Information Processing System and Log Recording Method in Information Processing System
The information processing system addresses overlapping user names by converting identification information within audit logs, ensuring accurate user attribution without manual matching, thereby simplifying log verification and enhancing system collaboration.
Patent Information
- Application Number
- JP2023095786
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-09
- Publication Date
- 2025-07-03
- Estimated Expiration
- 2043-06-09
AI Technical Summary
In systems collaborating via cloud services, overlapping user names make it difficult to determine which user performed an operation, necessitating cumbersome manual matching of unique identification information like UUID with user names in audit logs.
An information processing system that associates user identification information within the system with source user identification information, converting between them as needed for request processing and log output, ensuring user names are correctly attributed in audit logs without manual matching.
Audit logs accurately record user names from the source system, eliminating the need for manual UUID-to-user name matching, thus simplifying log verification and promoting system collaboration.
Smart Images

Figure 0007702448000001 
Figure 0007702448000002 
Figure 0007702448000003
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system and a log recording method in the information processing system.
Background Art
[0002] An audit log is used as one of the pieces of information for proving or confirming that the operation of an information system complies with laws and regulations, security evaluation criteria, etc.
[0003] In recent years, in addition to the method of directly managing systems such as servers and storage, services for managing these via cloud services have emerged. Even when operating a server or storage from such a cloud service, the server or storage records it in the audit log.
[0004] As the cooperation with such cloud services increases, the number of users increases, and the user names when operating from the cloud service and when directly operating the server or storage overlap, making it impossible to tell which user performed the operation even when looking at the audit log.
[0005] As a method of managing names such as such potentially conflicting user names so as not to overlap, there is a method of using UUID (Universally Unique Identifier). For example, in Patent Document 1, by using UUID to identify a server, it is possible to manage the server while avoiding duplication.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0007] When collaborating between systems, it is possible to avoid duplicate usernames and enable collaboration by using unique identification information such as UUID for the username.
[0008] However, if unique identification information such as UUID is output in the audit log that requires human confirmation, it becomes necessary to match the unique identification information such as UUID with the user by a person. This matching work is very cumbersome.
[0009] The present invention has been made in view of the above circumstances, and an object thereof is to generate a log that can be confirmed without matching users while avoiding duplicate usernames between systems.
Means for Solving the Problems
[0010] As one aspect for solving the above problems, there is provided an information processing system that cooperates with a source system and processes a request received via the source system and a request directly received without going through the source system. The information processing system includes a processor and a storage unit. The storage unit stores user information that manages, in association with each other, user identification information that uniquely identifies a user in the information processing system and source user identification information that identifies the source user in the source system when the user is the source user. The processor receives the request, determines whether the source user identification information corresponding to the identification information of the user included in the received request exists in the user information, and when the source user identification information exists in the user information, converts the identification information into the user identification information corresponding to the source user identification information in the user information, processes the request based on the user identification information, and when outputting a log related to the processing of the request, determines whether the source user identification information corresponding to the user identification information exists in the user information, and when the source user identification information corresponding to the user identification information exists in the user information, converts the user identification information into the source user identification information corresponding to the user identification information in the user information, and outputs the log including the source user identification information into which the user identification information has been converted.
Effect of the Invention
[0011] According to the present invention, after avoiding duplication of user names between systems, an operation performed from the source system can be recorded in the audit log of the destination system with the user name of the source system. As a result, the audit log can be confirmed without matching the UUID with the user.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Embodiments for Carrying Out the Invention
[0013] The embodiments will be described with reference to the drawings. Note that the embodiments described below do not limit the invention according to the claims, and not all of the elements and combinations thereof described in the embodiments are essential for the solution means of the invention.
[0014] In the following description, the program that realizes each processing function unit is executed by a processor (for example, a CPU (Central Processing Unit)), and the defined processing is performed while appropriately using a storage resource (for example, a memory) and / or a communication interface device (for example, a port). Therefore, the processing executed by each processing function unit may be the processing performed by the processor or a computer having the processor.
