Log policy management apparatus, log policy management method, and log policy management program
The log policy management system addresses complex log information management by associating service providers, roles, and operational statuses to simplify and facilitate log information processing across multiple terminal devices.
Patent Information
- Application Number
- JP2024013332
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-31
- Publication Date
- 2025-08-13
- Estimated Expiration
- 2044-01-31
AI Technical Summary
In systems with multiple terminal devices, managing the information processing format of log information becomes complicated and troublesome due to varying log information types and system control requirements, exacerbated by the number of devices to be managed.
A log policy management system that includes a policy detection unit to associate service providers, log policy targets, log setting classifications, and policy levels to detect and set appropriate policy information, and a policy setting unit to apply this information to the corresponding targets.
Simplifies and facilitates the management of log information processing across terminal devices by centralizing policy application based on service providers, roles, and operational statuses.
Smart Images

Figure 2025118182000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a log policy management device, a log policy management method, and a log policy management program. [Background technology]
[0002] Patent Document 1 (JP 2016-130997 A) discloses an information processing device that can provide an MFP that can reliably execute port opening and closing control that reflects security policies, even when an extended AP is installed.
[0003] When installing an extended AP, this information processing device edits policy setting items, including existing ones, based on the analysis results of port control information related to the specific port used by the extended AP. Then, it accepts setting input via the edited policy setting items and generates setting information. This allows for applying filtering rules to the firewall unit according to the setting information, thereby maintaining security when the extended AP is installed. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-130997 Summary of the Invention [Problem to be solved by the invention]
[0005] Here, in a system that has multiple terminal devices, such as a so-called cloud system or data center, the type or pattern of log information acquired by each terminal device differs depending on the level of system control required by the customer that operates the system or the customer's system implementation process, etc.
[0006] This has led to a problem that managing the information processing format of the log information of each terminal device becomes complicated and troublesome, and this problem becomes more pronounced as the number of terminal devices to be managed increases.
[0007] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a log policy management device, a log policy management method, and a log policy management program that simplify and facilitate the management of the information processing form of log information of each terminal device. [Means for solving the problem]
[0008] In order to solve the above-mentioned problems and achieve the objectives, the log policy management device of the present invention has a policy detection unit that references, based on the judgment target, log policy target, log setting classification, and policy level, a memory unit in which the judgment target that is the entity providing the service, the log policy target to which policy information that controls the acquisition of log information is applied, the log setting classification that indicates the type of log information collected for each log policy target, the policy level that indicates the information processing form of the acquired log information, and the policy information to be set are respectively associated, and detects policy information that corresponds to the judgment target, log policy target, log setting classification, and policy level, and a policy setting unit that sets the detected policy information to the corresponding log policy target.
[0009] In addition, in order to solve the above-mentioned problems and achieve the objective, the log policy management method of the present invention includes a policy detection step in which a policy detection unit references a memory unit to which a determination target that is the entity providing the service, a log policy target to which policy information that controls the acquisition of log information is applied, a log setting classification that indicates the type of log information to be collected for each log policy target, a policy level that indicates the information processing form of the acquired log information, and the policy information to be set, based on the determination target, log policy target, log setting classification, and policy level, and detects policy information corresponding to the determination target, log policy target, log setting classification, and policy level; and a policy setting step in which a policy setting unit sets the detected policy information to the corresponding log policy target.
[0010] In addition, in order to solve the above-mentioned problems and achieve the objective, the log policy management program of the present invention causes a computer to function as a policy detection unit that references a memory unit, based on the judgment target, log policy target, log setting classification, and policy level, to which are respectively associated the judgment target that is the entity providing the service, the log policy target to which policy information that controls the acquisition of log information is applied, the log setting classification that indicates the type of log information collected for each log policy target, the policy level that indicates the information processing form of the acquired log information, and the policy information to be set, and detects policy information corresponding to the judgment target, log policy target, log setting classification, and policy level, and as a policy setting unit that sets the detected policy information to the corresponding log policy target. [Effects of the Invention]
[0011] The present invention can simplify and facilitate management of the information processing form of log information of each terminal device. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 illustrates a system configuration of a log policy management system according to a first embodiment. [Figure 2]FIG. 2 is a diagram showing an outline of the configuration of the configuration information management master provided in the log policy management device according to the first and second embodiments. [Figure 3] FIG. 3 is a diagram showing an outline of the configuration of the policy master provided in the log policy management device according to the first and second embodiments. [Figure 4] FIG. 4 is a diagram showing an outline of the configuration of the setting master provided in the log policy management device according to the first and second embodiments. [Figure 5] FIG. 5 is a block diagram showing the hardware configuration of a log policy management device provided in the log policy management system of the first embodiment. [Figure 6] FIG. 6 illustrates an example of a configuration information management master provided in the log policy management device of the log policy management system according to the first embodiment. [Figure 7] FIG. 7 illustrates an example of a policy master provided in the log policy management device of the log policy management system according to the first embodiment. [Figure 8] FIG. 8 illustrates an example of a setting master provided in the log policy management device of the log policy management system according to the first embodiment. [Figure 9] FIG. 9 is a diagram showing a configuration information management master table in which update flag information is set for each server function that sets policy information in the log policy management device of the log policy management system according to the first embodiment. [Figure 10] FIG. 10 is a diagram showing how policy information corresponding to the operating status is set for each server function for which update flag information is set by the log policy management device of the log policy management system of the first embodiment. [Figure 11] Figure 11 is a diagram showing a configuration information management master table in which the update flag information for each server function for which policy information has been set has been erased and the master change history for the server function for which policy information has been changed has been incremented in the log policy management device of the first embodiment of the log policy management system. [Figure 12] FIG. 12 is a diagram showing an example in which the operating status of each server device in the configuration information management master table is changed to another operating status. [Figure 13] FIG. 13 is a diagram showing how new policy information is set for a server device whose operating status has been changed to another operating status. [Figure 14] FIG. 14 is a diagram showing an example in which the server role of each server device in the configuration information management master table has been changed. [Figure 15] FIG. 15 is a diagram showing an example in which new policy information is set for a server device whose server role has been changed. [Figure 16] FIG. 16 is a diagram showing a state in which various information about a newly added server device has been added to the configuration information management master table. [Figure 17] FIG. 17 is a diagram showing an example in which policy information corresponding to the operating status is set for a newly added server device. [Figure 18] FIG. 18 illustrates a system configuration of a log policy management system according to the second embodiment. [Figure 19] FIG. 19 is a block diagram illustrating a hardware configuration of a log policy management device in the log policy management system according to the second embodiment. [Figure 20] FIG. 20 illustrates an example of a configuration information management master table provided in the log policy management device of the log policy management system according to the second embodiment. [Figure 21] FIG. 21 illustrates an example of a policy master table provided in the log policy management device of the log policy management system according to the second embodiment. [Figure 22] FIG. 22 illustrates an example of a setting master table provided in the log policy management device of the log policy management system according to the second embodiment. [Figure 23]FIG. 23 is a diagram showing how policy information according to employee rank is set in each server device by the log policy management device of the log policy management system according to the second embodiment. [Figure 24] Figure 24 is a diagram showing a configuration information management master table in which the update flag information of each server device for which policy information is set is erased and the master change history of the server device for which the policy information has been changed is incremented in the log policy management device of the second embodiment. [Figure 25] FIG. 25 is a diagram showing an example of changing the worker rank in the configuration information management master table. [Figure 26] FIG. 26 is a diagram showing how new policy information is set for a server device of a worker whose worker rank has changed. [Figure 27] FIG. 27 is a diagram showing an example of a change in the operation content of a server device in the configuration information management master table. [Figure 28] FIG. 28 is a diagram showing how new policy information is set for a server device whose work content has changed. [Figure 29] FIG. 29 is a diagram showing a state in which the work content and worker rank of the worker of the newly added server device have been added to the configuration information management master table. [Figure 30] FIG. 30 is a diagram showing how policy information corresponding to worker ranks is set for a newly added server device. DETAILED DESCRIPTION OF THE INVENTION
[0013] A log policy management system according to an embodiment of the present invention will be described in detail below with reference to the accompanying drawings. However, the present invention is not limited to the following embodiment.
