Log management apparatus, log management method, and log management program

The log management system optimizes table creation by using a combination of user-specific and common tables based on log frequency, addressing slow search speeds caused by numerous tables, ensuring efficient log storage and retrieval.

JP2025079100APending Publication Date: 2025-05-21FUJITSU LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023191555
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-09
Publication Date
2025-05-21

AI Technical Summary

Technical Problem

The problem of slow log search speed due to the increasing number of tables when logs are categorized and stored in multiple tables, especially with a growing number of users, is addressed.

Method used

A log management system that creates a limited number of user-specific tables and a common table for storing logs of users not assigned to specific tables, dynamically determining the number of individual tables based on the number of logs in the previous period, and assigning users to these tables to balance the load.

Benefits of technology

This approach reduces the overall number of tables while ensuring all logs are stored, thereby improving the speed of log searches by balancing the distribution of logs across tables.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025079100000001_ABST
    Figure 2025079100000001_ABST
Patent Text Reader

Abstract

To create a table for high-speed log search.SOLUTION: A processing unit 2b is configured to: create tables T1a, T1b, T2 in a storage unit 2a; select users in descending order of the number of logs acquired, based on the logs by user acquired from user terminals 1a to 1d in a period P1; and allocate each of the selected users to the tables T1a, T1b. When receiving a first log of a first user from one of the user terminals 1a to 1d, in a period P2 later than the period P1, the processing unit 2b is configured to: store, if the first user is allocated to one of the tables T1a, T1b, the first log in the table to which the first user is allocated, out of the tables T1a, T1b; and store the first log in the table T2 if the first user is not allocated to any of the tables T1a, T1b.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a log management device, a log management method, and a log management program. [Background technology]

[0002] In terminal devices such as personal computers, logs showing the operating status are automatically recorded. Collecting these logs enables various analyses such as the usage status of the terminal device, the execution status of business using the terminal device, and the occurrence status of abnormalities in the terminal device. When the logs collected from the terminal device are stored in a management server or the like, the collected logs are often classified and stored in multiple tables according to predetermined conditions such as by date and time or by user.

[0003] Here, as a technology related to table creation, for example, a shift work support system has been proposed in which a headquarters server analyzes response data acquired from a store server to obtain a daily predicted operation time required for work in the store, and creates a one-month shift table based on the predicted operation time. Also, an information management device has been proposed that, when searching a database including a value table and a date table, if it is determined that the value data to be searched in the value table is a search result but the equivalent value data is blank, it outputs the date data in the date table corresponding to that value data as a search result. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2016-38633 A [Patent Document 2] JP 2008-146513 A Summary of the Invention [Problem to be solved by the invention]

[0005] When collecting logs, categorizing and storing them in multiple tables, the problem is that the more tables there are, the slower the log search speed becomes. For example, when storing logs in tables for each user, the more users there are, the more tables there are, and the slower the log search speed becomes.

[0006] According to one aspect, the present invention has an object to provide a log management device, a log management method, and a log management program capable of creating a table that enables high-speed log search. [Means for solving the problem]

[0007] In one proposal, a log management device having a storage unit and a processing unit is provided. In this log management device, the processing unit creates one or more first tables and one second table in the storage unit, and selects users in descending order of the number of logs acquired based on user-specific logs acquired from a plurality of user terminals during a first period, and assigns the selected users to one or more first tables one by one. In addition, when the processing unit receives a first log of a first user from one of the plurality of user terminals during a second period after the first period, if the first user is assigned to one of the one or more first tables, the processing unit stores the first log in the first table to which the first user is assigned among the one or more first tables, and if the first user is not assigned to any of the one or more first tables, the processing unit stores the first log in the second table.

[0008] Also, one proposal provides a log management method in which a computer executes the same process as the above log management device. Furthermore, in one proposal, a log management program is provided that causes a computer to execute the same processing as the above-mentioned log management device. Effect of the Invention

[0009] On the one hand, it allows you to create tables that allow for fast log searches. [Brief description of the drawings]

[0010] [Figure 1] 1 illustrates a configuration example and a processing example of an information processing system according to a first embodiment; [Diagram 2] FIG. 11 illustrates an example of a configuration of an information processing system according to a second embodiment. [Diagram 3] FIG. 2 illustrates an example of a hardware configuration of a management server. [Figure 4] FIG. 2 is a diagram illustrating an example of a configuration of processing functions provided in each device of the information processing system. [Diagram 5] FIG. 4 illustrates an example of a data configuration of a log. [Figure 6] 1 shows an example for comparing hierarchically structured tables. [Figure 7] FIG. 11 illustrates an example of a configuration of a table in which logs are stored in the second embodiment; [Figure 8] FIG. 13 is a diagram illustrating a method for determining the number of individual tables. [Figure 9] FIG. 11 is a diagram illustrating an example of a configuration of a management table in the second embodiment. [Figure 10] 11A and 11B are diagrams illustrating an example of data configurations of an individual table and a common table. [Figure 11] FIG. 13 is a diagram illustrating an example of a table configuration for dealing with exceptions related to date and time. [Figure 12] 11A and 11B are diagrams illustrating an example of the data configuration of a Past table and a Future table. [Figure 13] 13 is a flowchart illustrating an example of a first table creation process. [Figure 14] 13 is a flowchart showing an example of a table creation process from the second time onward. [Figure 15] 13 is a flowchart (part 1) showing an example of a table creation process for the next month. [Figure 16] 13 is a flowchart (part 2) illustrating an example of a table creation process for the next month. [Figure 17] 13 is a flowchart illustrating an example of a Past table confirmation process. [Figure 18]13 is a flowchart illustrating an example of a Future table confirmation process. [Figure 19] 13 is a flowchart illustrating an example of a process for storing collected logs in a table. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. First Embodiment Fig. 1 is a diagram showing a configuration example and a processing example of an information processing system according to a first embodiment. The information processing system includes a plurality of user terminals and a log management device 2. The information processing system of Fig. 1 includes, as an example, four user terminals 1a to 1d. The user terminals 1a to 1d and the log management device 2 are connected via a network.

[0012] The user terminals 1a to 1d are terminal devices used by users, such as personal computers. In this embodiment, for example, the user terminal 1a is used by a user U0, the user terminal 1b is used by a user U1, the user terminal 1c is used by a user U2, and the user terminal 1d is used by a user U3. However, for example, a single user may use multiple user terminals.

