Database exception detection method and device, electronic equipment and storage medium
By performing multi-dimensional anomaly detection on database traffic data, operation logs, and inspection indicator data, the problem of difficult fault diagnosis in database operation and maintenance has been solved, enabling rapid location and resolution of anomalies, and improving operation and maintenance efficiency and database stability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- QILU SECURITIES
- Filing Date
- 2026-02-13
- Publication Date
- 2026-06-02
AI Technical Summary
In a highly heterogeneous database ecosystem, database fault diagnosis is difficult, the detection system is weak, and the operation and maintenance efficiency is low. Especially in core businesses such as high-frequency trading and real-time clearing, the timeliness of fault response is directly related to market risk and investor rights.
By collecting traffic data, operation logs, and inspection indicator data from the database, we perform abnormal detection for request counts, access statements, logs, and indicators, generate corresponding detection results, and trigger alarm information when an anomaly is detected, so as to quickly locate and resolve abnormal issues.
It improves database operation and maintenance efficiency, enables rapid location and resolution of anomalies, ensures database stability and response efficiency, and reduces market risks.
Smart Images

Figure CN122132374A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of computer technology, and in particular to a database anomaly detection method and apparatus, electronic device, and computer-readable storage medium. Background Technology
[0002] As the core foundation of enterprise information systems, databases are responsible for the efficient storage and real-time processing of data. They ensure cross-departmental data flow through collaborative management mechanisms, empowering business decision-making, and safeguarding information assets through access control and auditing. Their stable and reliable operation and efficient and rapid response are key supports for business continuity and core drivers of continuous innovation. Currently, to meet diverse business needs, enterprises have built technical architectures encompassing multiple database types, resulting in complex technology stacks, large instance scales, and a highly heterogeneous database ecosystem. This leads to an exponential increase in operational and maintenance complexity. Therefore, quickly locating database anomalies and improving database operational efficiency are crucial. Summary of the Invention
[0003] This disclosure provides a database anomaly detection method and apparatus, electronic device, computer-readable storage medium, and computer program product.
[0004] Firstly, this disclosure provides a database anomaly detection method, including:
[0005] Collect traffic data, operation logs, and inspection indicator data from the database;
[0006] Perform request count anomaly detection on the traffic data to obtain a first detection result of the request count anomaly detection; perform access statement anomaly detection on the traffic data to obtain a second detection result of the access statement anomaly detection.
[0007] Perform log anomaly detection on the running log to obtain a third detection result of the log anomaly detection;
[0008] To perform anomaly detection on the inspection indicator data, a fourth detection result of the anomaly detection is obtained;
[0009] If an anomaly is detected in the anomaly detection results of the database, an alarm message corresponding to the anomaly is triggered, wherein the anomaly detection results of the database include the first detection result, the second detection result, the third detection result, and the fourth detection result.
[0010] Secondly, this disclosure provides a database anomaly detection device, comprising:
[0011] The data acquisition module is configured to collect traffic data, operation logs, and inspection indicator data from the database.
[0012] The first detection module is configured to perform request count anomaly detection on the traffic data, obtain a first detection result of the request count anomaly detection, and perform access statement anomaly detection on the traffic data, obtain a second detection result of the access statement anomaly detection.
[0013] The second detection module is configured to perform log anomaly detection on the running log and obtain a third detection result of the log anomaly detection;
[0014] The third detection module is configured to perform anomaly detection on the inspection index data and obtain a fourth detection result of the anomaly detection.
[0015] The triggering module is configured to trigger an alarm message corresponding to the abnormal problem when an abnormal problem is found in the abnormal detection results of the database, wherein the abnormal detection results of the database include the first detection result, the second detection result, the third detection result, and the fourth detection result.
[0016] Thirdly, this disclosure provides an electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores one or more computer programs executable by the at least one processor, the one or more computer programs being executed by the at least one processor to enable the at least one processor to perform the aforementioned database anomaly detection method.
[0017] Fourthly, this disclosure provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the aforementioned database anomaly detection method.
[0018] Fifthly, this disclosure provides a computer program product that includes computer-readable code or a non-volatile computer-readable storage medium carrying computer-readable code. When the computer-readable code is run in a processor of an electronic device, the processor in the electronic device executes the database anomaly detection method described above.
[0019] The database anomaly detection method provided in this disclosure can collect database traffic data, operation logs during operation, and inspection indicator data, and perform anomaly detection on the traffic data, operation logs, and inspection indicator data respectively to obtain a first detection result and a second detection result corresponding to the traffic data, a third detection result corresponding to the operation logs, and a fourth detection result corresponding to the inspection indicator data. Based on the first detection result, the second detection result, the third detection result, and the fourth detection result, it can be determined whether there are any abnormal problems in the database. If so, alarm information corresponding to the abnormal problem is triggered, realizing rapid location of database anomalies. In this way, the database anomalies can be resolved in subsequent processes based on the triggered alarm information, thereby improving the operational efficiency of the database.
[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0021] The accompanying drawings are provided to further illustrate the present disclosure and form part of the specification. They are used together with the embodiments of the present disclosure to explain the disclosure and do not constitute a limitation thereof. The above and other features and advantages will become more apparent to those skilled in the art from the detailed description of exemplary embodiments with reference to the accompanying drawings, in which:
[0022] Figure 1 This is a flowchart of a database anomaly detection method provided in an embodiment of this disclosure;
[0023] Figure 2 This is a schematic diagram of a log anomaly detection provided in an embodiment of this disclosure;
[0024] Figure 3 This is a schematic diagram of a log classification method provided in an embodiment of this disclosure;
[0025] Figure 4 This is a block diagram of a database anomaly detection device provided in an embodiment of this disclosure;
[0026] Figure 5 This is a block diagram of an electronic device provided in an embodiment of this disclosure. Detailed Implementation
[0027] To enable those skilled in the art to better understand the technical solutions of this disclosure, exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments of this disclosure to aid understanding. These should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0028] Where there is no conflict, the various embodiments of this disclosure and the features thereof in the embodiments may be combined with each other.
