processor to execute the log analysis method according to any one of the embodiments of the present application when the processor executes the computer instructions.

[0020] According to another aspect of the present application, a computer program product is provided, which includes a computer program for enabling a processor to execute the log analysis method according to any one of the embodiments of the present application when the processor executes the computer program.

[0021] The technical scheme of the embodiment of the present application determines a log to be analyzed and a to-be-analyzed vector corresponding to the log to be analyzed; inputs the to-be-analyzed vector into a positioning attribution model, and outputs an error module in the log to be analyzed; according to the error module, outputs a responsibility attribution result corresponding to the error module from the positioning attribution model; and generates a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result. The log to be analyzed is analyzed by introducing the positioning attribution model, the accuracy and depth of analyzing the log are improved, the error module and the responsibility attribution result corresponding to the log to be analyzed are obtained, automatic analysis of the log to be analyzed is realized, manual participation is not required, and the analysis complexity is reduced. Finally, the processing suggestion for the log to be analyzed is determined, and the problems of long time consumption and low analysis accuracy caused by manual analysis of the log are solved.

[0022] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0024] Figure 1 is a flow chart of a log analysis method provided by the first embodiment of the present application;

[0025] Figure 2 is a flow chart of a log determination method provided by the second embodiment of the present application;

[0026] Figure 3 is a structural schematic diagram of a log analysis device provided by the third embodiment of the present application;

[0027] Figure 4 is a block diagram of an electronic device provided by the fourth embodiment of the present application. DETAILED DESCRIPTION

[0028] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.

[0029] It is to be understood that the terminology "first", "second", and the like used throughout this specification and the annexed drawings is merely intended to distinguish between similar objects and not necessarily to describe a specific sequential or chronological order. It is to be understood that the use of such terms as "first", "second", and the like can be interchanged, as appropriate, to distinguish between analogous objects in the context of the embodiments of the application described herein. Furthermore, the terms "comprise", "comprising", "comprises", "include", "including", "includes", "contain", "containing", "contains", and the like are used throughout this specification in their open-ended, conventional sense, that is to say, these terms are used to indicate both direct and indirect possession of the stated step or element, and that the listed steps or elements can be supplemented by other steps or elements. It is to be understood that such terms as "comprise", "comprising", "comprises", "include", "including", "includes", "contain", "containing", "contains", and the like are not to be interpreted as excluding the presence of steps or elements that are not recited.

[0030] Embodiment One

[0031] Figure 1 is a flow chart of a log analysis method according to an embodiment of the application. The embodiment can be applicable to the case of analyzing a log to be analyzed. The method can be executed by a log analysis device, which can be implemented in the form of hardware and / or software. The log analysis device can be configured in an electronic device, which can include a manufacturing execution system, an automatic test equipment platform, etc. As shown in Figure 1 the method includes:

[0032] S110, determining a log to be analyzed, and a to-be-analyzed vector corresponding to the log to be analyzed.

[0033] The log to be analyzed includes a test log that is not analyzed and is generated when a detection failure problem occurs. The detection failure problem includes a problem that occurs when a product is detected.

[0034] In this embodiment, the log to be analyzed can be understood as a log generated when a detection failure problem occurs when a product is tested, and the log to be analyzed is a test log that has not been analyzed. The to-be-analyzed vector can be understood as a vector obtained by fusing a semantic vector corresponding to the log to be analyzed and a combined feature corresponding to the log to be analyzed. The detection failure problem can be understood as a case of detection failure when a product is tested. The test log can include logs of various formats.

[0035] Specifically, when a detection failure problem occurs when a product is tested, a test log is output. If the test log has not been analyzed, the test log is determined as a log to be analyzed. By parsing the log to be analyzed, a semantic vector corresponding to the log to be analyzed and a combined feature are fused to obtain a to-be-analyzed vector.