[0014] [System Overview] Fig. 1 is a diagram for explaining an overview of a log policy management system according to an embodiment. As shown in Fig. 1, the log policy management system includes a log policy management device 1 that performs centralized management of policy information that controls the acquisition of log information, a setting terminal device 51 that sets policy information in the log policy management device 1, and a log policy target to which the policy information is applied.
[0015] 1 shows an example in which a log policy is applied to a server function 53, which is a virtual server function built in the log policy management device 1. The server function 53 loads file (OS image, disk image) data prepared for each virtual server on a server device of a host OS (Operating System), and provides a predetermined service role to each company programmatically.
[0016] In addition to this virtual server function, the log policy can also be applied to other devices on which policy information can be set, such as physical server devices, client terminal devices, mobile devices, or IoT (Internet of Things) devices.
[0017] The log policy management device 1 is provided with a configuration information management master table 11 (or a configuration information management master table 81, which will be described later). As shown in Fig. 2, this configuration information management master table 11 stores a policy judgment target, an environment unit name, a log setting classification, a policy level, an update flag, and the like. The policy judgment target is an entity that provides a service, and will be described as a "company name" in the first embodiment, and as a "worker" in the second embodiment, which will be described later.
[0018] In the first embodiment, the environment unit name is the "server name" assigned to the server function of each company that sets policy information. In the second embodiment, the environment unit name is the "server name" of the server device operated by the operator.
[0019] The log setting classification indicates the type of log information to be collected for each target to which the log policy is applied. In the first embodiment, this log setting classification indicates the type of log information to be collected based on the role (server role) provided by each server function 53. That is, in the first embodiment, the log setting classifications are set to the roles of "DB: database function," "AP: application server function," "WEB: web server function," "AD (Active Directory (registered trademark)): active directory (registered trademark) server function," and "other (roles)."
[0020] As will be described later with reference to FIG. 8, when the server function 53 is a "DB: database server function," database log information is collected. When the server function 53 is an "AP: application server function," unique log information according to a specific application program is collected. When the server function 53 is a "WEB: web server function," IIS (Internet Information Services) log information is collected. When the server function 53 is an "other (role)" server function, any log information is collected.
[0021] In contrast, in the second embodiment, the log setting classification is set to log information collected in accordance with the work content performed on the server device 63, such as "data correction," "file import," "file export," "system shutdown," and "investigation."
[0022] As will be described later with reference to Figure 22, when the work content performed by the server device 63 is "data correction," database log information is collected. When the work content performed by the server device 63 is "file import" or "file export," file access log information is collected. When the server device 63 is put into "system shutdown," fault monitoring log information is collected. When the work content performed by the server device 63 is "investigation," performance log information is collected.
[0023] The policy level is information that indicates the information processing format of the acquired log information. In the first embodiment, it indicates the information processing format of the log information corresponding to the "operation status" of each server function 53, and in the second embodiment, it indicates the information processing format of the log information corresponding to the "operator rank" of the operator operating each server device 63.
[0024] The "update flag" is information that is set for the server function 53 or server device 63 that sets the policy information, and is erased after the policy information is set. Details will be described later.
[0025] As shown in Fig. 3, the policy master table 12 (and the policy master table 82 described later) has a policy number set for each policy level that indicates the information processing format of the policy information. Specifically, in the case of the first embodiment, policy numbers such as "Policy 01" and "Policy 02" are associated with operation states (policy levels) such as "Before and after operation," "Preparation for operation," or "Failure." In addition, in the case of the second embodiment, policy numbers such as "Policy 01" and "Policy 02" are associated with worker ranks (policy levels) such as "A" and "B."
[0026] As shown in Figure 4, the setting master table 13 (and the setting master table 83 described later) associates and sets the log setting classification, the log information to be acquired, the setting items, and the information processing format of the acquired log information (how the acquired log information is processed = policy information) corresponding to each policy number.
[0027] In the first embodiment, the "log setting classification" is the function (role; DB, AP, etc.) of each server function 53 described above. The "log information" is information indicating the type of log information acquired by the server function 53. The "setting item" indicates the maximum amount of log information to be acquired (maximum log size (MB)). Furthermore, the policy information indicates the information processing mode, such as "overwrite" or "archive (store in memory unit 2)" the log information acquired thereafter when the amount of acquired log information reaches the maximum log size (MB).
[0028] In contrast, in the second embodiment, the "log setting classification" is the work content (data modification, file import, etc.) of each server device 63 described above. The "log information" is information indicating the type of log information acquired by the server device 63. The "setting item" indicates the maximum amount of log information to be acquired (maximum log size (MB)). Furthermore, the policy information indicates the information processing mode, such as "overwriting" or "archiving (storing in the memory unit 2)" the log information acquired thereafter when the amount of acquired log information reaches the maximum log size (MB).
[0029] Such a log policy management system pre-registers the configuration information to which the log policy applies and the management policy for log information in a master group (configuration information management master tables 11, 81 in Figure 2, policy master tables 12, 82 in Figure 3, and setting master tables 13, 83 in Figure 4).
[0030] Next, the server function 53 (or server device 63) reads the master group and applies the policy information to each environment unit. At this time, the log policy is applied to the environment unit whose update flag is "1", and the policy information application process is executed for the environment unit detected using the policy judgment target and environment unit name as keys. In addition, the policy information change process for acquiring log information is also executed for the environment unit whose policy level or log setting classification has been changed or the added environment unit.
[0031] This allows the policy information to be set in accordance with the policy level, such as the operating status or worker rank, to be centrally managed and reflected in each environment unit all at once.
[0032] [First embodiment] A specific embodiment of such a log policy management system will be described below.
[0033] First, the log policy management system described as the first embodiment is an example in which policy information is centrally managed for each company name (each policy judgment target) and each server name (each environment unit).
[0034] (System configuration of the first embodiment) Fig. 5 is a block diagram showing the hardware configuration of the log policy management device 1 provided in the log policy management system of the first embodiment. As shown in Fig. 5, the log policy management device 1 includes a storage unit 2, a control unit 3, a communication interface unit 4, and an input / output interface unit 5. An input device 6 and an output device 7 are connected to the input / output interface unit 5.
[0035] The log policy management device 1 is also provided with a server function 53, which is a virtual server function, and a firewall function .
[0036] The storage unit 2 may be, for example, a storage device such as a read only memory (ROM), a random access memory (RAM), a hard disk drive (HDD), or a solid state drive (SSD).
[0037] A setting terminal device 51 is connected to the communication interface unit 4 via a private network 50 such as a LAN (Local Area Network).
[0038] The output device 7 may be a display unit such as a monitor (including a home television), a printer, or a speaker. The input device 6 may be a keyboard, a mouse, a microphone, or a monitor that functions as a pointing device in cooperation with a mouse.
[0039] The storage unit 2 stores a log policy management program that simplifies and facilitates the acquisition and management of log information for each server function 53. The storage unit 2 also has a configuration information management master table 11, a policy master table 12, and a setting master table 13, each of which is a storage area.
