Trace management device, trace management method, and trace management program
The trace management device addresses the challenge of assigning trace IDs in distributed systems by transmitting trace information to transmission requests based on the generation relationship between received and transmission requests, enhancing tracing and analysis capabilities.
Patent Information
- Application Number
- JP2021213903
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-28
- Publication Date
- 2025-05-12
- Estimated Expiration
- 2041-12-28
AI Technical Summary
Existing technologies struggle to assign trace IDs to requests in distributed systems, especially when dealing with applications in binary formats like C, as they require hardcoding, which is costly and not feasible for applications from different companies.
A trace management device that inputs received requests, outputs transmission requests, and transmits trace information to the corresponding requests, using a processor to identify the generation relationship between received and transmission requests and assign trace information accordingly.
Enables easy and appropriate provision of trace information to transmission requests from application processes, facilitating effective tracing and analysis in distributed systems without the need for hardcoding.
Smart Images

Figure 0007675006000001 
Figure 0007675006000002 
Figure 0007675006000003
Abstract
Description
[Technical field]
[0001] The present invention relates to a technique for adding trace information to a request that is output from a process and transmitted. [Background technology]
[0002] In distributed systems such as microservice architectures, distributed tracing is used to trace the flow of requests in order to analyze the causes of failures and performance degradation. Distributed tracing can trace the flow of requests by assigning the same trace ID to the flow of a series of requests. In order to assign a trace ID to a request, it is necessary to hard-code it in the application that issues the request.
[0003] There is a problem in that it is costly to assign a trace ID to an application, and in cases where the application is a product of another company, it is impossible to hard-code the application, and therefore it is impossible to assign a trace ID.
[0004] Known techniques for assigning trace IDs include analyzing scripts or intermediate languages such as Python or Java (registered trademark) to understand the correspondence between HTTP reception and transfer, and embedding code that assigns trace IDs to necessary locations when the application is launched (see, for example, non-patent document 1). [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] Jonathan Mace, Ryan Roelke, and Rodrigo Fonseca. 2015. Pivot tracing: dynamic causal monitoring for distributed systems. In Proceedings of the 25th Symposium on Operating Systems Principles (SOSP '15). Association for Computing Machinery, New York, NY, USA, P.378-393. Summary of the Invention [Problem to be solved by the invention]
[0006] However, the technology disclosed in Patent Document 1 is applicable to scripts and intermediate languages, and cannot be applied to applications in binary format such as C language.
[0007] Thus, the problem remains that binary applications must be hard-coded, which is costly or impossible.
[0008] The present invention has been made in consideration of the above circumstances, and has an object to provide a technique that can easily and appropriately add trace information to a transmission request output from an application process. [Means for solving the problem]
[0009] In order to achieve the above-mentioned object, a trace management device according to one aspect is a trace management device that inputs a receive request received from a first device, executes a process to output a transmit request to be sent to a second device, and assigns trace information to the transmit request and sends it to the second device, and has a processor. The processor identifies corresponding transmit requests and receive requests based on the generation relationship between the receive request in the process and the transmit request corresponding to the receive request, and includes at least a portion of the trace information assigned to the identified receive request in the trace information to be assigned to the identified transmit request and sends it to the second device. Effect of the Invention
[0010] According to the present invention, trace information can be easily and appropriately added to a transmission request output from an application process. [Brief description of the drawings]
[0011] [Figure 1] FIG. 1 is a functional configuration diagram of a computer according to the first embodiment. [Diagram 2] FIG. 2 is a configuration diagram of the traffic information according to the first embodiment. [Diagram 3] FIG. 3 is a configuration diagram of ID correspondence information according to the first embodiment. [Figure 4] FIG. 4 is a configuration diagram of the filter information according to the first embodiment. [Diagram 5] FIG. 5 is a hardware configuration diagram of a computer according to the first embodiment. [Figure 6] FIG. 6 is a diagram illustrating a flow of information acquisition according to the first embodiment. [Figure 7] FIG. 7 is a flowchart of the trace information control process according to the first embodiment. [Figure 8] FIG. 8 is a diagram for explaining an example of a process that is a target of a computer according to the second embodiment. [Figure 9]FIG. 9 is a functional configuration diagram of a computer according to the second embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of additional information according to the second embodiment. [Figure 11] FIG. 11 is a diagram illustrating an example of traffic information according to the second embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] The following embodiments will be described with reference to the drawings. Note that the following embodiments do not limit the scope of the invention, and not all of the elements and combinations thereof described in the embodiments are necessarily essential to the solution of the invention.
