Log analysis apparatus, log analysis method, and log analysis program
The log analysis apparatus efficiently converts detailed trace information into summary metrics for improved analysis efficiency and accuracy, addressing the limitations of existing technologies by enabling rapid comparison and problem identification.
Patent Information
- Application Number
- JP2023053319
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-29
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2043-03-29
AI Technical Summary
Existing log analysis technologies do not efficiently convert detailed trace information into summary metrics, leading to prolonged analysis times and reduced accuracy in identifying problem causes.
A log analysis apparatus and method that acquire metrics for log outlines and traces for detailed information, convert traces to approximate the data format of metrics for comparison, and display both on a unified analysis screen, facilitating efficient comparison and analysis.
This approach significantly improves the efficiency and accuracy of log analysis by enabling quick conversion and comparison of detailed trace information with summary metrics, thereby shortening problem-solving times.
Smart Images

Figure 0007697982000001 
Figure 0007697982000002 
Figure 0007697982000003
Abstract
Description
Technical Field
[0001] The present invention relates to a log analysis apparatus, a log analysis method, and a log analysis program.
Background Art
[0002] For example, in a system executed on a computer, logs including event results or messages are output. When an abnormality occurs in the system or the like, the user identifies the cause of the abnormality by analyzing and examining the output logs. Conventionally, as an apparatus for analyzing logs, there is, for example, Patent Document 1.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, Patent Document 1 does not describe anything regarding improving the efficiency and accuracy of log analysis and shortening the time to solve problems by performing an approximate conversion from detailed information in a trace to summary information in metrics for logs output from a monitoring target, visualizing information with different granularities in a unified data format, and facilitating comparison.
[0005] The present invention has been made in view of the above, and an object of the present invention is to provide a log analysis apparatus, a log analysis method, and a log analysis program capable of improving the efficiency and accuracy of log analysis and shortening the time to solve problems by performing an approximate conversion from detailed information in a trace to summary information in metrics for logs output from a monitoring target, visualizing information with different granularities in a unified data format, and facilitating comparison.
Means for Solving the Problems
[0006] In order to solve the above problems and achieve the object, the present invention includes an acquisition means for acquiring a metric for checking an outline of a log output from a monitoring target and a trace for checking details, a conversion means for converting the trace so as to approximate the data format of the metric to be compared, and an output means for displaying and outputting the metric to be compared and the converted trace on a comparison analysis screen.
[0007] Further, according to one aspect of the present invention, the trace includes a process that is a unit for recording a log to be a conversion source or a unit for logically aggregating a call source of the process, an end time, a process time, and weight information that is an index of the conversion source corresponding to the metric to be compared.
[0008] Further, according to one aspect of the present invention, the process may include a screen name or job name of an application log, a URI of a web server, or a stored procedure or function name of a DB log, and the weight may include CPU time that is a CPU load, physical read that is a memory load, physical read / write that is a disk load, or the number of data acquisition rows that is a network load and the number of rows to be updated.
[0009] Further, according to one aspect of the present invention, the conversion means calculates a start time from the end time and the process time for the trace, calculates an average weight per acquisition interval of the metric to be compared, maps the calculated weight per time to a table in time series, generates a stacked graph with the horizontal axis being time and the vertical axis being the magnitude of the weight, and may use the waveform of the stacked graph as an approximation value of the metric to be compared.
[0010] Further, according to one aspect of the present invention, the conversion means may include a load ranking generation function for generating a load ranking of each process for a specific period based on a table in which the calculated weight per time is mapped in time series.
[0011] Further, according to one aspect of the present invention, the conversion means may be provided with a simulation function of changing the weight of the processing in each time zone by a user operation and generating a stacked graph with the horizontal axis representing time and the vertical axis representing the magnitude of the weight for the changed weight.
[0012] Also, in order to solve the above-described problems and achieve the object, the present invention is a log analysis method executed by an information processing apparatus including a control unit, the method including: an acquisition step of acquiring a metric for confirming an outline of a log output from a monitoring target and a trace for confirming details; a conversion step of converting the trace so as to approximate the data format of the metric to be compared; and an output step of displaying and outputting the metric to be compared and the converted trace on a comparison analysis screen.