[0040] The server function 53 is a function that operates as a virtual server device based on the host OS and specified application programs stored in the memory unit 2, and loads file data (OS image or disk image, etc.) prepared for each virtual server, and provides programs with specified functions to each company.
[0041] 6, the configuration information management master table 11 provided in the storage unit 2 stores company names, server names, server roles, operating status, update flags, etc. The "company name" is the target of the policy determination described above, and in this example, it is "Company A," "Company B," and "Company C." Furthermore, the server names, which are the above-mentioned environmental unit names, are as follows: the server names for "Company A" are "xxx101" and "xxx102," the server names for "Company B" are "xxx201," "xxx202," and "xxx203," and the server name for "Company C" is "xxx301."
[0042] Furthermore, the server role of the server function 53 of "XXX101" of "Company A" is "DB: database server device," and the server role of the server function 53 of "XXX102" is "AP: application server device."
[0043] Furthermore, the server role of the server function 53 of "XXX201" of "Company B" is "WEB: Web server device." Furthermore, the server roles of the server function 53 of "XXX202" of "Company B" are "DB: Database server device," "AP: Application server device," "Web: Web server device," and "AD (Active Directory (registered trademark)): Active Directory (registered trademark) server device." Furthermore, the server role of the server function 53 of "XXX203" of "Company B" is "Other."
[0044] In addition, the server roles of server function 53 of "XXX301" of "Company C" are "DB: database server device," "WEB: web server device," and "AD (Active Directory (registered trademark)): active directory (registered trademark) server device."
[0045] As for the operational status, which is the policy level mentioned above, "pre-operation" is set for each of the server functions 53, "xxx101" and "xxx102" of "Company A." Also, "operation preparation" is set for each of the server functions 53, "xxx201," "xxx202," and "xxx203" of "Company B." Also, "failure" is set for the server function 53, "xxx301" of "Company C."
[0046] The operating status of each company's server function 53 is set in the log policy management device 1 from the setting terminal device 51. The "operating status," which is a policy level, is a status that indicates the state of the service installation and operation process for each company. This operating status is changed collectively for each "company name" that is the customer to which the system is installed. Furthermore, when it is known in advance that a failure has occurred in a specific server function of a specific company, the "operating status" is updated to the operating status of "failure." Furthermore, when a failure occurs and the server function causing the failure has not been identified, the policy levels of all server functions are changed in order to investigate the failure. This changes the log information to be acquired, making it possible to identify the server function causing the failure.
[0047] The update flag information is information that is attached to the server function 53 that sets the policy information. The example in Fig. 6 is an example in which update flag information of "1" is attached to all the server functions 53 of "Company A" to "Company C" (an example in which all the server functions 53 are set as targets for setting policy information).
[0048] In the policy master table 12, as shown in Fig. 7, a policy number is set for each operation status. The policy number is a number for identifying the policy information to be set in the server function 53. Specifically, the policy number "Policy01" is set for the operation status "operation preparation", and the policy number "Policy02" is set for the operation status "test process". Furthermore, the policy number "Policy03" is set for the operation status "before and after operation", and the policy number "Policy04" is set for the operation status "stable operation". Furthermore, the policy number "Policy05" is set for the operation status "failure".
[0049] As shown in Figure 8, the setting master table 13 stores, for each role of each server function 53, the type of log information to be acquired, the maximum amount of log information to be acquired (maximum log size (MB)), and policy information, which is the information processing format indicated by a policy number to be performed according to each operating status when the acquired log information reaches the maximum log size (MB).
[0050] Specifically, when the operation status is "preparing for operation," the server function 53 of the "DB: database server device" performs information processing to overwrite the database log information acquired up to that point if the acquired database log information exceeds, for example, "100 MB" (information processing mode of Policy 01). Also, when the operation status is "test process," the server function 53 of the "DB: database server device" performs information processing to overwrite the database log information acquired up to that point if the acquired database log information exceeds, for example, "500 MB" (information processing mode of Policy 02).
[0051] Furthermore, when the operating status is "before and after operation", if the acquired database log information exceeds, for example, "1,000 MB", the server function 53 of the "DB: database server device" performs information processing (archiving) to store the database log information acquired up to that point in the storage unit 2 (information processing mode of Policy 03). Furthermore, when the operating status is "stable operation", if the acquired database log information exceeds, for example, "500 MB", the server function 53 of the "DB: database server device" performs information processing (archiving) to store the database log information acquired up to that point in the storage unit 2 (information processing mode of Policy 04).
[0052] Furthermore, when the operating status is "failed," if the acquired database log information exceeds, for example, "2,000 MB," the server function 53 of the "DB: database server device" performs information processing (archiving) to store the database log information acquired up to that point in the memory unit 2 (information processing form of Policy 05).
[0053] Similarly, the server function 53 of the "WEB: web server device" acquires "IIS log information (IIS: Internet Information Services)." Then, when the operation status is "preparation for operation," if the acquired IIS log information exceeds, for example, "100 MB," it performs information processing to overwrite the IIS log information acquired up to that point (information processing mode of Policy01). Also, when the operation status is "testing process," if the acquired IIS log information exceeds, for example, "500 MB," it performs information processing to overwrite the IIS log information acquired up to that point (information processing mode of Policy02).
[0054] Furthermore, when the operation status is "before and after operation", if the acquired IIS log information exceeds, for example, "1,000 MB", the server function 53 of "WEB: web server device" performs information processing (archiving) to store the IIS log information acquired up to that point in the storage unit 2 (information processing mode of Policy 03). Furthermore, when the operation status is "stable operation", if the acquired IIS log information exceeds, for example, "500 MB", the server function 53 of "WEB: web server device" performs information processing (archiving) to store the IIS log information acquired up to that point in the storage unit 2 (information processing mode of Policy 04).
[0055] Furthermore, when the operating status of the "WEB: web server device" is "failed," if the acquired IIS log information exceeds, for example, "2,000 MB," the server function 53 of the "WEB: web server device" performs information processing (archiving) to store the IIS log information acquired up to that point in the memory unit 2 (information processing form of Policy 05).
[0056] Such information processing (policy) of log information is set based on the importance of the log information, which changes depending on the operating status. For example, log information generated during the preparation period for the operation of the server function 53 is of low importance and is therefore managed by overwriting, but after the operation of the server function 53, log information becomes necessary for verifying any failures that have occurred and therefore becomes more important, so log information generated in the past is saved by archiving.
[0057] In addition, a particularly large amount of log information is required for analysis before and after operation and when a failure occurs. For this reason, a large maximum log size is set, and after stable operation, a smaller maximum log size is set. Note that the relationship between the server role or type of log information of server function 53 and the setting items is an example, and can be set arbitrarily depending on the configuration.
[0058] (Functional configuration of the log policy management device) Next, the control unit 3 executes the log policy management program stored in the memory unit 2, and thereby functions as a policy detection unit 22, a policy setting unit 23, an update flag control unit 24, and a change history storage control unit 25, as shown in FIG. 5.
[0059] In the following description, the policy detection unit 22 to the change history storage control unit 25 are assumed to be realized by a software program based on a log policy management program. However, all or part of the policy detection unit 22 to the change history storage control unit 25 may be realized by hardware. In either case, the same effects as those described below can be obtained.
[0060] The policy detection unit 22 refers to the storage units (configuration information management master table 11 to setting master table 13) in which the determination target (policy determination target such as company name or worker) that is the entity providing the service, the log policy application target (server name) to which policy information that controls the acquisition of log information is applied, the log setting classification (server role or work content) that indicates the type of log information collected for each log policy application target, the policy level (operation status or worker rank) that indicates the information processing form of the acquired log information, and the policy information to be set are respectively associated, based on the determination target, log policy application target, log setting classification, and policy level.The policy detection unit 22 then detects policy information corresponding to the determination target, log policy application target, log setting classification, and policy level.