[0013] Furthermore, the user terminals 1a to 1d generate logs indicating the operation history of their own devices and transmit them to the log management device 2. The generated logs include, for example, operation logs indicating processing contents according to user operations. Furthermore, the generated logs contain identification information of the users who use the user terminals.

[0014] The log management device 2 is a device capable of receiving and storing logs transmitted from the user terminals 1a to 1d. The log management device 2 is a computer device such as a server device or a personal computer, and has a storage unit 2a and a processing unit 2b.

[0015] The storage unit 2a is a storage area secured in a storage device (not shown) included in the log management device 2. The storage unit 2a stores logs received from the user terminals 1a to 1d. The processing unit 2b is, for example, a processor (not shown) included in the log management device 2. The processing unit 2b creates a table for storing logs acquired from the user terminals 1a to 1d during a certain period, and stores the table in the storage unit 2a. As such a table, at least one or more tables are created in which logs for each user are stored. However, if a table corresponding to each user is created, the number of tables increases as the number of users increases, resulting in a problem of a decrease in search speed for logs stored in the tables.

[0016] Therefore, the processing unit 2b creates only a limited number of user-specific tables, and also creates a table in which logs of other users who are not assigned a user-specific table are commonly stored. In the example of Fig. 1, two user-specific tables T1a and T1b and one table T2 common to other users are created as tables for storing logs in the period P2. This makes it possible to suppress the number of tables to be created.

[0017] Furthermore, the processing unit 2b determines which user's log to store in the user-specific tables T1a, T1b based on the acquisition status of logs from the user terminals 1a-1d in a period P1 prior to the period P2. In the example of Fig. 1, it is assumed that in the period P1, logs L1, L2,... of user U0, logs L11, L12,... of user U1, logs L21, L22,... of user U2, and logs L31, L32,... of user U3 are acquired and stored in the storage unit 2a.

[0018] The processing unit 2b counts the logs acquired during the period P1 by each user. Then, the processing unit 2b selects users in descending order of the number of acquired logs, and assigns the selected users to tables T1a and T1b one by one. In the example of FIG. 1, the number of logs is largest for users U0, U2, U3, and U1 in that order. In this case, the processing unit 2b assigns user U0, who has the largest number of logs, to table T1a, and assigns user U2, who has the second largest number of logs, to table T1b.

[0019] Thereafter, when a log is transmitted from the user terminals 1a to 1d during the period P2, the processing unit 2b receives the log and determines whether the user corresponding to the received log is assigned to the user-specific table T1a or T1b. If the user corresponding to the received log is assigned to either the table T1a or T1b, the processing unit 2b stores the log in the table to which the user is assigned, among the tables T1a and T1b. On the other hand, if the user corresponding to the received log is not assigned to either the table T1a or T1b, the processing unit 2b stores the log in the table T2.

[0020] 1, during period P2, the log of user U0 is stored in table T1a, and the log of user U2 is stored in table T1b, while the logs of users U1 and U3 are stored in table T2.

[0021] Here, even if the number of tables T1a and T1b created for each user is reduced, the more logs stored in the common table T2, the slower the search speed for logs from the table T2. In contrast, in this embodiment, as described above, the logs of users who had a large number of logs in the period P1 are preferentially stored in the tables T1a and T1b in the period P2. This increases the possibility that the number of logs stored in the table T2 in the period P2 will decrease compared to the case where the logs of users who had a small number of logs in the period P1 are stored in the tables T1a and T1b in the period P2. In addition, the number of logs stored in the tables T1a, T1b, and T2 in the period P2 is uniformed, and the relative number of logs stored in the table T2 to the number of logs stored in each of the tables T1a and T1b is likely to be suppressed.

[0022] Therefore, according to this embodiment, it is possible to reduce the number of logs stored in the common table T2 while reducing the number of user-specific tables T1a and T1b created, thereby improving the speed of searching for logs from the tables T1a, T1b, and T2.

[0023] Second Embodiment FIG. 2 is a diagram showing a configuration example of an information processing system according to a second embodiment. The information processing system shown in FIG. 2 includes user terminals 10a, 10b, 10c, etc. and a management server 100. The user terminals 10a, 10b, 10c, etc. and the management server 100 are connected via a network 20. The network 20 may include a wide area network (WAN) such as the Internet, or a local area network (LAN). The user terminals 10a, 10b, 10c, etc. are examples of the user terminals 1a to 1d in FIG. 1. The management server 100 is an example of the log management device 2 in FIG. 1.

[0024] The user terminals 10a, 10b, 10c,... are computer terminals used by users. For example, when the information processing system is used in a company, the users are employees of the company. Note that one user may use two or more user terminals. The user terminals 10a, 10b, 10c,... generate and store logs showing the operation history of each device.

[0025] The management server 100 is a server computer for managing the operation status of the user terminals 10a, 10b, 10c, .... The management server 100 collects logs from the user terminals 10a, 10b, 10c, ..., and analyzes the operation status of the user terminals 10a, 10b, 10c, ..., based on the collected logs. In addition, the management server 100 creates hierarchically structured tables to facilitate the analysis of logs, and stores the collected logs in these tables.

[0026] The logs collected by the management server 100 include, for example, an operation log indicating the processing contents executed in response to the user's operation. The logs may also include logs of operations unrelated to the user's operation, such as a log indicating a hardware abnormality or a communication log.

[0027] Fig. 3 is a diagram showing an example of a hardware configuration of a management server. The management server 100 is realized, for example, as a computer as shown in Fig. 3. The management server 100 shown in Fig. 3 includes a processor 101, a random access memory (RAM) 102, a hard disk drive (HDD) 103, a graphics processing unit (GPU) 104, an input interface (I / F) 105, a reader 106, and a communication interface (I / F) 107.

[0028] The processor 101 performs overall control of the entire management server 100. The processor 101 is, for example, a central processing unit (CPU), a micro processing unit (MPU), a digital signal processor (DSP), an application specific integrated circuit (ASIC), or a programmable logic device (PLD). The processor 101 may also be a combination of two or more elements of a CPU, an MPU, a DSP, an ASIC, or a PLD.