[0029] As used herein, the term “and / or” includes any and all combinations of one or more related enumerated entries.
[0030] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. As used herein, the singular forms “a” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that when the terms “comprising” and / or “made of” are used in this specification, the presence of the stated feature, integral, step, operation, element, and / or component is specified, but the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof is not excluded. Words such as “connected” or “linked” are not limited to physical or mechanical connections but can include electrical connections, whether direct or indirect.
[0031] Unless otherwise specified, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this disclosure, and will not be interpreted as having an idealized or overly formal meaning, unless expressly so defined herein.
[0032] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information in this technical solution comply with relevant laws and regulations and do not violate public order and good morals. The use of user data in this technical solution follows relevant national laws and regulations (e.g., the "Information Security Technology - Personal Information Security Specification"). For example, appropriate measures are taken for personal information access control; restrictions are imposed on the display of personal information; the purpose of using personal information does not exceed the scope of direct or reasonable association; and explicit identity targeting is eliminated when using personal information to avoid precisely identifying specific individuals.
[0033] As the core foundation of enterprise information systems, databases are responsible for the efficient storage and real-time processing of data. They ensure cross-departmental data flow through collaborative management mechanisms, empowering business decisions, and safeguarding information assets through access control and auditing. Their stable and reliable operation and efficient and rapid response are key supports for business continuity and core drivers of continuous innovation. Currently, to meet diverse business needs, enterprises have built technical architectures encompassing multiple database types, resulting in complex technology stacks, large instance scales, and a highly heterogeneous database ecosystem. This leads to an exponential increase in the complexity of operation and maintenance management.
[0034] In particular, in the securities industry, core businesses such as high-frequency trading and real-time clearing require databases to handle millions of concurrent operations daily. This places extremely stringent demands on database throughput, response latency, and stability, as fault response time directly impacts market risk and investor rights. Against this backdrop, enterprises face numerous challenges, including difficulties in database fault diagnosis, weak detection systems, low operational efficiency, and insufficient intelligence.
[0035] Based on this, the present disclosure provides a database anomaly detection method, a database anomaly detection device, an electronic device, a computer-readable storage medium, and a computer program product, which will be described in detail in the following embodiments.
[0036] The database anomaly detection method according to embodiments of this disclosure can be executed by electronic devices such as terminal devices or servers. The terminal device can be a user equipment (UE), mobile device, user terminal, terminal, cellular phone, cordless phone, personal digital assistant (PDA), handheld device, computing device, in-vehicle device, wearable device, etc. The server can be an independent physical server, a server cluster composed of multiple physical servers, or a cloud server capable of cloud computing. This method can be implemented by a processor calling computer-readable program instructions stored in memory.
[0037] See Figure 1 , Figure 1 A flowchart of a database anomaly detection method according to an embodiment of this disclosure is shown, which specifically includes the following steps:
[0038] Step 102: Collect traffic data, operation logs, and inspection indicator data from the database.
[0039] In this context, "database" refers to any database that requires anomaly detection. The database can be a standalone database or a database within a heterogeneous database environment. Database types include, but are not limited to, Oracle, MySQL, SQL Server, GaussDB, DM, TiDB, and many others. The specific database type is determined based on the actual application, and this embodiment does not impose any limitations. Traffic data refers to database network packets. Operation logs refer to real-time logs generated during database operation, including but not limited to multi-source heterogeneous logs such as application logs, operating system logs, database operation logs, error logs, and slow query logs. Inspection indicator data refers to basic indicator data such as database configuration data, operational status data, and capacity data.
[0040] Specifically, bypass mirroring traffic acquisition technology can be used to collect database traffic data. Runtime logs are collected by integrating a log collection component; for example, the log collection component could be the Filebeat log collection component, or other log collection components, which are not limited in this embodiment. By adapting to various types of databases, Java Database Connectivity (JDBC) is used to connect to the databases and obtain the inspection indicator data for each database.
[0041] By collecting traffic data, operation logs, and inspection indicator data from the database separately, anomaly detection can be performed on these data in subsequent processes. Based on the anomaly detection results, it can be determined whether there are any abnormal issues in the database, which helps improve the accuracy of database anomaly detection.
[0042] Step 104: Perform request count anomaly detection on the traffic data to obtain a first detection result of the request count anomaly detection; perform access statement anomaly detection on the traffic data to obtain a second detection result of the access statement anomaly detection.
[0043] After collecting traffic data from the database, anomaly detection can be performed on the traffic data. This includes anomaly detection of request counts and access statement anomalies, thereby obtaining a first detection result for request count anomalies and a second detection result for access statement anomalies. The first detection result is the result of request count anomaly detection; the second detection result is the result of access statement anomaly detection. The specific implementation processes for request count anomaly detection and access statement anomaly detection are explained below.
[0044] In one specific embodiment provided in this disclosure, anomaly detection of request counts is performed on the traffic data to obtain a first detection result of the anomaly detection of request counts, including:
[0045] Extract multiple target access statements from the traffic data, and obtain the average number of requests for the access statements in the database within a preset time interval and the corresponding rate of change threshold of the database;
[0046] The current rate of change of the database is determined based on the number of the multiple target access statements and the average number of requests.
[0047] If the current rate of change does not exceed the rate of change threshold, the first detection result is that no abnormality was detected in the database request count.
[0048] If the current rate of change exceeds the rate of change threshold, the first detection result is that the database request count anomaly has occurred.
[0049] In practical applications, traffic data is database network packets obtained using switches. Therefore, it is necessary to decode the database network packets through a server to extract the access statements in the database network packets, so as to complete the abnormal detection of the number of requests to traffic data based on the extracted access statements.