[0061] The policy setting unit 23 sets the detected policy information as the corresponding all log policy application target.
[0062] The update flag control unit 24 stores update flag information indicating a change in log setting classification (server role or work content), a change in policy level, or the addition of a new log policy application target (server function 53 or server device 63) in the memory unit (configuration information management master table 11) in association with the log policy application target whose log setting classification or policy level has been changed, or the added log policy application target.
[0063] In this case, the policy detection unit 22 detects policy information for the log policy application target for which update flag information is set from the storage unit (configuration information management master table 11). Also, the policy setting unit 23 sets the policy information detected from the storage unit (configuration information management master table 11 to setting master table 13) for the log policy application target for which update flag information is set.
[0064] In the first embodiment, the log setting classification is the role (server role) of the target to which the log policy is applied, and the policy level is the operating status of the target to which the log policy is applied (see FIG. 6). In this case, the policy detection unit 22 detects policy information corresponding to the role and operating status of the target to which the log policy is applied from the storage unit (configuration information management master table 11 to setting master table 13).
[0065] In addition, when the role of any of the log policy application targets is changed, or when the operating status of any of the log policy application targets is changed to another operating status, the update flag control unit 24 sets update flag information for the corresponding log policy application target and stores it in the memory unit (configuration information management master table 11).
[0066] After the policy information is set, the update flag control unit 24 erases the update flag information of the log policy application target from the storage unit (configuration information management master table 11).
[0067] The change history storage control unit 25 increments the master change history indicating that the policy information in the storage unit (configuration information management master table 11) has been changed every time the policy information is changed.
[0068] Furthermore, policy information is set in the storage unit (configuration information management master table 11 to setting master table 13) via a setting terminal device 51.
[0069] The policy setting unit 23 communicates with each log policy application target via a firewall (firewall function 54) that allows only one-way communication from the policy setting unit 23 to each log policy application target.
[0070] (Policy information setting operation) Next, the operation of setting policy information for each server function 53 in the log policy management device 1 according to the first embodiment will be described.
[0071] First, for the server functions 53 that set policy information as described above, update flag information of "1" is added by the update flag control unit 24 on the configuration information management master table 11 shown in Fig. 9. The example in Fig. 9 is an example in which update flag information of "1" is added to all server functions 53 of companies A to C.
[0072] Based on the operation status of each server function 53, the policy detection unit 22 refers to the policy master table 12 shown in FIG. 7 and detects the policy number (Policy01 to Policy05) for each server function 53 for which update flag information is set.
[0073] 8 based on the server role and policy number of the server function 53 for which the update flag information is set. Then, the policy detection unit 22 detects policy information indicating the information processing mode of the acquired log information that corresponds to the server role and policy number of the server function 53 for which the update flag information is set.
[0074] 10, the policy setting unit 23 sets the policy information detected by the policy detection unit 22 for the server functions 53 for which update flag information has been set. In this example, as described above, update flag information of "1" has been added to all server functions 53. Therefore, the policy setting unit 23 sets policy information indicating the information processing mode of log information according to the operating status and server role of each server function 53 for all server functions 53, as shown in FIG.
[0075] When the policy information is set in this manner, the update flag control unit 24 deletes the update flag information of the server function 53 for which the policy information has been set from the configuration information management master table 11, as shown in Fig. 11. The example in Fig. 11 is an example in which the setting of policy information for all server functions 53 of companies A to C has been completed, and therefore the update flag information attached to each of the server functions 53 of companies A to C has been deleted.
[0076] The update flag control unit 24 re-adds update flag information to the server function 53 for which policy information is to be changed. Then, the policy setting unit 23 sets policy information corresponding to the operating status and role at that time for the server function 53 to which the update flag information has been added.
[0077] 11, the change history storage control unit 25 increments the master change history in the configuration information management master table 11, which indicates that the policy information has been changed, every time the policy information is changed. In this example, since this is the first time that policy information is set for each server function 53, a master change history of "1 (time)" is set for each server function 53. When the policy information is changed, the master change history of that server function 53 is incremented by one by the change history storage control unit 25 to "2 (times)."
[0078] (When the operating status changes to another operating status) Next, as shown in Figure 12(a), the initial operation status of server function 53 of "XXX101" of Company A was "before and after operation", but this operation status is changed to the operation status of "failure" as shown in Figure 12(b) via the setting terminal device 51. Also, as shown in Figure 12(a), the initial operation status of server function 53 of "XXX301" of Company C was "failure", but this operation status is changed to the operation status of "stable operation" as shown in Figure 12(b) via the setting terminal device 51.
[0079] As shown in Figure 12(b), the update flag control unit 24 adds an update flag of "1" to the server function 53 of Company A's "XXX101" and the server function 53 of Company C's "XXX301" whose operating status has changed.
[0080] The server role of the server function 53 of "XXX101" of Company A is "DB" and the operating status has changed to "failure," so under this condition, the policy detection unit 22 refers to the policy master table 12 shown in Fig. 7 and the setting master table 13 shown in Fig. 8. In this case, the policy detection unit 22 detects "Policy05," which is the policy number for "failure," from the policy master table 12.
[0081] 8, the policy detection unit 22 detects policy information that "the maximum log size of the database log is set to 2000 MB, and when the amount of acquired database log (log size) reaches this maximum log size of 2000 MB, the database log of 2000 MB is stored (archived) in the storage unit 2" as policy information for "Policy05" in the role of "DB".Then, the policy setting unit 23 sets the detected policy information in the server function 53 of "XXX101" of Company A as shown in FIG.
[0082] As a result, in the server function 53 of "xxx101" of Company A, information processing of the database log information is performed in the information processing format of the set policy information "Policy05".
[0083] In this way, when the previous policy information is changed to other policy information and set, the change history storage control unit 25 increments the master change history shown in Fig. 11 for the server function 53 of "xxx101" of Company A by one. In this case, the master change history of the server function 53 of "xxx101" of Company A is incremented from "1 (time)" to "2 (times)".
[0084] Similarly, as shown in Figure 12(b), the server roles of server function 53 of "XXX301" of Company C are "DB," "WEB," and "AD," and the operation status has changed to "stable operation." Therefore, under this condition, policy detection unit 22 refers to policy master table 12 shown in Figure 7 and setting master table 13 shown in Figure 8. In this case, policy detection unit 22 detects "Policy04," which is the policy number for "stable operation," from policy master table 12.
[0085] Furthermore, the policy detection unit 22 detects the policy information of "Policy04" for the roles of "DB," "WEB," and "AD" from the setting master table 13 shown in Fig. 8. In this example, the log information corresponding to the roles of "DB," "WEB," and "AP" is database log information, IIS log information, and product A's own log information.
[0086] Furthermore, regardless of the role, the policy information of "Policy04" is policy information that "the maximum log size of log information is 500 MB, and when the amount of acquired log information (log size) reaches this maximum log size of 500 MB, this 500 MB of log information is stored (archived) in the storage unit 2." The policy setting unit 23 sets this policy information in the server function 53 of "XXX301" of Company C, as shown in Fig. 13.
[0087] As a result, in the server function 53 of "xxx301" of Company C, the database log information, IIS log information, and product A's own log information are processed in the information processing format of the set policy information of "Policy04."
[0088] In this way, when the previous policy information is changed to other policy information and set, the change history storage control unit 25 increments the master change history shown in Fig. 11 for the server function 53 of "xxx301" of company C by one. In this case, the master change history of the server function 53 of "xxx301" of company C is incremented from "1 (time)" to "2 (times)".