[0036] Exemplarily, the product can include intelligent software, a communication device, etc. that needs to be tested, and the product can be detected by a test station. The log to be analyzed can include various formats, such as a text file format, a comma-separated value file format, an extensible markup language format, or an object representation format. The semantic vector corresponding to the log to be analyzed can be obtained by a semantic model (for example, BERT). And the combined feature can be combined by the word frequency, the inverse document frequency, the error code field, and the keyword.

[0037] S120, inputting the vector to be analyzed into a positioning attribution model, and outputting an error module in the log to be analyzed.

[0038] The error module indicates a position of the product where the detection failure problem occurs.

[0039] In this embodiment, the positioning attribution model can be understood as a model for analyzing the vector to be analyzed, and the positioning attribution model can output the module in the log to be analyzed where the detection failure problem occurs. The error module can be understood as a module in the log to be analyzed where the detection failure problem occurs, and the error module can indicate the position of the product where the detection failure problem occurs.

[0040] Specifically, the vector to be analyzed is input into the positioning attribution model, and the positioning attribution model can be composed of an error classification model, a responsibility attribution model, etc. The error classification model can be used to analyze the error module in the vector to be analyzed where the detection failure problem occurs.

[0041] Exemplarily, the error module can include a power supply module, a radio frequency module, an IO module, etc., and the error module can be recorded as module A.

[0042] S130, according to the error module, outputting a responsibility attribution result corresponding to the error module by the positioning attribution model.

[0043] In this embodiment, the responsibility attribution result can be understood as a cause of the detection failure problem, and the responsibility attribution result can include an error type to which the error module belongs and a person responsible for the error module.

[0044] Specifically, the responsibility attribution corresponding to the error module can be analyzed by a responsibility attribution model in the positioning attribution model. The responsibility attribution model can be composed of a graph structure and a graph neural network modeling, and the error module can be traced back to its error type and the person responsible for the error module. The error type can include a type to which a department where the detection failure problem occurs belongs.

[0045] S140, generating a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result.

[0046] Specifically, after determining the error module causing the detection failure problem and the responsibility attribution result corresponding to the error module, a small language model can be used to generate a processing suggestion for solving the detection failure problem. The processing suggestion can be a structured suggestion automatically generated based on the responsibility attribution result and historical experience, which assists personnel responsible for the error module to quickly respond and repair.

[0047] For example, when generating a processing suggestion for solving the detection failure problem, prompt information can be generated, which can include phenomena of the detection failure problem, possible causes of the detection failure problem, and recommended inspection and repair methods. Among them, the phenomena of the detection failure problem can briefly describe the detection failure problem reflected in the log to be analyzed; the possible causes of the detection failure problem can be the possible causes of the detection failure problem; and the recommended inspection and repair methods can be recommended diagnosis and troubleshooting steps or direct processing solutions for the detection failure problem, which can be generated in combination with historical experience / knowledge base / rules.

[0048] The technical scheme of the embodiment of the present application determines a log to be analyzed and a to-be-analyzed vector corresponding to the log to be analyzed; inputs the to-be-analyzed vector into a positioning attribution model to output an error module in the log to be analyzed; according to the error module, outputs a responsibility attribution result corresponding to the error module from the positioning attribution model; and generates a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result. The positioning attribution model is introduced to analyze the log to be analyzed, which improves the accuracy and depth of log analysis, obtains the error module and the responsibility attribution result corresponding to the log to be analyzed, realizes automatic analysis of the log to be analyzed without human intervention, and reduces the analysis complexity. Finally, the processing suggestion for the log to be analyzed is determined, which solves the problem of time-consuming and low analysis accuracy caused by manual log analysis.

[0049] On the basis of the above-mentioned embodiments, variant embodiments of the above-mentioned embodiments are proposed. It should be noted that, in order to make the description brief, only the differences between the variant embodiments and the above-mentioned embodiments are described in the variant embodiments.

[0050] In one embodiment, the determination of the to-be-analyzed vector corresponding to the log to be analyzed comprises:

[0051] Determining a to-be-analyzed semantic vector corresponding to the log to be analyzed;

[0052] Extracting a combined feature of the log to be analyzed, the combined feature comprising features contained in words and fields constituting the log to be analyzed;

[0053] Fusing the combined feature into the to-be-analyzed semantic vector to obtain the to-be-analyzed vector corresponding to the log to be analyzed.