[0013] In the following description, the processing may be described with a "program" as the operating subject, but since the program is executed by a processor to perform a defined process using at least one of the memory unit and the interface unit as appropriate, the operating subject of the processing may be the processor (or a computer having a processor). The program may be installed on the computer from a program source. The program source may be, for example, a program distribution server or a storage medium readable by a computer. Also, in the following description, two or more programs may be realized as one program, and one program may be realized as two or more programs.
[0014] FIG. 1 is a functional configuration diagram of a computer according to the first embodiment.
[0015] The computer 100 is, for example, a computer constituting a part of a distributed system (not shown), and is an example of a resource management device. The computer 100 may be a physical computer (physical computer), or may be a virtual computer (virtual computer) configured based on the resources of a physical computer. The computer 100 includes one or more processes 110 that execute applications, and an ID assignment server 120. In this embodiment, the process 110 and the ID assignment server 120 share, for example, a kernel of an OS (Operating System) executed by the computer 100. The process 110 has one or more threads 111. The threads 111 include, for example, a process that inputs and processes a reception request received from an external device (first device), and generates and outputs one or more transmission requests to be transmitted to an external device (second device) based on the reception request.
[0016] The ID assigning server 120 performs a process of assigning trace information to a transmission request output by the process 110 and transmitting the same. The ID assigning server 120 stores a traffic acquisition program 121, an ID manipulation program 122, a pattern analysis program 123, a mapping program 124, a communication program 125, traffic information 126, ID correspondence information 127, target information 128, pattern logic 129, and filter information 132.
[0017] The traffic acquisition program 121 is executed by the processor 201 (see FIG. 5) described later to acquire traffic information related to a received request input to the process 110 and a transmitted request output from the process 110, and stores the traffic information in the traffic information 126. For example, when the OS is Linux (registered trademark), the traffic acquisition program 121 may acquire the traffic information by acquiring a system call using a Strace command, or may acquire the traffic information by acquiring communication data using a BPF (Berkeley Packet Filter). In this embodiment, the traffic acquisition program 121 acquires traffic information that meets the conditions specified in the filter information 132, for example.
[0018] The ID manipulation program 122 is executed by the processor 201 to obtain ID information (traffic information) from a received request and store it in the ID correspondence information 127, or to assign ID information to a transmission request. In this embodiment, the ID manipulation program 122 stores ID information in the HTTP header of a transmission request, so that L7 (application layer) control is possible.
[0019] In this embodiment, for example, the ID information obtained from the ID information of the received request and included (propagated) in the transmitted request includes at least a trace-id (an example of a trace ID) if it complies with the Trace Context standard of the W3C (World Wide Web Consortium), and may further include trace-flag and tracestate, and includes at least an x-b3-traceid (an example of a trace ID) if it complies with the Trace Context standard of the B3 Propagation, and may further include an x-b3-parentspanid, an x-b3-sampled, and an x-3b-flags.
[0020] The trace-id is an ID that indicates a series of traffic flows. The trace-flag is, for example, a sampling rate. The ID assigning server 120 may set a unique value for the trace-flag without propagating the data of the received request. The tracestate is vendor-specific data. A parameter (for example, Span-id) may be added to the tracestate according to the processing of the ID assigning server 120.
[0021] x-b3-traceid is an ID that represents a series of traffic flows. x-b3-parentspanid is the x-b3-spanid of the received request. Note that x-b3-parentspanid is not required, and it does not need to be propagated if the received request has no parameters. x-b3-sampled is information that indicates whether or not to sample. x-b3-sampled does not need to be propagated if the received request has no parameters. x-3b-flags is information that indicates whether debugging is enabled. x-b3-flags does not need to be propagated if the received request has no parameters.
[0022] The pattern analysis program 123 judges whether or not a pattern of the generation relationship between the reception request and the transmission request in the traffic information 126 matches a pattern of the judgment logic 130 of the pattern logic 129. The mapping program 124 associates the corresponding reception request and the transmission request in the traffic information 126 using the mapping logic 131. The communication program 125 transmits the transmission request output from the thread 111 to a destination device (second device). In this embodiment, for example, in the communication pattern analysis (step S10 in FIG. 7) described later, the communication program 125 transmits a transmission request to which ID information is not assigned by the ID operation program 122, and in the ID assignment process (step S12 in FIG. 7) described later, the communication program 125 transmits a transmission request to which ID information is assigned by the ID operation program 122.