[0029] The RAM 102 is used as a main storage device of the management server 100. The RAM 102 temporarily stores at least a part of the OS program and application programs to be executed by the processor 101. The RAM 102 also stores various data necessary for processing by the processor 101.

[0030] The HDD 103 is used as an auxiliary storage device for the management server 100. The OS program, application programs, and various data are stored in the HDD 103. Note that other types of non-volatile storage devices such as SSDs (Solid State Drives) can also be used as the auxiliary storage device.

[0031] A display device 104a is connected to the GPU 104. The GPU 104 displays an image on the display device 104a in accordance with an instruction from the processor 101. The display device 104a may be a liquid crystal display or an organic EL (ElectroLuminescence) display.

[0032] An input device 105a is connected to the input interface 105. The input interface 105 transmits a signal output from the input device 105a to the processor 101. The input device 105a may be a keyboard or a pointing device. The pointing device may be a mouse, a touch panel, a tablet, a touch pad, a trackball, or the like.

[0033] A portable recording medium 106a is detachably attached to the reading device 106. The reading device 106 reads data recorded on the portable recording medium 106a and transmits it to the processor 101. The portable recording medium 106a may be an optical disk, a semiconductor memory, or the like.

[0034] The communication interface 107 transmits and receives data to and from other devices such as the user terminals 10a, 10b, 10c, . . . via the network 20. The above hardware configuration can realize the processing functions of the management server 100. Note that the user terminals 10a, 10b, 10c, . . . can also be realized as computers having a configuration as shown in FIG.

[0035] 4 is a diagram showing an example of the configuration of processing functions provided in each device of the information processing system. In the following description, when the user terminals 10a, 10b, 10c, etc. are referred to without any particular distinction, they may be written as "user terminal 10."

[0036] The user terminal 10 includes a log storage unit 11, a log generation unit 12, and a log transmission unit 13. The log storage unit 11 is a storage area secured in a storage device (not shown) included in the user terminal 10. In the log storage unit 11, logs generated by the log generation unit 12 are stored.

[0037] The processing of the log generating unit 12 and the log transmitting unit 13 is realized, for example, by a processor (not shown) included in the user terminal 10 executing a predetermined program. The log generating unit 12 generates a log indicating the operation details of the user terminal 10 and stores it in the log storage unit 11. The log transmitting unit 13 transmits unsent logs among the logs stored in the log storage unit 11 to the management server 100 at regular time intervals. The time interval at which the logs are transmitted is set shorter than the time interval at which a table is created in the management server 100 (one month in this embodiment), and is, for example, 24 hours.

[0038] The management server 100 includes a table storage unit 110 , a log collection unit 121 , a table creation unit 122 , and a log analysis unit 123 . The table storage unit 110 is a storage area secured in a storage device included in the management server 100, such as the RAM 102 or the HDD 103. The table storage unit 110 stores a hierarchical table in which logs collected by the log collection unit 121 are stored.

[0039] The processes of the log recorder 121, the table creator 122, and the log analyzer 123 are realized, for example, by the processor 101 executing a predetermined program. The log collection unit 121 receives logs transmitted from the log transmission units 13 of the user terminals 10 (user terminals 10a, 10b, 10c, . . . ), and stores them in a corresponding table in the table storage unit 110.

[0040] The table creation unit 122 creates a table for storing logs and stores it in the table storage unit 110. The table creation unit 122 determines the configuration of the table for storing logs for the next fixed period according to the log generation status in the most recent fixed period. In this embodiment, the fixed period is set to one month as an example.

[0041] The log analysis unit 123 executes a predetermined analysis process using the logs accumulated in the table storage unit 110. For example, the log analysis unit 123 executes processes such as analysis of the user's work situation, analysis of the application usage situation, detection of unauthorized operations, and detection of unauthorized processing due to viruses, etc. The log analysis unit 123 retrieves the tables stored in the table storage unit 110 to obtain the desired logs to be used in the analysis process.

[0042] Fig. 5 is a diagram showing an example of the data structure of a log. In the user terminal 10, a log including data such as that shown in Fig. 5 is acquired. The log shown in Fig. 5 has the following items: terminal name, update date and time, user name, type, category, content, and remarks.

[0043] The terminal name is identification information of the user terminal 10. The update date and time indicates the date and time when the log was generated. The user name is identification information of the user using the user terminal 10. As the user name, for example, the user name of the user logged in to the user terminal 10 is used. The type indicates the content of the operation indicated by the log. Examples of the type include starting and closing the user terminal 10, starting and closing an application, and sending and receiving data with other devices. The category indicates whether the operation is normal or abnormal. The content indicates the content of the operation. In the notes field, predetermined information according to the type, such as detailed information on the content of the operation, is recorded.

[0044] Next, a description will be given of the structure of the tables stored in table storage unit 110. First, a comparative example of tables will be described with reference to Fig. 6, and then the tables of this embodiment will be described with reference to Figs.

[0045] FIG. 6 shows a comparative example of a hierarchically structured table. Logs generated by the user terminal 10 can be used for various analysis processes. However, the amount of data of logs generated by the user terminal 10 is huge, and analysis processes using those logs take time. In addition, for example, a company may have more than 1000 user terminals 10 to be analyzed, and it may not be possible to analyze all user terminals 10, so analysis may have to be performed in units of about 100. In such cases, the accuracy of the analysis decreases.

[0046] Here, by storing logs in a hierarchically structured table, the efficiency of log search processing can be improved. Such efficient search processing makes it possible to quickly obtain logs required for analysis processing, thereby shortening the time required for analysis processing.

[0047] 6 shows an example of the configuration of a management table when logs are stored in a table by user and by date. The management table is used as an index for searching the table in which the logs are stored. The corresponding table items included in each management table store instruction information pointing to the lower level table. In the following explanation, it is assumed that the corresponding table items store the table name (file name) as instruction information, but the instruction information may also store, for example, the address of the table.

[0048] The management table [root] at the top level of the first hierarchy stores instruction information indicating the management table by month. In the example of Fig. 6, it is assumed that logs from January 2020 to December 2023 are stored in the table storage unit 110, and the management table [root] stores instruction information indicating the management table by month for this period.

[0049] The next management table, the second hierarchical level, stores instruction information indicating a daily management table. For example, the management table [yt1mt1] corresponding to January 2020 stores instruction information indicating a daily management table for January 2020.

