Log data search method, log data search device, computer device, and computer program

By building a log search time tree and scanning a leaf node, the problem of low log data search efficiency is solved, and fast and efficient log data retrieval is achieved.

JP2025514992AActive Publication Date: 2025-05-13TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024563951
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-20
Filing Date
2023-05-04
Publication Date
2025-05-13
Estimated Expiration
2043-05-04

AI Technical Summary

Technical Problem

The prior art is inefficient when searching for large amounts of log data, especially when the log data is distributed in multiple disk sectors, resulting in frequent read and write operations and reducing search efficiency.

Method used

By building a log search time tree, determining the target node and target subtree, performing leaf node scanning to find the boundary time value, and then obtaining log data matching the search time range.

Benefits of technology

It improves the efficiency of log data search, reduces read and write operations to disk sectors, reduces search time, and improves the performance of data retrieval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025514992000001_ABST
    Figure 2025514992000001_ABST
Patent Text Reader

Abstract

The present application relates to a log data search method, the method includes: a step (202) of determining a target node matching a search time range from a log search time tree, where each node in the log search time tree records a time range of a log search, and the time range recorded in the target node and the search time range have an intersection; a step (204) of determining a target subtree from a subtree under the target node; a step (206) of starting a leaf node scanning process from an edge leaf node of the target subtree, and stopping the scanning after finding a target leaf node by scanning, where log data corresponding to a time value within the target time range recorded in the target leaf node exists on a disk; a step (208) of obtaining a boundary time value corresponding to the search time range by determining a time value in a critical state corresponding to the log data recorded in the target leaf node; and a step (210) of obtaining the log data matching the search time range from the disk based on the boundary time value.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] This application claims priority from a Chinese patent application filed with the China Patent Office on July 20, 2022, bearing application number 202210862134.9 and titled "Log data search method, device, equipment, and medium," the entire contents of which are incorporated herein by reference.

[0002] The present application relates to a data search technology, and further to a cloud technology field, and in particular to a log data search method, device, equipment, and medium. [Background technology]

[0003] Log data generated by daily business transactions is usually stored on a disk. Since the amount of log data is generally relatively large, there is a high probability that the log data is stored in multiple sectors of the disk. This brings about great difficulties in searching for log data. For example, when searching for log data within a certain time range from a disk using a binary search method, distributed access is likely to occur. That is, there is a high probability that log data at an intermediate position related to the binary search process is distributed to multiple sectors of the disk. Every time log data at an intermediate position is read once, a read / write operation must be performed once on the corresponding sector. Since multiple read / write operations on multiple sectors take a long time, the efficiency of searching for log data is low. Summary of the Invention [Problem to be solved by the invention]

[0004] Based on this, there is a need to provide a log data searching method, device, equipment, and medium for solving the above technical problems. [Means for solving the problem]

[0005] According to a first aspect, the present application provides a method for searching log data implemented by a computing device, the method comprising: determining a target node matching a search time range from a log search time tree, where each node in the log search time tree is for recording a time range for log searching, and there is an intersection between the time range recorded in the target node and the search time range; determining a target subtree from a subtree under the target node, the target subtree being for searching a boundary time value corresponding to the search time range; starting a leaf node scanning process from an edge leaf node of the target subtree, and stopping the scanning (also called "traversal") after finding a target leaf node by scanning, where log data corresponding to a time value within a target time range recorded in the target leaf node exists on a disk; determining a time value in a critical state corresponding to log data recorded in the target leaf node, thereby obtaining a boundary time value corresponding to the search time range; and retrieving log data matching the search time range from a disk based on the boundary time value.

[0006] According to a second aspect, the present application provides a log data searching device, the device including: a determining module, a scanning module, and an acquiring module; The determination module determines a target node that matches a search time range from a log search time tree, and each node in the log search time tree is for recording a time range used for log search, and there is an intersection between the time range recorded in the target node and the search time range; The determination module further determines a target subtree from a subtree under the target node, the target subtree is for searching a boundary time value corresponding to the search time range; the scanning module starts a leaf node scanning process from an edge leaf node of the target subtree, and stops the scanning after finding a target leaf node by scanning; and log data corresponding to a time value within a target time range recorded in the target leaf node exists on a disk; The determination module further determines a time value in a critical state, which is recorded in the target leaf node and corresponds to the log data, to obtain a boundary time value corresponding to the search time range; The acquisition module acquires log data matching the search time range from a disk based on the boundary time value.

[0007] According to a third aspect, the present application provides a computing device comprising a memory and one or more processors, the memory having computer readable instructions stored therein that, when executed, perform steps in each of the method embodiments of the present application.

[0008] According to a fourth aspect, the present application provides one or more computer-readable storage media having computer-readable instructions stored thereon that, when executed by one or more processors, cause the application to perform steps in each of the method embodiments of the present application.

[0009] According to a fifth aspect, the present application provides a computer program product including computer readable instructions that, when executed by one or more processors, cause the implementation of steps in each of the method embodiments of the present application.

[0010] The details of one or more embodiments of the application are set forth in the drawings and description below. Other features, objects, and advantages of the application will become apparent from the description, drawings, and claims.

[0011] In order to more clearly describe the configuration of the embodiments of the present application, the following briefly introduces drawings necessary for the description of the embodiments. Obviously, the drawings in the following description only show some embodiments of the present application, and those skilled in the art can obtain other drawings from these drawings without creative labor. [Brief description of the drawings]

[0012] [Figure 1] FIG. 2 is a diagram illustrating an application environment of a log data search method according to an embodiment. [Diagram 2] 4 is a schematic diagram showing the flow of a log data search method in one embodiment. [Diagram 3] FIG. 13 is a schematic diagram of a log search time tree structure in one embodiment. [Figure 4] FIG. 2 is a schematic diagram of the principle of binary search in one embodiment. [Diagram 5] FIG. 13 is a schematic diagram of the intersection between the search time range and each subtree under the target node in one embodiment. [Figure 6] FIG. 13 is a schematic diagram showing the flow of a boundary time value search step in one embodiment. [Figure 7] FIG. 11 is a schematic diagram showing the flow of a log data search method according to another embodiment. [Figure 8] 1 is a configuration block diagram of a log data search device according to an embodiment. [Figure 9] FIG. 2 is a diagram showing the internal configuration of a computer device according to an embodiment. [Figure 10] FIG. 11 is a diagram showing the internal configuration of a computer device according to another embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0013] In order to make the object, configuration and advantages of the present application clearer, the present application will be described in more detail below with reference to the drawings and examples. It should be understood that the specific examples described herein are merely for the purpose of interpreting the present application, and are not intended to limit the present application.

[0014] The log data search method provided in the present application is applicable to an application environment as shown in FIG. 1. Here, the terminal 102 communicates with the server 104 via a network. The data storage system can store data that the server 104 needs to process. The data storage system may be embedded in the server 104 or placed in a cloud or other server. Here, the terminal 102 may be, but is not limited to, various desktop computers, laptops, smartphones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices may be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. The portable wearable devices may be smart watches, smart bracelets, head-mounted devices, etc. The server 104 may be an independent physical server, a server cluster or a distributed system consisting of multiple physical servers, or a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDNs, and base cloud computing services such as big data and artificial intelligence platforms. The terminal 102 and the server 104 may be directly or indirectly connected to each other through a wired or wireless communication method, although the present application is not limited thereto.