[0089] (When a server role is added to a server device) Next, as shown in Figure 14(a), "AP" has been set as the server role of server function 53 of "xxx102" of Company A, but in addition to this "AP" role, suppose that a "WEB" server role has been set as shown in Figure 14(b). This setting is performed by an administrator or the like via setting terminal device 51 shown in Figure 1.
[0090] As shown in FIG. 14(b), the update flag control unit 24 adds an update flag of "1" to the server function 53 of "xxx102" of company A to which the server role of "WEB" has been newly added.
[0091] If the server roles of the server function 53 of "xxx102" of Company A are "AP" and "WEB" and the operation status is "before and after operation," the policy detection unit 22 references the policy master table 12 shown in FIG. 7 and the setting master table 13 shown in FIG. 8 under this condition. In this case, the policy detection unit 22 detects "Policy03," which is the policy number for "before and after operation," from the policy master table 12. The policy detection unit 22 also detects the policy information for "Policy03" in the roles of "AP" and "WEB." In this example, the log information corresponding to the roles of "AP" and "WEB" is product A's own log information and IIS log information.
[0092] Furthermore, regardless of the role, the policy information of "Policy03" is policy information that "the maximum log size of log information is 1000 MB, and when the amount of acquired log information (log size) reaches this maximum log size of 1000 MB, this 1000 MB of log information is stored (archived) in the storage unit 2." The policy setting unit 23 sets this policy information in the server function 53 of "xxx102" of Company A, as shown in Fig. 15.
[0093] As a result, in the server function 53 of "xxx102" of Company A, the product A's own log information and IIS log information are processed in the information processing format of the set policy information of "Policy03".
[0094] In this way, when the previous policy information is changed to other policy information and set, the change history storage control unit 25 increments the master change history shown in Fig. 11 for the server function 53 of "xxx102" of Company A by one. In this case, the master change history of the server function 53 of "xxx102" of Company A is incremented from "1 (time)" to "2 (times)".
[0095] (When the number of managed server devices is increased) Next, as shown in FIG. 16(a), the number of server functions 53 managed by the log policy management device 1 in the first embodiment was "6 units", but as shown in FIG. 16(b), one server function 53, "XXX401" of Company D, is added.
[0096] When a server function 53 is added, the administrator registers (stores) the company name (Company D), server name (XXX401), server role (DB and AP), and operation status (preparation for operation) of the added server function 53 in the configuration information management master table 11, as shown in FIG. 16(b), via the setting terminal device 51 shown in FIG. 1.
[0097] 16(b), the update flag control unit 24 adds an update flag of "1" to the added server function 53 of "XXX401" of Company D. This update flag may be set by the administrator via the setting terminal device 51.
[0098] Next, the server roles of the added server function 53 of "XXX401" of Company D are "DB" and "AP", and the operation status is "preparation for operation". Therefore, under this condition, the policy detection unit 22 refers to the policy master table 12 shown in FIG. 7 and the setting master table 13 shown in FIG. 8. In this case, the policy detection unit 22 detects "Policy01", which is the policy number for "preparation for operation", from the policy master table 12. The policy detection unit 22 also detects the policy information for "Policy01" in the roles of "DB" and "AP".
[0099] In this example, the log information corresponding to the roles of "DB" and "AP" is database log information and product A's own log information. Furthermore, the policy information of "Policy01" is policy information that, regardless of the role, "the maximum log size of each piece of log information is 100 MB, and each time the amount of acquired log information (log size) reaches the maximum log size of 100 MB, new 100 MB of log information is overwritten over the acquired log information." The policy setting unit 23 sets this policy information in the server function 53 of "xxx401" of Company D, which has been added as shown in FIG. 17.
[0100] As a result, in the added server function 53 of "xxx401" of Company D, the database log information and product A's unique log information are processed in the information processing format of the set policy information of "Policy01."
[0101] In this example, the policy information is set to the initial setting, so the change history storage control unit 25 sets the master change history shown in Figure 11 for the added server function 53 of Company D's "XXX401" to "1 (time)" (does not increment).
[0102] (Effects of the first embodiment) In a cloud system or data center or the like that has multiple terminal devices, the type of log information acquired by each server function 53 and the information processing format differ depending on the system control level desired by the client who operates the system or the client's system implementation process, etc. This has led to a problem that acquiring and managing the log information of each server function 53 becomes complicated and tedious. This problem becomes more pronounced as the number of server functions 53 to be managed increases.
[0103] For this reason, the log policy management device 1 of the first embodiment centrally manages policy information indicating the information processing mode of log information that is set for each server function 53 according to the server role provided by the server function 53 and the operating status of the server function 53. Then, this policy information is collectively reflected in each corresponding server function 53 according to changes in the operating status, etc.
[0104] This allows the management of the information processing form of the log information in each server function 53 to be simple and easy to manage centrally.
[0105] [Second embodiment] Next, a log policy management system according to a second embodiment of the present invention will be described. The above-described first embodiment is an example in which a virtual server function 53 for each policy judgment target (each company) is constructed within the log policy management device 1, and policy information is set for this server function 53. In contrast, the log policy management system according to the second embodiment is an example in which the system is configured by connecting the log policy management device to a setting terminal device and a server device that serves as an environmental unit for each policy judgment target via the same or multiple different networks, such as the Internet or a LAN (Local Area Network).
[0106] The configuration of the log policy management device of the log policy management system of the second embodiment may be configured to have a virtual server function as in the first embodiment described above. Even in this case, the same effects as those described below can be obtained.
[0107] In addition, in the description of this second embodiment, the same reference numerals as in the first embodiment are used for parts showing the same operations as in the first embodiment, thereby avoiding redundant explanations.
[0108] 18 and 19, the log policy management system according to the second embodiment is configured by interconnecting a setting terminal device 61, each server device 63, and a log policy management device 70 via the same network 60 such as a LAN. Note that a router device 64 that functions as a firewall as described above is provided between each server device 63 and the log policy management device 70.
[0109] In the configuration information management master table 81, as shown in Fig. 20, the work content and worker rank are set for each server device 63 of employees A to E. Specifically, the work content "data correction" is set for employee A's server device 63 with the server name "xxx101". Employee A's worker rank is set to "A". Employee B's server device 63 with the server name "xxx102" is set to "file import". Employee B's worker rank is set to "B".
[0110] Furthermore, for employee C's server device 63 with the server name "xxx201", the work content "file take-out" is set. Employee C's worker rank is set to rank "C". For employee D's server device 63 with the server name "xxx202", the work content is "system shutdown". Employee D's worker rank is set to rank "A". For employee E's server device 63 with the server name "xxx203", the work contents "file take-in", "file take-out", and "investigation" are set. Employee E's worker rank is set to rank "C".
[0111] In the policy master table 82, a policy number of policy information is set for each worker rank, as shown in Fig. 21. Specifically, the policy number "Policy01" is set for worker rank "A." Furthermore, the policy number "Policy02" is set for worker rank "B." Furthermore, the policy number "Policy03" is set for worker rank "C."
[0112] As shown in Figure 22, the setting master table 83 stores the type of log information acquired corresponding to each work content, the upper limit of the amount of log information acquired (maximum log size (MB)), and the information processing format (policy information) indicated by the policy number to be performed according to each worker rank when the amount of log information acquired reaches the maximum log size (MB).