[0050] The next third-level management table stores instruction information indicating the management table for each department to which the user belongs. For example, the management table [yt1mt1dt1] corresponding to January 1, 2020 stores instruction information indicating the management table for each department corresponding to January 1, 2020.

[0051] The next fourth-level management table stores instruction information indicating a table for each user. For example, the management table [yt1mt1dt1dp1] corresponding to January 1, 2020 and department dp1 stores instruction information indicating a table for each user corresponding to January 1, 2020 and department dp1. The instruction information stored in the fourth-level management table indicates a table in which logs for each user are stored.

[0052] For example, assume that a user and a period are specified as search conditions for logs. When a hierarchical table like the one described above is used, the search range is first narrowed down by the specified period, and the user's logs are searched for within the narrowed down search range. This makes it possible to make the log search process more efficient and shorten the processing time.

[0053] However, when using a table with a hierarchical structure as described above, for example, the log storage period and target users are determined in advance, and the hierarchical structure is defined in advance according to the determined contents. Therefore, when a log not defined in the hierarchical structure occurs (for example, a log not included in the storage period or a log of a non-target user), there is no storage destination for the log, and the log is lost, which is a problem.

[0054] Furthermore, in the above configuration, the more users there are and the longer the time since the start of log collection, the more tables there are. As the number of tables increases, there is also the problem that the search speed decreases.

[0055] FIG. 7 is a diagram illustrating an example of a configuration of a table in which logs are stored in the second embodiment. In the management server 100 of this embodiment, one or more individual tables and one common table are created as tables in which logs are stored. Each individual table stores the log of one user. Meanwhile, the common table stores the logs of other users who are not assigned an individual table.

[0056] The table creation unit 122 of the management server 100 dynamically determines the number of individual tables for the next fixed period according to the occurrence of logs for each user in the most recent fixed period, and also dynamically determines the users whose logs are to be stored in the individual tables. In this embodiment, one month is used as an example of a fixed period. As a result, one or more individual tables are defined for the hierarchical structure for each month, and users are assigned to each individual table. In addition, one common table is defined as an exception table. When logs are generated for a user to which no individual table is assigned, those logs are considered as exceptions and stored in the common table.

[0057] This limits the number of tables for storing logs on a monthly basis, making it possible to suppress the number of tables. At the same time, logs for users who are not assigned individual tables are stored in a common table, making it possible to reliably store logs for all users. This makes it possible to prevent logs from being lost while suppressing the number of tables and suppressing a decrease in search speed.

[0058] However, the more individual tables are created, the slower the search speed becomes. On the other hand, the fewer individual tables are created, the more logs are stored in the common table, and the slower the search speed becomes in the common table.

[0059] As an example of a method for solving this problem, the table creation unit 122 can select users in descending order of the number of logs in the most recent fixed period, and assign the selected users to individual tables for the next fixed period. As a result, the logs of users with fewer logs in the most recent fixed period are stored in the common table for the next fixed period. Since it is estimated that the number of logs in the next fixed period will be smaller for users with fewer logs in the most recent fixed period, there is a high possibility that the number of logs stored in the common table for the next fixed period will be reduced. Therefore, it is possible to reduce the number of individual tables created while also reducing the number of logs in the common table, thereby improving the search speed of the common table.

[0060] Incidentally, the operation log acquired by the user terminal 10 has the following characteristics. The first feature is that there is a change in the users who use the user terminal 10. For example, there may be users (guest users, etc.) who use the user terminal 10 temporarily, and employees may join, leave, or be transferred, so the users may change. For this reason, there is a problem in that it is not possible to define all users in advance.

[0061] A second feature is that the frequency of use of the user terminal 10 (i.e., the number of logs) varies from user to user. For example, as described above, the frequency of use is clearly different between a user who uses the user terminal 10 temporarily and a user who uses it regularly. For this reason, there are users for whom individual tables should be created and users for whom they should not. For example, it is estimated that search efficiency will be improved by assigning individual tables to users who use the terminal frequently.

[0062] The third feature is that the usage time of the user terminal 10 (i.e., the number of logs) is often determined to some extent for each day of the week. This is due to the work system, and for example, there may be users who do not generate logs on Saturdays and Sundays, and users who only generate logs on Wednesday mornings.

[0063] In consideration of such characteristics, the table creation unit 122 of this embodiment determines the table configuration for the next month for each day of the week based on the tendency of the number of logs for each day of the week in the most recent month. That is, the table creation unit 122 determines the number of individual tables and the users to be assigned to each individual table for each day of the week.

[0064] FIG. 7 shows an example in which a table for March 2020 is determined based on the occurrence of logs in February 2020. In FIG. 7, two individual tables are created for each of the Sundays of March 1, 8, 15, 22, and 29, and users us11 and us12 are assigned to each of them. For example, individual tables TB1a and TB2a and common table TB0a are created for March 1. In this case, of the logs generated on March 1, the log of user us11 is stored in individual table TB1a, the log of user us12 is stored in individual table TB2a, and the logs of users other than users us11 and us12 are stored in common table TB0a.

[0065] 7, three individual tables are created for each of the Mondays, March 2, 9, 16, 23, and 30, and users us5, us6, and us7 are assigned to each of them. For example, individual tables TB1b, TB2b, and TB3b and common table TB0b are created for March 2. In this case, of the logs generated on March 2, the log of user us5 is stored in individual table TB1b, the log of user us6 is stored in individual table TB2b, the log of user us7 is stored in individual table TB3b, and the logs of users other than users us5, us6, and us7 are stored in common table TB0b.

[0066] 7, two individual tables are created for each of the Saturdays, March 7, 14, 21, and 28, and users us13 and us14 are assigned to each of them. For example, individual tables TB1g and TB2g and common table TB0g are created for March 7. In this case, of the logs generated on March 7, the log of user us13 is stored in individual table TB1g, the log of user us14 is stored in individual table TB2g, and the logs of users other than users us13 and us14 are stored in common table TB0g.

[0067] For any day of the week in Figure 7, users whose logs were stored in the previous month (February) are assigned to each individual table. On the other hand, even if a log of a user whose log was not stored in the previous month occurs in the current month (March), that log is stored in the common table. Therefore, it is possible to store the logs of all users in a table without omission, without defining all users in advance.