[0015] The server 104 may determine a target node that matches the search time range from the log search time tree. Each node in the log search time tree is for recording a time range to be used for log search, and there is a common set between the time range recorded in the target node and the search time range. The server 104 may determine a target subtree for searching for a boundary time value corresponding to the search time range from a subtree under the target node, start a leaf node scanning process from an edge leaf node of the target subtree, and stop the scanning after finding the target leaf node by scanning. Log data corresponding to the time value within the target time range recorded in the target leaf node exists on a disk. The server 104 may obtain a boundary time value corresponding to the search time range by determining a time value in a critical state corresponding to the log data recorded in the target leaf node. The server 104 may obtain the log data that matches the search time range from the disk based on the boundary time value.

[0016] As can be understood, the terminal 102 may obtain a search time range and transmit the search time range to the server 104. Furthermore, the server 104 may determine a target node that matches the search time range from the log search time tree. Also, as can be understood, the server 104 may transmit the obtained log data that matches the search time range to the terminal 102, thereby allowing the terminal 102 to perform business processing accordingly. This embodiment is not limited thereto. As can be understood, the application scenario in FIG. 1 is merely a schematic description and is not limited thereto.

[0017] In one embodiment, a log data search method is provided, as shown in Fig. 2. This method is applicable to a computer device (the computer device may be a terminal or a server), and may be executed solely by the terminal or server itself, or may be realized by the interaction between the terminal and the server. In this embodiment, the method is described by taking the case where the method is applied to a computer device as an example. The method includes the following steps:

[0018] In step 202, a target node that matches the search time range is determined from the log search time tree, and each node in the log search time tree is for recording a time range used for log search, and there is an intersection between the time range recorded in the target node and the search time range.

[0019] Here, the search time range is the time range for searching log data. For example, if a user wants to search log data in the time range from 10:00 to 11:00 yesterday, the time range from 10:00 to 11:00 yesterday is the search time range. The target node is a node in the log search time tree that has a common set with the search time range.

[0020] Specifically, a time range for log searching may be recorded in each node in the log search time tree, and the log search time tree may be stored in a disk of a computer device. The computer device may determine a target node that matches the search time range input by a user from the log search time tree in the disk.

[0021] In step 204, a target subtree is determined from the subtrees under the target node, and the target subtree is for searching a boundary time value corresponding to the search time range.

[0022] Here, the boundary time value is a time value in a critical state corresponding to log data among each time value in the search time range. For understanding, an example will be given. For example, the search time range input by the user is 10:00 to 11:00. If there is no log data corresponding to each time point in the two time ranges of 10:00 to 10:09 and 10:51 to 11:00, but there is log data corresponding to two time values ​​of 10:10 and 10:50, and there is also a possibility that there is log data corresponding to each time value in the time range of 10:10 to 10:50, as can be understood, the two time values ​​of 10:10 and 10:50 are at the critical point in the time range of 10:10 to 10:50. Therefore, the two time values ​​of 10:10 and 10:50 are boundary time values.

[0023] Specifically, the number of subtrees under the target node is at least one, and the computer device may determine a target subtree for searching for a boundary time value from each subtree under the target node.

[0024] In one embodiment, the computer device may determine an intersection status between the search time range entered by the user and each subtree under the target node, and determine a target subtree for searching for a boundary time value corresponding to the search time range from each subtree under the target node based on the intersection status between the search time range and each subtree under the target node.

[0025] In step 206, the leaf node scanning process starts from the edge leaf node of the target subtree, and after the target leaf node is found by scanning, the scanning is stopped, and the log data corresponding to the time value within the target time range recorded in the target leaf node exists on the disk.

[0026] Here, a leaf node is a leaf node that has no out-degree among the nodes in the log search time tree. As can be understood, a leaf node has no successor nodes or is a terminal node of a branch in the log search time tree. An edge leaf node is a leaf node located at an edge among the leaf nodes in the target subtree. As can be understood, the edge leaf nodes may include a left edge leaf node and a right edge leaf node. The left edge leaf node is the leftmost leaf node in the target subtree. The right edge leaf node is the rightmost leaf node in the target subtree. A target leaf node is a leaf node for which log data corresponding to a time value within a recorded time range is present on disk. A target time range is a time range recorded in the target leaf node.

[0027] Specifically, the computer device may perform leaf node scanning processing from the edge leaf node of the target subtree to the adjacent leaf node in sequence, and stop scanning after finding the target leaf node through scanning. As can be understood, the computer device may perform leaf node scanning processing from the edge leaf node of the target subtree to the adjacent leaf node in sequence. Once log data corresponding to a time value within the time range recorded in the currently scanned leaf node exists on the disk, the computer device may take the currently scanned leaf node as the target leaf node and stop the leaf node scanning processing, i.e., do not scan the leaf nodes after the target leaf node.

[0028] In one embodiment, the computer may determine attribute information of the boundary time value that needs to be searched currently. Furthermore, the computer device may determine whether to start the leaf node scanning process from the left edge leaf node of the target subtree or the right edge leaf node of the target subtree based on the attribute information of the boundary time value that needs to be searched currently. Here, the attribute information of the boundary time value is for indicating whether the boundary time value that needs to be searched currently is a lower boundary time value corresponding to the search time range or an upper boundary time value corresponding to the search time range. The lower boundary time value is the minimum boundary time value of the two boundary time values ​​corresponding to the search time range, and the upper boundary time value is the maximum boundary time value of the two boundary time values ​​corresponding to the search time range.

[0029] As can be seen, the time value of 10:10 in the above example is the lower bound time value corresponding to the search time range, and the time value of 10:50 is the upper bound time value corresponding to the search time range.

[0030] In one embodiment, the log search time tree may be specifically a multiple search tree for recording the time range for log search, such as a binary search tree or a ternary search tree, but this embodiment is not limited thereto.

[0031] In one embodiment, the log search time tree is a binary search tree for recording a time range for log search. As shown in FIG. 3, the log search time tree includes seven nodes (i.e., node 1 to node 7). If the time range recorded in the log search time tree is [min, max], it can be understood that node 1 is the root node of the log search time tree, and the time range recorded in node 1 is also [min, max]. Here, min represents the minimum value of the time range recorded in the log search time tree, and max represents the maximum value of the time range recorded in the log search time tree. Intermediate value 1 is a time value at the middle position in the time range [min, max]. It can be understood that the time range of node 1 can be divided into two parts based on intermediate value 1 to form node 2 and node 3 respectively. The time range recorded in node 2 is [min, intermediate value 1], and the time range recorded in node 3 is [intermediate value 1, max]. Similarly, intermediate value 2 is a time value at the middle position in the time range [min, intermediate value 1], and intermediate value 3 is a time value at the middle position in the time range [intermediate value 1, max]. Based on intermediate value 2, the time range of node 2 can be divided into two parts to form node 4 and node 5, respectively. Based on intermediate value 3, the time range of node 3 can be divided into two parts to form node 6 and node 7, respectively. As can be seen, node 4 to node 7 do not have successor nodes. Node 4 to node 7 are leaf nodes of the log search time tree.

[0032] In step 208, a boundary time value corresponding to the search time range is obtained by determining a time value in a critical state that corresponds to the log data recorded in the target leaf node.

[0033] Specifically, the computer device may obtain the boundary time value corresponding to the search time range by determining a time value in a critical state corresponding to the log data recorded in the target leaf node. As can be understood, within the search time range input by the user, there may be a plurality of time values ​​each corresponding to the log data. The computer device may determine a time value in a critical state from among the plurality of time values ​​corresponding to the log data, and set the determined time value as the boundary time value corresponding to the search time range.