[0023] The traffic information 126 is, for example, data in a table format, and stores information (traffic information) regarding received requests input to threads in a process and transmitted requests output from the threads. The ID correspondence information 127 stores trace information (ID information) included in received requests. The target information 128 stores information (for example, a process ID) that specifies a process to be assigned an ID (target process).
[0024] The pattern logic 129 is logic that determines whether there is a pattern to which trace information is to be added to a transmission request, and adds trace information to the target transmission request according to the corresponding pattern. The pattern logic 129 is prepared for the number of target patterns. The pattern logic 129 includes a determination logic 130 and a mapping logic 131. The determination logic 130 and the mapping logic 131 may be set by, for example, an administrator of the computer 100, or may be set by another system.
[0025] The determination logic 130 is logic that indicates a pattern to be determined for the receive requests and transmit requests of the process 110, i.e., a pattern to be determined for the receive requests and transmit requests of the traffic information 126. The pattern of the determination logic 130 is a pattern (an example of a generation relationship) in which one or more N transmit requests are generated for one receive request. The value of N is dynamically determined by the pattern analysis program 123 based on the traffic information 126.
[0026] The mapping logic 131 is logic for identifying send requests and receive requests that match a pattern when the determination logic 130 has determined the pattern. In this embodiment, the mapping logic 131 is logic for identifying a corresponding receive request and N send requests that are generated after receiving the receive request.
[0027] The filter information 132 stores information (filter information) that specifies the traffic information that the traffic acquisition program 121 acquires.
[0028] Next, the traffic information 126 will be described in detail.
[0029] FIG. 2 is a configuration diagram of the traffic information according to the first embodiment.
[0030] The traffic information 126 stores history information of information (trace information) related to requests (received requests) input to a process (target process) to which trace information is to be added and requests (transmitted requests) output from the target process. The traffic information 126 stores an entry for each request. The entry of the traffic information 126 includes fields for type 301, process ID 302, thread ID 303, source IP 304, source port 305, destination IP 306, and destination port 307.
[0031] Type 301 stores the type indicating whether the request corresponding to the entry is a receive request or a transmit request. Process ID 302 stores the ID (process ID) of the process related to the request corresponding to the entry. Thread ID 303 stores the ID (thread ID) of the thread related to the request corresponding to the entry. Source IP 304 stores the source IP (Internet Protocol) address of the request corresponding to the entry. Source Port 305 stores the source port number of the request corresponding to the entry. Destination IP 306 stores the destination IP address of the request corresponding to the entry. Destination Port 307 stores the destination port number of the request corresponding to the entry.
[0032] Next, the ID correspondence information 127 will be described in detail.
[0033] FIG. 3 is a configuration diagram of ID correspondence information according to the first embodiment.
[0034] The ID correspondence information 127 stores trace information included in a reception request (target reception request) to which trace information is to be added to the corresponding transmission request. The ID correspondence information 127 stores an entry for each target reception request.
[0035] An entry of the ID correspondence information 127 includes fields for a source IP 401 , a source port 402 , a destination IP 403 , a destination port 404 , and ID information 405 .
[0036] Source IP 401 stores the IP address of the sender of the receive request corresponding to the entry. Source Port 402 stores the port number of the sender of the receive request corresponding to the entry. Destination IP 403 stores the IP address of the destination of the receive request corresponding to the entry. Destination Port 404 stores the port number of the destination of the receive request corresponding to the entry. ID information 405 stores the ID information of the receive request corresponding to the entry. Note that ID information 405 may store only information (at least the trace ID) that needs to be included in the trace information of the send request among the trace information of the receive request.
[0037] Next, the filter information 132 will be described in detail.
[0038] FIG. 4 is a configuration diagram of the filter information according to the first embodiment.
[0039] The filter information 132 stores entries that specify requests that are not to be acquired by the traffic acquisition program 121. The entries of the filter information 132 include fields for a source IP 801, a source port 802, a destination IP 803, and a destination port 804.
