Log analysis

Automatically obtain the keywords of the log analysis appeal instructions through the natural language big model, and combine it with the functional function library to process the log, solving the problems of inconvenient operation of existing tools and limitations in the analysis form, and achieving simple and widely applicable log analysis.

WO2025162050A1PCT designated stage Publication Date: 2025-08-07ANT WEALTH (SHANGHAI) FINANCIAL INFORMATION SERVICES CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/073540
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-29
Filing Date
2025-01-21
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

The existing log analysis tools are inconvenient to operate and the analysis form and content are limited, making it difficult to meet the diverse analysis needs of users.

Method used

The natural language big model is used to automatically obtain the primary and secondary keywords of the log analysis appeal instruction, and the log repository is processed through the functional function call interface and parameters to achieve simple multi-form log analysis.

Benefits of technology

It realizes the simplicity and wide applicability of log analysis operations, and can automatically perform various forms of log analysis and processing according to user needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025073540_07082025_PF_FP_ABST
    Figure CN2025073540_07082025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in embodiments of the present description are a log analysis method and system. The method comprises: acquiring a log analysis request instruction; inputting the log analysis request instruction into a natural language large model, and on the basis of the natural language large model, determining a performance function calling interface corresponding to the log analysis request instruction and determining log analysis parameters corresponding to the log analysis request instruction; on the basis of the performance function calling interface, calling a performance function corresponding to the performance function calling interface in a performance function library, and taking the log analysis parameters as input parameters of the performance function; and processing logs in a log storage library by means of the performance function and the input parameters of the performance function so as to obtain a log processing result corresponding to the log analysis request instruction. The system is implemented on the basis of the method.
Need to check novelty before this filing date? Find Prior Art

Description

Log analysis Technical Field

[0001] The embodiments of this specification mainly relate to the field of log analysis technology, and specifically to a log analysis method and system. Background Art

[0002] Log analysis is the process of parsing, processing, and analyzing log files generated by systems, applications, or network devices. By analyzing log data, you can obtain useful information about system operating status, user behavior, and troubleshooting.

[0003] Existing technologies typically use log analysis tools (e.g., ELK (Elasticsearch, Logstash, Kibana), Splunk, Apache Hadoop, etc.) for log analysis. While these log analysis tools can assist with log analysis, they can be inconvenient to perform and limited in terms of the form and content of log analysis. Summary of the Invention

[0004] In order to solve the problems existing in the prior art, the embodiments of this specification propose a log analysis method and system, and the technical solutions are as follows.

[0005] In the first aspect, an embodiment of the present specification provides a log analysis method, including: obtaining a log analysis request instruction; inputting the log analysis request instruction into a natural language big model, determining a function function call interface corresponding to the log analysis request instruction based on the natural language big model, and determining log analysis parameters corresponding to the log analysis request instruction; calling a function function corresponding to the function function call interface in a function function library according to the function function call interface, and using the log analysis parameters as input parameters of the function function; processing the logs in the log repository through the function function and the input parameters of the function function to obtain a log processing result corresponding to the log analysis request instruction.

[0006] On the second aspect, an embodiment of the present specification provides a log analysis system, including: a request instruction acquisition module, used to obtain log analysis request instructions; an interface and parameter determination module, used to input the log analysis request instructions into a natural language large model, and determine the function function call interface corresponding to the log analysis request instructions based on the natural language large model, and determine the log analysis parameters corresponding to the log analysis request instructions; a function function call module, used to call the function function corresponding to the function function call interface in the function function library according to the function function call interface, and use the log analysis parameters as input parameters of the function function; a log processing result acquisition module, used to process the logs in the log storage library through the function function and the input parameters of the function function to obtain the log processing results corresponding to the log analysis request instructions.

[0007] In a third aspect, an embodiment of this specification provides an electronic device, comprising: a memory for storing a program; and a processor for running the program stored in the memory to execute the log analysis method of the first aspect.