[0034] In one embodiment, the target time range has two end time values, which are the range start value and the range end value of the target time range, respectively. The computer device may search for a time value in a critical state corresponding to the log data from the target time range by scanning each time value within the target time range from one end time value in the target time range to the other end time value, and obtain a boundary time value corresponding to the search time range. In this way, by sequentially scanning each time value within the target time range from one end time value in the target time range to the other end time value in the target time range, it is possible to avoid missing a time value and improve the search accuracy of the log data.

[0035] In step 210, log data that matches the search time range is retrieved from the disk based on the boundary time value.

[0036] In one embodiment, each boundary time value corresponding to the search time range corresponds to a log data identifier of the log data stored in the disk, and the computer device may retrieve the log data matching the search time range from the disk according to the log data identifier corresponding to each boundary time value.

[0037] In the above log data search method, a target node that matches the search time range is determined from the log search time tree, and each node in the log search time tree is for recording a time range to be used for log search, and the time range recorded in the target node and the search time range have a common set. The time range recorded in the log search time tree is for use in log search, and the amount of data is small. Therefore, the storage space used for the log search time tree is smaller than the storage space used for storing log data, and it is not necessary to use as many sectors as needed to store log data. A target subtree for searching a boundary time value corresponding to the search time range is determined from a subtree under the target node, a leaf node scanning process is started from an edge leaf node of the target subtree, and after the target leaf node is found by scanning, the scanning is stopped, and log data corresponding to the time value within the target time range recorded in the target leaf node exists on the disk. A boundary time value corresponding to the search time range is obtained by determining a time value in a critical state corresponding to the log data recorded in the target leaf node, and log data matching the search time range is obtained from the disk based on the boundary time value. The storage space used for the log search time tree does not need to use as many sectors as necessary to store the log data, thereby reducing the read and write operations on the sectors, saving the search time for the log data, and improving the search efficiency for the log data.

[0038] In addition, in the present application, the leaf node scanning process starts from the edge leaf node of the target subtree, and the scanning is stopped after the target leaf node is found through scanning, so that the boundary time value corresponding to the search time range can be accurately searched for without scanning all leaf nodes, thereby saving the time required for searching for the boundary time value and further improving the search efficiency of log data.

[0039] Incidentally, the conventional log search method can be realized by a binary search method. When the log data is stored in the internal memory, the binary search method is efficient for log search in the internal memory because the log data is not stored in the internal memory sector by sector. However, considering that the amount of log data is huge, it is costly to store the log data in the internal memory, and the risk of data loss is high when the log data is stored in the internal memory, the log data is usually stored in the disk, and since the amount of log data is large, the log data is stored in multiple sectors of the disk. If the binary search method is directly used to search for log data within a certain time range from the disk, distributed access occurs, and the search efficiency of the log data is low.

[0040] For ease of understanding, an example will be given. As shown in FIG. 4, each gray rectangular block 401 represents a time value. For ease of understanding, each time value is ordered from left to right. 402 is one sector of a disk. If the binary search method is directly used to search for log data within a certain time range from a disk, it is necessary to perform read and write operations on multiple sectors in the binary search process, and each sector access takes time, resulting in low search efficiency for log data. In this application, a log search time tree with a small amount of data is introduced to record the time range used for log search. For this reason, the storage space used for the log search time tree is smaller than the storage space used for storing log data, and it is not necessary to use as many sectors as the log data is stored. The read and write operations on the sectors are reduced, the search time for log data is saved, and the search efficiency for log data is improved.

[0041] In one embodiment, there are at least two subtrees under the target node, and the step of determining a target subtree from the subtrees under the target node includes a step of determining, if there is an intersection between the search time range and a time range recorded in one of the at least two subtrees under the target node, the subtree with the intersection as the target subtree.

[0042] Specifically, there are at least two subtrees under the target node, and the computer device may determine an intersection situation between the search time range and the time range recorded in each subtree under the target node. If there is an intersection between the search time range and the time range recorded in one of the at least two subtrees under the target node, the subtree with the intersection is set as a target subtree for searching for a boundary time value corresponding to the search time range.

[0043] In one embodiment, the log search time tree is a binary search tree for recording the time range used for log search, and the subtrees under the target node include a left subtree and a right subtree. As shown in FIG. 5, part (a) of FIG. 5 shows the search time range input by the user, and the search time range is [search-min, search-max]. In part (b) of FIG. 5, the gray rectangular frame represents the target node, the time range recorded in the target node is [node-min, node-max], and the intermediate value is the time value at the intermediate position in the time range [node-min, node-max]. Based on the intermediate value, the target node can be divided into a left subtree and a right subtree, where the time range recorded in the left subtree is [node-min, intermediate value], and the time range recorded in the right subtree is [intermediate value, node-max]. If there is an intersection between the search time range and the time range recorded in the left subtree under the target node (i.e., case 1 in part (b) of FIG. 5), the computer device may select the left subtree in which the intersection exists as a target subtree for searching for a boundary time value corresponding to the search time range. If there is an intersection between the search time range and the time range recorded in the right subtree under the target node (i.e., case 2 in part (b) of FIG. 5), the computer device may select the right subtree in which the intersection exists as a target subtree for searching for a boundary time value corresponding to the search time range.

[0044] In the above embodiment, if there is a common set between the search time range and the time range recorded in at least one of the two subtrees under the target node, the boundary time value that needs to be searched can only exist in the subtree with the common set, so the subtree with the common set can be directly selected as the target subtree for searching the boundary time value, thereby improving the search efficiency of the boundary time value.

[0045] In one embodiment, the log search time tree includes a log search time binary tree, the subtrees under the target node include a left subtree and a right subtree of the log search time binary tree, and the boundary time values ​​include a lower boundary time value. The step of determining a target subtree from the subtrees under the target node includes a step of setting the left subtree as the target subtree if there is an intersection between the search time range and the time ranges recorded in both the left subtree and the right subtree and it is necessary to search for the lower boundary time value. The step of starting a leaf node scanning process from an edge leaf node of the target subtree and stopping the scanning after finding the target leaf node by the scanning includes a step of starting a leaf node scanning process from a left edge leaf node of the left subtree and stopping the scanning after finding the target leaf node by the scanning.

[0046] Specifically, the log search time binary tree is a binary search tree for recording a time range to be used for log search, and the subtrees under the target node include a left subtree and a right subtree, and the boundary time values ​​corresponding to the search time range include a lower boundary time value and an upper boundary time value. The computer device may determine the intersection status between the search time range and the time range recorded in each subtree under the target node. If there is a common set between the search time range and the time ranges recorded in both the left subtree and the right subtree (i.e., case 3 in part (b) of FIG. 5), and it is necessary to search for the lower boundary time value, the computer device may take the left subtree (i.e., the subtree whose recorded time range is [node-min, midpoint] in FIG. 5) as the target subtree, start a leaf node scanning process from the left edge leaf node of the left subtree, and stop scanning after finding the target leaf node by scanning.

[0047] In the above embodiment, if there is a common set between the search time range and the time range recorded in both the left subtree and the right subtree, it indicates that the boundary time value that needs to be searched for may exist in both the left subtree and the right subtree. For each level of the log search time tree, the time values ​​recorded in each node in the level increase sequentially from left to right, so the probability that the lower boundary time value exists in the left subtree is greater than the probability that it exists in the right subtree. Therefore, if it is necessary to search for the lower boundary time value, the left subtree may be directly set as the target subtree, and scanning may be started from the left subtree with priority to search for the lower boundary time value. In this way, the search efficiency for the lower boundary time value can be improved.