[0015] In the following description, various information is represented in a table format. However, the information is not limited to the table format and may be in other formats such as CSV (Comma Separated Values). Since the various information is independent of the data format, for example, "XXX table" can be referred to as "XXX information".
[0016] Among the items in the various information, the names such as "identification information", "ID", and "name" of the items that include information for distinguishing the corresponding record from other records may be replaced with each other. For example, "user ID" may be replaced with "user identification information".
[0017] [Embodiment 1] (Configuration of the cooperation system S according to Embodiment 1) FIG. 1 is a block diagram showing a schematic configuration example of the cooperation system S according to Embodiment 1.
[0018] In FIG. 1, the cooperation system S includes a source cooperation system 101, a destination cooperation system 102, a client 103, and the Internet 104 that connects them.
[0019] The source cooperation system 101 is connected to the destination cooperation system 102 and the client 103. The user operates the client 103 to connect to the source cooperation system 101 via the Internet 104. The operations performed on the source cooperation system 101 are transferred to the destination cooperation system 102 via the Internet 104 and processed as necessary.
[0020] Note that the client 103 is not limited to a terminal that connects to the source system 101 by a user's operation and transfers a request to the destination system 102. That is, the client 103 includes a terminal that connects to the destination system 102 by a user's operation and directly sends a request to the destination system 102.
[0021] In addition, the source system 101 holds source system user information 111 for performing authentication and authorization of users accessing the provided services.
[0022] The destination system 102 can be operated via the Internet 104 from the source system 101 and can also be directly accessed.
[0023] In addition, the destination system 102 holds destination system user information 121 for performing authentication and authorization of users who perform operations. Furthermore, it has an audit log 122 for leaving a record of operations by users.
[0024] The client 103 is a system that serves as an interface for a user to connect to and use the source system 101 via the Internet 104. Specifically, it is a computer, a smartphone, and a web browser or application operating thereon.
[0025] The Internet 104 is a network that interconnects the source system 101, the destination system 102, and the client 103. Note that the Internet 104 may be replaced with any network such as a LAN (Local Area Network).
[0026] (Hardware Configuration of the Destination System 102 According to Embodiment 1) FIG. 2 is a block diagram showing a hardware configuration example of the destination system 102 according to Embodiment 1.
[0027] In FIG. 2, the cooperation destination system 102 is configured to include a CPU (Central Processing Unit) 202, a memory 203, a drive 204, and a NIC (Network Interface Card) 205. The CPU 202, the memory 203, the drive 204, and the NIC 205 are connected to each other via a bus 201.
[0028] The memory 203 is a main storage device that can be read from and written to by the CPU 202. The memory 203 is, for example, a semiconductor memory such as SRAM or DRAM. Programs being executed by the CPU 202 can be stored in the memory 203, and a work area for the CPU 202 to execute programs can be provided.
[0029] The drive 204 is a secondary storage device that can be read from and written to by the CPU 202. The drive 204 is, for example, a hard disk device or an SSD (Solid State Drive). The drive 204 can hold execution files of various programs, data used for program execution, and user information. Note that the drive 204 may be composed of a plurality of hard disk devices or SSDs using RAID (Redundant Arrays of Independent Disks) technology or the like.
[0030] The CPU 202 reads the program stored on the drive 204 onto the memory 203 and executes it. The CPU 202 can be connected to the NIC 205 via the bus 201 and communicate with the cooperation source system 101 via the Internet 104.
[0031] Note that the cooperation destination system 102 may be composed of a plurality of systems using clustering technology or the like.
[0032] (Functional Configuration of the Cooperation Destination System 102 According to Embodiment 1) FIG. 3 is a block diagram showing a functional configuration example of the partner system 102 according to Embodiment 1. The partner system 102 is, for example, a storage system, but is not limited thereto, and may be any information processing system that receives a request from a user terminal via another system or directly from the user terminal, processes the request, and outputs a log related to the processing. The log may be, for example, an audit log, but is not limited thereto, and may be any log that records the processing result of the request.