[0068] 8 is a diagram showing a method for determining the number of individual tables. The table creation unit 122 determines the number of individual tables for each day of the week in the next month and the users to which the individual tables are assigned, based on the occurrence status of logs by day of the week in the most recent month. In the following explanation, as an example, it is assumed that the table configuration for the next month is determined near 12:00 p.m. (for example, 11:00 p.m.) on the last day of the month, based on the status of logs stored in the most recent month. For example, when the table configuration for September is determined on August 31st, the table configuration for September is determined based on the status of logs stored from August 1st to the current time of August 31st.

[0069] The table creation unit 122 executes the following process for each day of the week. First, the table creation unit 122 calculates the total number of logs L ALL_d and the average number of logs for other days of the week in the past month, L AVE Calculate the average number of logs for other days of the week, L AVE is the total number of logs for all days of the week in the last month, L ALL and the total number of logs above, L ALL_d Using and, (L ALL -L ALL_d ) / 6. Note that the number of identical days of the week varies from month to month, so the total number of logs L ALL ,L ALL_d Both are normalized to the sum of the logs over four weeks.

[0070] The table creation unit 122 calculates the total number of logs for the corresponding day of the week L ALL_d and the average number of logs on other days of the week L AVEBased on the result of this comparison, the table creation unit 122 determines the number of users Y to which the individual table is to be assigned in one of the following two ways. d (i.e. how many separate tables to create).

[0071] L ALL_d <L AVE In this case, the table creation unit 122 d is determined using the following formula (1). Y d =Y ALL_d ×L ALL_d / L AVE (1) Y in Equation (1) ALL_d indicates the total number of users whose logs were stored on the corresponding day of the week in the most recent month. In reality, the number of users Y is calculated by rounding up the decimal point in formula (1). d The table creation unit 122 determines the number of users Y d The system selects users in descending order of the number of logs on the relevant day of the week in the most recent month. An individual table is assigned to each selected user.

[0072] On the other hand, L ALL_d ≧L AVE In this case, the table creation unit 122 d The threshold value TH for determining is calculated using the following formula (2). TH=L ALL_d ×(Y ALL_d -1) / Y ALL_d (2) The table creation unit 122 selects users in descending order of the number of logs for the relevant day of the week in the most recent month, and adds up the number of logs for the selected users. The table creation unit 122 assigns individual tables to each user who was selected when the total value reaches or exceeds the threshold value TH. In other words, the number of users selected at this point in time is equal to or greater than the number of users Y. d It becomes.

[0073] In the example in Figure 8, the total number of logs for one month is L ALL =57000, total number of Sunday logs in a month L ALL_d= 3000, the total number of users whose logs were stored on Sundays in a month Y ALL_d = 7, total number of logs on Mondays in a month L ALL_d = 11000, the total number of users whose logs were stored on Monday in a month Y ALL_d Let's say =7.

[0074] As for Monday, the average number of logs on other days of the week, L AVE = 7667. In this case, L ALL_d ≧L AVE Therefore, the threshold value TH is calculated as 9428 (decimals are discarded) using formula (2). Table 32 in FIG. 8 shows users whose logs were stored on Mondays in the most recent month, sorted in descending order of the number of logs. If users are selected in order from the top and the number of logs is added up, the total value will exceed the threshold value TH when four users us1, us4, us3, and us2 are selected. Therefore, when the number of users Y d = 4, and four individual tables are created. Then, the logs of users us1, us4, us3, and us2 are stored in the four individual tables, respectively, and the logs of other users are stored in a common table.

[0075] This method can prevent individual tables corresponding to temporary users such as guest users from being proliferated. For example, the greater the difference in the number of logs between users on a given day of the week, the more the number of individual tables is suppressed. When the difference in the number of logs between users is large, it is considered that there is a temporary user with a small number of logs. In this case, the above method ensures that individual tables are assigned to a limited number of users with a relatively large number of logs, and the logs of other users, including temporary users, are stored in the common table. This increases the possibility of equalizing the number of logs stored between each individual table and the common table in the next month while suppressing the number of tables. As a result, it increases the possibility of improving the efficiency of table searches.

[0076] Conversely, the smaller the difference in the number of logs between users on a given day of the week, the more individual tables there are.ALL_d ≧L AVE Therefore, the total number of logs for the corresponding day is relatively large. Therefore, even if the number of individual tables is increased, each individual table will store a certain number of logs or more, and the number of logs stored in each individual table and the common table is likely to be uniform. As a result, the table search efficiency is likely to improve.

[0077] On the other hand, for Sundays, as shown on the left side of Figure 8, the average number of logs on other days of the week, L AVE = 9000. In this case, L ALL_d <L AVE It can be seen that the number of logs for the day is smaller than for other days. In such a case, the number of users Y d When the number of users Y is determined, many individual tables with a small number of stored logs are created, which may reduce search efficiency. Therefore, we use formula (1) to further reduce the number of individual tables. d is determined.

[0078] Since the calculation result of formula (1) is 2.333..., the number of users Y d = 3. Table 31 in FIG. 8 lists users whose logs were stored on Sundays in the most recent month in order of the number of logs. The top three users us1, us3, and us4 are selected, and individual tables are assigned to the selected users us1, us3, and us4, while the logs of the other users are stored in the common table. This increases the likelihood that the number of logs stored in each individual table and the common table in the next month can be equalized while suppressing the number of tables. As a result, it increases the likelihood that table search efficiency will improve.

[0079] Fig. 9 is a diagram showing a configuration example of a management table in the second embodiment. In Fig. 9, it is assumed that logs from January 2020 to December 2023 are stored in the table storage unit 110, similar to Fig. 6. In addition, the same table name (file name) is given to the management table similar to Fig. 6.

[0080] As shown in Fig. 9, in this embodiment, the configuration of the fourth-level management table in which instruction information pointing to the log table is stored is different from that in Fig. 6. The fourth-level management table stores the number of users Y determined based on the situation in the previous month. d In Figure 9, the user and individual table records for the number of users and one common table record are stored. In Figure 9, "us0" is stored in the user item corresponding to the common table. For example, in the fourth-level management table [yt1mt9dt1dp1] on September 1, 2020, the number of users Y d = 2. In this management table [yt1mt9dt1dp1], individual tables [yt1mt9dt1dp1us11] and [yt1mt9dt1dp1us12] corresponding to two users us11 and us12, respectively, and a common table [yt1mt9dt1dp1us0] are registered.