[0048] In one embodiment, the method further includes the step of starting the leaf node scanning process from a left edge leaf node of the right subtree when the target leaf node is not found by scanning the left subtree, and stopping the scanning after the target leaf node is found by scanning.

[0049] Specifically, if the target leaf node is not found by scanning the left subtree (i.e., in FIG. 5, the subtree whose recorded time range is [node-min, midvalue]), the computing device may start the leaf node scanning process from the left edge leaf node of the right subtree (i.e., in FIG. 5, the subtree whose recorded time range is [midvalue, node-max]), and stop the scanning after finding the target leaf node through the scanning.

[0050] In the above embodiment, if the target leaf node is not found by scanning the left subtree, it indicates that the boundary time value to be searched exists in the right subtree. Since the time values ​​recorded in each node in each layer of the log search time tree increase sequentially from left to right, the leaf node scanning process can be started directly from the left edge leaf node of the right subtree to improve the search efficiency of the boundary time value.

[0051] In one embodiment, the subtrees under the target node include a left subtree and a right subtree, and the boundary time values ​​include an upper boundary time value, and the step of determining a target subtree from the subtrees under the target node includes a step of setting the right subtree as the target subtree if there is an intersection between the search time range and the time ranges recorded in both the left subtree and the right subtree and if it is necessary to search for an upper boundary time value, and the step of starting a leaf node scanning process from an edge leaf node of the target subtree and stopping the scanning after finding the target leaf node by the scanning includes a step of starting a leaf node scanning process from a right edge leaf node of the right subtree and stopping the scanning after finding the target leaf node by the scanning.

[0052] Specifically, the log search time tree is a binary search tree for recording a time range to be used for log search, and the subtrees under the target node include a left subtree and a right subtree, and the boundary time values ​​corresponding to the search time range include a lower boundary time value and an upper boundary time value. The computer device may determine the intersection status between the search time range and the time range recorded in each subtree under the target node. If there is a common set between the search time range and the time ranges recorded in both the left subtree and the right subtree (i.e., case 3 in part (b) of FIG. 5), and it is necessary to search for the upper boundary time value, the computer device may take the right subtree (i.e., the subtree in FIG. 5 whose recorded time range is [intermediate value, node-max]) as the target subtree, start a leaf node scanning process from the right edge leaf node of the right subtree, and stop scanning after finding the target leaf node by scanning.

[0053] In the above embodiment, if there is a common set between the search time range and the time range recorded in both the left subtree and the right subtree, it indicates that the boundary time value that needs to be searched for may exist in both the left subtree and the right subtree. For each level of the log search time tree, the time values ​​recorded in each node in the level increase sequentially from left to right, so the probability that the upper boundary time value exists in the right subtree is greater than the probability that it exists in the left subtree. Therefore, if it is necessary to search for the upper boundary time value, the right subtree may be preferentially scanned to search for the upper boundary time value, and the right subtree may be directly used as the target subtree. In this way, the search efficiency for the upper boundary time value can be improved.

[0054] In one embodiment, the method further includes the step of starting the leaf node scanning process from a right edge leaf node of the left subtree when the target leaf node is not found by scanning the right subtree, and stopping the scanning after the target leaf node is found by scanning.

[0055] Specifically, when the target leaf node is not found by scanning the right subtree (i.e., in FIG. 5, the subtree whose recorded time range is [midvalue, node-max]), the computing device may start the leaf node scanning process from the right edge leaf node of the left subtree (i.e., in FIG. 5, the subtree whose recorded time range is [node-min, midvalue]), and stop the scanning after finding the target leaf node through the scanning.

[0056] In the above embodiment, if the target leaf node is not found by scanning the right subtree, it indicates that the boundary time value to be searched exists in the left subtree. Since the time values ​​recorded in each node in each layer of the log search time tree increase sequentially from left to right, the leaf node scanning process can be started directly from the right edge leaf node of the left subtree to improve the search efficiency of the boundary time value.

[0057] In one embodiment, as shown in FIG. 6 , the step of searching for time values ​​in a critical state corresponding to log data from the target time range by scanning each time value within the target time range from one end point time value within the target time range recorded in the target leaf node toward the other end point time value within the target time range to obtain a boundary time value corresponding to the search time range includes the following steps:

[0058] In step 602, the end point time value within the target time range is set as the start time value of this round, the search time range is set as the target search range of this round, and a log time value search process is performed within the target search range from the start time value, and the log time value is the time value corresponding to the log data.

[0059] Here, the end point time value is the time value corresponding to the end point in the target time range. The start time value of this round is the first time value to be searched in the log time value search process of this round. The target search range of this round is the time range of the log time value search process of this round. As can be seen, the start time value and the target search range are constantly updated.

[0060] Specifically, the target time range may include two end time values, and the computer device may take one of the two end time values ​​as the start time value of this round, and the search time range input by the user as the target search range of this round. Furthermore, the computer device may perform a log time value search process within the target search range from the start time value.

[0061] In step 604, after finding the logged time value by searching, the search time range is updated based on the logged time value to obtain an updated time range.

[0062] Specifically, the computing device may search for log time values ​​within the target search range, and then update the search time range input by the user based on the searched log time values ​​to obtain an updated time range.

[0063] In step 606, until the search termination condition is met, the log time value is set as the start time value of the next round of search, the updated time range is set as the target search range of the next round, and the next round of search is performed by returning to the step of performing log time value search processing within the target search range from the start time value, and the last log time value found in the search is obtained as the time value in a critical state corresponding to the log data recorded in the target leaf node, and the boundary time value corresponding to the search time range is obtained.

[0064] Here, the search termination condition is a condition for stopping the iterative process of the log time value search process.

[0065] In one embodiment, the search end condition includes at least one of the following: scanning of each time value in the target time range is completed; or the number of log time value search processes reaches a predetermined number of searches. In this way, the iteration stop condition of the log time value search process can be diversified, and the efficiency of the log time value search process can be improved.

[0066] Specifically, the computer device may return to the step of performing a log time value search process within the target search range from the start time value, with the log time value found by searching in the current round as the start time value of the next round of search, the updated time range of the current round as the target search range of the next round, and the next round as the current round, until the search end condition is satisfied. The computer device may obtain a boundary time value corresponding to the search time range by using the last log time value found by searching as a time value in a critical state corresponding to the log data recorded in the target leaf node.

[0067] In the above embodiment, the log time value search process is repeatedly performed within the target search range, and each time a log time value is searched, the search time range is updated based on the log time value, and the search range is gradually narrowed down, so that the time value in the critical state corresponding to the log data recorded in the target leaf node can be quickly found, and the search efficiency of the boundary time value can be improved, and the search efficiency of the log data can be further improved.

[0068] In one embodiment, the endpoint time value is a time value corresponding to the offset amount of the log data storage file in the disk pointed to by the target leaf node, and the step of performing a log time value search process within the target search range from the start time value, with the endpoint time value within the target time range as the start time value of this round, and the search time range as the target search range of this round, includes the step of starting to update the offset amount of the data storage file in the disk pointed to by the target leaf node from the start time value, with the time value corresponding to the offset amount as the start time value of this round, and the search time range as the target search range of this round, and performing a log time value search process within the target search range.

[0069] Here, the log data storage file is a file for storing log data.