[0013] Also, in order to solve the above-described problems and achieve the object, the present invention is a log analysis program for execution by an information processing apparatus including a control unit, the program including: an acquisition step of acquiring a metric for confirming an outline of a log output from a monitoring target and a trace for confirming details; a conversion step of converting the trace so as to approximate the data format of the metric to be compared; and an output step of causing a computer to display and output the metric to be compared and the converted trace on a comparison analysis screen, the log analysis program being characterized by this.
Effect of the Invention
[0014] According to the present invention, for a log output from a monitoring target, approximate conversion from a trace, which is detailed information, to a metric, which is outline information, is performed, and information with different granularities is visualized in a unified data format for easy comparison, thereby making it possible to improve the efficiency and accuracy of log analysis. This has the effect of achieving this.
Brief Description of the Drawings
[0015]
Figure 1
Figure 2
Figure 3
Figure 4A
Figure 4B
Figure 5A
Figure 5B
Figure 6
Figure 7
[0016] Embodiments of the present invention will be described in detail with reference to the drawings. Note that the present invention is not limited to the present embodiments.
[0017] [1. Overview] For example, in software monitoring, logs output from a monitoring target include a plurality of types of information such as metrics (summary information) for monitoring an overview and traces (detailed information) for monitoring details.
[0018] Traces have detailed information, but there is a problem in that the number of data is large and analysis takes time. Therefore, conventionally, a technique has been employed in which an abnormality is detected based on aggregated information such as metrics, and the analysis target is narrowed by setting the traces in the corresponding time range as the investigation target. That is, it has been necessary to detect an abnormality from the overview and then confirm the detailed information again.
[0019] However, with this method, it is necessary for a person to judge the association between data, which has problems such as taking a long time for analysis and making judgment errors. In addition, it is common for development and operation members to be separated, and since the members who check each piece of information are different, there are few opportunities for mutual confirmation.
[0020] In this embodiment, paying attention to the fact that as the importance of software increases socially, the number of monitoring targets increases and it is urgent to reduce the operation load, and that since it is carried out in one stop from development to operation and maintenance, there are findings by checking various logs.
[0021] In this embodiment, an approximate conversion from trace, which is detailed information, to metrics, which is summary information, is performed, and information with different granularities is visualized in a unified data format to facilitate comparison, thereby enabling the efficiency of analysis to be improved, the accuracy to be enhanced, and the time to solve problems to be shortened.
[0022] Referring to FIGS. 1 and 2, the background that poses problems will be described in detail. The logs required for software monitoring are provided by various systems such as the OS and MW (middleware), but it is difficult to handle them without mutual confirmation. In addition, the logs are of the following types, and since the granularities are different, it is difficult to grasp the association of logs for the same period.
[0023] Metrics are logs that record and process activities. Generally, they are data obtained by aggregating data for a certain period, and although the state can be confirmed with a small amount of data, on the other hand, detailed cause analysis is difficult. Metrics are, for example, Windows (registered trademark) performance logs (recording the average CPU usage rate per second or every 15 seconds, etc.).
[0024] A trace is a log that records what has occurred according to the time series. Generally, it is data that sequentially records the processes that occur within a program. It can be used for root cause analysis, but on the other hand, it has the characteristics that the data volume becomes large, so the capacity of the recording medium and the analysis cost are high. A trace is, for example, an extended event in SQL Server (which can record the start and end of specific processes, the resources consumed in the corresponding processes, etc.).
[0025] Figure 1 is a diagram showing an example of a metric (CPU usage rate obtained by the Windows (registered trademark) Performance Monitor). The horizontal axis is the time axis, and the vertical axis plots the CPU usage rate.
[0026] Figure 2 is a diagram showing an example of a trace (extended event in SQL Server). Processing time, CPU time, physical read count, etc. can be confirmed. The result of recording the completion of processing with the extended event is transferred to Excel, and the time axis is plotted on the horizontal axis and the cpu_time column is plotted on the vertical axis.
[0027] Although both of the above examples are metrics focusing on the CPU, it is difficult to analyze the causal relationship because the granularity of the logs is different. Since it is recorded at the time of completion in the trace, the relationship with the start time of the process (= the time when CPU utilization starts) and the usage rate is unclear.
[0028] What is recorded by the metric is "usage rate", and what is recorded by the trace is "CPU time", so conversion is required. "CPU time" is the time when the CPU is utilized in the corresponding process. For the sake of simplicity, when a process that loads the CPU is executed on a server with only 1 core of CPU, it is recorded as follows.