[0008] In a fourth aspect, an embodiment of this specification provides a computer-readable storage medium having computer program instructions stored thereon, which implement the log analysis method of the first aspect when the computer program instructions are executed by a processor. Beneficial effects

[0009] The log analysis method and system of the embodiments of this specification, when the user needs to analyze the log, only needs to issue a log analysis request instruction. The log analysis system can automatically obtain the main keywords and secondary keywords based on the natural language large model, and can automatically determine the function function call interface corresponding to the log analysis request instruction through the main keywords and determine the log analysis parameters corresponding to the log analysis request instruction through the main keywords and / or secondary keywords. It can also automatically call the function function in the function function library through the determined function function call interface and log analysis parameters to analyze and process the log to obtain the log processing results required by the user, making the log analysis operation very simple; in addition, the function functions in the function function library can be created according to usage requirements, so that the log analysis method and system of this embodiment can perform various forms of analysis and processing on the log, and has a wide applicability.

[0010] Further or more detailed beneficial effects will be described in conjunction with specific examples in the specific implementation manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the embodiments of this specification, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0012] FIG1 is a flow chart of the log analysis method provided in Example 1 of this specification.

[0013] FIG2 is a flow chart of obtaining a log analysis request instruction provided in Example 1 of this specification.

[0014] FIG3 is a flow chart of processing all initial log analysis request instructions to obtain log analysis request instructions provided in Example 1 of this specification.

[0015] FIG4 is a flow chart of a function calling interface and log analysis parameter determination process provided in Example 1 of this specification.

[0016] FIG5 is another flow chart of the log analysis method provided in Example 1 of this specification.

[0017] FIG6 is a flow chart of obtaining primary keywords and secondary keywords in a log analysis request instruction through a natural language large model provided in Example 1 of this specification.

[0018] FIG7 is a flow chart of determining a function call interface corresponding to a log analysis request instruction through a main keyword provided in Example 1 of this specification.

[0019] FIG8 is a schematic diagram of a flow chart of obtaining a similarity value between a main keyword and each interface identification code according to Example 1 of this specification.

[0020] FIG9 is another flow chart of the log analysis method provided in Example 1 of this specification.

[0021] FIG10 is a schematic diagram of the structure of the log analysis system provided in Example 2 of this specification.

[0022] FIG11 is a schematic diagram of the structure of the electronic device provided in Example 3 of this specification. DETAILED DESCRIPTION

[0023] The technical solutions in the embodiments of this specification will be described clearly and completely below in conjunction with the drawings in the embodiments of this specification.

[0024] Throughout this specification, the claims, and the accompanying drawings, the terms "first," "second," "third," and the like are used to distinguish between different items, not to describe a particular order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may include other steps or elements inherent to the process, method, product, or apparatus.

[0025] Example 1:

[0026] A log analysis method, as shown in FIG1 , includes the following steps.

[0027] Step 102: Obtain log analysis request instructions.

[0028] Log analysis requirements may include: Log quantity statistics: Count the total number of log records within the date range. Log level distribution: Count the number of different log levels (such as errors, warnings, information, etc.). Log source analysis: Count the number of logs generated by different sources (such as different applications, modules or users). Error type analysis: Identify the different error types that occur within the date range and count the number of each error type. Error frequency analysis: Count the frequency of different errors occurring within the date range. Time distribution analysis: Count the number of logs in different time periods within the date range.

[0029] Log analysis request instructions correspond to log analysis requests. Specifically, if the log analysis request is "Calculate the average of abnormal logs in the past 5 days," the log analysis request instruction is "Calculate the average of abnormal logs in the past 5 days." If the log analysis request is "Calculate the number of warnings from the previous 8 days to the previous 3 days," the log analysis request instruction is "Calculate the number of warnings from the previous 8 days to the previous 3 days."

[0030] In this embodiment, the log analysis request instruction can be obtained through the log analysis system. As shown in FIG2 , obtaining the log analysis request instruction in this embodiment specifically includes the following steps.

[0031] Step 202: Obtain a command input start signal.