[0050] The target access statement refers to the statement requesting access to the database contained in the traffic data. The preset time interval is a pre-defined time range used for detecting abnormal request counts, such as one minute, one hour, one day, or one week. The average number of requests is the average number of times (i.e., the number of access statements requesting access to the database) are initiated within the preset time interval. The rate of change threshold is the upper limit used to measure the current rate of change of the database within the preset time interval. Different databases may have different rate of change thresholds. The current rate of change is the rate of change of the number of access statements requesting access to the database within the preset time interval, determined based on the current number of access statements requesting access to the database and the average number of requests.
[0051] Specifically, after collecting traffic data from the database, the data is decoded, and multiple target access statements are extracted. The average number of requests to the database within a preset time interval and the corresponding rate of change threshold are then obtained. Dividing the number of target access statements by the average number of requests yields the quotient, which is the current rate of change for the database. This current rate of change is compared to the database's rate of change threshold. If the current rate of change does not exceed the threshold, the database request anomaly detection is considered normal; otherwise, the first detection result is also considered abnormal. If the current rate of change exceeds the threshold, it indicates a surge in database requests, and the database request anomaly detection is considered abnormal. In cases where the first detection result indicates an abnormal database request count, a corresponding alarm can be triggered to allow relevant personnel to intervene and maintain the database promptly.
[0052] This embodiment of the disclosure can determine the current rate of change of the database by the number of target access statements currently accessing the database and the average number of requests for access statements to the database within a preset time interval. Based on the corresponding rate of change threshold of the database, it can determine whether the current rate of change of the database is too high, thereby determining the first detection result and improving the accuracy of the first detection result. Since the traffic data is obtained in real time during the database operation, this embodiment of the disclosure can perform abnormal request count detection on the traffic data in real time and obtain the corresponding first detection result. On the basis of improving the accuracy of the first detection result, it also ensures the real-time nature of the first detection result, which is conducive to triggering alarm information in a timely manner when the first detection result is abnormal.
[0053] Furthermore, in this embodiment of the disclosure, the database anomaly detection method can be applied to a heterogeneous database environment. That is, the database that needs to be anomaly detected can be any one or more databases in the heterogeneous database environment. Therefore, in order to ensure the accuracy of anomaly detection of the number of requests for each database, a corresponding sensitivity and change rate threshold are set for each database.
[0054] Based on this, in a specific embodiment provided in this disclosure, the rate of change threshold is determined based on the following method:
[0055] Obtain the database's historical access statements, average number of historical requests, and preset sensitivity within a historical time interval;
[0056] The historical change rate of the database is determined based on the number of historical access statements and the average number of historical requests.
[0057] Determine the lower quartile and upper quartile of the historical rate of change;
[0058] The rate of change threshold is determined based on the lower quartile, the upper quartile, and the preset sensitivity.
[0059] The historical time interval refers to the historical time interval set to determine the database's rate of change threshold, such as the past 5 days or a directly specified past time period. Historical access statements refer to the access statements that requested access to the database within the historical time interval. The average number of historical requests is the average number of access requests (i.e., the number of historical access statements) made to the database within the historical time interval. Preset sensitivity refers to the sensitivity to anomalies pre-set for each database; for example, database 1 has a preset sensitivity of 1.5, database 2 has a preset sensitivity of 2, and database 3 has a preset sensitivity of 5. Different preset sensitivities for databases result in different rate of change thresholds for those databases. The lower quartile (Q1) refers to the value located at the 25th percentile of the historical rate of change dataset. The upper quartile (Q3) refers to the value located at the 75th percentile of the historical rate of change dataset.
[0060] Specifically, for any database in a heterogeneous database environment, obtain the average number of historical access statements and requests within a historical time interval (e.g., the past 5 days), along with a preset sensitivity. Divide the number of historical access statements per minute by the average number of historical requests to obtain multiple historical change rates for the database. Determine the lower and upper quartiles of these historical change rates, and then determine the interquartile range (Q3-Q1) based on the lower and upper quartiles. Finally, based on the upper quartile, the preset sensitivity, and the interquartile range, determine the change rate threshold, as shown in Formula 1 below.
[0061] Historical rate of change = Q3 + preset sensitivity × (Q3 - Q1) Formula 1
[0062] This embodiment of the disclosure can set different preset sensitivities for each database in a heterogeneous database environment. After determining the historical rate of change of the database, the lower quartile and upper quartile of the historical rate of change are further determined. The historical rate of change of the database is determined by combining the preset sensitivity, thereby realizing the setting of different rate of change thresholds for each database and improving the accuracy of determining the rate of change thresholds.
[0063] After collecting traffic data from the database, access statement anomaly detection can be performed on the traffic data. It should be noted that request count anomaly detection and access statement anomaly detection can be executed in parallel or sequentially, depending on the actual application. This embodiment does not limit the execution order of request count anomaly detection and access statement anomaly detection. The specific implementation process of access statement anomaly detection for traffic data will be explained below.
[0064] In one specific embodiment provided in this disclosure, access statement anomaly detection is performed on the traffic data to obtain a second detection result of the access statement anomaly detection, including:
[0065] Extract multiple target access statements from the traffic data and obtain the execution time of each target access statement;
[0066] Based on the execution time of each target access statement, detect whether there are any abnormal access statements among the plurality of target access statements;
[0067] If the abnormal access statement exists among the multiple target access statements, the second detection result is that the database access statement anomaly detection has occurred;
[0068] If no abnormal access statement is found among the multiple target access statements, the second detection result is that no abnormality was found in the database access statement anomaly detection.
[0069] Execution time refers to the execution duration of the target access statement, such as 1 second or 2 seconds. An abnormal access statement refers to a target access statement with a long execution time (exceeding the set abnormal threshold).