[0054] In the embodiment, the semantic vector to be analyzed can be understood as a semantic vector corresponding to the log to be analyzed.

[0055] Specifically, first, a language model is used to determine the semantic vector to be analyzed corresponding to the log to be analyzed. Then, combined features of the log to be analyzed are extracted. The combined features can be combined from the word frequency, the inverse document frequency, the error code field, and the keyword, etc. The word frequency is the number of occurrences of a word in the log to be analyzed. The inverse document frequency can indicate the frequency of occurrence of a word in the entire log library. The less frequently a word occurs, the higher the weight of the inverse document frequency. The error code field is the code returned by the test system or the chip firmware when a test failure problem occurs, which can be a structured field in the log to be analyzed or a field extracted by a regular expression. The keyword can be a word related to the fault type, the test stage, and the hardware module. The combined features are fused into the semantic vector to be analyzed to obtain the semantic vector to be analyzed corresponding to the log to be analyzed.

[0056] For example, the semantic vector to be analyzed E(x) = BERT(x), x is the log to be analyzed. The error code field is, for example, “ERR_CODE: 0x0F1A” and “TestResult = FAIL(Code = 1053)”. The keyword can be obtained by the following methods: based on word frequency statistics, or manually collected from historical analysis reports, or using a key term table constructed by a domain dictionary.

[0057] In one embodiment, the responsibility attribution result corresponding to the error module is output by the positioning attribution model according to the error module, comprising:

[0058] The positioning attribution model performs the following operations:

[0059] determining an error type to which the error module belongs, the error type including a type of a department where the detection failure problem occurs;

[0060] determining an engineer responsible for the error module according to the error type;

[0061] composing the responsibility attribution result corresponding to the error module from the error module, the error type, and the engineer.

[0062] Specifically, according to the indication of the error module, the positioning attribution model analyzes the responsibility attribution result corresponding to the error module. First, the error type to which the error module belongs is analyzed, which can be traced back by a responsibility attribution model in the positioning attribution model. Then, according to the department where the detection failure problem occurs indicated by the error type, the engineer of the department is found. Finally, the responsibility attribution result corresponding to the error module is composed of the error module, the error type, and the engineer.

[0063] For example, the error module is module A, and the error type is displayed in the form of a triple, i.e., department B, $(\text{module A},\text{belongs to},\text{department B})$. Then, the engineer included in the error type, i.e., department B, is found, i.e., engineer C, $(\text{department B},\text{contains},\text{engineer C})$.

[0064] In an embodiment, the training operation of the positioning and attribution model comprises:

[0065] A sample log set is obtained, and at least one sample log is included in the sample log set.

[0066] For each sample log, a sample feature corresponding to the sample log is determined, and the sample feature comprises a sample error module, a sample responsibility attribution result, and a sample processing suggestion corresponding to the sample log.

[0067] Each sample log and the sample feature corresponding to each sample log are determined as labeled data.

[0068] The labeled data is input into an initial model for training to obtain a positioning and attribution model.

[0069] In this embodiment, the sample log set can be understood as a set for storing sample logs, and the sample log set can be stored in a database. The sample log can be understood as a test log generated when a detection failure problem occurs and has been analyzed, and the sample log is a log with a known responsibility attribution result. The sample feature can be understood as a feature composed of information corresponding to the sample log, including a sample error module, a sample responsibility attribution result, and a sample processing suggestion. The sample error module can be understood as a position on a product where a detection failure problem occurs, indicated by the sample log. The sample responsibility attribution result can be understood as a cause of the detection failure problem, indicated by the sample log. The labeled data can be understood as data for training the positioning and attribution model.