[0033] In FIG. 3, the partner system 102 includes a cooperation request receiving unit 301 that receives an operation request from the cooperation source system 101 via the Internet 104, and a cooperation request processing unit 303 that processes the received operation request. The partner system 102 also includes a cooperation response transmission unit 304 that returns the processing result of the operation request to the cooperation source system 101 via the Internet 104.
[0034] The partner system 102 also includes a cooperation user creation unit 302 that creates a user (cooperation user) who performs the operation of the cooperation source system 101 within the partner system 102, and a partner system user information 121 that stores user information of the cooperation user and normal users. A normal user is a user who directly operates the partner system 102 from the client 103. The partner system user information 121 is stored in a predetermined storage unit.
[0035] The partner system 102 also includes an audit log 122 that stores audit logs, and an audit log writing unit 305 that writes the operations of the cooperation request processing unit 303 to the audit log 122.
[0036] Note that a gateway, a firewall, or the like may exist between the cooperation request receiving unit 301 and the cooperation response transmission unit 304 and the Internet 104. Also, the audit log 122 may be transferred to an external log data storage server (such as syslog).
[0037] (Configuration of the partner system user information 121 according to Embodiment 1) FIG. 4 is a diagram showing the configuration of the partner system user information 121 held by the partner system 102 according to Embodiment 1.
[0038] The partner system user information 121 is used to manage a user (cooperation user) used when cooperating with the source system 101 and a normal user of the partner system 102.
[0039] The partner system user information 121 is managed as information including a user ID 401 for identifying a user, a cooperation flag 402 indicating that the user is a user for cooperation with the source system 101, and a source user name 403 indicating the user name in the source system. The partner system user information 121 may have information other than these. The source user name 403 is an example of source user identification information.
[0040] Record 411 is an example of a cooperation user. In this record 411, the user ID 401 is a UUID, the cooperation flag 402 is Yes (a user for cooperation), and the source user name 403 is the user name used in the source system 101. On the other hand, record 412 is a normal user used within the partner system 102. In this case, the user ID 401 is a character string such as a name, the cooperation flag 402 is No (not a user for cooperation), and the source user name 403 is NULL.
[0041] (Functional Configuration of the Source System 101 According to Embodiment 1) FIG. 5 is a block diagram showing a functional configuration example of the source system 101 according to Embodiment 1.
[0042] In FIG. 5, the source system 101 includes a request receiving unit 501, a response transmitting unit 502, a cooperation request transmitting unit 504, a cooperation response receiving unit 505, and a request processing unit 503.
[0043] The request receiving unit 501 receives an operation request from the client 103 via the Internet 104. The response sending unit 502 returns the processing result of the operation request to the client 103 via the Internet 104. The cooperation request sending unit 504 sends an operation request to the cooperation destination system 102 via the Internet 104. The cooperation response receiving unit 505 receives the result of the operation request from the cooperation destination system 102 via the Internet 104. The request processing unit 503 sends the operation request received by the request receiving unit 501 from the cooperation request sending unit 504 to the cooperation destination system 102 via the Internet 104. Then, the request processing unit 503 receives the transmission result of the operation request at the cooperation response receiving unit 505 via the Internet 104 and returns it to the client 103 via the Internet 104 from the response sending unit 502.
[0044] Note that a gateway, a firewall, or the like may exist between the request receiving unit 501, the response sending unit 502, the cooperation request sending unit 504, and the cooperation response receiving unit 505 and the Internet 104.
[0045] (Configuration of the cooperation source system user information 111 according to Embodiment 1) FIG. 6 is a diagram showing the configuration of the cooperation source system user information 111 held by the cooperation source system 101 according to Embodiment 1.
[0046] The cooperation source system user information 111 is used to manage users who use the cooperation source system 101. In the cooperation source system user information 111, each user is managed as information including a user ID 601 that identifies the user. The cooperation source system user information 111 may also have information other than these.