[0113] Specifically, when the work rank of the worker is "A," the server device 63 whose work content is "data correction" performs information processing to overwrite the database log information acquired up to that point when the acquired database log information exceeds, for example, "100 MB" (Policy 01). Also, when the work rank of the worker is "B," the server device 63 whose work content is "data correction" performs information processing to overwrite the database log information acquired up to that point when the acquired database log information exceeds, for example, "500 MB" (Policy 02).
[0114] In addition, when the server device 63 whose work content is "data correction" has a worker's work rank of "C," if the acquired database log information exceeds, for example, "1,000 MB," it performs information processing (archive) to store the database log information acquired up to that point in the memory unit 2 (Policy03).
[0115] Similarly, the server device 63 whose work content is "file import" acquires "file access log information." If the worker's work rank is "A," and the acquired file access log information exceeds, for example, "100 MB," the server device 63 performs information processing to overwrite the file access log information acquired up to that point (Policy 01). Also, if the worker's work rank is "B," and the acquired file access log information exceeds, for example, "500 MB," the server device 63 whose work content is "file import" performs information processing to overwrite the file access log information acquired up to that point (Policy 02).
[0116] Furthermore, when the worker's work rank is "C," the "file import" server device 63 performs information processing (archive) to store the file access log information acquired up to that point in the memory unit 2 when the acquired file access log information exceeds, for example, 1,000 MB (Policy 03).
[0117] (Functional configuration of the log policy management device) Next, the control unit 3 executes the log policy management program stored in the memory unit 2, thereby functioning as a policy detection unit 42, a policy setting unit 43, an update flag control unit 44, and a change history storage control unit 45, as shown in Figure 19.
[0118] The following description will be given assuming that the policy detection unit 42 to the change history storage control unit 45 are implemented as software programs based on a log policy management program. However, all or part of the policy detection unit 42 to the change history storage control unit 45 may be implemented as hardware. In either case, the same effects as those described below can be obtained.
[0119] In the second embodiment, the log setting classification is the work content of the log policy application target (server device 63), and the policy level is the worker rank of the worker performing the work on the log policy application target (see FIG. 20).
[0120] The policy detection unit 42 detects policy information corresponding to the work content and worker rank of the log policy application target (server device 63) from the memory unit (configuration information management master table 81 in Figure 20, policy master table 82 in Figure 21, and setting master table 83 in Figure 22).
[0121] When the work content is changed in any of the log policy application targets (server device 63), or when the worker rank of a worker in any of the log policy application targets is changed, the update flag control unit 44 sets update flag information for the corresponding log policy application target and stores it in the memory unit (configuration information management master table 81 in Figure 20).
[0122] After the policy information is set, the update flag control unit 44 erases the update flag information of the log policy application target from the storage unit (the configuration information management master table 81 in FIG. 20).
[0123] The change history storage control unit 45 increments the master change history indicating that the policy information in the storage unit (the configuration information management master table 81 in FIG. 20) has been changed every time the policy information is changed.
[0124] Furthermore, policy information is set in the storage unit (configuration information management master table 81 to setting master table 83) via the setting terminal device 61 (see FIG. 19).
[0125] In addition, when a log policy application target (server device 63) is added, the policy setting unit 43 sets policy information corresponding to the work content and worker rank of the added log policy application target, which is detected by the policy detection unit 42, to the added log policy application target.
[0126] In addition, the policy setting unit 43 communicates with each log policy target via a firewall (router device 64) that is provided between each log policy target and the log policy management device 70 and that allows only one-way communication from the log policy management device 70 to each log policy target (server device 63).
[0127] (Policy information setting operation) Next, the operation of setting policy information for each server device 63 in the log policy management device 70 of the second embodiment will be described.
[0128] First, for the server device 63 that sets policy information as described above, update flag information of "1" is added by the update flag control unit 44 on the configuration information management master table 81 shown in Fig. 20. The example in Fig. 20 is an example in which update flag information of "1" is added to all server devices 63 of employees A to E.
[0129] The policy detection unit 42 references the configuration information management master table 81 shown in FIG. 20 based on the work content of the server device 63 for which update flag information is set, and detects the worker rank of each employee of each server device 63.
[0130] Based on the detected worker rank, the policy detection unit 42 also detects the policy number corresponding to each task rank by referring to the policy master table 82. The policy detection unit 22 then detects the task content of the server device 63 for which update flag information is set and the policy information corresponding to the detected policy number from the setting master table 83 shown in FIG.
[0131] 23, the policy setting unit 43 sets the policy information detected by the policy detection unit 42 for the server devices 63 for which update flag information has been set. In the above example, update flag information of "1" has been added to all server devices 63. Therefore, the policy setting unit 43 sets, for all server devices 63, policy information indicating the information processing mode of log information according to the work content and worker rank of each server device 63, as shown in FIG.
[0132] When the policy information is set in this manner, the update flag control unit 44 deletes the update flag information of the server device 63 for which the policy information has been set from the configuration information management master table 81, as shown in Fig. 24. The example in Fig. 24 is an example in which the setting of policy information for all server devices 63 for employees A to E has been completed, and therefore the update flag information added to each of the server devices 63 for employees A to E has been deleted.
[0133] When it becomes necessary to change the policy information, the update flag information is added again by the update flag control unit 44. Then, the policy setting unit 43 sets policy information corresponding to the work content of the server device 63 and the worker rank of the worker for the server device 63 to which the update flag information has been added.
[0134] 24, the change history storage control unit 45 increments the master change history in the configuration information management master table 81, which indicates that the policy information has been changed, every time the policy information is changed. In this example, since this is the first time that policy information is set for each server device 63, "1 (time)" is set as the master change history for each server device 63. The next time, the change history storage control unit 45 increments the master change history for the server device 63 whose policy information has been changed by one to "2 (times)."
[0135] (When the worker rank is changed) Next, as shown in Figure 25(a), it is assumed that the worker rank of employee A on the server device 63 of "XXX101" was "A," but this worker rank was changed to "B" as shown in Figure 25(b) by an administrator or the like via the setting terminal device 61. Also, as shown in Figure 25(a), it is assumed that the worker rank of employee C on the server device 63 of "XXX201" was "C," but this worker rank was changed to "B" as shown in Figure 25(b) by an administrator or the like via the setting terminal device 61.
[0136] As shown in Figure 25(b), the update flag control unit 24 adds an update flag of "1" to the server device 63 for employee A's "XXX101" and the server device 63 for employee C's "XXX201", whose worker rank has been changed.
[0137] As shown in Fig. 25(b), the worker rank of employee A of server device 63 of "XXX101" has changed from "A" to "B," so under this condition, the policy detection unit 42 refers to the policy master table 82 shown in Fig. 21 and the setting master table 83 shown in Fig. 22. In this case, the policy detection unit 42 detects "Policy02," which is the policy number for worker rank "B," from the policy master table 82.
[0138] Furthermore, the policy detection unit 42 detects, from the setting master table 83 shown in Fig. 22, policy information for "Policy02" in the work content of "data correction," which states that "the maximum log size of the database log is 500 MB, and when the amount of acquired database log information (log size) reaches the maximum log size of 500 MB, this 500 MB of database log information is overwritten over previous database log information." The policy setting unit 23 then sets the detected policy information in the server device 63 of "XXX101" of employee A, as shown in Fig. 26.
[0139] As a result, in the server device 63 of employee A's "XXX101," the database log information is processed in the information processing format of the set policy information "Policy02."
[0140] In this way, when the previous policy information is changed to other policy information, the change history storage control unit 25 increments the master change history shown in Fig. 24 for the server device 63 of "XXX101" of employee A by one. In this case, the master change history of the server device 63 of "XXX101" of employee A is incremented from "1 (time)" to "2 (times)".