[0040] Source IP 801 stores the IP address of the sender of the request that is not to be acquired. If any value is acceptable, then Source IP 801 stores a value indicating that any value is acceptable (for example, *). Source Port 802 stores the port number of the sender of the request that is not to be acquired. If any value is acceptable, then Source Port 802 stores a value indicating that any value is acceptable (for example, *). Destination IP 803 stores the IP address of the destination of the request that is not to be acquired. If any value is acceptable, then Destination IP 803 stores a value indicating that any value is acceptable (for example, *). Destination Port 804 stores the port number of the destination of the request that is not to be acquired. If any value is acceptable, then Destination Port 804 stores a value indicating that any value is acceptable (for example, *).
[0041] For example, the entry in the first line of the filter information 132 indicates that all requests with a destination IP address of 10.0.0.254 are to be excluded from acquisition.
[0042] Next, the computer 100 will be described in detail.
[0043] FIG. 5 is a hardware configuration diagram of a computer according to the first embodiment.
[0044] The computer 100 is configured by a physical computer such as a PC (Personal Computer) or a server. The computer 100 includes a processor 201, a communication interface (I / F) 202, a main storage device 203, an auxiliary storage device 204, and an internal bus 205. The processor 201, the communication interface (I / F) 202, the main storage device 203, and the auxiliary storage device 204 are connected via the internal bus 205.
[0045] The communication I / F 202 is, for example, an interface such as a wired LAN card or a wireless LAN card, and communicates with other devices (for example, other computers constituting a distributed system) via a network 210.
[0046] The processor 201 executes various processes according to programs stored in the main storage device 203 and / or the auxiliary storage device 204 .
[0047] The main memory device 203 is an example of a storage unit, and is, for example, a RAM (RANDOM ACCESS MEMORY), and stores programs executed by the processor 201 and necessary information. In this embodiment, the main memory device 203 stores, for example, an OS, a traffic acquisition program 121, an ID operation program 122, a pattern analysis program 123, a mapping program 124, a communication program 125, traffic information 126, ID correspondence information 127, target information 128, a pattern logic 129, and filter information 132. These may be stored in the auxiliary memory device 204. Here, the trace management program is composed of, for example, the traffic acquisition program 121, the ID operation program 122, the pattern analysis program 123, and the mapping program 124.
[0048] The auxiliary storage device 204 is an example of a storage unit, and is, for example, a hard disk drive or a solid state drive (SSD), and stores programs executed by the processor 201 and data used by the processor 201.
[0049] Next, the processing operation by the computer 100 will be described.
[0050] First, a description will be given of acquisition of various information by the computer 100. This acquisition of various information is performed, for example, every time the thread 111 of the target process 110 receives (inputs) or transmits (outputs) a request.
[0051] The traffic acquisition program 121 of the computer 100 acquires the destination IP, destination port, source IP, and source port of the received request and the transmitted request in the thread 111 of the target process 110, and stores them in the traffic information 126. For example, the traffic acquisition program 121 may acquire the destination IP, destination port, source IP, and source port from the output result of a command such as tcpconnect or tcpaccept in the BPF tool, or may acquire System call information, acquire the destination IP, destination port, source IP, and source port of the transmitted request from connect and getsocket, and acquire the destination IP, destination port, source IP, and source port of the received request from accept. Note that the traffic acquisition program 121 does not store requests that have an error (for example, a system call whose return value of System call information is other than 0) in the traffic information 126.
[0052] On the other hand, the ID operation program 122 of the computer 100 acquires the destination IP, destination port, source IP, and source port of the received request, and ID information (trace information) included in the HTTP header of the received request, for example, using a reverse proxy that receives the received request before the thread or a BPF tool, and stores them in the ID correspondence information 127. Note that the traffic acquisition program 121 does not store requests that have an error (for example, a system call where the return value of the System call information is other than 0) in the ID correspondence information 127.
[0053] In this way, the computer 100 can obtain and manage the destination IP, destination port, source IP, and source port of the received request and transmitted request in the thread 111, as well as the ID information of the received request.
[0054] Next, the trace information control process performed by the computer 100 will be described.
[0055] FIG. 7 is a flowchart of the trace information control process according to the first embodiment.
[0056] The pattern analysis program 123 of the ID assigning server 120 executes a communication pattern analysis using the judgment logic 130 of the pattern logic 129 to analyze whether or not the request of the traffic information 126 satisfies the pattern of the judgment logic 130 (step S10). The pattern analysis program 123 outputs the analysis result to a system log or the like. The pattern analysis program 123 may output the analysis result and the request related to the analysis result of the traffic information 126 to a user terminal or the like.