[0070] Specifically, a sample log set storing sample logs that have been analyzed is obtained, and the sample logs in the sample log set are logs in which a detection failure problem occurs when a product is detected, and the cause of the detection failure problem has been analyzed. For each sample log, a sample error module, a sample responsibility attribution result, and a sample processing suggestion corresponding to the sample log are determined, and a sample feature is obtained by combination. The sample features of each sample log in the sample log set are stored to obtain labeled data, and the initial model is trained using the labeled data to obtain the positioning and attribution model. The initial model can be a model composed of a classification model, an attribution prediction model, and the like.

[0071] Exemplarily, the classification model is, for example, an ensemble learning algorithm XGBoost based on gradient boosting, a deep neural network DNN, a deep learning model Transformer based on a self-attention mechanism, etc., and the responsibility attribution prediction model is, for example, a graph neural network GNN, etc.

[0072] In one embodiment, the generating of the processing suggestion for solving the detection failure problem according to the error module corresponding to the log to be analyzed and the responsibility attribution result comprises:

[0073] The generating of the initial processing suggestion according to the error module corresponding to the log to be analyzed and the responsibility attribution result;

[0074] The modifying of the initial processing suggestion in response to a modification operation on a suggestion modification page to obtain the processing suggestion for solving the detection failure problem.

[0075] In the embodiment, the initial processing suggestion can be understood as a processing suggestion output by the small language model according to the error module and the responsibility attribution result. The modification page can be understood as a page that accepts operations on the initial processing suggestion.

[0076] Specifically, after the error module of the detection failure problem and the responsibility attribution result corresponding to the error module are determined, the small language model can be used to generate an initial processing suggestion for solving the detection failure problem. For the initial processing suggestion, the modification operation of the engineering personnel on the suggestion modification page can be received to modify the initial processing suggestion, and the processing suggestion for solving the detection failure problem can be obtained.

[0077] Exemplarily, the modification operation of the engineering personnel on the modification page can be received, and the modification operation can include modification, confirmation or feedback on the initial suggestion result. Finally, the processing suggestion for solving the detection failure problem can be obtained.

[0078] Embodiment Two

[0079] Figure 2 is a flowchart of a log determination method according to the embodiment two of the present application. The embodiment is directed to the method of determining the log to be analyzed in the above-mentioned embodiments. As shown in the figure, the method comprises: Figure 2

[0080] S210, determining a log to be processed and a semantic vector to be processed corresponding to the log to be processed.

[0081] The log to be processed comprises a test log generated when the detection failure problem occurs.

[0082] ​In the embodiment, the to-be-processed log includes a test log generated when the detection failure problem occurs. The to-be-processed semantic vector can be understood as a semantic vector corresponding to the to-be-processed log, and the to-be-processed semantic vector only includes the text features of the to-be-processed log.

[0083] Specifically, when the detection failure problem occurs in the test of the product, the to-be-processed log generated is determined, and the to-be-processed log is converted into a semantic vector to obtain the to-be-processed semantic vector.

[0084] For example, the to-be-processed log can be converted into the to-be-processed semantic vector by using a semantic model (for example, BERT), for example, to-be-processed semantic vector Ecur=BERT(xcur), where xcur is the to-be-processed log.

[0085] S220, obtaining a historical log and a historical semantic vector corresponding to the historical log.

[0086] The historical log includes an analyzed test log generated when the detection failure problem occurs.

[0087] In the embodiment, the historical log can be understood as a test log generated when the detection failure problem occurs and has been stored. The historical semantic vector can be understood as a semantic vector corresponding to the historical log, and the historical semantic vector only includes the text features of the historical log.

[0088] For example, the stored historical log can be converted into the historical semantic vector by using a semantic model (for example, BERT), for example, historical semantic vector Ehist=BERT(xhist), where xhist is the historical log.

[0089] S230, calculating the similarity between the to-be-processed semantic vector and the historical semantic vector to obtain a similarity calculation result, and performing S240 or S250.

[0090] In the embodiment, the similarity calculation result can indicate the similarity between the to-be-processed semantic vector and the historical semantic vector, that is, the similarity between the to-be-processed log and the historical log.