[0070] Specifically, after extracting multiple target access statements from the traffic data, the execution time of each target access statement is obtained. It is then determined whether the execution time of each target access statement exceeds a pre-set exception threshold. Target access statements whose execution time exceeds the exception threshold are identified as exception access statements. If an exception access statement is found among multiple target access statements, it indicates that the database access statement exception detection has failed, meaning the second detection result is that the database access statement exception detection has failed. If no exception access statement is found among multiple target access statements, it indicates that the database access statement exception detection has not failed, meaning the second detection result is that the database access statement exception detection has not failed.
[0071] In practical applications, to facilitate the storage of detection results for each database in a heterogeneous database environment, this embodiment of the disclosure includes a real-time data warehouse. After extracting multiple target access statements, daily execution data for each target access statement can be obtained from the real-time data warehouse. The daily execution data includes the statement identifier, execution count, and average execution time of the target access statement. After obtaining the daily execution data of the target access statements, the average execution time of the target access statements can be extracted from the daily execution data. Based on the average execution time of the target access statements, access statement anomaly detection is performed on the target access statements.
[0072] Furthermore, an isolated forest model can be trained to perform anomaly detection on the target access statement, thereby improving the accuracy and efficiency of the obtained second detection results.
[0073] This disclosure embodiment can perform access statement anomaly detection on the collected traffic data to identify whether there are abnormal access statements (i.e. slow SQL) with long execution time in the target access statement, making the implementation of anomaly detection on traffic data more comprehensive.
[0074] Furthermore, for identified abnormal access statements, optimization can be performed based on a pre-built access statement knowledge base. This optimization can include index optimization, query reconstruction, and parameter tuning. Specifically, for each abnormal access statement, its database and table are determined. Using the table's metadata (e.g., table creation statements, field descriptions, and index information) and the access statement knowledge base, an optimization request is sent to the statement optimization model. In practical applications, the statement optimization model can be the Cangjie large model or other large language models; the specific type depends on the application and is not limited in this embodiment. The statement optimization model combines the metadata of the table to which the abnormal access statement belongs with the data stored in the access statement knowledge base to optimize the abnormal access statement and generate an optimized access statement. Furthermore, the statement optimization model can output the abnormal items present in the abnormal access statement and the processing instructions for these items. The abnormal items output by the statement optimization model, along with the processing instructions for these items, allow relevant personnel to clearly understand the problems existing in the abnormal access statement and how to improve these problems, thus facilitating the maintenance of abnormal access statements.
[0075] In addition, embodiments of this disclosure can also input the abnormal access statement and the optimized access statement into a statement optimization model, so that the statement optimization model judges the first execution result of the abnormal access statement and the second execution result of the optimized access statement to determine whether the first execution result and the second execution result are consistent. If it is determined that the first execution result and the second execution result are consistent, the optimized access statement, the exception items existing in the abnormal access statement, and the handling description of the exception items are stored in the database.
[0076] In this embodiment of the disclosure, when an abnormal access statement is identified, the abnormal access statement can be further optimized. The abnormal items in the abnormal access statement are processed by the statement optimization model to optimize the abnormal access statement and improve the quality of the access statements stored in the database.
[0077] In practical applications, for abnormal access statements stored in the database, and their corresponding optimized access statements, they can be further executed separately in a simulation test environment using JDBC. This yields the first test result of the abnormal access statement and the second test result of the optimized access statement, as well as the execution time of the first and second tests. The first test execution time refers to the time taken to execute the abnormal access statement in the simulation test environment, and the second test execution time refers to the time taken to execute the optimized access statement in the simulation test environment. If the first and second test results are consistent, the execution time of the second test is further compared to see if it is less than the execution time of the first test. If so, it indicates that the handling instructions for the exceptions output by the statement optimization model have improved the performance and quality of the abnormal access statement. At this point, the optimized access statement, the exceptions contained in the abnormal access statement, and the handling instructions for the exceptions can be sent to relevant personnel for use as optimization suggestions in subsequent practical applications.
[0078] Step 106: Perform log anomaly detection on the running log to obtain the third detection result of the log anomaly detection.
[0079] After collecting the database's runtime logs, log anomaly detection can be performed on the logs to obtain a third detection result. This third detection result is the result of the log anomaly detection on the runtime logs.
[0080] In one specific embodiment provided in this disclosure, log anomaly detection is performed on the running log to obtain a third detection result of the log anomaly detection, including:
[0081] The operation logs are categorized to obtain the categorization results.
[0082] The operation log is structured based on the classification results to obtain structured log data;
[0083] Identify whether there are preset abnormal keywords in the structured log data;
[0084] If the abnormal keyword exists in the structured log data, the third detection result is that the log anomaly detection of the database is abnormal;
[0085] If the abnormal keyword is not present in the structured log data, the third detection result is that no abnormality was found in the log anomaly detection of the database.
[0086] The classification result refers to the log category to which the runtime log belongs after classification. In practical applications, log categories can be divided according to multiple dimensions, such as time (e.g., day, week, month), log exception level (e.g., ERROR, WARN), and preset exception keywords (e.g., timeout, failure, disconnection). Structured log data is the runtime log after structured processing.
[0087] Specifically, for any acquired log entry, the log is categorized to determine its category. Based on this categorization, the log is then structured to obtain structured log data. Anomaly detection is performed on the structured log data using pre-defined anomaly keywords. In practice, a machine learning model can be pre-trained and used to detect anomalies. Specifically, the system identifies whether preset anomaly keywords, such as "timeout," "failure," or "disconnection," exist in the structured log data. If they do, the log is considered abnormal, indicating an anomaly in the database's log anomaly detection, resulting in a third detection result. If they do not exist, the log is considered normal, indicating no anomaly in the database's log anomaly detection, also resulting in a third detection result. If the third detection result indicates an anomaly in the database's log anomaly detection, the machine learning model can be used to generate corresponding optimization suggestions or solutions to address the anomaly promptly.