[0032] The log analysis system features a command input interface a, which includes a "Start Command Input" button. When a user wishes to perform log analysis, they first press the "Start Command Input" button on interface a. This generates a command input start signal, which the log analysis system then receives. Upon receiving the signal, the system transitions from interface a to interface b, where the user can enter specific log analysis commands.

[0033] Step 204: Determine the input instruction type and obtain the initial log analysis request instruction corresponding to the input instruction type.

[0034] The input instruction type can be a text type, that is, the user directly enters the text of the log analysis request instruction. For example, when the log analysis request instruction is "calculate the average value of the abnormal logs in the past 5 days", then directly enter the text of "calculate the average value of the abnormal logs in the past 5 days".

[0035] The input instruction type can also be a picture type, that is, the user directly inputs a picture with a log analysis request instruction. For example, when the log analysis request instruction is "calculate the average value of abnormal logs in the past 5 days", then directly input a picture with the text "calculate the average value of abnormal logs in the past 5 days".

[0036] The input instruction type can also be a voice type, that is, the user directly inputs a voice with a log analysis request instruction. For example, when the log analysis request instruction is "calculate the average value of the abnormal logs in the past 5 days", then the voice input content is directly "calculate the average value of the abnormal logs in the past 5 days".

[0037] The instruction input operation interface b is provided with options for inputting instruction types. For example, there may be options such as "text type", "picture type", "voice type", etc. The "text type" option corresponds to a log analysis request instruction filling area, the "picture type" option corresponds to a log analysis request instruction picture upload area, and the "voice type" option corresponds to a log analysis request instruction voice upload area.

[0038] When the input instruction type is text type, the user only needs to select the "text type" option first, and then enter the corresponding log analysis request instruction text in the log analysis request instruction filling area. At this time, the log analysis system obtains the corresponding initial log analysis request instruction. When the input instruction type is image type, the user only needs to select the "image type" option first, and then upload the corresponding log analysis request instruction image in the log analysis request instruction image upload area. At this time, the log analysis system obtains the corresponding initial log analysis request instruction. When the input instruction type is voice type, the user only needs to select the "voice type" option first, and then upload the corresponding log analysis request instruction voice in the log analysis request instruction voice upload area. At this time, the log analysis system obtains the corresponding initial log analysis request instruction.

[0039] Step 206: Obtain the instruction input completion signal.

[0040] The command input interface b of the log analysis system also features a "Command Input Complete" button. After a user completes entering text, uploading an image, or uploading a voice message of a log analysis request, they can press the "Command Input Complete" button on the command input interface b. This generates a command input complete signal. Upon receiving the command input complete signal, the log analysis system concludes the initial log analysis request command acquisition operation and proceeds to step 208.

[0041] Step 208: Process the initial log analysis request instruction to obtain a log analysis request instruction.

[0042] When the log analysis system obtains the instruction input completion signal, it will process the obtained initial log analysis request instruction to obtain the required log analysis request instruction.

[0043] As shown in FIG3 , in this embodiment, processing the initial log analysis request instruction to obtain the log analysis request instruction specifically includes the following steps.

[0044] Step 302: Determine whether there is an initial log analysis request instruction whose input instruction type is a picture type. If there is an initial log analysis request instruction whose input instruction type is a picture type, convert the picture type initial log analysis request instruction into a text type initial log analysis request instruction.

[0045] When the type of the initial log analysis request instruction obtained by the log analysis system is a picture type, it is necessary to extract the text in the picture and use the extracted text as a new initial log analysis request instruction, that is, to change the initial log analysis request instruction of the picture type into an initial log analysis request instruction of the text type.

[0046] Step 304: Determine whether there is an initial log analysis request instruction whose input instruction type is voice type. If there is an initial log analysis request instruction whose input instruction type is voice type, convert the initial log analysis request instruction of voice type into an initial log analysis request instruction of text type.

[0047] When the type of the initial log analysis request instruction obtained by the log analysis system is voice type, it is necessary to convert the voice into text, and use the converted text as the new initial log analysis request instruction, thereby turning the voice type initial log analysis request instruction into a text type initial log analysis request instruction.