[0081] In Figure 9, the number of users for each day of the week, Y d is calculated by department. In this case, the total number of logs above, L ALL ,L ALL_d , the average number of logs L AVE , total number of users Y ALL ,Y ALL_d will be calculated by department.

[0082] Furthermore, the following is an example of a scenario in which a table structured as described above can be used. The administrator searches for all logs from April 5, 2023 to April 8, 2023, and analyzes the obtained logs. As a result of this analysis, the administrator wants to expand the period for the logs of users us1 and us3 to be analyzed from March 1, 2023 to May 31, 2023. For this reason, the administrator searches for the logs of users us1 and us3 from March 1, 2023 to May 31, 2023.

[0083] In this embodiment, the number of individual tables for each user is smaller than in the case of Fig. 6. Furthermore, the tables are created so that the difference in the number of logs between each individual table and the common table on the same date is small. Therefore, the search speed in the above-mentioned usage scenario can be increased, and the time required for the search can be reduced.

[0084] FIG. 10 is a diagram illustrating an example of the data structure of the individual table and the common table. As an example of an individual table, Figure 10 shows an individual table [yt1mt9dt1dp1us11] corresponding to user us11, which is registered in the management table [yt1mt9dt1dp1] in Figure 9. This individual table [yt1mt9dt1dp1us11] stores data on each of the items of the log shown in Figure 5, including terminal name, update date and time, type, category, content, and remarks.

[0085] Also, in Figure 10, as an example of a common table, a common table [yt1mt9dt1dp1us0] registered in the management table [yt1mt9dt1dp1] is shown. This common table [yt1mt9dt1dp1us0] stores data for all items included in the log shown in Figure 5. Compared to the individual table [yt1mt9dt1dp1us11], the common table [yt1mt9dt1dp1us0] further stores the user name, making it possible to search for the log of a desired user.

[0086] 11 is a diagram showing an example of a table configuration for dealing with exceptions related to date and time. When an abnormality occurs in the user terminal 10, the update date and time of a log collected by the user terminal 10 may be incorrect. When the management server 100 receives such a log, a table corresponding to the update date and time may not exist, and the received log may be missing. In order to prevent the loss of logs whose update dates and times are considered to be exceptions in this way, the management server 100 further creates a Past table 112 and a Future table 113 in addition to the daily table group 111 including the individual table and common table described above.

[0087] As an example of an abnormal update date and time, the update date and time of the received log may be earlier than the correct date and time, and therefore may be earlier than the log storage period (particularly the month in which the first table was created) in the table created in the management server 100. In such a case, the received log is stored in the Past table 112.

[0088] Another example of an abnormal update date and time is when the update date and time of the received log is later than the correct date and time, which means that the update date and time is later than the log storage period, and the table corresponding to the update date and time has not yet been created. In such a case, the received log is stored in the Future table 113.

[0089] In the example of FIG. 11, a table storing logs having update dates and times from January 2020 to December 2023 is created in the daily table group 111. In this case, if the update date and time of a log received from the user terminal 10 is included in the log storage period from January 2020 to December 2023, the log collection unit 121 of the management server 100 stores the log in the table of the corresponding date and time in the daily table group 111. In addition, if the update date and time of the log received from the user terminal 10 is before the above log storage period, the log collection unit 121 stores the log in the Past table 112. In addition, if the update date and time of the log received from the user terminal 10 is after the above log storage period, the log collection unit 121 stores the log in the Future table 113. As a result, even if the update date and time of a log is incorrect due to an abnormality occurring in the user terminal 10, it can be reliably stored in the table storage unit 110 and can be used for analysis later.

[0090] When an individual table and a common table for the next month are created, if a log whose update date and time is the next month is stored in the Future table 113, the log is moved to either the individual table or the common table that was created.

[0091] FIG. 12 illustrates an example of the data structure of the Past table and the Future table. Past table 112 stores data indicating the storage date and time in addition to data of all items included in the log shown in Fig. 5. The storage date and time indicates the date and time when the log was stored in Past table 112. Similarly, Future table 113 stores data indicating the storage date and time in addition to data of all items included in the log shown in Fig. 5. The storage date and time indicates the date and time when the log was stored in Future table 113. Note that Future table 113 stores abnormal logs whose update date and time are later than the storage date and time.

[0092] Next, the processing of the management server 100 will be described with reference to a flowchart. Fig. 13 is a flowchart showing an example of the initial table creation process, which is executed when the management server 100 starts collecting logs in a state in which no individual tables or common tables have been created yet.

[0093] [Step S 11 ] The table creation unit 122 creates the Past table 112 . [Step S12] The table creation unit 122 creates the Future table 113.

[0094] [Step S13] The table creation unit 122 creates a common table for each department for each day of the current month. 13 is completed, collection of logs from the user terminal 10 is started. No individual table is created for the month in which the process of Fig. 13 is executed. Therefore, when the log collection unit 121 receives a log of a user who belongs to a certain department and whose update date and time are correct, the log collection unit 121 stores the received log in the common table corresponding to the reception date among the common tables corresponding to the department.

[0095] 14 is a flowchart showing an example of the table creation process from the second time onward. The process in FIG. 14 is executed periodically at a predetermined time on the last day of the month. [Step S21] The table creation unit 122 executes a table creation process to create an individual table and a common table for the next month.

[0096] [Step S22] The table creation unit 122 executes a Past table checking process to delete unnecessary logs from among the logs stored in the Past table 112. [Step S23] The table creation unit 122 executes a Future table confirmation process to delete unnecessary logs from the logs stored in the Future table 113 and to move the logs.

[0097] Figures 15 and 16 are flow charts showing an example of table creation processing for the next month. The processing in Figures 15 and 16 corresponds to the processing in step S21 in Figure 14. The processing in Figures 15 and 16 is executed for each department.

[0098] [Step S31] The table creation unit 122 selects one day of the week. Hereinafter, the selected day of the week will be referred to as the "corresponding day of the week." [Step S32] The table creation unit 122 calculates the average number of logs L for the days of the week other than the day of the week in the most recent month. AVE As mentioned above, the average logarithm L AVE is the total number of logs for all days of the week in the last month, L ALL and the total number of logs for the corresponding day of the week in the last month L ALL_d Using and, (L ALL -L ALL_d ) / 6.