[0088] Further, see Figure 2 , Figure 2 A schematic diagram of a log anomaly detection method according to an embodiment of this disclosure is shown. Figure 2As shown, this embodiment supports both real-time streaming collection of runtime logs (via Kafka) and batch offline collection of runtime logs (based on the file system), meeting the dual requirements of low-latency online analysis and periodic full-volume processing. The collected runtime logs can be parsed, filtered, and categorized in real-time by the Flink stream processing engine, and the processed runtime logs are stored in a real-time data warehouse. The runtime logs stored in the real-time data warehouse (specifically structured log data) can be used for log querying, statistical analysis, triggering corresponding alarm information, etc.
[0089] This disclosure presents a distributed log collection and analysis system, overcoming the limitations of traditional single-point log analysis and improving the fault diagnosis capabilities of database operations and maintenance. In the real-time log stream, dynamic matching with preset abnormal keywords improves the accuracy of the determined third-party detection results.
[0090] To ensure the accuracy and efficiency of classifying operational logs, this embodiment of the disclosure preferentially employs the Drain (Dynamic and Robust Adaptive Prefix Tree for Online Log Parsing) log parsing algorithm to classify the collected operational logs. The specific implementation method is as follows:
[0091] In one specific embodiment provided in this disclosure, classifying the operation logs to obtain the classification results includes:
[0092] For any of the aforementioned operation log entries, identify the fields to be replaced in the operation log;
[0093] Replace the field to be replaced with a delimiter, and then split the runtime log into multiple tokens based on the delimiter;
[0094] Based on the number and content of the multiple tokens, candidate log groups are determined in a pre-built tree structure;
[0095] Determine the similarity between the runtime log and the log template corresponding to the candidate log group;
[0096] If the similarity reaches a preset similarity threshold, the running log is classified into the candidate log group to obtain the classification result of the running log;
[0097] If the similarity does not reach the preset similarity threshold, a new candidate log group is created based on the running log, and the running log is classified into the new candidate log group to obtain the classification result of the running log.
[0098] In this document, "fields to be replaced" refers to the fields in the runtime log that need to be replaced, such as timestamps, thread numbers, and IP addresses. "Separator" refers to the word segmentation symbol used to segment the runtime log. The separator can be customized or the fields to be replaced can be used directly as separators; this disclosure does not limit the specific form of the separator. "Token" refers to the word segmentation tokens obtained after segmenting the runtime log. "Candidate log group" refers to a group of log templates that match the number and content of tokens in the runtime log. "Preset similarity threshold" refers to a pre-set similarity threshold between the runtime log to be classified and its corresponding candidate log group, used to measure the similarity between the runtime log to be classified and the candidate log group.
[0099] Specifically, the system identifies fields in the runtime log that need to be replaced, such as timestamps, thread numbers, and IP addresses. These fields are then replaced with pre-defined delimiters, or the fields themselves are used as delimiters. The runtime log is then segmented (tokenized) based on the delimiters, resulting in multiple tokens. Further details can be found in [link to documentation]. Figure 3 , Figure 3 A schematic diagram of a log classification method according to an embodiment of this disclosure is shown. Figure 3 As shown, the first layer of the tree structure is the root node, which has no business significance. The second layer is the number of tokens after segmenting the operation log. The third layer is the prefix words in the log template. The bottom layer is the candidate log groups with the same prefix words. In the pre-constructed tree structure (e.g., a prefix tree), the corresponding branch is searched based on the number of tokens after segmentation. In this branch, the candidate log group corresponding to the operation log is determined based on the token content of each token. The similarity between the operation log and the candidate log group is determined and compared with a preset similarity threshold. If the similarity reaches the preset similarity threshold, it means that the similarity between the operation log and the log template of the candidate log group is high. In this case, the operation log is classified into the candidate log group, and the classification result of the operation log is obtained. If the similarity does not reach the preset similarity threshold, it means that the similarity between the operation log and the log template of the candidate log group is low. In this case, a new candidate log group is created based on the operation log, and the log template of the operation log is used as the initial log template of the new candidate log group, and the classification result of the operation log is obtained.
[0100] In addition to the above-described classification of operation logs, this embodiment can further classify operation logs in multiple dimensions, such as by time, by log anomaly level, or by anomaly keywords. This allows for more refined classification of operation logs and improves classification accuracy.
[0101] This embodiment of the disclosure increases the diversity and flexibility of database anomaly detection by performing log anomaly detection on the collected operation logs and obtaining the corresponding third detection result.
[0102] Step 108: Perform anomaly detection on the inspection index data to obtain the fourth detection result of the anomaly detection.
[0103] In practical applications, inspection indicator data from the database can be collected and stored in the data warehouse according to a preset inspection cycle. After collecting the inspection indicator data, anomaly detection can be performed on the inspection indicators based on detection rules constructed for different types of databases, thereby obtaining a fourth detection result for the anomaly detection of the inspection indicator data. This fourth detection result is the detection result of the anomaly detection of the inspection indicator data.
[0104] In one specific embodiment provided in this disclosure, anomaly detection is performed on the inspection indicator data to obtain a fourth detection result of the anomaly detection, including:
[0105] The system identifies whether preset inspection keywords exist in the inspection indicator data, and obtains the identification results.
[0106] If the identification result meets the inspection threshold, the fourth detection result is that no abnormality was found in the database index anomaly detection;
[0107] If the identification result does not meet the inspection threshold, the fourth detection result is that the database index anomaly detection has occurred.
[0108] The identification result is obtained by executing a target access statement containing inspection keywords on the inspection indicator data. The inspection threshold is used to characterize whether the identification result of the inspection indicator data reaches the expected state. In practical applications, different categories of inspection indicator data correspond to different inspection thresholds, which can be set according to the actual application situation. This disclosure embodiment does not limit this.