[0048] Step 306: Concatenate the initial log analysis request instructions in text format to obtain a log analysis request instruction.

[0049] Case 1: A log analysis request instruction includes only one input instruction type, and the log analysis request instruction is input or uploaded as a whole at one time.

[0050] For example, when the initial log analysis request instruction obtained in step 208 is a text-based initial log analysis request instruction, this step directly uses the text-based initial log analysis request instruction as the final log analysis request instruction. Specifically, when the initial log analysis request instruction obtained in step 208 is "calculate the average value of abnormal logs in the past 5 days" and the initial log analysis request instruction is text-based, step 306 directly uses "calculate the average value of abnormal logs in the past 5 days" as the final log analysis request instruction.

[0051] For another example, when the initial log analysis request instruction obtained in step 208 is an initial log analysis request instruction of the image type, it is necessary to first convert the initial log analysis request instruction of the image type into an initial log analysis request instruction of the text type through step 302, and then use the newly obtained initial log analysis request instruction of the text type as the final log analysis request instruction through step 306. Specifically, when the initial log analysis request instruction obtained in step 208 is "Count the number of warnings from the previous 8 days to the previous 3 days", and the initial log analysis request instruction is of the image type, then first extract the text "Count the number of warnings from the previous 8 days to the previous 3 days" on the image through step 302, and then use the text "Count the number of warnings from the previous 8 days to the previous 3 days" as the final log analysis request instruction through step 306.

[0052] For another example, when the initial log analysis request instruction obtained in step 208 is a voice-type initial log analysis request instruction, it is necessary to first convert the voice-type initial log analysis request instruction into a text-type initial log analysis request instruction through step 304, and then use the newly obtained text-type initial log analysis request instruction as the final log analysis request instruction through step 306. Specifically, when the initial log analysis request instruction obtained in step 208 is "Count the frequency of log errors in the past week", and the initial log analysis request instruction is of voice type, then first convert the voice into text "Count the frequency of log errors in the past week" through step 304, and then use the text "Count the frequency of log errors in the past week" as the final log analysis request instruction through step 306.

[0053] Case 2: A log analysis request instruction includes multiple input instruction types.

[0054] For example, in step 204, the user enters the text "Statistics for the past 5 days" through the command input interface b, uploads an image with the text "Abnormal log", and uploads a voice message with the content "Average value". Then, in step 208, the log analysis system obtains the text-based initial log analysis request instruction "Statistics for the past 5 days", the image-based initial log analysis request instruction "Abnormal log", and the voice-based initial log analysis request instruction "Average value".

[0055] At this point, the log analysis system converts the image-type initial log analysis request instruction "abnormal log" into a text-type initial log analysis request instruction "abnormal log" in step 302, and converts the voice-type initial log analysis request instruction "average value" into a text-type initial log analysis request instruction "average value" in step 304. Finally, in step 306, all the text-type initial log analysis request instructions "Statistics of the past 5 days," "abnormal log," and "average value" are concatenated to obtain the final log analysis request instruction "Statistics of the average value of abnormal logs in the past 5 days."

[0056] Case 3: A log analysis request instruction includes only one input instruction type, but is divided into multiple parts for input or upload.

[0057] For example, in step 204, the user selects the "Voice Type" option on the command input interface b, and then uploads three voice commands: "Statistics for the past 5 days," "Abnormal logs," and "Average" in the log analysis request voice upload area. The log analysis system then retrieves the initial log analysis request commands of the voice types "Statistics for the past 5 days," "Abnormal logs," and "Average" in step 208.

[0058] At this point, the log analysis system converts the initial log analysis request instructions of voice type, "Count the past 5 days," "Abnormal logs," and "Average value," into initial log analysis request instructions of text type, "Count the past 5 days," "Abnormal logs," and "Average value," in step 304. Finally, in step 306, all the initial log analysis request instructions of text type, "Count the past 5 days," "Abnormal logs," and "Average value," are concatenated to obtain the final log analysis request instruction, "Count the average value of abnormal logs in the past 5 days."