[0091] Specifically, the similarity calculation result can be obtained by calculating the semantic cosine similarity between the to-be-processed semantic vector and the historical semantic vector. The semantic cosine similarity is a measurement method for measuring the similarity between the to-be-processed semantic vector and the historical semantic vector.

[0092] For example, the semantic cosine similarity between the to-be-processed semantic vector and the historical semantic vector can be calculated by the following formula:

[0093] sim(Ecur, Ehisl) = Ecur · Ehisl / ||Ecur|| · ||Ehisl||

[0094] wherein sim(Ecur, Ehist) is a semantic cosine similarity, Ecur is the to-be-processed semantic vector, and Ehist is the historical semantic vector.

[0095] S240, in a case where the similarity calculation result is less than the set threshold, determining the to-be-processed log as a to-be-analyzed log.

[0096] In this embodiment, the set threshold can be understood as a set similarity threshold, and the set threshold can be used to determine whether the to-be-processed log is a historical log.

[0097] For example, the set threshold can be set to 0.85. In a case where the similarity calculation result is less than the set threshold, it indicates that the similarity between the to-be-processed log and the historical log is small, and thus the to-be-processed log is not a historical log. The to-be-processed log is determined as a to-be-analyzed log, and an analysis operation is performed on the to-be-analyzed log.

[0098] S250, in a case where the similarity calculation result is greater than or equal to the set threshold, determining the to-be-processed log as a historical log.

[0099] For example, in a case where the similarity calculation result is greater than or equal to the set threshold, it indicates that the similarity between the to-be-processed log and the historical log is large, and thus the to-be-processed log can be considered as a historical log. The to-be-processed log is processed according to the processing suggestion corresponding to the historical log.

[0100] Optionally, after the to-be-processed log is determined as the historical log, the method further includes:

[0101] determining the processing suggestion corresponding to the historical log as a processing suggestion corresponding to the to-be-processed log.

[0102] Specifically, after the to-be-processed log is considered as a historical log, the to-be-processed log is processed according to the processing suggestion corresponding to the historical log. The error module, the responsibility attribution result, and the processing suggestion corresponding to the historical log are extracted as the error module, the responsibility attribution result, and the processing suggestion corresponding to the to-be-processed log.

[0103] S260, inputting the to-be-analyzed vector into a positioning attribution model to output an error module in the to-be-analyzed log.

[0104] S270, outputting, by the positioning attribution model, a responsibility attribution result corresponding to the error module according to the error module.

[0105] S280, generating a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result.

[0106] The technical scheme of the embodiment of the present application determines a to-be-processed log and a to-be-processed semantic vector corresponding to the to-be-processed log, acquires a historical log and a historical semantic vector corresponding to the historical log, calculates the similarity of the to-be-processed semantic vector and the historical semantic vector to obtain a similarity calculation result, determines the to-be-processed log as a to-be-analyzed log in the case where the similarity calculation result is less than the set threshold, and determines the to-be-processed log as a historical log in the case where the similarity calculation result is greater than or equal to the set threshold. By calculating the similarity of the to-be-processed semantic vector and the historical semantic vector, the log similarity determination is realized, it is determined whether the to-be-processed log is a historical log, the repeated log analysis is avoided, and the analysis difficulty and complexity are reduced.

[0107] Embodiment three

[0108] Figure 3 Fig. 1 is a structural schematic diagram of a log analysis device according to the embodiment three of the present application. As shown in the figure, the device comprises: Figure 3

[0109] A determination module 310 is configured to determine a to-be-analyzed log and a to-be-analyzed vector corresponding to the to-be-analyzed log, wherein the to-be-analyzed log comprises a test log that is not analyzed and is generated when a detection failure problem occurs, and the detection failure problem comprises a problem that occurs when a product is detected;

[0110] An input module 320 is configured to input the to-be-analyzed vector into a positioning attribution model, and output an error module in the to-be-analyzed log, wherein the error module indicates a position where the detection failure problem occurs on the product;

[0111] An output module 330 is configured to output a responsibility attribution result corresponding to the error module by the positioning attribution model according to the error module;

[0112] A generation module 340 is configured to generate a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result.