[0109] This disclosure pre-sets different inspection indicators and detection rules for different types of databases. Specifically, different inspection indicators are set for different types of databases. For example, for SQL Server databases, the corresponding inspection indicators include database file corruption, virtual log files, database file status, database file growth method, and job execution status; for DM databases, the corresponding inspection indicators include database runtime, database authorization expiration, database user login failure, data table checks, and database physical backup checks. During the inspection process, according to the preset inspection cycle, the corresponding inspection indicator data for different types of databases are collected, and each type of inspection indicator data is checked for anomalies based on the detection rules corresponding to different types of databases. If any inspection indicator data is abnormal, an anomaly alarm message is generated to notify relevant personnel that the database has an anomaly in that inspection indicator. The inspection results are then visualized and displayed on the user terminal.
[0110] The embodiments disclosed herein can realize automated inspection of the database according to the inspection cycle and generate corresponding inspection reports. Once potential risks or performance bottlenecks are detected, multi-level early warning notifications can be triggered in real time, driving administrators or automated processes to intervene in advance, effectively ensuring the continuous stability and high-performance operation of the database.
[0111] Step 110: If an anomaly is found in the anomaly detection results of the database, trigger the alarm information corresponding to the anomaly.
[0112] After completing the database anomaly detection, the results can be used to determine if any abnormal issues exist in the database. If so, an alarm message corresponding to the abnormal issue is triggered, allowing relevant personnel to intervene and resolve the problem promptly. The database anomaly detection results include a first detection result, a second detection result, a third detection result, and a fourth detection result.
[0113] It should be noted that the database request count anomaly detection, access statement anomaly detection, log anomaly detection, and metric anomaly detection can be executed in parallel. Therefore, these detections may not be completed simultaneously. If any of the first, second, third, or fourth detection results is abnormal, the corresponding alarm message can be triggered to avoid delayed alarms.
[0114] In practical applications, database operating parameters can also be collected, including database operating metrics (such as IP address, running file, deployment location, etc.), timestamps, database identifiers, etc. The collected operating parameters are structured and stored in a real-time data warehouse to provide data support for subsequent analysis, processing, and alarms.
[0115] In addition, the database anomaly detection method provided in this disclosure also offers rich visualization functions, presenting the status and trend curves of key indicators in real time through a graphical dashboard. Access statement anomaly detection supports drill-down from multiple dimensions such as client IP and execution time, while hot access statement detection provides ranking views from multiple perspectives such as execution count and response time. This enables a visual display of the detection results, improving the intelligence level of database operation and maintenance.
[0116] The database anomaly detection method disclosed herein includes: collecting database traffic data, operation logs, and inspection indicator data; performing request count anomaly detection on the traffic data to obtain a first detection result of the request count anomaly detection; performing access statement anomaly detection on the traffic data to obtain a second detection result of the access statement anomaly detection; performing log anomaly detection on the operation logs to obtain a third detection result of the log anomaly detection; performing indicator anomaly detection on the inspection indicator data to obtain a fourth detection result of the indicator anomaly detection; and triggering alarm information corresponding to the anomaly problem if an anomaly is found in the database anomaly detection results, wherein the database anomaly detection results include the first detection result, the second detection result, the third detection result, and the fourth detection result.
[0117] This embodiment of the disclosure achieves the following: by collecting traffic data, operation logs during operation, and inspection indicator data from the database, anomaly detection is performed on the traffic data, operation logs, and inspection indicator data respectively to obtain a first detection result and a second detection result corresponding to the traffic data, a third detection result corresponding to the operation logs, and a fourth detection result corresponding to the inspection indicator data. Based on the first detection result, the second detection result, the third detection result, and the fourth detection result, it can be determined whether there are any abnormal problems in the database. If so, alarm information corresponding to the abnormal problem is triggered, realizing rapid location of abnormal problems in the database. In this way, the abnormal problems in the database can be resolved in subsequent processes based on the triggered alarm information, thereby improving the operational efficiency of the database.
[0118] It is understood that the various method embodiments mentioned above in this disclosure can be combined with each other to form combined embodiments without violating the principle and logic. Due to space limitations, this disclosure will not elaborate further. Those skilled in the art will understand that in the above methods of specific implementation, the specific execution order of each step should be determined by its function and possible internal logic.
[0119] In addition, this disclosure also provides a database anomaly detection device, electronic device, computer-readable storage medium, and computer program product, all of which can be used to implement any of the database anomaly detection methods provided in this disclosure. The corresponding technical solutions and descriptions are described in the corresponding section of the method and will not be repeated here.
[0120] Figure 4 A block diagram of a database anomaly detection apparatus according to an embodiment of this disclosure is shown. See also Figure 4 The database anomaly detection device includes:
[0121] The data acquisition module 402 is configured to collect traffic data, operation logs, and inspection indicator data from the database.
[0122] The first detection module 404 is configured to perform request count anomaly detection on the traffic data, obtain a first detection result of the request count anomaly detection, and perform access statement anomaly detection on the traffic data, obtain a second detection result of the access statement anomaly detection.
[0123] The second detection module 406 is configured to perform log anomaly detection on the running log and obtain a third detection result of the log anomaly detection.
[0124] The third detection module 408 is configured to perform anomaly detection on the inspection index data and obtain a fourth detection result of the anomaly detection.
[0125] Trigger module 410 is configured to trigger alarm information corresponding to the abnormal problem when there is an abnormal problem in the abnormal detection results of the database, wherein the abnormal detection results of the database include the first detection result, the second detection result, the third detection result and the fourth detection result.