[0070] Specifically, the end point time value is a time value corresponding to the offset amount of the log data storage file in the disk pointed to by the target leaf node, and the computer equipment may take the time value corresponding to the offset amount as the start time value of this round, take the search time range as the target search range of this round, start updating the offset amount of the data storage file in the disk pointed to by the target leaf node from the start time value, and read log data from the corresponding position of the log data storage file on the disk, thereby performing a log time value search process within the target search range.

[0071] In one embodiment, referring to FIG. 3, if node 7 is the target leaf node found by searching, the time range recorded in node 7 is [middle value 3, max], so that the end point time value is "middle value 3", then the "middle value 3" recorded in the log data storage file (i.e., the time value corresponding to 301 in FIG. 3) is the time value corresponding to the offset amount of the log data storage file in the disk pointed to by node 7. The computer device may start updating the offset amount of the data storage file in the disk pointed to by the target leaf node from the time value corresponding to 301 in FIG. 3, and read the log data from the corresponding position of the log data storage file in the disk, thereby realizing the log time value searching process within the target searching range. As can be seen, if a log data number corresponding to the time value found by searching exists in the log data storage file, it can represent that the log data corresponding to the time value found by searching exists in the log data storage file, and the time value found by searching is, i.e., the log time value found by searching. Here, the log data number is for uniquely identifying the log data. As can be seen, the log data number is one representation manner of the log data identifier.

[0072] In the above embodiment, the time value corresponding to the offset amount is taken as the start time value of this round, and the offset amount of the data storage file in the disk pointed to by the target leaf node is continuously updated from the start time value, and the corresponding data is quickly read from the disk, and the log time value search process is performed within the target search range, thereby improving the search efficiency of the boundary time value and further improving the search efficiency of the log data.

[0073] In one embodiment, after finding the logged time value by searching, updating the search time range based on the logged time value to obtain an updated time range includes, when searching for a lower boundary time value corresponding to the search time range, updating an upper limit value of the search time range with the logged time value to obtain an updated time range.

[0074] Here, the upper limit of the search time range refers to the maximum time value among all the time values ​​within the search time range.

[0075] Specifically, the boundary time value corresponding to the search time range includes an upper boundary time value and a lower boundary time value. When searching for the lower boundary time value corresponding to the search time range, the computer device may obtain the updated time range by updating the upper limit value of the search time range with the logged time value.

[0076] Take an example: if the search time range is [min, max] and a log time value searched from [min, max] is V1, the computer device may obtain an updated time range [min, V1] by updating the upper limit value max of the search time range [min, max] with the log time value V1.

[0077] In the above embodiment, when searching for a lower boundary time value corresponding to a search time range, the lower boundary time value finally found by the search is always the logged time value that is closest to the lower limit value of the search time range, so by updating the upper limit value of the search time range with the logged time value, the updated time range can be obtained, thereby improving the search efficiency for the lower boundary time value.

[0078] In one embodiment, after finding the logged time value by searching, updating the search time range based on the logged time value to obtain an updated time range includes, when searching for an upper boundary time value corresponding to the search time range, updating a lower limit value of the search time range with the logged time value to obtain an updated time range.

[0079] Here, the lower limit of the search time range refers to the smallest time value among all the time values ​​within the search time range.

[0080] Specifically, the boundary time value corresponding to the search time range includes an upper boundary time value and a lower boundary time value. When searching for the upper boundary time value corresponding to the search time range, the computer device may update the lower limit value of the search time range with the log time value to obtain an updated time range.

[0081] Take an example: if the search time range is [min, max] and a log time value found by searching from [min, max] is V2, the computer device may obtain an updated time range [V2, max] by updating the lower limit min of the search time range [min, max] with the log time value V2.

[0082] In the above embodiment, when searching for the upper and lower boundary time values ​​corresponding to the search time range, the upper boundary time value finally found by the search is always the logged time value that is closest to the upper limit value of the search time range, so by updating the lower limit value of the search time range with the logged time value, the updated time range can be obtained, thereby improving the search efficiency for the upper boundary time value.

[0083] In one embodiment, the boundary time value includes a lower boundary time value and an upper boundary time value, and the step of retrieving log data matching the search time range from the disk based on the boundary time value includes the step of retrieving log data corresponding to each log data number in the target number range from the disk as log data matching the search time range, where the target number range is a number range with the log data number corresponding to the lower boundary time value as a range start value and the log data number corresponding to the upper boundary time value as a range end value.

[0084] Specifically, the boundary time value includes a lower boundary time value and an upper boundary time value. The computer device may obtain a log data number corresponding to the lower boundary time value and obtain a log data number corresponding to the upper boundary time value. The computer device may construct a target number range by using the log data number corresponding to the lower boundary time value as a range start value and the log data number corresponding to the upper boundary time value as a range end value. The computer device may obtain log data corresponding to each of the log data numbers in the target number range from the disk as log data matching the search time range.

[0085] In the above embodiment, the target number range is a number range with the log data number corresponding to the lower boundary time value as the range start value and the log data number corresponding to the upper boundary time value as the range end value, so that each log data number included in the target number range has a corresponding relationship with each log time value within the search time range. Furthermore, the log data corresponding to each log data number within the target number range can be obtained from the disk and directly matched with the search time range, which further improves the search efficiency of the log data.

[0086] As shown in Fig. 7, in one embodiment, a log data search method is provided. This method is applicable to a computer device (the computer device may be a terminal or a server), and may be executed by the terminal or server itself alone, or may be realized by the terminal and the server through an exchange. In this embodiment, the method is described by taking the case where the method is applied to a computer device as an example. Specifically, this method includes the following steps:

[0087] In step 702, a target node that matches the search time range is determined from the log search time tree, and each node in the log search time tree is for recording a time range to be used for log search, and there is an intersection between the time range recorded in the target node and the search time range.

[0088] In step 704, if there is an intersection between the search time range and the time range recorded in one of the left subtree and the right subtree under the target node, the subtree in which the intersection is found is set as the target subtree for searching for boundary time values, including a lower boundary time value and an upper boundary time value.

[0089] In step 706, if there is an intersection between the search time range and the time ranges recorded in both the left subtree and the right subtree, if it is necessary to search for a lower boundary time value, the left subtree is taken as the target subtree, and a leaf node scanning process is started from the left edge leaf node of the left subtree, and after the target leaf node is found by scanning, the scanning is stopped; if the target leaf node is not found by scanning the left subtree, a leaf node scanning process is started from the left edge leaf node of the right subtree, and after the target leaf node is found by scanning, the scanning is stopped.

[0090] In step 708, if there is an intersection between the search time range and the time ranges recorded in both the left subtree and the right subtree, if it is necessary to search for an upper boundary time value, the right subtree is taken as the target subtree, and a leaf node scanning process is started from the right edge leaf node of the right subtree, and after the target leaf node is found by scanning, the scanning is stopped; if the target leaf node is not found by scanning the right subtree, a leaf node scanning process is started from the right edge leaf node of the left subtree, and after the target leaf node is found by scanning, the scanning is stopped.

[0091] In step 710, the leaf node scanning process starts from an edge leaf node of the target subtree, and after the target leaf node is found by scanning, the scanning is stopped, and the log data corresponding to the time value within the target time range recorded in the target leaf node exists on the disk.

[0092] In step 712, the end point time value within the target time range is set as the start time value of this round, the search time range is set as the target search range of this round, and a log time value search process is performed within the target search range from the start time value, and the log time value is the time value corresponding to the log data.