[0057] The pattern analysis program 123 executes the communication pattern analysis for, for example, a certain period of time (for example, 5 minutes) and / or until the analyzed traffic volume (amount of requests) reaches a certain volume. Note that, if the communication pattern analysis does not detect that the pattern of the determination logic 130 is satisfied, the pattern analysis program 123 determines that there is no communication pattern.
[0058] Next, the mapping program 124 judges whether or not the ID assignment process can be performed, that is, whether or not the analysis result indicates that the pattern of the judgment logic 130 is satisfied (step S11). As a result, if the analysis result indicates that the pattern of the judgment logic 130 is not satisfied (step S11: No), the mapping program 124 ends the process, whereas if the analysis result indicates that the pattern of the judgment logic 130 is satisfied (step S11: Yes), the mapping program 124 advances the process to step S12.
[0059] In step S12, the mapping program 124 and the ID operation program 122 constantly execute the ID assignment process. In the ID assignment process, the mapping program 124 uses the mapping logic 131 to identify corresponding reception requests and transmission requests in the traffic information 126. In this embodiment, it is identified that one reception request corresponds to N transmission requests transmitted thereafter. Here, the mapping program 124 collectively stores a set of the source IP, source port, destination IP, and destination port for the identified reception request and transmission request. Next, the ID operation program 122 assigns the ID information of the reception request to the transmission request identified by the mapping program 124. Specifically, the mapping program 124 acquires the ID information of the reception request from the ID correspondence information 127, and sets the ID information based on the acquired ID information as a parameter of the HTTP header of the transmission request. Note that, when the mapping program 124 has transmitted all transmission requests corresponding to the reception request, for example, when a normal response corresponding to the reception request is returned, the entry of this reception request may be deleted from the ID correspondence information 127.
[0060] In this manner, the transmission request to which the ID information has been assigned by the mapping program 124 is transmitted by the communication program 125 to the device that is the destination of the transmission request.
[0061] According to the above embodiment, it is possible to appropriately add information that needs to be propagated in the trace information of a received request corresponding to a send request output from the process 110 to the trace information without making any changes to the process 110. This makes it possible to appropriately trace the flow of a request using the trace information (such as a trace ID) added to the request and use it for analysis.
[0062] Next, a second embodiment will be described.
[0063] FIG. 8 is a diagram for explaining an example of a process that is a target of a computer according to the second embodiment.
[0064] The process 110 targeted by the computer 100A (see FIG. 9) according to the second embodiment is assumed to be a process in which the thread 111 (Thread 1) that receives a receive request is different from the threads 111 (Threads 1000, 1001) that output a transmit request. In this embodiment, there are multiple threads 111 that output transmit requests, and processing based on the receive requests is assigned to these threads 111 in a round robin manner (in order). In this process 110, the traffic information for Thread 1 is only the receive request, and the traffic information for Thread 1000 and Thread 1001 is only the transmit request.
[0065] In this process 110, when Thread 1 receives a receive request (receive A), Thread 1000 outputs a transmit request (transmit B) corresponding to this receive request, and when Thread 1 receives a receive request (receive C), the next Thread 1001 outputs a transmit request (transmit D) corresponding to this receive request. Similarly, when a receive request (receive E) is received, the next Thread 1000 outputs a transmit request (transmit F) corresponding to the receive request. In the example of FIG. 8, thread 111 transmits one transmit request for one receive request, but thread 111 may transmit multiple transmit requests for one receive request. Note that the output order of transmit requests in one thread 111 is assumed to maintain the order of the corresponding receive requests.
[0066] Next, a computer 100A according to the second embodiment will be described.
[0067] 9 is a functional configuration diagram of a computer according to the second embodiment. In the computer 100A according to the second embodiment, the same components as those in the computer 100 according to the first embodiment are denoted by the same reference numerals.
[0068] In the computer 100A, the process 110 may have an information detection program 900. The information detection program 900 detects additional information in the process 110 (information similar to additional information 903 described later) and transmits the additional information to the ID assigning server 120A. If the information detection program 900 is not included, there is no need to change the program of the process 110, and if the information detection program 900 is included, it can be handled with a relatively simple change without making a major change to the program of the process 110.
[0069] The ID assignment server 120A further stores additional information 903 compared to the ID assignment server 120, has a pattern analysis program 901 instead of the pattern analysis program 123, has a mapping program 902 instead of the mapping program 124, and has a decision logic 904 and mapping logic 905 in the pattern logic 129.