[0126] Optionally, the first detection module 404 is further configured to:
[0127] Extract multiple target access statements from the traffic data, and obtain the average number of requests for the access statements in the database within a preset time interval and the corresponding rate of change threshold of the database;
[0128] The current rate of change of the database is determined based on the number of the multiple target access statements and the average number of requests.
[0129] If the current rate of change does not exceed the rate of change threshold, the first detection result is that no abnormality was detected in the database request count.
[0130] If the current rate of change exceeds the rate of change threshold, the first detection result is that the database request count anomaly has occurred.
[0131] Optionally, the first detection module 404 is further configured to:
[0132] Obtain the database's historical access statements, average number of historical requests, and preset sensitivity within a historical time interval;
[0133] The historical change rate of the database is determined based on the number of historical access statements and the average number of historical requests.
[0134] Determine the lower quartile and upper quartile of the historical rate of change;
[0135] The rate of change threshold is determined based on the lower quartile, the upper quartile, and the preset sensitivity.
[0136] Optionally, the first detection module 404 is further configured to:
[0137] Extract multiple target access statements from the traffic data and obtain the execution time of each target access statement;
[0138] Based on the execution time of each target access statement, detect whether there are any abnormal access statements among the plurality of target access statements;
[0139] If the abnormal access statement exists among the multiple target access statements, the second detection result is that the database access statement anomaly detection has occurred;
[0140] If no abnormal access statement is found among the multiple target access statements, the second detection result is that no abnormality was found in the database access statement anomaly detection.
[0141] Optionally, the second detection module 406 is further configured to:
[0142] The operation logs are categorized to obtain the categorization results.
[0143] The operation log is structured based on the classification results to obtain structured log data;
[0144] Identify whether there are preset abnormal keywords in the structured log data;
[0145] If the abnormal keyword exists in the structured log data, the third detection result is that the log anomaly detection of the database is abnormal;
[0146] If the abnormal keyword is not present in the structured log data, the third detection result is that no abnormality was found in the log anomaly detection of the database.
[0147] Optionally, the second detection module 406 is further configured to:
[0148] For any of the aforementioned operation log entries, identify the fields to be replaced in the operation log;
[0149] Replace the field to be replaced with a delimiter, and then split the runtime log into multiple tokens based on the delimiter;
[0150] Based on the number and content of the multiple tokens, candidate log groups are determined in a pre-built tree structure;
[0151] Determine the similarity between the runtime log and the log template corresponding to the candidate log group;
[0152] If the similarity reaches a preset similarity threshold, the running log is classified into the candidate log group to obtain the classification result of the running log;
[0153] If the similarity does not reach the preset similarity threshold, a new candidate log group is created based on the running log, and the running log is classified into the new candidate log group to obtain the classification result of the running log.
[0154] Optionally, the third detection module 408 is further configured as follows:
[0155] The system identifies whether preset inspection keywords exist in the inspection indicator data, and obtains the identification results.
[0156] If the identification result meets the inspection threshold, the fourth detection result is that no abnormality was found in the database index anomaly detection;
[0157] If the identification result does not meet the inspection threshold, the fourth detection result is that the database index anomaly detection has occurred.
[0158] The database anomaly detection device provided in this disclosure includes: a collection module configured to collect database traffic data, operation logs, and inspection indicator data; a first detection module configured to perform request count anomaly detection on the traffic data to obtain a first detection result of the request count anomaly detection, and perform access statement anomaly detection on the traffic data to obtain a second detection result of the access statement anomaly detection; a second detection module configured to perform log anomaly detection on the operation logs to obtain a third detection result of the log anomaly detection; a third detection module configured to perform indicator anomaly detection on the inspection indicator data to obtain a fourth detection result of the indicator anomaly detection; and a triggering module configured to trigger alarm information corresponding to the anomaly if an anomaly is found in the database anomaly detection results, wherein the database anomaly detection results include the first detection result, the second detection result, the third detection result, and the fourth detection result.
[0159] This embodiment of the disclosure achieves the following: by collecting traffic data, operation logs during operation, and inspection indicator data from the database, anomaly detection is performed on the traffic data, operation logs, and inspection indicator data respectively to obtain a first detection result and a second detection result corresponding to the traffic data, a third detection result corresponding to the operation logs, and a fourth detection result corresponding to the inspection indicator data. Based on the first detection result, the second detection result, the third detection result, and the fourth detection result, it can be determined whether there are any abnormal problems in the database. If so, alarm information corresponding to the abnormal problem is triggered, realizing rapid location of abnormal problems in the database. In this way, the abnormal problems in the database can be resolved in subsequent processes based on the triggered alarm information, thereby improving the operational efficiency of the database.
[0160] Each module in the aforementioned database anomaly detection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0161] Figure 5 This is a block diagram of an electronic device provided in an embodiment of the present disclosure.
[0162] See Figure 5This disclosure provides an electronic device 500, which includes: at least one processor 501; at least one memory 502; and one or more I / O interfaces 503 connected between the processor 501 and the memory 502; wherein the memory 502 stores one or more computer programs that can be executed by the at least one processor 501, and the one or more computer programs are executed by the at least one processor 501 to enable the at least one processor 501 to perform the above-described database anomaly detection method.
[0163] The modules in the aforementioned electronic devices can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0164] This disclosure also provides a computer-readable storage medium storing a computer program thereon, wherein the computer program, when executed by a processor, implements the aforementioned database anomaly detection method. The computer-readable storage medium may be volatile or non-volatile.
[0165] This disclosure also provides a computer program product, including computer-readable code, or a non-volatile computer-readable storage medium carrying computer-readable code. When the computer-readable code is run in the processor of an electronic device, the processor in the electronic device executes the database anomaly detection method described above.
[0166] Those skilled in the art will understand that all or some of the steps, systems, and apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware implementations, the division between functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software can be distributed on a computer-readable storage medium, which may include computer storage media (or non-transitory media) and communication media (or transient media).