[0113] ​The log analysis device provided by the embodiment of the present application determines a to-be-analyzed log and a to-be-analyzed vector corresponding to the to-be-analyzed log through a determination module; inputs the to-be-analyzed vector into a positioning attribution model through an input module, and outputs an error module in the to-be-analyzed log; outputs a responsibility attribution result corresponding to the error module from the positioning attribution model according to the error module through an output module; and generates a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result through a generation module. Through the mutual cooperation between the modules, the positioning attribution model is introduced to analyze the to-be-analyzed log, the accuracy and depth of analyzing the log are improved, the error module and the responsibility attribution result corresponding to the to-be-analyzed log are obtained, the automatic analysis of the to-be-analyzed log is realized, manual participation is not required, and the analysis complexity is reduced. Finally, the processing suggestion for the to-be-analyzed log is determined, and the problems of long time consumption and low analysis accuracy caused by manual analysis of the log are solved.

[0114] In one embodiment, the determination module 310 comprises:

[0115] The first determination unit is configured to determine a to-be-processed log and a to-be-processed semantic vector corresponding to the to-be-processed log, wherein the to-be-processed log comprises a test log generated when the detection failure problem occurs.

[0116] The acquisition unit is configured to acquire a historical log and a historical semantic vector corresponding to the historical log, wherein the historical log comprises an analyzed test log generated when the detection failure problem occurs.

[0117] The calculation unit is configured to calculate the similarity of the to-be-processed semantic vector and the historical semantic vector to obtain a similarity calculation result.

[0118] The second determination unit is configured to determine the to-be-processed log as a to-be-analyzed log in a case where the similarity calculation result is less than the set threshold.

[0119] The third determination unit is configured to determine the to-be-processed log as a historical log in a case where the similarity calculation result is greater than or equal to the set threshold.

[0120] In one embodiment, the determination module 310 further comprises a fourth determination unit, which is specifically configured to:

[0121] Determine the processing suggestion corresponding to the historical log as the processing suggestion corresponding to the to-be-processed log.

[0122] In one embodiment, the determination module 310 is specifically configured to:

[0123] Determine a to-be-analyzed semantic vector corresponding to the to-be-analyzed log.

[0124] extracting a combination feature of the log to be analyzed, the combination feature including features contained by words and fields constituting the log to be analyzed;

[0125] fusing the combination feature into the semantic vector to be analyzed to obtain a to-be-analyzed vector corresponding to the log to be analyzed.

[0126] In an embodiment, the output module 330 includes:

[0127] The positioning attribution model performs the following operations:

[0128] determining an error type to which the error module belongs, the error type including a type to which a department in which the detection failure problem occurs belongs;

[0129] determining an engineer responsible for the error module according to the error type;

[0130] composing a responsibility attribution result corresponding to the error module from the error module, the error type, and the engineer.

[0131] In an embodiment, the input module 320 includes:

[0132] obtaining a sample log set, the sample log set including at least one sample log;

[0133] determining, for each sample log, a sample feature corresponding to the sample log, the sample feature including a sample error module, a sample responsibility attribution result, and a sample processing suggestion corresponding to the sample log;

[0134] determining each sample log and the sample feature corresponding to each sample log as labeled data;

[0135] inputting the labeled data into an initial model to obtain a positioning attribution model.

[0136] In an embodiment, the generation module 340 includes:

[0137] generating an initial processing suggestion according to the error module and the responsibility attribution result corresponding to the log to be analyzed;

[0138] In response to a modification operation on the suggestion modification page, modifying the initial processing suggestion to obtain a processing suggestion for solving the detection failure problem.

[0139] The log analysis device provided in the embodiments of the present application can execute the log analysis method provided in any of the embodiments of the present application, and through mutual cooperation and collaborative work between the modules, the analysis of the log is completed, and the log analysis device has the corresponding functional modules and beneficial effects of the execution method.