[0047] (Request processing of the cooperation system S according to Embodiment 1) FIG. 7 is a flowchart showing the request processing of the cooperation system S according to Embodiment 1. The request processing starts when the cooperation source system 101 receives a request from the client 103.
[0048] First, the cooperation source system 101 receives a request from the client 103 via the Internet 104 (S711). Next, the cooperation source system 101 refers to the cooperation source system user information 111 based on the received request and authenticates the user who sent the request using an ID, password, etc. (S712). The authentication method used at this time may use public key authentication or the like. Next, after the user authentication is completed, the cooperation source system 101 adds the user name authenticated and operated in the cooperation source system 101 to the request and sends a cooperation request to the cooperation destination system 102 (S713). Note that the information added in S713 may include information other than the user name, for example, the ID of the cooperation source system.
[0049] Next, the cooperation destination system 102 receives the cooperation request sent from the cooperation source system 101 via the Internet 104 (S721). Next, the cooperation destination system 102 checks whether the cooperation user for the user is registered in the cooperation destination system user information 121 from the user name of the cooperation source system 101 included in the cooperation request (S722). If the cooperation user is not registered (S722No), the cooperation destination system 102 creates a cooperation user (S723) and registers it in the cooperation destination system user information 121 (S723). At this time, a UUID is used for the user ID 401 so as not to overlap with other users. Also, the cooperation flag 402 is set to Yes, and the cooperation source user name 403 stores the user name in the cooperation source system 101 included in the cooperation request.
[0050] Note that the cooperation flag 402 only needs to be able to identify that the user is a user created for cooperation with the cooperation source system 101, and does not necessarily have to be set to Yes. Also, the fact that the cooperation source user name 403 is "not NULL" may be used as a substitute for the cooperation flag 402 being Yes.
[0051] If the linked system 102 has a registered linked user (S722 Yes), or after the registration of the linked user is completed in S723, the link request is processed as an operation by the linked user to the linked system 102 (S724). After the process of S724 is completed, the linked system 102 transmits the processing result to the linking source system 101 as a link response (S725). Also, the result is output as an audit log (S726). The output of the audit log in S726 will be described later with reference to FIGS. 8 and 9.
[0052] Next, the linking source system 101 receives a link response from the linked system 102 (S714). Thereafter, the linking source system 101 transmits a response based on the received link response to the client 103 via the Internet 104 (S715). The above flow is repeated every time the client 103 transmits a request to the linking source system 101 via the Internet 104.
[0053] Note that in the request processing of the linking system S shown in FIG. 7, it is assumed that the request received by the linked system 102 is a request received via the linking source system 101. However, there are also requests directly transmitted from the client 103 that the linked system 102 receives. Therefore, the identification information of the requesting source system is included in the request. And when the identification information of the requesting source system included in the received request corresponds to the linking source system 101, the processes of S722 to S723 are executed in the linked system 102. On the other hand, when it does not correspond to the identification information of the linking source system 101 (such as being a user of the linked system 102), S722 to S723 are omitted, and the request is processed based on the user ID included in the request received in S724.
[0054] (Example of the audit log 122 according to Embodiment 1) FIG. 8 shows, in tabular form, an example of an audit log 122 output by the audit log writing unit 305 of the partner system 102 according to Embodiment 1.
[0055] The audit log 800 output by the audit log writing unit 305 does not have to be tabular data, and may be text data using a delimiter such as “,” (comma) like the CSV format.
[0056] The audit log 800 includes a date and time 801, a user name 802, an operation source 803, an operation content 804, an operation result 805, etc. These orderings may be swapped. Also, some of these items may be missing, or additional items may exist.
[0057] In the example shown in FIG. 8, in record 811, the user name 802 of “abcdefgh” in the partner system 102 is converted to the user name 802 of “taro.Suzuki” in the source system 101 and output. Also, in record 812, since the user name “jiro.ito” in the partner system 102 is a user specific to the partner system 102, the conversion of the user name 802 is not performed, and the user name “jiro.ito” in the partner system 102 is directly output.