[0093] In step 714, after finding the logged time value by searching, the search time range is updated based on the logged time value to obtain an updated time range.

[0094] In step 716, until the search termination condition is met, the log time value is set as the start time value of the next round of search, the updated time range is set as the target search range of the next round, and the step of performing log time value search processing within the target search range from the start time value is returned to, and the next round of search is performed. The last log time value found in the search is used as the time value in a critical state corresponding to the log data recorded in the target leaf node, and the boundary time value corresponding to the search time range is obtained.

[0095] In step 718, log data corresponding to each log data number within the target number range is obtained from the disk as log data matching the search time range, and the target number range is a number range whose range start value is the log data number corresponding to the lower boundary time value and whose range end value is the log data number corresponding to the upper boundary time value.

[0096] In this application, an application scenario is further provided. In this application scenario, the above log data search method is applied. Specifically, the log data search method is applicable to a scenario that realizes log data search based on a binary search tree. As can be understood, the log search time tree is a log search time binary tree. The computer device may determine a target node that matches a search time range from the log search time binary tree. Each node in the log search time binary tree is for recording a time range for log search, and there is a common set between the time range recorded in the target node and the search time range. If there is a common set between the search time range and the time range recorded in one of the left subtree and the right subtree under the target node, the subtree with the common set is taken as a target subtree for searching for a boundary time value. The boundary time value includes a lower boundary time value and an upper boundary time value.

[0097] If there is a common set between the search time range and the time ranges recorded in both the left subtree and the right subtree, if it is necessary to search for a lower boundary time value, the computer device may take the left subtree as a target subtree, start a leaf node scanning process from the left edge leaf node of the left subtree, and stop the scanning after finding the target leaf node by scanning, if the target leaf node is not found by scanning the left subtree, start a leaf node scanning process from the left edge leaf node of the right subtree, and stop the scanning after finding the target leaf node by scanning. If there is a common set between the search time range and the time ranges recorded in both the left subtree and the right subtree, if it is necessary to search for an upper boundary time value, the computer device may take the right subtree as a target subtree, start a leaf node scanning process from the right edge leaf node of the right subtree, and stop the scanning after finding the target leaf node by scanning, if the target leaf node is not found by scanning the right subtree, start a leaf node scanning process from the right edge leaf node of the left subtree, and stop the scanning after finding the target leaf node by scanning.

[0098] The computer device may start the leaf node scanning process from an edge leaf node of the target subtree, and stop the scanning after finding the target leaf node by scanning. Log data corresponding to the time value within the target time range recorded in the target leaf node exists on the disk. The end point time value within the target time range is set as the start time value of the current round, and the search time range is set as the target search range of the current round, and a log time value search process is performed within the target search range from the start time value. The log time value is a time value corresponding to the log data. After the log time value is found by searching, the search time range is updated based on the log time value to obtain an updated time range. Until a search end condition is met, the step of performing the log time value search process within the target search range from the start time value with the log time value set as the start time value of the search of the next round and the updated time range set as the target search range of the next round is returned to, and the next round of search is performed, and the last log time value found by searching is set as the time value in a critical state corresponding to the log data recorded in the target leaf node, and a boundary time value corresponding to the search time range is obtained.

[0099] The computer device may retrieve from the disk the log data corresponding to each log data number within the target number range as log data matching the search time range, where the target number range is a number range whose range start value is the log data number corresponding to the lower boundary time value and whose range end value is the log data number corresponding to the upper boundary time value.

[0100] Another application scenario is further provided in this application scenario. In this application scenario, the above log data search method is applied. Specifically, the log data search method is applicable to a scenario in which log data search is realized based on a multi-word search tree. As can be understood, the log search time tree can be a log search time multi-word tree, such as a log search time ternary tree or a log search time quad tree. As can be understood, each node in the log search time multi-word tree is for recording a time range for log search. Based on the log search time multi-word tree, a high-speed search for log data in a disk can be realized, and the search efficiency of log data can be improved.

[0101] It should be understood that although the steps in the flowcharts of the above embodiments are shown in sequence, the steps are not necessarily executed in sequence. Unless otherwise clearly described in this specification, there is no strict restriction on the execution order of the steps. The steps may be executed in other orders. In addition, at least some of the steps in the above embodiments may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, and may be executed at different times. The execution order of these sub-steps or stages is also not necessarily executed in sequence, and may be executed in an alternative or alternating manner with other steps or at least some of the sub-steps or stages of other steps.

[0102] In one embodiment, as shown in Fig. 8, a log data search device 800 is provided. The device can be part of a computer device through a software module or a hardware module, or a combination of both. The device specifically includes the following modules:

[0103] The determination module 802 determines a target node that matches the search time range from the log search time tree, and each node in the log search time tree is for recording a time range for log search, and there is an intersection between the time range recorded in the target node and the search time range.

[0104] The determining module 802 further determines a target subtree from the subtree under the target node, where the target subtree is for searching a boundary time value corresponding to the search time range.

[0105] The scanning module 804 starts the leaf node scanning process from an edge leaf node of the target subtree, and after finding the target leaf node through scanning, stops the scanning, and log data corresponding to the time value within the target time range recorded in the target leaf node exists on the disk.

[0106] The determination module 802 further obtains a boundary time value corresponding to the search time range by determining a time value in a critical state corresponding to the log data recorded in the target leaf node.

[0107] The acquisition module 806 acquires log data matching the search time range from the disk based on the boundary time value.

[0108] In one embodiment, there are at least two subtrees under the target node, and the determination module 802 further determines that if there is an intersection between the search time range and the time range recorded in one of the at least two subtrees under the target node, the subtree with the intersection is the target subtree.

[0109] In one embodiment, the subtrees under the target node include a left subtree and a right subtree, and the boundary time values ​​include a lower boundary time value, and the determination module 802 further determines that if there is an intersection between the search time range and the time ranges recorded in both the left subtree and the right subtree, the left subtree is the target subtree if the lower boundary time value needs to be searched for, and the scanning module 804 further starts the leaf node scanning process from the left edge leaf node of the left subtree, and stops the scanning after finding the target leaf node through the scanning.

[0110] In one embodiment, the scanning module 804 further starts the leaf node scanning process from the left edge leaf node of the right subtree when the target leaf node is not found by scanning the left subtree, and stops scanning after the target leaf node is found by scanning.

[0111] In one embodiment, the subtrees under the target node include a left subtree and a right subtree, and the boundary time values ​​include an upper boundary time value, and the determination module 802 further determines that if there is an intersection between the search time range and the time ranges recorded in both the left subtree and the right subtree, the right subtree is the target subtree if an upper boundary time value needs to be searched for, and the scanning module 804 further starts a leaf node scanning process from a right edge leaf node of the right subtree, and stops the scanning after finding the target leaf node through the scanning.

[0112] In one embodiment, the scanning module 804 further starts the leaf node scanning process from the right edge leaf node of the left subtree when the target leaf node is not found by scanning the right subtree, and stops scanning after the target leaf node is found by scanning.

[0113] In one embodiment, the target time range recorded in the target leaf node has two end time values, and the determination module 802 further searches for a time value in a critical state corresponding to the log data from the target time range by scanning each time value in the target time range from one end time value in the target time range recorded in the target leaf node toward the other end time value in the target time range, and obtains a boundary time value corresponding to the search time range.