[0141] Similarly, as shown in Figure 25(b), the worker rank of employee C has changed from "C" to "B." Therefore, the policy detection unit 42 refers to the policy master table 82 shown in Figure 21 and detects the policy number of "Policy02" that corresponds to the worker rank "B."
[0142] Furthermore, the policy detection unit 42 detects the policy information "Policy02" for the task content "file take-out" from the setting master table 83 shown in Fig. 22. In this example, the policy information "Policy02" is policy information that "the maximum log size of file access log information is 500 MB, and when the amount of acquired file access log information (log size) reaches this maximum log size of 500 MB, the file access log information of this 500 MB is overwritten over the previous file access log information." The policy setting unit 23 sets this policy information in the server device 63 of "XXX201" of employee C, as shown in Fig. 26.
[0143] As a result, in the server device 63 of employee C's "XXX201", the file access log information is processed in the information processing format of the policy information "Policy02".
[0144] In this way, when the previous policy information is changed to other policy information and set, the change history storage control unit 25 increments the master change history shown in Fig. 24 for the server device 63 of "XXX201" of employee C by one. In this case, the master change history of the server device 63 of "XXX201" of employee C is incremented from "1 (time)" to "2 (times)".
[0145] (If additional work is required for the server equipment) Next, as shown in Fig. 27(a), "file import" was set as the work content for employee B's server device 63 at "xxx102," but as shown in Fig. 27(b), the work content of "system shutdown" is additionally set. This setting is made by an administrator or the like via the setting terminal device 61 shown in Fig. 18.
[0146] As shown in FIG. 27(b), the update flag control unit 24 adds an update flag of "1" to the server device 63 of "XXX102" of employee B to which the work content "system shutdown" has been added.
[0147] The policy detection unit 42 references the policy master table 82 shown in FIG. 21 and the setting master table 83 shown in FIG. 22 under the conditions that the work contents of the server device 63 for employee B's "XXX102" are "file import" and "system shutdown" and the worker rank is "B." In this case, the policy detection unit 42 detects "Policy02," which is the policy number for worker rank B, from the policy master table 82. Furthermore, by referencing the setting master table 83, the policy detection unit 42 detects the policy information of "Policy02" corresponding to the work contents of "file import" and "system shutdown."
[0148] Regardless of whether the work content is "file import" or "system shutdown," the policy information of "Policy02" is policy information that "the maximum log size of log information is 500 MB, and when the amount of acquired log information (log size) reaches this maximum log size of 500 MB, the log information of this 500 MB will be overwritten over the previous log information." The policy setting unit 23 sets this policy information in the server device 63 of employee B's "XXX102," as shown in FIG. 28.
[0149] As a result, in the server device 63 of employee B's "XXX102", the file access log information and the fault monitoring log information are processed in the information processing format of the policy information of "Policy02".
[0150] In this way, when the previous policy information is changed to other policy information, the change history storage control unit 25 increments the master change history shown in Fig. 24 for the server device 63 of "XXX102" of employee B by one. In this case, the master change history of the server device 63 of "XXX102" of employee B is incremented from "1 (time)" to "2 (times)".
[0151] (When the number of managed server devices is increased) Next, suppose that the number of server devices 63 managed by the log policy management device 1 of the embodiment was "five" as shown in FIG. 29(a), but one server device 63 for employee F's "XXX301" is added as shown in FIG. 29(b).
[0152] When a server device 63 is added, the administrator registers (stores) the operator (employee F), server name (XXX301), work content (data modification), and operator rank (A) of the added server device 63 in the configuration information management master table 81 via the setting terminal device 61 shown in FIG. 18, as shown in FIG. 29(b).
[0153] 29(b), the update flag control unit 24 adds an update flag of "1" to the server device 63 of "XXX301" of the added employee F. This update flag may be set by the administrator via the setting terminal device 61.
[0154] Next, the work content of the server device 63 for the added employee "XXX301" of Company F is "data modification," and the worker rank is "A." Therefore, based on the worker rank of "A," the policy detection unit 42 references the policy master table 82 shown in FIG. 21 and detects the policy number of "Policy01." Furthermore, based on the work content of "data modification" and the policy number of "Policy01," the policy detection unit 42 references the setting master table 83 shown in FIG. 22 and detects policy information that states, "The maximum log size of each piece of database log information is 100 MB, and each time the amount of acquired database log information (log size) reaches the maximum log size of 100 MB, new 100 MB of database log information is overwritten over the acquired database log information." The policy setting unit 23 sets this policy information in the server device 63 for "XXX301" of employee F, as shown in FIG. 30.
[0155] As a result, in the server device 63 of "XXX301" of the added employee F, the database log information is processed in the information processing format of the set policy information "Policy01".
[0156] In this example, the policy information is set to the initial setting, so the change history storage control unit 25 sets the master change history shown in Figure 24 for the server device 63 of the added employee F's "XXX301" to "1 (time)" (not incremented).
[0157] (Effects of the second embodiment) As is clear from the above explanation, the log policy management system of the second embodiment centrally manages, in the log policy management device 70, policy information for setting the information processing mode of log information according to the worker rank, etc., of the worker who operates each server device 63. Then, this policy information is collectively reflected in the server devices 63 whose worker rank, etc. has changed.
[0158] This allows the management of the information processing form of the log information of each server device 63 to be simple and easy to manage in a unified manner.
[0159] [Contribution to the United Nations-led Sustainable Development Goals (SDGs)] This invention can contribute to improving business efficiency and promoting appropriate management decisions by companies, thereby contributing to the achievement of goals "8" and "9" of the SDGs.
[0160] Furthermore, this invention can contribute to reducing waste and promoting paperless and electronic systems, thereby contributing to the achievement of SDGs goals 12, 13, and 15.
[0161] Furthermore, the present invention can contribute to strengthening control and governance, thereby contributing to the achievement of Goal 16 of the SDGs.
[0162] [Other embodiments] The present invention can be implemented in various different forms other than the above-described embodiments within the scope of the technical concept described in the claims.
[0163] For example, among the processes described in the embodiments, all or part of the processes described as being performed automatically may be performed manually, or all or part of the processes described as being performed manually may be performed automatically using a known method or the like.
[0164] Furthermore, the processing procedures, control procedures, specific names, registered data for each process, information including parameters such as search conditions, screen examples, and database configurations shown in the specification or drawings may be changed as desired unless otherwise specified.
[0165] Furthermore, with regard to the log policy management device 1, 70, etc., the components shown in the drawings are conceptual functional elements and do not necessarily have to have the physical configurations shown in the drawings. For example, all or any part of the processing functions provided in the log policy management device 1, 70, particularly the processing functions performed by the control unit 3, may be realized by a program interpreted and executed by the control unit 3 (CPU: Central Processing Unit), or may be realized by hardware using wired logic.
[0166] The program is recorded on a non-transitory computer-readable recording medium containing programmed instructions for causing the log policy management device 1, 70, etc. to execute the processes described in the embodiments, and is mechanically read by the log policy management device 1, 70 as needed. That is, a storage unit 2 such as a ROM or HDD stores a computer program for working with an OS (Operating System) to give instructions to a control unit 3 (CPU) and perform various processes. This computer program is loaded into RAM, expanded, and executed appropriately by the control unit 3.
[0167] In addition, the log policy management program of this log policy management device 1, 70 may be stored in another server device connected to the log policy management device 1, 70 via any network, and all or part of it may be downloaded and executed as needed.
[0168] Furthermore, the log policy management program for executing the processes described in the embodiments may be stored in a non-transitory computer-readable recording medium, or may be configured as a program product.