[0059] Directly entering the initial log analysis request instruction in text type has a high accuracy rate, but text input is more cumbersome. Directly uploading the initial log analysis request instruction in voice type is relatively convenient, but because there may be errors in the voice-to-text conversion, the accuracy of the instruction expression is not very high. Directly uploading the initial log analysis request instruction in image type is convenient and has a high accuracy rate, but it is not always suitable. For example, the initial log analysis request instruction of a certain log analysis is "Calculate the average value of abnormal logs in the past 5 days". This is directly entered through text and a screenshot is saved when the input is completed. Then, the next time the log analysis is performed, if the initial log analysis request instruction is still "Calculate the average value of abnormal logs in the past 5 days", the initial log analysis request instruction can be entered directly by uploading the corresponding image. However, if the initial log analysis request instruction changes to "Calculate the average value of abnormal logs in the past 7 days", the initial log analysis request instruction cannot be entered by uploading the image.

[0060] In summary, this embodiment can select the most appropriate way to input the initial log analysis request instruction according to actual conditions, so that the log analysis system can obtain the corresponding log analysis request instruction.

[0061] As shown in FIG1 , the log analysis method of this embodiment further includes the following steps.

[0062] Step 104: Input the log analysis request instruction into the natural language big model, and determine the function call interface corresponding to the log analysis request instruction and the log analysis parameters corresponding to the log analysis request instruction based on the natural language big model.

[0063] When the log analysis system receives a log analysis request, it inputs it into a large natural language model, which then helps determine the function call interface and log analysis parameters. A large natural language model is a model trained using machine learning and artificial intelligence technologies to understand natural language. This model is trained using a large corpus to learn language features such as syntax, semantics, and context, enabling it to understand and process human language. This means that the large natural language model is able to understand and process the log analysis request in this embodiment.

[0064] As shown in FIG4 , in this embodiment, determining the function call interface corresponding to the log analysis request instruction based on the natural language large model and determining the log analysis parameters corresponding to the log analysis request instruction specifically include the following steps.

[0065] Step 402: Obtain the primary keywords and secondary keywords in the log analysis request instructions through the natural language large model.

[0066] As shown in FIG5 , before step 102 , the log analysis method of this embodiment further includes the following steps.

[0067] Step 502: Obtain log analysis request history instructions, perform primary keyword tagging and secondary keyword tagging on the log analysis request history instructions, and train a natural language large model by completing the primary keyword tagging and secondary keyword tagging of the log analysis request history instructions.

[0068] That is, before the natural language large model is officially used, it is necessary to first train the natural language large model through a large number of log analysis request history instructions. The log analysis request history instructions need to be manually marked with primary keywords and secondary keywords. For example, when the log analysis request history instruction is "calculate the average value of abnormal logs in the past 5 days", you can manually mark "the past 5 days" and "abnormal" as secondary keywords and "average value" as the primary keyword based on the semantics of the historical instruction. For another example, when the log analysis request history instruction is "calculate the number of warnings from the previous 8 days to the previous 3 days", you can manually mark "the previous 8 days to the previous 3 days" as the secondary keyword and "warning" as the primary keyword based on the semantics of the historical instruction. In short, this step will train the natural language large model through a sufficient number of log analysis request history instructions that have completed primary keyword marking and secondary keyword marking, so that the natural language large model can be used in step 402.

[0069] Returning to step 402, as shown in FIG6, in this embodiment, obtaining the primary keywords and secondary keywords in the log analysis request instruction through the natural language large model specifically includes the following steps.

[0070] Step 602: Obtain keywords in the log analysis request instruction.

[0071] The natural language model can directly capture all the keywords in the log analysis request instruction. Assume in this embodiment that the current log analysis request instruction is "calculate the average value of abnormal logs in the past 5 days". After the log analysis system inputs this log analysis request instruction "calculate the average value of abnormal logs in the past 5 days" into the trained natural language model, the natural language model will automatically output all the keywords "past 5 days", "abnormal", and "average value".

[0072] Step 604: Obtain the intent matching score value of each keyword, determine the keyword with the highest intent matching score value as the primary keyword of the log analysis request instruction, and determine the remaining keywords as secondary keywords of the log analysis request instruction.