[0070] The additional information 903 is information (an example of generation relationship information) indicating the execution order of multiple threads 111 in the process 110 and the number of transmission requests output from one thread 111 for one reception request. In this embodiment, the additional information 903 also includes information (samples) of sets of actual source IP, source port, destination IP, and destination port of the actual reception request and transmission request in the thread 111. The additional information 903 may be received from the information detection program 900 of the process 110, or may be accepted by input by the administrator of the computer 100A.
[0071] The pattern analysis program 901 uses the additional information 903 to determine whether the received requests and transmitted requests in the traffic information 126 match the patterns of the determination logic 904 of the pattern logic 129. The mapping program 902 uses the additional information 903 and the mapping logic 905 to identify corresponding received requests and transmitted requests from the traffic information 126 and associate them.
[0072] The determination logic 904 is logic that indicates conditions to be determined for the receive requests and transmit requests of the process 110, that is, a pattern to be determined for the receive requests and transmit requests of the traffic information 126. An example of a pattern of the determination logic 904 is that the order in which the threads 111 are called is round robin, the read order of the threads 111 is known, samples of the corresponding receive requests and transmit requests are provided as additional information 903, and the samples are actually stored in the traffic information 126.
[0073] The mapping logic 905 is a logic for identifying a reception request and a transmission request that match a pattern when the determination logic 130 has determined that the pattern exists. In this embodiment, the mapping logic 905 is a logic for repeatedly executing a process of identifying a next reception request and a transmission request of the next thread corresponding to the reception request from the traffic information 126 based on the correspondence between the reception request and the transmission request in the thread 111 of the additional information 903. For example, in the example of FIG. 8, the mapping logic 905 is a logic for identifying a correspondence between the next reception C and the next transmission D of the Thread 1001 from the samples of reception A and transmission B, and further similarly identifying subsequent receptions.
[0074] Next, the additional information 903 will be described.
[0075] FIG. 10 is a diagram illustrating an example of additional information according to the second embodiment.
[0076] The additional information 903 is, for example, information in a JSON (JavaScript (registered trademark) Oblect Notation) format. The additional information 903 includes an order description area 951 that describes the call order of each thread 111 of the same process 110, and a sample description area 952 that describes a sample of traffic information. The order description area 951 is not necessary when samples for all threads 111 are described in the sample description area 952 according to the call order.
[0077] The sample description area 952 has one or more thread description areas 953. When the call order of the threads 111 is described in the order description area 951, the sample description area 952 may have only one thread description area 953 for one thread 111.
[0078] The thread description area 953 includes a thread ID area 954, reception request information 955, and one or more pieces of transmission request information 956. When multiple transmission requests are sent in response to one reception request, the transmission request information 956 includes as many pieces of transmission requests as there are to be sent. The thread ID area 954 stores the thread ID of the thread 111 corresponding to the thread description area 953. The reception request information 955 stores information (source IP, source port, destination IP, and destination port) of a transmission request that exists in the traffic information 126 and that has called the thread 111. The transmission request information 956 stores information (source IP, source port, destination IP, and destination port) of a transmission request that exists in the traffic information 126 and that is sent based on the reception request.
[0079] According to this additional information 903, the relationship between the received request in the traffic information 126 and the transmission request corresponding to the received request can be properly understood.
[0080] Next, an example of the traffic information 126 when the additional information 903 is in the state shown in FIG. 10 will be described.
[0081] FIG. 11 is a diagram illustrating an example of traffic information according to the second embodiment.
[0082] The configuration of the entries of the traffic information 126 shown in FIG. 11 is the same as that of the traffic information 126 shown in FIG. 2, and the values of each entry of the traffic information 126 correspond to the process 110 shown in FIG. 8 and the additional information 903 shown in FIG. 10.
[0083] In the traffic information 126, as shown in the first line, a reception request is received by Thread1, and as shown in the second line, Thread1000 is called by this reception request to transmit a transmission request, and as shown in the third line, the next reception request is received by Thread1, and as shown in the fourth line, Thread1001, which is the next thread 111, is called by this reception request to transmit a transmission request, and every time a reception request is received thereafter, the next thread 111 is called to transmit a transmission request. Note that in the traffic information 126 of FIG. 11, an example is shown in which a reception request and a corresponding transmission request are arranged in consecutive rows, but in some cases, multiple reception requests may occur consecutively, or a transmission request corresponding to a previous reception request may occur next to a reception request. Based on the additional information 903, the correspondence between the reception request and the transmission request in the traffic information 126 can be appropriately understood. Specifically, the additional information 903 includes an actual sample, and a specific corresponding reception request and a specific transmission request in the traffic information 126 can be identified. Therefore, the next receive request and the send request of the next thread corresponding to the receive request can be appropriately identified.