[0029] When process A that completes in 10 seconds alone is executed, process A has a processing time of 10 seconds and a CPU time of 10 seconds. When process A and process B that complete in 10 seconds alone are executed simultaneously, process A has a processing time of 20 seconds and a CPU time of 10 seconds, and process B has a processing time of 20 seconds and a CPU time of 10 seconds.
[0030] In the present invention, by converting traces (detailed information) into the form of metrics (summary information), the time from situation understanding to cause analysis is shortened.
[0031] The log analysis device of the present invention is applicable to all industries and all sectors.
[0032] [2. Configuration] With reference to FIG. 3, an example of the configuration of the log analysis device 100 according to the present embodiment will be described. FIG. 3 is a block diagram showing an example of the configuration of the log analysis device 100.
[0033] The log analysis device 100 is, for example, a commercially available desktop personal computer, a workstation, or the like.
[0034] The log analysis device 100 includes a control unit 102, a communication interface unit 104, a storage unit 106, and an input / output interface unit 108. Each part included in the log analysis device 100 is communicably connected via an arbitrary communication path.
[0035] The communication interface unit 104 communicably connects the log analysis device 100 to the network 300 via a communication device such as a router and a wired or wireless communication line such as a dedicated line. The communication interface unit 104 has a function of communicating data with other devices via a communication line. Here, the network 300 has a function of communicably connecting the log analysis device 100, the server 200, and a system to be monitored (not shown) to each other, and is, for example, the Internet or a LAN (Local Area Network).
[0036] An input / output interface unit 108 is connected to an input device 112 and an output device 114. In addition to a monitor (including a home TV), a speaker or a printer can be used as the output device 114. In addition to a keyboard, a mouse, and a microphone, a monitor that cooperates with the mouse to realize a pointing device function can be used as the input device 112. In the following, the output device 114 may be described as the monitor 114, and the input device 112 may be described as the keyboard 112 or the mouse 112. Also, displaying information on the monitor 114 and the user operating the input device 112, etc. may be described as "user operation via the UI".
[0037] The storage unit 106 stores various databases, tables, and files, etc. A computer program for giving instructions to the CPU (Central Processing Unit) to perform various processes in cooperation with the OS (Operating System) is recorded in the storage unit 106. As the storage unit 106, for example, a memory device such as a RAM (Random Access Memory)·ROM (Read Only Memory), a fixed disk device such as a hard disk, a flexible disk, and an optical disk, etc. can be used. The storage unit 106 stores information such as traces and metrics.
[0038] The control unit 102 is a CPU or the like that comprehensively controls the log analysis device 100. The control unit 102 has an internal memory for storing control programs such as the OS, programs defining various processing procedures, etc., and required data, etc., and executes various information processes based on these stored programs.
[0039] The control unit 102 is configured to be able to access information such as traces and metrics stored in the storage unit 106. Note that the information such as traces and metrics may be stored in another location (for example, the server 200), as long as the control unit 102 can access it.
[0040] Functionally conceptually, the control unit 102 includes an acquisition unit 102a, a conversion unit 102b, and an output unit 102c.
[0041] The acquisition unit 102a acquires a metric for checking the outline of the log output from the system to be monitored and a trace for checking the details, and stores them in the storage unit 106.
[0042] The conversion unit 102b converts the trace so as to approximate it to the data format of the metric to be compared.
[0043] In this case, the "trace" may include a process that is a unit for recording the log to be converted or a unit for logically aggregating the call sources of the processes, an end time, a processing time, and weight information that is an index of the conversion source corresponding to the metric to be compared.
[0044] The "process" may include the screen name or job name of the application log, the URI of the web server, or the stored procedure or function name of the DB log. The "weight" may include the CPU time that is the CPU load, the physical read that is the memory load, the physical read / write that is the disk load, or the number of data acquisition rows or the number of updated target rows that is the network load.
[0045] Also, the conversion unit 102b calculates the start time from the end time and the processing time for the trace, calculates the average weight per acquisition interval of the metric to be compared, maps the calculated weight per time to a table in time series, generates a stacked graph with the horizontal axis being time and the vertical axis being the magnitude of the weight, and may use the waveform of the stacked graph as an approximation of the metric to be compared.