[0114] In one embodiment, the determination module 802 further performs a log time value search process within the target search range from the start time value, with the end time value within the target time range recorded in the target leaf node as the start time value of the current round, and the search time range as the target search range of the current round. After finding a log time value through the search, the search time range is updated based on the log time value to obtain an updated time range. Until the search termination condition is met, the step of performing a log time value search process within the target search range from the start time value, with the log time value as the start time value of the search of the next round, and the updated time range as the target search range of the next round, returns to the step of performing a log time value search process within the target search range from the start time value, and performs a search of the next round. The last log time value found by the search is used as the time value in a critical state corresponding to the log data recorded in the target leaf node, and obtains a boundary time value corresponding to the search time range, where the log time value is the time value corresponding to the log data.

[0115] In one embodiment, the end point time value is a time value corresponding to the offset amount of the log data storage file in the disk pointed to by the target leaf node, and the determination module 802 further sets the time value corresponding to the offset amount as the start time value of this round, and sets the search time range as the target search range of this round, and starts updating the offset amount of the data storage file in the disk pointed to by the target leaf node from the start time value, and performs a log time value search process within the target search range.

[0116] In one embodiment, when the determination module 802 further searches for a lower boundary time value corresponding to the search time range, it obtains an updated time range by updating the upper limit value of the search time range with the logged time value.

[0117] In one embodiment, when the determination module 802 further searches for an upper boundary time value corresponding to the search time range, it obtains an updated time range by updating the lower limit value of the search time range with the logged time value.

[0118] In one embodiment, the search termination condition includes at least one of: scanning each time value in the target time range is completed; or the number of logged time value search processes reaches a predetermined number of searches.

[0119] In one embodiment, the boundary time value includes a lower boundary time value and an upper boundary time value, and the acquisition module 806 further acquires log data corresponding to each log data number in the target number range from the disk as log data matching the search time range, where the target number range is a number range with the log data number corresponding to the lower boundary time value as the range start value and the log data number corresponding to the upper boundary time value as the range end value.

[0120] The log data search device determines a target node that matches the search time range from the log search time tree, and each node in the log search time tree is for recording a time range to be used for log search, and the time range recorded in the target node and the search time range have a common set. The time range recorded in the log search time tree is for use in log search, and the amount of data is small. Therefore, the storage space used for the log search time tree is smaller than the storage space used for storing log data, and it is not necessary to use as many sectors as needed to store log data. A target subtree for searching for a boundary time value is determined from a subtree under the target node, a leaf node scanning process is started from an edge leaf node of the target subtree, and after the target leaf node is found by scanning, the scanning is stopped, and log data corresponding to the time value within the target time range recorded in the target leaf node exists on the disk. A boundary time value corresponding to the search time range is obtained by determining a time value in a critical state corresponding to the log data recorded in the target leaf node, and log data matching the search time range is obtained from the disk based on the boundary time value. The storage space used for the log search time tree does not need to use as many sectors as necessary to store the log data, thereby reducing the read and write operations on the sectors, saving the search time for the log data, and improving the search efficiency for the log data.

[0121] Each module of the log data search device may be realized in whole or in part by software, hardware, or a combination thereof. Each module may be embedded in or stand-alone in the processor of a computer device in the form of hardware, or may be stored in the memory of a computer device in the form of software, which makes it easy for the processor to call and execute the operation corresponding to each module.

[0122] In one embodiment, a computer device is provided. The computer device may be a server, and its internal configuration diagram may be as shown in FIG. 9. The computer device includes one or more processors, a memory, an input / output interface (I / O: Input / Output), and a communication interface. Here, the processor, the memory, and the input / output interface are connected via a system bus, and the communication interface is connected to the system bus via the input / output interface. Here, the processor of the computer device provides a calculation and control function. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, computer-readable instructions, and a database. The internal memory provides an environment for the execution of the operating system and the computer-readable instructions in the non-volatile storage medium. The input / output interface of the computer device is for exchanging information between the processor and an external device. The network interface of the computer device is for communicating with an external terminal via a network connection. When executed by the processor, the computer-readable instructions realize a log data search method.

[0123] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal configuration diagram may be as shown in FIG. 10. The computer device includes one or more processors, a memory, an input / output interface, a communication interface, a display unit, and an input device. Wherein, the processor, the memory, and the input / output interface are connected via a system bus, and the communication interface, the display unit, and the input device are connected to the system bus via the input / output interface. Wherein, the processor of the computer device provides a function of calculation and control. The memory of the computer device includes a non-volatile storage medium, an internal memory. The non-volatile storage medium stores an operating system and computer-readable instructions. The internal memory provides an environment for the execution of the operating system and the computer-readable instructions in the non-volatile storage medium. The input / output interface of the computer device is for exchanging information between the processor and an external device. The communication interface of the computer device is for communicating with an external terminal in a wired or wireless manner, and the wireless manner may be realized by WIFI, a mobile cellular network, a near field communication (NFC), or other technologies. The computer readable instructions, when executed by a processor, realize a log data search method. The display unit of the computer device is for forming a visually visible screen, and may be a display screen, a projection device, or a virtual reality imaging device. The display screen may be a liquid crystal display screen or an E-ink display screen. The input device of the computer device may be a touch layer superimposed on the display screen, a button, a trackball, or a touch pad provided on the housing of the computer device, or an external keyboard, touch pad, mouse, etc.

[0124] As will be understood by those skilled in the art, the configurations shown in Figures 9 and 10 are merely block diagrams of some configurations according to the present invention, and do not limit the computer device to which the present invention is applied. A specific computer device may include more or fewer components than those shown, may combine some components, or may have a different arrangement of components.

[0125] In one embodiment, there is further provided a computing device comprising a memory and one or more processors, the memory having computer readable instructions stored therein that, when executed, perform the steps in each of the method embodiments described above.

[0126] In one embodiment, one or more computer readable storage media are provided having computer readable instructions stored thereon that, when executed by one or more processors, cause the computer to perform the steps in each of the method embodiments described above.

[0127] In one embodiment, a computer program product is provided that includes computer readable instructions that, when executed by one or more processors, cause the computer to perform the steps in each of the method embodiments described above.

[0128] In addition, all user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to analytical data, stored data, display data, etc.) related to this application are information and data authorized by the user or fully authorized by each party, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0129] As can be understood by those skilled in the art, all or part of the flow of the method according to the above embodiments may be realized by instructing relevant hardware via computer readable instructions. The computer readable instructions may be stored in a non-volatile computer readable storage medium. When the computer readable instructions are executed, the flow of each of the above-mentioned method embodiments is performed. Herein, any reference to memory, storage, database, or other medium used in each of the embodiments provided herein may include at least one of non-volatile memory and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, etc. Volatile memory may include random access memory (RAM) or external cache. By way of explanation and not limitation, RAM may be in many forms, such as static random access memory (SRAM) and dynamic random access memory (DRAM).

[0130] The components of the above-mentioned embodiments may be combined in any manner. For the sake of brevity, not all possible combinations of the components of the above-mentioned embodiments are described. However, the combinations of these components should be considered to be within the scope described in this specification unless there is a contradiction.