[0084] The trace information control process by the computer 100A according to the second embodiment is obtained by replacing the processing of the programs of the computer 100 and the like in the trace information control process shown in FIG. 7 with the processing of the programs of the computer 100A and the like.
[0085] According to the computer 100A of the second embodiment, the thread 111 that receives the receive request is different from the thread 111 that outputs the transmit request, and even for a process 110 having multiple threads 111 that transmit transmit requests, trace information can be appropriately added to the transmit request corresponding to the receive request.
[0086] The present invention is not limited to the above-described embodiment, and can be modified as appropriate without departing from the spirit of the present invention.
[0087] For example, in the above embodiment, the filter information 132 is a so-called blacklist that specifies requests that are not to be acquired, but the present invention is not limited to this. For example, the filter information 132 may be a so-called whitelist that specifies requests that are to be acquired.
[0088] In the above-described embodiments, a part or all of the processing performed by the processor may be performed by a hardware circuit. The programs in the above-described embodiments may be installed from a program source. The program source may be a program distribution server or a storage medium (e.g., a portable storage medium). [Explanation of symbols]
[0089] 100, 100A...computer, 110...process, 111...thread, 120...ID assignment server, 121...traffic acquisition program, 122...ID operation program, 123, 901...pattern analysis program, 124, 902...mapping program, 125...communication program, 126...traffic information, 127...ID correspondence information, 128...target information, 129...pattern logic, 130, 904...judgment logic, 131, 905...mapping logic, 132...filter information, 201...processor, 202...communication I / F, 203...main memory device, 204...auxiliary memory device, 205...internal bus, 210...network, 900...information detection program, 903...additional information
Claims
1. A trace management device that inputs a reception request received from a first device, executes a process of outputting a transmission request to be transmitted to a second device, and adds trace information to the transmission request and transmits it to the second device, A processor is included. The processor, Identifying a corresponding transmission request and a reception request based on a generation relationship between the reception request and the transmission request corresponding to the reception request in the process; Transmitting at least a part of the trace information added to the specified reception request to the second device, the trace information being added to the specified transmission request; Further comprising a storage unit, The processor, storing history information of reception requests and transmission requests in the process in the storage unit; determining whether or not a predetermined generation relationship exists between the received request and the transmitted request based on the history information; If the predetermined generating relationship exists, identifying corresponding send requests and receive requests based on the predetermined generating relationship; The predetermined generating relationship is a relationship in which one or more send requests are generated after a receive request is input in one thread of the process. Trace management device.
2. A trace management device that inputs a reception request received from a first device, executes a process of outputting a transmission request to be transmitted to a second device, and adds trace information to the transmission request and transmits it to the second device, A processor is included. The processor, Identifying a corresponding transmission request and a reception request based on a generation relationship between the reception request and the transmission request corresponding to the reception request in the process; Transmitting at least a part of the trace information added to the specified reception request to the second device, the trace information being added to the specified transmission request; Further comprising a storage unit, The processor, storing history information of reception requests and transmission requests in the process in the storage unit; determining whether or not a predetermined generation relationship exists between the received request and the transmitted request based on the history information; If the predetermined generating relationship exists, identifying corresponding send requests and receive requests based on the predetermined generating relationship; The predetermined generating relationship is a relationship in which a send request corresponding to each receive request is processed in sequence by multiple threads in the process. Trace management device.
3. the storage unit stores, as the generation relationship information indicating the predetermined generation relationship, information on an order of a thread to which a process based on a reception request is handed over when a transmission request corresponding to the reception request is generated by a plurality of threads in a process, and information on the number of transmission requests generated for one reception request in the thread; The processor, Identifying corresponding send requests and receive requests based on the predetermined generating relationship based on the generating relationship information. The trace management device according to claim 2 .
4. The processor, By executing the process, generation relationship information is generated and stored in the storage unit, the generation relationship information including information on the order of threads to which processing based on a reception request is handed over when transmission requests corresponding to a reception request are generated in a plurality of threads in the process, and information on the number of transmission requests generated for one reception request in the thread. The trace management device according to claim 3.