[0099] [Step S33] The table creation unit 122 calculates the total number of logs for the corresponding day of the week, L ALL_d and the average number of logs on other days of the week L AVE Compare with L ALL_d ≧L AVE If so, the process proceeds to step S39. ALL_d <L AVE If so, the process advances to step S34.

[0100] [Step S34] The table creation unit 122 calculates the total number Y of users whose logs were stored on the corresponding day of the week in the most recent month. ALL_d , the total number of logs for that day L ALL_d and the average number of logs for other days of the week L AVE Using the above formula (1), the number of users Y d The table creation unit 122 calculates the number of users Y (the number of individual tables). d is decided.

[0101] [Step S35] The table creation unit 122 calculates the number of users Y d The users are selected in descending order of the number of logs on the corresponding day of the week in the most recent month. [Step S36] The table creation unit 122 calculates the determined number of users Y for each corresponding day of the week in the next month. d Then, individual tables are created for each of the users selected in step S35, and each user is assigned to an individual table.

[0102] [Step S37] The table creation unit 122 creates a common table for each corresponding day of the week in the next month. [Step S38] The table creation unit 122 determines whether all days of the week in a week have been processed. If there are any days of the week that have not been processed, the process proceeds to step S31, where one of the days of the week that has not been processed is selected. On the other hand, if all days of the week have been processed, the table creation process ends.

[0103] [Step S39] The table creation unit 122 calculates the total number of logs for the corresponding day of the week, L ALL_d and the total number of users whose logs were stored on that day Y ALL_d The threshold value TH is calculated using the above-mentioned formula (2).

[0104] [Step S40] The table creation unit 122 selects the user with the largest number of logs on a given day of the week in the most recent month. [Step S41] The table creation unit 122 adds up the number of logs for the selected user on the corresponding day of the week in the most recent month.

[0105] [Step S42] The table creation unit 122 compares the sum in step S41 with a threshold value TH. If the sum is equal to or greater than the threshold value TH, the process proceeds to step S44. If the sum is smaller than the threshold value TH, the process proceeds to step S43.

[0106] [Step S43] The table creation unit 122 additionally selects the user with the next largest number of logs on the relevant day of the week in the most recent month. In the following step S41, the numbers of logs of all the users selected up to this point are added up.

[0107] [Step S44] The table creation unit 122 creates individual tables for each of the corresponding days of the week in the next month, each assigned to the currently selected user. [Step S45] The table creation unit 122 creates a common table for each corresponding day of the week in the next month. After that, the process proceeds to step S38.

[0108] 17 is a flowchart showing an example of a Past table confirmation process, which corresponds to step S22 in FIG. [Step S51] The table creation unit 122 determines whether any of the logs stored in the Past table 112 has a table storage period exceeding a predetermined number of days. The table storage period is a length of time obtained by subtracting the storage date and time of the log in the Past table 112 from the current date and time. The predetermined number of days for comparison is set arbitrarily by the administrator. If there is one or more applicable logs, the process proceeds to step S52; if there is no applicable log, the Past table confirmation process ends.

[0109] <Step S52> The table creation unit 122 deletes all applicable logs from the Past table 112. In this way, by deleting logs whose table storage period exceeds a predetermined number of days from the Past table 112, logs that are not useful for analysis can be deleted from the Past table 112, and the amount of data in the Past table 112 can be reduced.

[0110] 18 is a flowchart showing an example of a Future table confirmation process, which corresponds to step S23 in FIG. [Step S61] The table creation unit 122 determines whether any of the logs stored in the Future table 113 has a table storage period exceeding a predetermined number of days. The table storage period is a length of time obtained by subtracting the storage date and time of the log in the Future table 113 from the current date and time. The predetermined number of days for comparison is set arbitrarily by the administrator. If there is one or more applicable logs, the process proceeds to step S62; if there is no applicable log, the process proceeds to step S63.

[0111] [Step S62] The table creation unit 122 deletes all applicable logs from the Future table 113. In this way, by deleting logs whose table storage period exceeds a predetermined number of days from the Future table 113, logs that are not useful for analysis can be deleted from the Future table 113, thereby reducing the amount of data in the Future table 113.

[0112] [Step S63] The table creation unit 122 determines whether there is a log whose update date and time is for the next month among the logs stored in the Future table 113. If there is one or more matching logs, the process proceeds to step S64; if there is no matching log, the Future table confirmation process ends.

[0113] [Step S64] The table creation unit 122 moves the corresponding log to one of the tables created in step S21 of FIG. 14, which corresponds to the update date and time and the user name included in the log.

[0114] In this way, it is possible to move the log stored in the Future table 113 to an individual table or a common table. This makes it possible to search for the log in question from the daily table group 111.

[0115] Fig. 19 is a flowchart showing an example of a storage process for a table of collected logs. The log transmission unit 13 of the user terminal 10 transmits unsent logs accumulated in the log storage unit 11 to the management server 100 at regular time intervals. The process of Fig. 19 is executed for each transmitted log.

[0116] [Step S71] The log recorder 121 receives a log from the user terminal 10. [Step S72] The log recorder 121 determines whether the date indicated by the update date and time included in the received log (update date) is later than the current date. If the update date is later than the current date, the process proceeds to step S73. If the update date is the same as or earlier than the current date, the process proceeds to step S74.

[0117] [Step S73] The log recorder 121 stores the received log in the Future table 113. At this time, a storage date and time indicating the current date and time is added to the log. [Step S74] The log recorder 121 determines whether the update date of the received log is a past date for which no table with a corresponding date exists in the daily table group 111. If this condition is met, the process proceeds to step S75; if not, the process proceeds to step S76.

[0118] [Step S75] The log recorder 121 stores the received log in the Past table 112. At this time, a storage date and time indicating the current date and time is added to the log. [Step S76] The log collection unit 121 searches the daily table group 111 to determine whether there is an individual table corresponding to the update date and time and the user name included in the received log. In this search, the log collection unit 121 searches for a second-level management table corresponding to the update date based on the management table [root], and then searches for a third-level management table corresponding to the department to which the user belongs based on that management table. Furthermore, the log collection unit 121 determines whether there is an individual table corresponding to the user name based on that management table. If there is a corresponding individual table, the process proceeds to step S77. If there is no corresponding individual table, the process proceeds to step S78.