[0167] As is known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable program instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), static random access memory (SRAM), flash memory or other memory technologies, portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, it is known to those skilled in the art that communication media typically contain computer-readable program instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0168] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0169] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing the status information of the computer-readable program instructions to implement various aspects of this disclosure.
[0170] The computer program product described herein can be implemented specifically through hardware, software, or a combination thereof. In one alternative embodiment, the computer program product is specifically embodied in a computer storage medium; in another alternative embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.
[0171] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0172] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0173] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.
[0174] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0175] Example embodiments have been disclosed herein, and while specific terminology has been used, it is for illustrative purposes only and should be construed as such, and is not intended to be limiting. In some instances, it will be apparent to those skilled in the art that features, characteristics, and / or elements described in connection with particular embodiments may be used alone, or in combination with features, characteristics, and / or elements described in connection with other embodiments, unless otherwise expressly indicated. Therefore, those skilled in the art will understand that various changes in form and detail may be made without departing from the scope of this disclosure as set forth by the appended claims.
Claims
1. A database anomaly detection method, characterized in that, include: Collect traffic data, operation logs, and inspection indicator data from the database; Perform request count anomaly detection on the traffic data to obtain a first detection result of the request count anomaly detection; perform access statement anomaly detection on the traffic data to obtain a second detection result of the access statement anomaly detection. Perform log anomaly detection on the running log to obtain a third detection result of the log anomaly detection; Anomaly detection is performed on the inspection indicator data to obtain a fourth detection result of the anomaly detection. If an anomaly is detected in the anomaly detection results of the database, an alarm message corresponding to the anomaly is triggered, wherein the anomaly detection results of the database include the first detection result, the second detection result, the third detection result, and the fourth detection result.
2. The method as described in claim 1, characterized in that, Perform request count anomaly detection on the traffic data to obtain a first detection result of the request count anomaly detection, including: Extract multiple target access statements from the traffic data, and obtain the average number of requests for the access statements in the database within a preset time interval and the corresponding rate of change threshold of the database; The current rate of change of the database is determined based on the number of the multiple target access statements and the average number of requests. If the current rate of change does not exceed the rate of change threshold, the first detection result is that no abnormality was detected in the database request count. If the current rate of change exceeds the rate of change threshold, the first detection result is that the database request count anomaly has occurred.
3. The method as described in claim 2, characterized in that, The rate of change threshold is determined based on the following method: Obtain the database's historical access statements, average number of historical requests, and preset sensitivity within a historical time interval; The historical change rate of the database is determined based on the number of historical access statements and the average number of historical requests. Determine the lower quartile and upper quartile of the historical rate of change; The rate of change threshold is determined based on the lower quartile, the upper quartile, and the preset sensitivity.
4. The method as described in claim 1, characterized in that, The traffic data is subjected to access statement anomaly detection to obtain a second detection result of the access statement anomaly detection, including: Extract multiple target access statements from the traffic data and obtain the execution time of each target access statement; Based on the execution time of each target access statement, detect whether there are any abnormal access statements among the plurality of target access statements; If the abnormal access statement exists among the multiple target access statements, the second detection result is that the database access statement anomaly detection has occurred; If no abnormal access statement is found among the multiple target access statements, the second detection result is that no abnormality was found in the database access statement anomaly detection.
5. The method as described in claim 1, characterized in that, Perform log anomaly detection on the runtime logs to obtain a third detection result, including: The operation logs are categorized to obtain the categorization results. The operation log is structured based on the classification results to obtain structured log data; Identify whether there are preset abnormal keywords in the structured log data; If the abnormal keyword exists in the structured log data, the third detection result is that the log anomaly detection of the database is abnormal; If the abnormal keyword is not present in the structured log data, the third detection result is that no abnormality was found in the log anomaly detection of the database.
6. The method as described in claim 5, characterized in that, The operation logs are categorized to obtain the categorization results, including: For any of the aforementioned operation log entries, identify the fields to be replaced in the operation log; Replace the field to be replaced with a delimiter, and then split the runtime log into multiple tokens based on the delimiter; Based on the number and content of the multiple tokens, candidate log groups are determined in a pre-built tree structure; Determine the similarity between the runtime log and the log template corresponding to the candidate log group; If the similarity reaches a preset similarity threshold, the running log is classified into the candidate log group to obtain the classification result of the running log; If the similarity does not reach the preset similarity threshold, a new candidate log group is created based on the running log, and the running log is classified into the new candidate log group to obtain the classification result of the running log.
7. The method as described in claim 1, characterized in that, Anomaly detection is performed on the inspection indicator data to obtain a fourth detection result, including: The system identifies whether preset inspection keywords exist in the inspection indicator data, and obtains the identification results. If the identification result meets the inspection threshold, the fourth detection result is that no abnormality was found in the database index anomaly detection; If the identification result does not meet the inspection threshold, the fourth detection result is that the database index anomaly detection has occurred.
8. A database anomaly detection device, characterized in that, include: The data acquisition module is configured to collect traffic data, operation logs, and inspection indicator data from the database. The first detection module is configured to perform request count anomaly detection on the traffic data, obtain a first detection result of the request count anomaly detection, and perform access statement anomaly detection on the traffic data, obtain a second detection result of the access statement anomaly detection. The second detection module is configured to perform log anomaly detection on the running log and obtain a third detection result of the log anomaly detection; The third detection module is configured to perform anomaly detection on the inspection index data and obtain a fourth detection result of the anomaly detection. The triggering module is configured to trigger an alarm message corresponding to the abnormal problem when an abnormal problem is found in the abnormal detection results of the database, wherein the abnormal detection results of the database include the first detection result, the second detection result, the third detection result, and the fourth detection result.
9. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores one or more computer programs that can be executed by the at least one processor to enable the at least one processor to perform the method as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-7.