[0140] Embodiment Four

[0141] According to embodiments of the present application, the present application also provides an electronic device, a computer readable storage medium and a computer program product.

[0142] Figure 4 is a block diagram of an electronic device according to an embodiment of the present application, which can implement the log analysis method according to the embodiments of the present application. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown in the figure, their connections and relationships, and their functions, are meant to be examples only, and are not meant to limit implementations of the present application described and / or claimed in this document.

[0143] As shown in Figure 4 The electronic device 410 includes at least one processor 411, and a memory, such as a read-only memory (ROM) 412, a random access memory (RAM) 413, etc., connected to the at least one processor 411 in communication, wherein the memory stores a computer program executable by the at least one processor 411, and the processor 411 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 412 or loaded into the random access memory (RAM) 413 from the storage unit 418. In the RAM 413, various programs and data required for the operation of the electronic device 410 can also be stored. The processor 411, the ROM 412, and the RAM 413 are connected to each other through a bus 414. An input / output (I / O) interface 415 is also connected to the bus 414.

[0144] A plurality of components in the electronic device are connected to the I / O interface 415, including: an input unit 416, such as a keyboard, a mouse, etc.; an output unit 417, such as various types of displays, speakers, etc.; a storage unit 418, such as a magnetic disk, an optical disk, etc.; and a communication unit 419, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 419 allows the electronic device to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunications networks.

[0145] The processor 411 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 411 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, and the like. The processor 411 performs various methods and processes described above, such as the log analysis method.

[0146] In some embodiments, the log analysis method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 418. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 410 via the ROM 412 and / or the communication unit 419. When the computer program is loaded onto the RAM 413 and executed by the processor 411, one or more steps of the log analysis method described above can be performed. Alternatively, in other embodiments, the processor 411 can be configured to perform the log analysis method by any other suitable means, such as by means of firmware.

[0147] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0148] Computer programs used to implement the methods of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program, when executed by the processor, implements the functions / acts specified in the flowcharts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine and partially on a remote machine or entirely on a remote machine or server.

[0149] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0150] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0151] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), blockchain network, and the Internet.

[0152] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. Servers can be cloud servers, also known as cloud computing servers or cloud hosts, which are a host product in the cloud computing service system to solve the defects of great management difficulty and weak business scalability in traditional physical hosts and VPS services.

[0153] In some embodiments, the computer program product includes a computer program which, when executed by a processor, implements the log analysis method provided by the embodiments of the present application.

[0154] The technical scheme of the embodiments of the present application is a log analysis method, device, electronic equipment, storage medium and program product. The log to be analyzed and the to-be-analyzed vector corresponding to the log to be analyzed are determined. The to-be-analyzed vector is input into a positioning attribution model, and an error module in the log to be analyzed is output. According to the error module, the positioning attribution model outputs a responsibility attribution result corresponding to the error module. According to the error module and the responsibility attribution result, a processing suggestion for solving the detection failure problem is generated. The positioning attribution model is introduced to analyze the log to be analyzed, which improves the accuracy and depth of log analysis, obtains the error module and the responsibility attribution result corresponding to the log to be analyzed, realizes automatic analysis of the log to be analyzed, reduces the analysis complexity, and finally determines the processing suggestion for the log to be analyzed, solving the problem of long time consumption and low analysis accuracy caused by manual log analysis.

[0155] It should be understood that the various forms of flow shown above can be reordered, added to, or deleted from without departing from the scope of the present application. For example, the steps described in the present application can be executed in parallel, in sequence, or in a different order, as long as the desired results of the technical scheme of the present application can be achieved, and this is not limited herein.