[0058] (Processing performed by the audit log writing unit 305 according to Embodiment 1) FIG. 9 is a flowchart showing the processing performed by the audit log writing unit 305 of the partner system 102 according to Embodiment 1. FIG. 9 shows a flow for detailing S726 in FIG. 7.
[0059] First, the audit log writing unit 305 receives the content to be written to the audit log 800 from the cooperation request processing unit 303 (S726a).
[0060] Next, when the audit log writing unit 305 receives the content to be written to the audit log 800, it searches for the user name of the user who performed the operation from the linked destination system user information 121 of the linked destination system 102, and finds the one with the matching user ID 401. Then, the audit log writing unit 305 checks the link flag 402 of the linked destination system user information 121 for the found user (S726b). When the link flag 402 is No (S726bNo), the audit log writing unit 305 writes the content to be written to the audit log 800 received from the link request processing unit 303 as it is (S726d).
[0061] On the other hand, when the link flag 402 is Yes (S726bYes), the audit log writing unit 305 converts the content to be written to the audit log 800 received from the link request processing unit 303. That is, among the content to be written to the audit log 800, the user name 802 is converted to the source system user name 403, and the operation source 803 is converted to the source system 101 (S726c). After that, the audit log writing unit 305 writes the audit log 800 with the converted content (S726d). Every time the audit log writing unit 305 receives the content to be written to the audit log 800 from the link request processing unit 303, it performs the processing shown in the flow of FIG. 9.
[0062] In the above operation flow, the operation from the source system 101 to the destination system 102 is such that in the audit log 122 of the destination system 102, the user name 802 is the user name of the source system 101, and the operation source 803 is the source system. This can reduce the work of matching the UUID and the user name when checking the audit log 122 of the destination system 102.
[0063] (Effect of Embodiment 1) In the above-described Embodiment 1, when processing a request from the source system 101, the user name of the source system 101 included in the request is converted to the user ID (ID of the linked user) of the destination system 102, and the request is processed. Then, at the time of log output during request processing, it is reconverted from the ID of the linked user to the user name of the source system 101, and the user name of the source system 101 is output to the log.
[0064] Therefore, according to Embodiment 1, after avoiding the duplication of user names between systems using the linked user, the operations performed from the source system 101 can be recorded in the log of the destination system 102 with the user name of the source system 101. Therefore, at the time of log auditing, it can be confirmed without matching unique user identification information such as UUID and the user name of the source system 101.
[0065] Also, in Embodiment 1, a log including the source system identification information as the identification information of the request source system together with the linked source user identification information whose user identification information has been converted is output. Therefore, the name of the source system 101 that sent the request can be determined from the log.
[0066] Also, in Embodiment 1, when a request is received, if the linked source user name corresponding to the identification information of the user included in the request does not exist in the destination system user information 121, the following processing is performed. That is, this identification information is used as the linked source user name, and the linked source user name and new user identification information are associated and registered in the destination system user information 121. Further, the identification information of the source system 101 included in the request may be associated and registered in the destination system user information 121. In particular, by using UUID as the new user identification information, it is possible to easily create a linked user that avoids duplication of user names between systems, so that system linking can be promoted.
[0067] [Embodiment 2] In Embodiment 1, in the linked system S, it is assumed that one source system 101 is linked to one destination system 102. However, not limited to this, in Embodiment 2, an example in which a plurality of source systems 101 are linked to one destination system 102 in the linked system S will be described.
[0068] (Configuration of the destination system user information 121B according to Embodiment 2) FIG. 10 is a diagram showing the configuration of the partner system user information 121B held by the partner system 102 according to Embodiment 2.
[0069] The partner system user information 121B is different from the partner system user information 121 of Embodiment 1 in that the ID of the partner source system 101 (partner source system identification information) is stored together with “Yes” in the cooperation flag 402. This ID of the partner source system 101 may be any information that can uniquely identify the partner source system 101 within the cooperation system S.