[0046] Also, the conversion unit 102b may be provided with a load ranking generation function that generates a load ranking for each process in a specific period based on the table in which the calculated weight per time is mapped in time series.
[0047] Further, the conversion unit 102b may be provided with a simulation function that changes the weights of the processes in each time zone according to user operations and generates a stacked graph with the horizontal axis representing time and the vertical axis representing the magnitude of the weights for the changed weights.
[0048] The output unit 102c displays and outputs the metrics to be compared and the converted trace on the comparison analysis screen of the monitor 114, and visualizes them so that the two can be easily compared.
[0049] [3. Specific Example] With reference to FIGS. 3 to 7, a specific example of the processing of the control unit 102 of the log analysis apparatus 100 in the present embodiment will be described. FIGS. 4 to 7 are diagrams for explaining a specific example of the processing of the control unit 102 of the log analysis apparatus 100 in the present embodiment.
[0050] (3-1. Outline of Log Conversion) With reference to FIGS. 4A and 4B, the outline of the log conversion executed by the conversion unit 102b will be described. FIGS. 4A and 4B are diagrams for explaining the outline of the log conversion executed by the conversion unit 102b.
[0051] The conversion unit 102b converts the point information of the trace into the line information of the metrics. Here, the definitions of "process" and "weight" are as follows.
[0052] "Process" refers to a unit for recording a log that is a conversion source such as a trace or a unit for logically aggregating the call sources of the processes. For example, "process" is an application log: screen name or job name, web server: URI, DB log (extended event, etc.): stored procedure or function name.
[0053] "Weight" is an index of the conversion source corresponding to the metrics to be compared (explained here based on extended events). For example, "weight" is CPU load: CPU time, memory load: physical read (disk read occurs when there is no data in the cache), disk load: physical read / write, network load: number of data acquisition rows, number of updated target rows.
[0054] (1) In tracing, the information of points is recorded as described above. FIG. 4A(A) is a diagram showing an example of the information of the trace to be recorded. In this example, for process A, the end time is "09:40", the processing time is "0:20", and the weight is "60"; for process B, the end time is "10:00", the processing time is "0:50", and the weight is "50"; for process C, the end time is "10:40", the processing time is "1:10", and the weight is "70".
[0055] (2) Calculate the start time from the end time and the processing time. FIG. 4A(B) is a diagram showing an example of calculating the start time. For process A, the start time is "09:20 (= 09:40 - 0:20)"; for process B, the disclosure time is "09:10 (= 10:00 - 0:50)"; for process C, the start time is "09:30 (= 10:40 - 1:10)".
[0056] (3) Calculate the average weight per acquisition interval (here it is 10 minutes) of the metrics to be compared. FIG. 4B(C) is a diagram showing an example of calculating the weight per unit time. For process A, the weight per unit time is "3 (= 60 ÷ 20)"; for process B, the weight per unit time is "1 (= 50 ÷ 50)"; for process C, the weight per unit time is "1 (= 70 ÷ 70)".
[0057] (4) Map the calculated weight per unit time to a time-series table. FIG. 4B(D) is a diagram showing an example of mapping the calculated weight per unit time to a time-series table (at 10-minute intervals).
[0058] (5) Generate a stacked graph with the horizontal axis representing time and the vertical axis representing the magnitude of the weight. FIG. 4B(E) shows the weights for each time of processes A, B, and C. FIG. 4B(F) shows an example of the stacked graph of processes A, B, and C with the horizontal axis representing time and the vertical axis representing the magnitude of the weight. The waveform of this stacked graph becomes the approximate value of the metrics.
[0059] (3-2. Specific example of logarithmic conversion) Referring to FIGS. 5A and 5B, a specific example of the log conversion described in the overview of the log conversion will be described. FIGS. 5A and 5B are diagrams for explaining a specific example of the log conversion of the conversion unit 102b. Hereinafter, the case where the trace: extended event (log of SQL Server), process: stored procedure, and weight: CPU time will be described.
[0060] (1) In the trace, the point information is recorded as described above. FIG. 5A(A) is a diagram showing an example of the trace information to be recorded. In this example, for stored procedure A, the end time is "09:40", the processing time is "0:20", the CPU time is "1:00", for stored procedure B, the end time is "10:00", the processing time is "0:50", the CPU time is "0:50", and for stored procedure C, the end time is "10:40", the processing time is "1:10", and the CPU time is "1:10".