[0131] The above examples merely show some embodiments of the present application, and the explanations are specific and detailed, but they should not be understood as limitations on the patent scope of the present application. It should be noted that those skilled in the art can make some modifications and improvements without departing from the concept of the present application. All of these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of patent protection of the present application should be subject to the scope of the attached claims. [Explanation of symbols]

[0132] 102 Terminals 104 Server 401 Gray Rectangular Block 800 Log data search device 802 Decision Module 804 Scanning Module 806 Acquisition Module

Claims

1. A log data search method executed by a computer device, comprising: determining a target node matching a search time range from a log search time tree, where each node in the log search time tree is for recording a time range for log searching, and there is an intersection between the time range recorded in the target node and the search time range; determining a target subtree from a subtree under the target node, the target subtree being for searching a boundary time value corresponding to the search time range; starting a leaf node scanning process from an edge leaf node of the target subtree, and stopping the scanning after finding a target leaf node by scanning, where log data corresponding to a time value within a target time range recorded in the target leaf node exists on a disk; determining a time value in a critical state corresponding to log data recorded in the target leaf node, thereby obtaining a boundary time value corresponding to the search time range; and acquiring log data matching the search time range from a disk based on the boundary time value. A log data search method comprising:

2. The number of subtrees under the target node is at least two, The step of determining a target subtree from a subtree under the target node includes: If there is an intersection between the search time range and a time range recorded in one of at least two subtrees under the target node, the subtree having the intersection is selected as a target subtree.

2. The log data search method according to claim 1.

3. The log search time tree includes a log search time binary tree, the subtrees under the target node include a left subtree and a right subtree of the log search time binary tree, and the boundary time value includes a lower boundary time value; The step of determining a target subtree from a subtree under the target node includes: if there is an intersection between the search time range and the time ranges recorded in both the left subtree and the right subtree, then the left subtree is taken as the target subtree if the lower boundary time value needs to be searched for; the step of starting a leaf node scanning process from an edge leaf node of the target subtree and stopping the scanning after finding the target leaf node through the scanning; starting a leaf node traversal process from a left edge leaf node of the left subtree, and stopping the traversal after finding a target leaf node through the traversal; 2. The log data search method according to claim 1.

4. if the target leaf node is not found by scanning the left subtree, starting a leaf node scanning process from a left edge leaf node of the right subtree, and stopping the scanning after the target leaf node is found by scanning the left subtree; 4. The log data search method according to claim 3.

5. the subtrees under the target node include a left subtree and a right subtree, and the boundary time values ​​include an upper boundary time value; The step of determining a target subtree from a subtree under the target node includes: if there is an intersection between the search time range and the time ranges recorded in both the left subtree and the right subtree, then the right subtree is selected as the target subtree if the upper boundary time value needs to be searched for; the step of starting a leaf node scanning process from an edge leaf node of the target subtree and stopping the scanning after finding the target leaf node through the scanning; starting a leaf node scanning process from a right edge leaf node of the right subtree, and stopping the scanning after finding a target leaf node through the scanning; 2. The log data search method according to claim 1.

6. if the target leaf node is not found by scanning the right subtree, starting a leaf node scanning process from a right edge leaf node of the left subtree, and stopping the scanning after the target leaf node is found by scanning the right subtree; 6. The log data search method according to claim 5.

7. The target time range recorded in the target leaf node has two end time values, and the step of obtaining a boundary time value corresponding to the search time range by determining a time value in a critical state recorded in the target leaf node and corresponding to the log data includes: The method includes a step of searching for a time value in a critical state corresponding to log data from the target time range by scanning each time value within the target time range from one of the end point time values ​​within the target time range recorded in the target leaf node toward the other end point time value within the target time range, thereby obtaining a boundary time value corresponding to the search time range.

2. The log data search method according to claim 1.

8. the step of searching for a time value in a critical state corresponding to log data from the target time range by scanning each time value within the target time range from one of the end point time values ​​within the target time range recorded in the target leaf node toward the other end point time value within the target time range to obtain a boundary time value corresponding to the search time range, a step of performing a log time value search process within the target search range from an end point time value recorded in the target leaf node as a start time value of the current round, and a search time range as a target search range of the current round, the log time value being a time value corresponding to log data; After finding a log time value by searching, updating the search time range based on the log time value to obtain an updated time range; and performing a search in the next round by returning to the step of performing a log time value search process within the target search range from the start time value, with the log time value set as a start time value of the search in the next round and the updated time range set as a target search range in the next round until a search end condition is satisfied, and acquiring a boundary time value corresponding to the search time range by setting the last log time value found by the search as a time value in a critical state corresponding to the log data recorded in the target leaf node.

8. The log data search method according to claim 7.

9. the end point time value is a time value corresponding to an offset amount of a log data storage file in a disk to which the target leaf node is pointed; The step of performing a log time value search process within the target search range from the start time value, with the end point time value within the target time range as the start time value of this round, and the search time range as the target search range of this round, a time value corresponding to the offset amount as a start time value of the current round, a search time range as a target search range of the current round, and starting to update the offset amount of the data storage file in the disk pointed to by the target leaf node from the start time value, and performing log time value search processing within the target search range; 9. The log data search method according to claim 8.

10. the step of updating the search time range based on the log time value after searching to obtain an updated time range includes: When searching for a lower boundary time value corresponding to the search time range, the step of updating an upper limit value of the search time range with the log time value to obtain an updated time range.

9. The log data search method according to claim 8.

11. the step of updating the search time range based on the log time value after searching to obtain an updated time range includes: When searching for an upper boundary time value corresponding to the search time range, the step of updating a lower limit value of the search time range with the log time value to obtain an updated time range is included.

9. The log data search method according to claim 8.

12. The search end condition includes at least one of: scanning of each time value within the target time range is completed; or the number of times the log time value search process has been performed has reached a predetermined number of searches.

9. The log data search method according to claim 8.

13. The boundary time value includes a lower boundary time value and an upper boundary time value, and the step of acquiring log data matching the search time range from a disk based on the boundary time value includes: A step of acquiring log data corresponding to each log data number within a target number range from a disk as log data matching the search time range, The target number range is a number range having a log data number corresponding to the lower boundary time value as a range start value and a log data number corresponding to the upper boundary time value as a range end value.

13. The log data search method according to claim 1,

14. A log data search device, comprising: a determining module, a scanning module, and an acquiring module; The determination module determines a target node that matches a search time range from a log search time tree, and each node in the log search time tree is for recording a time range used for log search, and there is an intersection between the time range recorded in the target node and the search time range; The determination module further determines a target subtree from a subtree under the target node, the target subtree is for searching a boundary time value corresponding to the search time range; the scanning module starts a leaf node scanning process from an edge leaf node of the target subtree, and stops the scanning after finding a target leaf node by scanning; and log data corresponding to a time value within a target time range recorded in the target leaf node exists on a disk; The determination module further determines a time value in a critical state, which is recorded in the target leaf node and corresponds to the log data, to obtain a boundary time value corresponding to the search time range; The acquisition module acquires log data matching the search time range from a disk based on the boundary time value. A log data search device comprising:

15. A computer device comprising a memory and one or more processors, the memory storing computer-readable instructions, the processor executing the computer-readable instructions to implement the steps of the log data search method of any one of claims 1 to 13.

16. One or more computer readable storage media having computer readable instructions stored thereon, the computer readable instructions, when executed by one or more processors, causing the implementation of the steps of the method of any one of claims 1 to 13.

17. 14. A computer program product comprising computer readable instructions which, when executed by one or more processors, cause the implementation of the steps of the method according to any one of claims 1 to 13.

Citation Information

Patent Citations

  • Method for management and search of history data

    JP2005196514A

  • Video signal retrieval method and method for generating binary tree for retrieval

    JP2008287544A

  • Storage system, control program for information processing unit, and control method for storage system

    JP2014199581A

  • Calendar range searching

    US20180336532A1