[0070] Record 411B indicates that the cooperation user name (user ID 401) in the partner system 102 of the user (partner source user name 403) of the system identified by the partner source system 101 as “SYSID1” is “abcdefgh1”. Further, record 412B indicates that the cooperation user name in the partner system 102 of the user “Saburo.tanaka” of the system identified by the partner source system 101 as “SYSID2” is “abcdefgh2”. Further, record 412B indicates that the user with the user ID 401 being “jiro.ito” is a unique user of the partner system 102.
[0071] Also, in Embodiment 2, in S713 of the request process (FIG. 7) of the cooperation system S, the ID of the partner source system 101 is added to the request together with the user name of the partner source system 101, and the cooperation request is transmitted to the partner system 102.
[0072] Also, in Embodiment 2, in S722, the user ID 401 and the cooperation flag 402 of the partner system user information 121 are referred to based on the user name of the partner source system 101 and the ID of the partner source system 101 included in the cooperation request. Then, it is confirmed whether a cooperation user for the user corresponding to the combination of the user name of the partner source system 101 and the ID of the partner source system 101 is registered.
[0073] In Embodiment 2, in S725, the cooperation response is transmitted to the system identified by the ID of the cooperation source system 101 indicated in the cooperation request received in S721.
[0074] In Embodiment 2, in S726c of the process (Fig. 9) performed by the audit log writing unit 305 of the cooperation destination system 102, when converting the user name to be written in the audit log to the user name of the cooperation source system, the operation source is converted to the ID of the cooperation source system 101. This ID of the cooperation source system 101 may be shared in advance during cooperation between the cooperation source system 101 and the cooperation destination system 102, or may be transmitted and received together with the cooperation request in S713 to S721 (Fig. 7).
[0075] In Embodiment 2, when a request is received, if the cooperation source user name corresponding to the identification information of the user included in the request does not exist in the cooperation destination system user information 121, the following process is performed. That is, using this identification information as the cooperation source user name, the cooperation source user name, new user identification information, and the identification information of the cooperation source system 101 included in the request are associated and registered in the cooperation destination system user information 121. In particular, by using UUID as the new user identification information, even when there are multiple cooperation source systems 101, it is possible to easily create cooperation users that avoid duplicate user names between systems, thus promoting system cooperation.
[0076] (Effect of Embodiment 2) In the above-described Embodiment 2, when there are a plurality of cooperation source systems 101, a log including the cooperation source system identification information of the corresponding cooperation source system 101 among the plurality of cooperation source systems 101 is output as the identification information of the request source system together with the cooperation source user identification information. Therefore, even when there are a plurality of cooperation source systems 101, it is possible to determine on the log which cooperation source system 101 transmitted the request.
[0077] As described above in detail, the embodiments according to the present disclosure are not limited to the above-described embodiments, and various modifications are possible without departing from the gist thereof. For example, the above-described embodiments have been described in detail for easy understanding of the present invention, and are not necessarily limited to those having all the configurations described. Also, with respect to a part of the configuration of the above-described embodiments, addition, deletion, or replacement with other configurations is possible.
[0078] Also, each of the above-described configurations, functional units, processing units, etc. may be realized in hardware by designing part or all of them, for example, with an integrated circuit. Further, each of the above-described configurations, functions, etc. may be realized in software by a processor interpreting and executing a program for realizing each function. Information such as a program, table, file, etc. for realizing each function can be stored in a recording device such as a memory, hard disk, SSD (Solid State Drive), or in a recording medium such as an IC card, SD card, DVD.
[0079] Also, in each of the above-described figures, control lines and information lines show those considered necessary for explanation, and do not necessarily show all the control lines and information lines in actual implementation. For example, it may be considered that almost all configurations are actually interconnected.