[0061] (2) Calculate the start time from the end time and the processing time. FIG. 5A(B) is a diagram showing an example of calculating the start time. For stored procedure A, the start time is "09:20 (= 09:40 - 0:20)", for stored procedure B, the disclosure time is "09:10 (= 10:00 - 0:50)", and for stored procedure C, the start time is "09:30 (= 10:40 - 1:10)".
[0062] (3) Calculate the average number of CPU usage cores per acquisition interval (here, 10 minutes) of the metrics to be compared. Note that when the CPU time > the processing time, it is assumed that parallel processing is being performed using multiple cores.
[0063] FIG. 5A(C) is a diagram showing an example of calculating the average number of CPU usage cores. For stored procedure A, the number of CPU usage cores per hour is "3 (= 60 ÷ 20)", for stored procedure B, the number of CPU usage cores per hour is "1 (= 50 ÷ 50)", and for stored procedure C, the number of CPU usage cores per hour is "1 (= 70 ÷ 70)".
[0064] (4) Map the calculated weight per time to a time-series table. FIG. 5A(D) is a diagram showing an example of mapping the calculated number of CPU cores used per time to a time-series table (at 10-minute intervals).
[0065] (5) Generate a stacked graph with the horizontal axis representing time and the vertical axis representing the number of CPU cores used. FIG. 5B(E) shows the weight for each time of stored procedures A, B, and C. FIG. 5B(F) shows an example of a stacked graph (approximate value) of stored procedures A, B, and C with the horizontal axis representing time and the vertical axis representing the number of CPU cores used. FIG. 5B(G) shows an example of a graph of metrics when the horizontal axis represents time and the vertical axis represents the CPU usage rate. The metrics to be compared and the converted trace in FIGS. 5B(E) and (F) are displayed and output on the comparison display screen by the output unit 102c and visualized.
[0066] As shown in FIGS. 5B(F) and (G), by comparing the cause of the abnormal value detected by monitoring the metrics with the converted trace, it can be identified that it is the stored procedure A (processing A).
[0067] In this example, since the CPU time is adopted as the criterion for "weight", it is possible to analyze the process where the CPU becomes a bottleneck. In addition to this, when physical reads are used as the "weight" criterion, it is possible to analyze the process where disk I / O becomes a bottleneck, and when the network transfer volume such as the number of rows retrieved is used as the criterion, it is possible to analyze the process where network I / O becomes a bottleneck.
[0068] Thus, according to this embodiment, general-purpose log conversion is possible by changing the criterion for "weight" according to the perspective to be analyzed.
[0069] (3-3. Developmental application example (1)) Referring to FIG. 6, the advanced application example (1) will be described. FIG. 6 is a diagram for explaining the advanced application example (1). The conversion unit 102b may be provided with a load ranking generation function that generates a load ranking for each process in a specific period based on a table in which the calculated weight per unit time is mapped in time series and displays and outputs it on a load ranking screen (not shown). By using the table of calculation results (FIG. 4B(D)) for obtaining an approximate value of the metric based on the weight of the unit time value, the ranking of the processes that have the highest load in a specific period can be generated.
[0070] As shown in FIGS. 6(A) to 6(D), a load ranking for a specific period is generated. Specifically, for example, the processes are rearranged in descending order of load for each specific period.
[0071] FIG. 6(A) shows the load ranking at 09:10. The process with the highest load at 09:10 is process B.
[0072] FIG. 6(B) shows the load ranking at 09:20. The process with the highest load at 09:20 is process A.
[0073] FIG. 6(C) shows the load ranking at 10:00. The process with the highest load at 10:00 is process C.
[0074] FIG. 6(D) shows the load ranking for the entire period. The process that has the highest total load over the entire period is process C.
[0075] This facilitates triage, such as prioritizing the processing in business-critical time periods, even when different processes are responsible for different time periods.
[0076] (3-4. Advanced Application Example (2)) Referring to FIG. 7, a developmental application example (2) will be described. FIG. 7 is a diagram for explaining the developmental application example (2). The conversion unit 102b may be provided with a simulation function of changing the weight of the processing in each time zone according to a user operation on a simulation screen (not shown), and generating a stacked graph with the horizontal axis representing time and the vertical axis representing the magnitude of the weight for the changed weight. That is, by providing a simulation function for the load improvement effect and manually changing the weight in each time zone, it becomes possible to simulate in advance the effect on the metrics by tuning the corresponding processing.