[0156] The above detailed description does not constitute a limitation on the scope of protection of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A log analysis method characterized by, The method comprises the following steps: determining a log to be analyzed and a vector corresponding to the log to be analyzed, wherein the log to be analyzed comprises a test log generated when a detection failure problem occurs, and the detection failure problem comprises a problem occurring when a product is detected; inputting the vector into a positioning attribution model to output an error module in the log to be analyzed, wherein the error module indicates a position on the product where the detection failure problem occurs; outputting, by the positioning attribution model, a responsibility attribution result corresponding to the error module according to the error module; generating a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result.

2. The method of claim 1, wherein, The method for determining the log to be analyzed comprises the following steps: determining a log to be processed and a semantic vector corresponding to the log to be processed, wherein the log to be processed comprises a test log generated when the detection failure problem occurs; obtaining a historical log and a historical semantic vector corresponding to the historical log, wherein the historical log comprises a test log that has been analyzed and generated when the detection failure problem occurs; calculating a similarity between the semantic vector and the historical semantic vector to obtain a similarity calculation result; determining the log to be processed as the log to be analyzed in a case where the similarity calculation result is less than a set threshold value; determining the log to be processed as the historical log in a case where the similarity calculation result is greater than or equal to the set threshold value.

3. The method of claim 2, wherein, After the log to be processed is determined as the historical log, the method further comprises the following step: determining a processing suggestion corresponding to the historical log as a processing suggestion corresponding to the log to be processed.

4. The method of claim 1, wherein, The method for determining the vector corresponding to the log to be analyzed comprises the following steps: determining a semantic vector corresponding to the log to be analyzed; extracting a combined feature of the log to be analyzed, wherein the combined feature comprises a feature contained in a word and a field constituting the log to be analyzed; fusing the combined feature into the semantic vector to obtain the vector corresponding to the log to be analyzed.

5. The method of claim 1, wherein, The method for outputting, by the positioning attribution model, the responsibility attribution result corresponding to the error module according to the error module comprises the following steps: The positioning attribution model performs the following operations: determining an error type to which the error module belongs, wherein the error type comprises a type to which a department where the detection failure problem occurs belongs; determining an engineer responsible for the error module according to the error type; composing the responsibility attribution result corresponding to the error module from the error module, the error type and the engineer.

6. The method of claim 1, wherein, The training operation of the positioning attribution model comprises the following steps: obtaining a sample log set, wherein the sample log set comprises at least one sample log; determining, for each sample log, a sample feature corresponding to the sample log, wherein the sample feature comprises a sample error module corresponding to the sample log, a sample responsibility attribution result and a sample processing suggestion; determining each sample log and the sample feature corresponding to each sample log as labeled data; inputting the labeled data into an initial model to obtain the positioning attribution model.

7. The method of claim 1, wherein, The processing suggestion for solving the detection failure problem is generated according to the error module corresponding to the log to be analyzed and the responsibility attribution result. An initial processing suggestion is generated according to the error module corresponding to the log to be analyzed and the responsibility attribution result. The initial processing suggestion is modified to obtain the processing suggestion for solving the detection failure problem in response to a modification operation on a suggestion modification page.

8. A log analysis apparatus characterized by comprising: The method comprises: A determination module is configured to determine a log to be analyzed and a vector to be analyzed corresponding to the log to be analyzed, the log to be analyzed comprising a test log that is not analyzed and is generated when a detection failure problem occurs, and the detection failure problem comprising a problem that occurs when a product is detected; An input module is configured to input the vector to be analyzed into a positioning attribution model to output an error module in the log to be analyzed, the error module indicating a position on the product where the detection failure problem occurs; An output module is configured to output, by the positioning attribution model, a responsibility attribution result corresponding to the error module according to the error module; A generation module is configured to generate a processing suggestion for solving the detection failure problem according to the error module and the responsibility attribution result.

9. An electronic device, comprising: The electronic device comprises: At least one processor; and A memory connected in communication with the at least one processor; wherein The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the log analysis method in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for enabling a processor to execute the log analysis method in any one of claims 1-7 when the computer instructions are executed by the processor.

11. A computer program product, characterised in that, The computer program product comprises a computer program that, when executed by a processor, implements the log analysis method according to any one of claims 1-7.