[0080] Also, the arrangement forms of the functions and data of the above-described cooperation source system 101 and cooperation destination system 102 are merely examples. The arrangement forms of the functions and data can be changed to an optimal arrangement form from viewpoints such as the performance of hardware and software, processing efficiency, communication efficiency, etc.
Explanation of Reference Numerals
[0081] S: Cooperation system, 101: Cooperation source system, 102: Cooperation destination system, 121, 121B: Cooperation destination system user information, 122, 800: Audit log, 202: CPU, 401: User ID, 403: Cooperation source user name, 401: User ID, 403: Cooperation source user name.
Claims
1. An information processing system that cooperates with a source system and processes a request received via the source system and a request received directly without going through the source system, comprising: a processor and a storage unit; The storage unit stores: user information that manages, in association with each other, user identification information that uniquely identifies a user in the information processing system and, when the user is a source user in the source system, source user identification information that identifies the source user in the source system; The processor: receives the request; determines whether the source user identification information corresponding to the identification information of the user included in the received request exists in the user information; when the source user identification information exists in the user information, converts the identification information into the user identification information corresponding to the source user identification information in the user information; processes the request based on the user identification information; when outputting a log related to the processing of the request, determines whether the source user identification information corresponding to the user identification information exists in the user information; when the source user identification information corresponding to the user identification information exists in the user information, converts the user identification information into the source user identification information corresponding to the user identification information in the user information; outputs the log including the source user identification information into which the user identification information has been converted. An information processing system characterized by the above.
2. The information processing system according to Claim 1, wherein: the user information manages, in association with each other, the user identification information, the source user identification information that identifies the source user in the source system when the user identified by the user identification information is the source user of the source system, and source system identification information that identifies the source system; The processor: when outputting the log, determines whether the source user identification information corresponding to the user identification information exists in the user information; When the linked source user identification information corresponding to the user identification information exists in the user information, convert the user identification information to the linked source user identification information corresponding to the user identification information in the user information, and convert the identification information of the requesting source system of the request to the linked source system identification information associated with the linked source user identification information in the user information. Output the log including the linked source system identification information as the identification information of the requesting source system, together with the linked source user identification information into which the user identification information has been converted. An information processing system characterized by the above.
3. The information processing system according to claim 1, wherein the processor when receiving the request from the linked source system and the linked source user identification information corresponding to the identification information does not exist in the user information, register the identification information as the linked source user identification information in the user information by associating the linked source user identification information with new user identification information. An information processing system characterized by the above.
4. The information processing system according to claim 3, wherein the new user identification information is a UUID (Universally Unique Identifier). An information processing system characterized by the above.
5. The information processing system according to claim 1, wherein the processor when receiving a request not via the linked source system, processes the request based on the user identification information included in the request, and outputs a log including the user identification information. An information processing system characterized by the above.
6. A log recording method in an information processing system that communicates with a linked source system and processes a request received via the linked source system and a request received directly without passing through the linked source system, wherein the information processing system includes a processor and a storage unit, and the storage unit stores user information that manages by associating user identification information that uniquely identifies a user in the information processing system with linked source user identification information that identifies the linked source user in the linked source system when the user is a linked source user in the linked source system, and the processor receives the request, Determine whether the source user identification information corresponding to the user identification information included in the received request exists in the user information, When the source user identification information exists in the user information, convert the identification information to the user identification information corresponding to the source user identification information in the user information, Process the request based on the user identification information, When outputting a log related to the processing of the request, determine whether the source user identification information corresponding to the user identification information exists in the user information, When the source user identification information corresponding to the user identification information exists in the user information, convert the user identification information to the source user identification information corresponding to the user identification information in the user information, Output the log including the source user identification information to which the user identification information has been converted, A log recording method characterized by including each process.
Citation Information
Patent Citations
Service cooperation system
JP2002312311A
Resource management method, information processing system, information processor and program
JP2009151560A
Access history provision system, and access history provision method
JP2014099017A
Information processing system, control method, and program thereof
JP2018195080A
Method for failure prediction and apparatus implementing the same method
US20220358380A1