[0077] FIG. 7(A) is a diagram showing an example of mapping the calculated weight per time to a time-series table (at 10-minute intervals), which is the same as FIG. 4B(C). FIG. 7(B) is a diagram showing the case where the operator changes the weight of process A from "3" to "1".
[0078] FIG. 7(C) shows a stacked graph when the weight of process A is "3", which is the same as FIG. 4B(F). FIG. 7(D) shows a stacked graph when the weight of process A is changed to "1". As shown in this figure, the maximum value of the weight can be improved from "5" to "3".
[0079] This makes it possible to simulate in advance the investment effect due to the improvement of the processing, and facilitates the investment decision. Thus, according to this embodiment, by converting the display formats of logs of different granularities and types, it becomes possible to respond to anomalies quickly and surely.
[0080] As described above, according to this embodiment, an acquisition unit 102a that acquires metrics for checking the outline of logs output from a monitoring target and traces for checking details, a conversion unit 102b that converts the traces so as to approximate the data format of the metrics to be compared, and an output unit 102c that displays and outputs the metrics to be compared and the converted traces on a comparison analysis screen are provided. Therefore, for the logs output from the monitoring target, approximate conversion from the traces, which are detailed information, to the metrics, which are outline information, is performed, and information with different granularities is visualized in a unified data format for easy comparison, thereby improving the efficiency and accuracy of log analysis and shortening the time to solve problems.
[0081] [4. Contribution to the United Nations' Sustainable Development Goals (SDGs)] According to this embodiment, since it can contribute to improving business efficiency and making appropriate business judgments of enterprises, it is possible to contribute to Goals 8 and 9 of the SDGs.
[0082] In addition, according to this embodiment, since it can contribute to reducing waste loss and promoting paperless and digitalization, it is possible to contribute to Goals 12, 13, and 15 of the SDGs.
[0083] In addition, according to this embodiment, since it can contribute to strengthening control and governance, it is possible to contribute to Goal 16 of the SDGs.
[0084] [5. Other Embodiments] The present invention may be implemented in various different embodiments within the scope of the technical idea described in the claims, in addition to the above-described embodiments.
[0085] For example, among the processes described in the embodiment, all or part of the processes described as being automatically performed can be manually performed, or all or part of the processes described as being manually performed can be automatically performed by a known method.
[0086] In addition, the processing procedures, control procedures, specific names, information including parameters such as registered data and search conditions for each process, screen examples, and database configurations shown in this specification and the drawings can be arbitrarily changed unless otherwise specified.
[0087] Regarding the log analysis apparatus 100, each illustrated component is a functional concept and does not necessarily have to be physically configured as shown in the figure.
[0088] For example, with respect to the processing functions provided by the log analysis apparatus 100, particularly each processing function performed by the control unit, all or any part of them may be realized by a CPU and a program interpreted and executed by the CPU, or may be realized as hardware by wired logic. Note that the program is recorded on a non-transitory computer-readable recording medium including programmed instructions for causing an information processing apparatus to execute the processing described in this embodiment, and is mechanically read by the log analysis apparatus 100 as necessary. That is, in a storage unit such as a ROM or HDD (Hard Disk Drive), a computer program for giving instructions to the CPU in cooperation with the OS to perform various processes is recorded. This computer program is executed by being loaded into the RAM and constitutes the control unit in cooperation with the CPU.
[0089] In addition, this computer program may be stored in an application program server connected to the log analysis apparatus 100 via an arbitrary network, and all or part of it can be downloaded as necessary.
[0090] Also, a program for executing the processes described in this embodiment may be stored in a non-transitory computer-readable recording medium, or may be configured as a program product. Here, this "recording medium" includes any "portable physical medium" such as a memory card, a USB (Universal Serial Bus) memory, an SD (Secure Digital) card, a flexible disk, a magneto-optical disk, a ROM, an EPROM (Erasable Programmable Read Only Memory), an EEPROM (registered trademark) (Electrically Erasable and Programmable Read Only Memory), a CD-ROM (Compact Disk Read Only Memory), an MO (Magneto-Optical disk), a DVD (Digital Versatile Disk), and a Blu-ray (registered trademark) Disc.