5. the storage unit stores filter information that defines reception requests and transmission requests that are targets of the history information; The processor selects receive requests and transmit requests to store in the history information based on the filter information.
3. The trace management device according to claim 1 or 2.
6. The processor, Outputting a determination result as to whether or not a predetermined generation relationship exists between the received request and the transmitted request.
3. The trace management device according to claim 1 or 2.
7. The processor, Outputting history information of the reception request and the transmission request related to the determination together with the determination result. The trace management device according to claim 6.
8. 1. A trace management method by a trace management device, which inputs a reception request received from a first device, executes a process to output a transmission request to be transmitted to a second device, and adds trace information to the transmission request and transmits it to the second device, The trace management device includes: Identifying a corresponding transmission request and a reception request based on a generation relationship between the reception request and the transmission request corresponding to the reception request in the process; Transmitting at least a part of the trace information added to the specified reception request to the second device, the trace information being added to the specified transmission request; storing history information of the received requests and the transmitted requests in the process in a storage unit of the trace management device; determining whether or not a predetermined generation relationship exists between the received request and the transmitted request based on the history information; If the predetermined generating relationship exists, identifying corresponding send requests and receive requests based on the predetermined generating relationship; The predetermined generating relationship is a relationship in which one or more send requests are generated after a receive request is input in one thread of the process. Trace management methods.
9. 1. A trace management method by a trace management device, which inputs a reception request received from a first device, executes a process to output a transmission request to be transmitted to a second device, and adds trace information to the transmission request and transmits it to the second device, The trace management device includes: Identifying a corresponding transmission request and a reception request based on a generation relationship between the reception request and the transmission request corresponding to the reception request in the process; Transmitting at least a part of the trace information added to the specified reception request to the second device, the trace information being added to the specified transmission request; storing history information of the received requests and the transmitted requests in the process in a storage unit of the trace management device; determining whether or not a predetermined generation relationship exists between the received request and the transmitted request based on the history information; If the predetermined generating relationship exists, identifying corresponding send requests and receive requests based on the predetermined generating relationship; The predetermined generating relationship is a relationship in which a send request corresponding to each receive request is processed in sequence by multiple threads in the process. Trace management methods.
10. 1. A trace management program executed by a computer, the program inputting a receive request received from a first device, executing a process for outputting a transmit request to be transmitted to a second device, and attaching trace information to the transmit request and transmitting the transmit request to the second device, the program comprising: The computer includes: Identifying a corresponding transmission request and a reception request based on a generation relationship between the reception request and the transmission request corresponding to the reception request in the process; transmitting at least a part of the trace information assigned to the specified reception request to the second device, the trace information being included in the trace information assigned to the specified transmission request; storing history information of receive requests and transmit requests in the process in a storage unit of the computer; determining whether or not a predetermined generation relationship exists between the received request and the transmitted request based on the history information; if the predetermined generating relationship exists, identifying corresponding send requests and receive requests based on the predetermined generating relationship; The predetermined generating relationship is a relationship in which one or more send requests are generated after a receive request is input in one thread of the process. Trace management program.
11. 1. A trace management program executed by a computer, the program inputting a receive request received from a first device, executing a process for outputting a transmit request to be transmitted to a second device, and attaching trace information to the transmit request and transmitting the transmit request to the second device, the program comprising: The computer includes: Identifying a corresponding transmission request and a reception request based on a generation relationship between the reception request and the transmission request corresponding to the reception request in the process; transmitting at least a part of the trace information assigned to the specified reception request to the second device, the trace information being included in the trace information assigned to the specified transmission request; storing history information of receive requests and transmit requests in the process in a storage unit of the computer; determining whether or not a predetermined generation relationship exists between the received request and the transmitted request based on the history information; if the predetermined generating relationship exists, identifying corresponding send requests and receive requests based on the predetermined generating relationship; The predetermined generating relationship is a relationship in which a send request corresponding to each receive request is processed in sequence by multiple threads in the process. Trace management program.
Citation Information
Patent Citations
Retrieval information recording device
JP1998222450A
Pattern match system for message trace and pattern match method and record medium recording program for pattern match
JP2000137626A
System, method, and computer program for recording operation log
JP2009053740A
Communication system, relay apparatus and program
JP2009100359A
Trace management
US20200201750A1