[0119] [Step S77] The log recorder 121 stores the received log in the corresponding individual table. [Step S78] The log recorder 121 stores the received log in the common table listed in the third hierarchical management table found in step S76.

[0120] The processing functions of the devices (e.g., the log management device 2, the management server 100) shown in each of the above embodiments can be realized by a computer. In this case, a program describing the processing contents of the functions that each device should have is provided, and the above processing functions are realized on the computer by executing the program on a computer. The program describing the processing contents can be recorded on a computer-readable recording medium. Examples of computer-readable recording media include magnetic storage devices, optical disks, and semiconductor memories. Examples of magnetic storage devices include hard disk drives (HDDs) and magnetic tapes. Examples of optical disks include CDs (Compact Discs), DVDs (Digital Versatile Discs), and Blu-ray Discs (BD, registered trademark).

[0121] When distributing a program, for example, the program is recorded on a portable recording medium such as a DVD or CD and then sold. The program can also be stored in a storage device of a server computer and transferred from the server computer to other computers via a network.

[0122] A computer that executes a program stores, for example, a program recorded on a portable recording medium or a program transferred from a server computer in its own storage device. The computer then reads the program from its own storage device and executes processing according to the program. The computer can also read the program directly from a portable recording medium and execute processing according to the program. The computer can also execute processing according to the received program each time a program is transferred from a server computer connected via a network. [Explanation of symbols]

[0123] 1a~1d User terminal 2. Log management device 2a Storage section 2b Processing section L1, L2, L11, L12, L21, L22, L31, L32 logs P1, P2 period T1a, T1b, T2 Tables U0~U3 users

Claims

1. A log management device having a storage unit and a processing unit, The processing unit includes: creating one or more first tables and one second table in the storage unit, selecting users in descending order of the number of acquired logs based on user-specific logs acquired from a plurality of user terminals during a first period, and allocating the selected users one by one to the one or more first tables; when receiving a first log of a first user from any one of the plurality of user terminals during a second period after the first period, if the first user is assigned to any one of the one or more first tables, storing the first log in a first table to which the first user is assigned among the one or more first tables, and if the first user is not assigned to any of the one or more first tables, storing the first log in the second table; Log management device.

2. In creating the one or more first tables, a number of first tables included in the one or more first tables is dynamically determined based on an acquisition status of logs for each user from the plurality of user terminals during the first period.

2. The log management device according to claim 1.

3. In generating the one or more first tables, acquiring a log acquisition status by day of the week based on the logs for each user acquired from the plurality of user terminals during the first period; determining, for each day of the week, the number of first tables included in the one or more first tables and users to be assigned to each of the one or more first tables based on the acquisition status for each day of the week; 2. The log management device according to claim 1.

4. In generating the one or more first tables, determining the number of tables corresponding to the first day of the week based on a total log number indicating the total number of logs acquired on the first day of the week in the first period, a total user number indicating the total number of users who acquired logs on the first day of the week in the first period, and a total user log number indicating the total number of logs acquired on the first day of the week in the first period for each user; selecting users in descending order of the number of acquired logs based on the logs acquired on the first day of the week during the first period, and allocating the selected users one by one to the one or more first tables corresponding to the first day of the week; 4. The log management device according to claim 3.

5. In generating the one or more first tables, Calculating a threshold value based on the total number of logs and the total number of users; based on the logs acquired on the first day of the week in the first period, select users in descending order of the number of acquired logs, add up the total number of user-specific logs corresponding to the selected users, and determine the number of second users selected at the point in time when the obtained total value becomes equal to or greater than the threshold value as the number of tables corresponding to the first day of the week; assigning the second users one by one to the one or more first tables corresponding to the first days of the week; 5. The log management device according to claim 4.

6. In generating the one or more first tables, comparing the total number of logs with an average number of logs per day of the week based on logs acquired on each day of the week other than the first day of the week during the first period; If the total number of logs is equal to or greater than the average number of logs, determining the number of tables corresponding to the first day of the week based on the total number of logs, the total number of users, and the total number of logs by user; If the total number of logs is less than the average number of logs, determining the number of tables corresponding to the first day of the week based on the total number of users, the total number of logs, and the average number of logs; 5. The log management device according to claim 4.

7. The processing unit further comprises: creating a third table in the storage unit; When a second log whose creation date and time is later than the second period is acquired from any one of the plurality of user terminals during the second period, the second log is stored in the third table.

2. The log management device according to claim 1.

8. The processing unit further comprises: when the one or more first tables and the second table corresponding to a third period after the second period are created, if the creation date and time of the second log stored in the third table is included in the third period, the second log is moved to any one of the one or more first tables and the second table corresponding to the third period; 8. The log management device according to claim 7.

9. The processing unit further comprises: creating a fourth table in the storage unit; when a third log having a creation date and time that is earlier than a log storage period corresponding to the one or more first tables and the second table created in the storage unit is acquired from any one of the plurality of user terminals, the third log is stored in the fourth table; 2. The log management device according to claim 1.

10. The computer creating one or more first tables and one second table in a storage unit, selecting users in descending order of the number of acquired logs based on user-specific logs acquired from a plurality of user terminals during a first period, and assigning the selected users one by one to the one or more first tables; when receiving a first log of a first user from any one of the plurality of user terminals during a second period after the first period, if the first user is assigned to any one of the one or more first tables, storing the first log in a first table to which the first user is assigned among the one or more first tables, and if the first user is not assigned to any of the one or more first tables, storing the first log in the second table; Log management methods.

11. On the computer, creating one or more first tables and one second table in a storage unit, selecting users in descending order of the number of acquired logs based on user-specific logs acquired from a plurality of user terminals during a first period, and assigning the selected users one by one to the one or more first tables; when receiving a first log of a first user from any one of the plurality of user terminals during a second period after the first period, if the first user is assigned to any one of the one or more first tables, storing the first log in a first table to which the first user is assigned among the one or more first tables, and if the first user is not assigned to any of the one or more first tables, storing the first log in the second table; The log management program that performs the processing.

Citation Information

Patent Citations

  • Information control device, and information control method and program for information control device

    JP2008146513A

  • Shift table creation support method, customer number prediction arithmetic method, shift work support system, shift table creation support device, customer number prediction arithmetic device, and programs thereof

    JP2016038633A