[0091] Also, the "program" is a data processing method described in any language or description method, and is not limited to a specific form such as source code or binary code. Note that the "program" is not necessarily limited to being configured as a single entity, and also includes those that are distributed as a plurality of modules or libraries, or those that achieve their functions in cooperation with another program represented by an OS. Regarding the specific configuration, reading procedure, and installation procedure after reading for reading the recording medium in each device shown in the embodiment, well-known configurations and procedures can be used.
[0092] The various databases and the like stored in the storage unit are storage means such as a memory device such as a RAM or a ROM, a fixed disk device such as a hard disk, a flexible disk, and an optical disk, and store various programs, tables, databases, and web page files used for various processes and website provision.
[0093] Further, the log analysis device 100 may be configured as an information processing device such as a known personal computer or workstation, or may be configured as the information processing device to which an arbitrary peripheral device is connected. Further, the log analysis device 100 may be realized by installing software (including programs or data, etc.) that realizes the processing described in the present embodiment in the device.
[0094] Furthermore, the specific form of the distribution and integration of the devices is not limited to that shown in the drawings, and all or part of them can be functionally or physically distributed and integrated in arbitrary units according to various additions or according to the functional load. That is, the above-described embodiments may be arbitrarily combined and implemented, or the embodiments may be selectively implemented.
Explanation of Signs
[0095] 100 Log analysis device 102 Control unit 102a Acquisition unit 102b Conversion unit 102c Output unit 104 Communication interface unit 106 Storage unit 108 Input / output interface unit 112 Input device 114 Output device 200 Server 300 Network
Claims
1. An acquisition means for acquiring a metric for confirming an outline of a log output from a monitoring target and a trace for confirming details; A conversion means for converting the trace so as to approximate the data format of a metric to be compared; An output means for displaying and outputting the metric to be compared and the converted trace on a comparison analysis screen; A log analysis apparatus characterized by comprising the above.
2. The log analysis apparatus according to claim 1, wherein the trace includes a process that is a unit for recording a log to be a conversion source or a unit for logically aggregating a call source of the process, an end time, a process time, and weight information that is an index of the conversion source corresponding to a metric to be compared.
3. The process includes a screen name or job name of an application log, a URI of a web server, or a stored procedure or function name of a DB log, The log analysis apparatus according to claim 2, wherein the weight includes a CPU time that is a CPU load, a physical read that is a memory load, a physical read / write that is a disk load, or a data acquisition row count or an update target row count that is a network load.
4. The conversion means: Calculates a start time from the end time and the process time for the trace; Calculates an average weight per acquisition interval of a metric to be compared; Maps the calculated weight per time to a time-series table; Generates a stacked graph with time on the horizontal axis and the magnitude of the weight on the vertical axis, and makes the waveform of the stacked graph an approximation of the metric to be compared. The log analysis apparatus according to claim 3 is characterized by this.
5. The log analysis apparatus according to claim 4, wherein the conversion means has a load ranking generation function for generating a load ranking of each process for a specific period based on a table in which the calculated weight per time is mapped in time series.
6. The log analysis apparatus according to claim 4, wherein the conversion means has a simulation function for changing the weight of a process in each time zone by a user operation and generating a stacked graph with time on the horizontal axis and the magnitude of the weight on the vertical axis for the changed weight.
7. A log analysis method executed by an information processing apparatus including a control unit, the method comprising: An acquisition step of acquiring a metric for confirming an outline of a log output from a monitoring target and a trace for confirming details; A conversion step of converting the trace so as to approximate the data format of a metric to be compared; An output step of displaying and outputting a comparison analysis screen of a metric to be compared and a converted trace, and a log analysis method characterized by including the same.
8. A log analysis program for execution by an information processing apparatus including a control unit, an acquisition step of acquiring a metric for confirming an outline of a log output from a monitoring target and a trace for confirming details, a conversion step of converting the trace so as to approximate the data format of the metric to be compared, an output step of displaying and outputting a comparison analysis screen of the metric to be compared and the converted trace, A log analysis program for causing a computer to execute.
Citation Information
Patent Citations
Apparatus and method for visual generation of graphic display of trace data
JP1995110781A
Log analysis device, log analysis method, and recording medium for storing program
WO2017169949A1