[0169] Here, the "recording medium" can be any "portable physical medium" such as a memory card, a USB (Universal Serial Bus) memory, an SD (Secure Digital) card, a flexible disk, a magneto-optical disk, a ROM, an EPROM (Erasable Programmable Read Only Memory), an EEPROM (registered trademark) (Electrically Erasable and Programmable Read Only Memory), a CD-ROM (Compact Disk Read Only Memory), an MO (Magneto-Optical Disk), a DVD (Digital Versatile Disk), and a Blu-ray (registered trademark) Disc.
[0170] Furthermore, a "program" is a data processing method written in any language or description method, regardless of the format, such as source code or binary code.
[0171] It should be noted that a "program" is not necessarily limited to a single structure, but includes a structure that is distributed as multiple modules or libraries, and a structure that achieves its function by working together with other programs, such as an OS.
[0172] Furthermore, the specific configuration for reading the recording medium in the log policy management device 1, 70 of the embodiment, the reading procedure, and the installation procedure after reading can be realized using well-known configurations or procedures.
[0173] The memory unit 2 is a storage means such as a memory device such as RAM or ROM, a fixed disk device such as a hard disk, a flexible disk, or an optical disk, and stores various programs, tables, databases, web page files, etc. used for various processes or providing websites.
[0174] The log policy management devices 1 and 70 may be configured as information processing devices such as known personal computers or workstations, or may be configured as information processing devices connected to any peripheral devices. The information processing devices may also be implemented with software (including programs or data) that realizes the processes described in the embodiments.
[0175] Furthermore, the specific forms of distribution and integration of the devices are not limited to those shown in the drawings, and all or part of them can be functionally or physically distributed or integrated in any unit depending on various additions or functional loads. In other words, the above-mentioned embodiments can be selectively implemented by combining them in any way. [Industrial Applicability]
[0176] The present invention is suitable for application to industries that manage many terminal devices, such as cloud service businesses and in-house systems of companies. [Explanation of symbols]
[0177] 1. Log policy management device 2 Storage section 3. Control Unit 4. Communication interface section 5 Input / output interface section 6 Input Devices 7 Output Devices 11 Configuration information management master table 12 Policy Master Table 13 Configuration Master Table 22 Policy Detector 23 Policy Setting Section 24 Update flag control section 25 Change history storage control unit 42 Policy Detector 43 Policy Setting Section 44 Update flag control section 45 Change history storage control unit 50 Network (LAN) 51 Setting terminal device 53 Virtual Server Function 54 Firewall function 60 Network (LAN) 61 Setting terminal device 63 Server equipment 64 Router device 70 Log Policy Management Device 81 Configuration Information Management Master Table 82 Policy Master Table 83 Setting Master Table
Claims
1. a policy detection unit that references a storage unit in which a determination target that is a service provider, a log policy target to which policy information that controls the acquisition of log information is applied, a log setting classification that indicates the type of log information to be collected for each of the log policy target, a policy level that indicates the information processing mode of the acquired log information, and policy information to be set are associated, based on the determination target, the log policy target, the log setting classification, and the policy level, and detects the policy information corresponding to the determination target, the log policy target, the log setting classification, and the policy level; a policy setting unit that sets the detected policy information as a target for applying the corresponding log policy; A log policy management device having:
2. an update flag control unit that stores update flag information indicating a change in the log setting classification, a change in the policy level, or an addition of a new log policy application target in the storage unit in association with the log policy application target whose log setting classification or policy level has been changed or the added log policy application target, the policy detection unit detects, from the storage unit, the policy information for the log policy application target for which the update flag information is set, the policy setting unit sets the policy information detected from the storage unit to the log policy application target for which the update flag information is set; 2. The log policy management device according to claim 1, wherein:
3. The log setting classification is a role to which the log policy is applied; the policy level is an operating status of an object to which the log policy is applied, the policy detection unit detects, from the storage unit, the policy information corresponding to the role and the operating status of the target to which the log policy is applied; 3. The log policy management device according to claim 2, wherein:
4. when the role of any of the log policy target objects is changed, or when the operating status of any of the log policy target objects is changed to another operating status, the update flag control unit sets the update flag information for the corresponding log policy target object and stores the update flag information in the storage unit; 4. The log policy management device according to claim 3, wherein:
5. the update flag control unit erases the update flag information to which the log policy is applied from the storage unit after the policy information is set; 5. The log policy management device according to claim 4, wherein:
6. a change history storage control unit that increments a master change history indicating that the policy information in the storage unit has been changed each time the policy information is changed; 6. The log policy management device according to claim 5,
7. the policy information is set in the storage unit via a setting terminal device; 7. The log policy management device according to claim 6, wherein:
8. the policy setting unit communicates with each of the log policy application targets via a firewall that allows only one-way communication from the policy setting unit to each of the log policy application targets; 8. The log policy management device according to claim 1, wherein:
9. The log setting classification is the work content to which the log policy is applied, the policy level is a worker rank of a worker who performs work on a target to which the log policy is applied, the policy detection unit detects, from the storage unit, the policy information corresponding to the work content and the worker rank to which the log policy is to be applied; 3. The log policy management device according to claim 2, wherein:
10. the update flag control unit, when the work content is changed in any of the log policy application targets or when the worker rank of the worker in any of the log policy application targets is changed, sets the update flag information for the corresponding log policy application target and stores it in the storage unit; 10. The log policy management device according to claim 9, wherein:
11. the update flag control unit erases the update flag information to which the log policy is applied from the storage unit after the policy information is set; 11. The log policy management device according to claim 10,
12. a change history storage control unit that increments a master change history indicating that the policy information in the storage unit has been changed each time the policy information is changed; The log policy management device according to claim 11,
13. the policy information is set in the storage unit via a setting terminal device; 13. The log policy management device according to claim 12, wherein:
14. when the log policy application target is increased, the policy setting unit sets the policy information corresponding to the work content and the worker rank of the increased log policy application target detected by the policy detection unit to the increased log policy application target; The log policy management device according to claim 13,
15. the policy setting unit communicates with each of the log policy target objects via a firewall that is provided between each of the log policy target objects and the log policy management device and that allows only one-way communication from the log policy management device to each of the log policy target objects; 15. The log policy management device according to claim 9, wherein:
16. a policy detection step in which a policy detection unit refers to a storage unit in which a determination target that is a service provider, a log policy target to which policy information that controls the acquisition of log information is applied, a log setting classification that indicates the type of log information to be collected for each of the log policy target, a policy level that indicates the information processing mode of the acquired log information, and policy information to be set are associated, based on the determination target, the log policy target, the log setting classification, and the policy level, and detects the policy information corresponding to the determination target, the log policy target, the log setting classification, and the policy level; a policy setting step in which a policy setting unit sets the detected policy information as a target for application of the corresponding log policy; A log policy management method comprising:
17. Computer, a policy detection unit that references a storage unit in which a determination target that is a service provider, a log policy target to which policy information that controls the acquisition of log information is applied, a log setting classification that indicates the type of log information to be collected for each of the log policy target, a policy level that indicates the information processing mode of the acquired log information, and policy information to be set are associated, based on the determination target, the log policy target, the log setting classification, and the policy level, and detects the policy information corresponding to the determination target, the log policy target, the log setting classification, and the policy level; a policy setting unit that sets the detected policy information as a target for application of the corresponding log policy; A log policy management program that features:
Citation Information
Patent Citations
Log management system for computer device
JP2003308227A
Log information management device, information processing device, log information management method and information processing method
JP2012155420A
Log storage condition generation apparatus and log storage condition generation method
JP2016224646A
Electronic apparatus, log collection system, and method for controlling electronic apparatus
JP2021189827A
On-vehicle device and log management method
JP2023149712A