[0073] After the log analysis system obtains all the keywords, it also obtains the intent matching score of each keyword. The keyword with the highest intent matching score is used as the primary keyword, and the remaining keywords are used as secondary keywords. Assuming in this embodiment, the intent matching score corresponding to the keyword "last 5 days" is 22 points, the intent matching score corresponding to the keyword "abnormal" is 33 points, and the intent matching score corresponding to the keyword "average value" is 45 points, then the log analysis system will use "average value" as the primary keyword and "last 5 days" and "abnormal" as secondary keywords.

[0074] Furthermore, this embodiment obtains the probability of the keyword being the main intention of the log analysis request instruction through the natural language large model, and determines the intention matching score value of the keyword through the probability.

[0075] In addition to being able to directly output all the keywords in the log analysis request instruction, the natural language large model can also directly output the probability of each keyword being the main intention of the log analysis request instruction. Assume that in this embodiment, the probability that the keyword "recent 5 days" is the main intention of the log analysis request instruction "calculate the average value of the abnormal logs in the past 5 days" is 22%, the probability that the keyword "abnormal" is the main intention of the log analysis request instruction "calculate the average value of the abnormal logs in the past 5 days" is 33%, and the probability that the keyword "average value" is the main intention of the log analysis request instruction "calculate the average value of the abnormal logs in the past 5 days" is 45%. Then at this time, the log analysis system can determine that the intention matching score value of the keyword "recent 5 days" is 22 points, the intention matching score value of the keyword "abnormal" is 33 points, and the intention matching score value of the keyword "average value" is 45 points.

[0076] After the log analysis system determines the main keywords and secondary keywords in the log analysis request instruction in step 402 (assuming that the log analysis request instruction in step 402 is "calculate the average value of abnormal logs in the past 5 days", the main keyword finally determined is "average value", and the secondary keywords are "past 5 days" and "abnormal"), it will continue to enter step 404.

[0077] Step 404: Determine the function call interface corresponding to the log analysis request instruction through the main keyword.

[0078] This embodiment provides a function library containing multiple functions, such as a time function, an average function, an outlier function, a variance function, and so on. In this embodiment, a log analysis request instruction can only call one function, and the function to be called is determined by the primary keyword. For example, when the primary keyword is "last 5 days," the time function is called; when the primary keyword is "abnormal," the outlier function is called; and when the primary keyword is "average," the average function is called.

[0079] Each function function needs to be called through the corresponding function calling interface. For example, the average value function can be directly called through the function calling interface No. 1, the time function can be directly called through the function calling interface No. 2, and the abnormal value function can be directly called through the function calling interface No. 3. Then after obtaining the main keyword "average value", it is necessary to first find the function calling interface No. 1 through the main keyword "average value", and then call the average value function through the function calling interface No. 1. Therefore, this embodiment needs to first find the function calling interface corresponding to the main keyword (i.e., the log analysis request instruction) through the main keyword.

[0080] As shown in FIG. 7 , in this embodiment, determining the function call interface corresponding to the log analysis request instruction through the main keyword specifically includes the following steps.

[0081] Step 702: Obtain the similarity value between the main keyword and each interface identification code.

[0082] Each function call interface has a unique interface identification code. Assume that this embodiment has function call interface No. 1, function call interface No. 2, and function call interface No. 3. The interface identification code for function call interface No. 1 can be XXXXXX1, the interface identification code for function call interface No. 2 can be XXXXXX2, and the interface identification code for function call interface No. 3 can be XXXXXX3.

[0083] This embodiment uses the interface identification code to determine the function call interface corresponding to the primary keyword. Specifically, the function call interface whose interface identification code has a high similarity value with the keyword is used as the function call interface corresponding to the primary keyword. Therefore, this embodiment requires obtaining the similarity value between the primary keyword and each interface identification code.

[0084] As shown in FIG8 , in this embodiment, obtaining the similarity value between the main keyword and each interface identification code specifically includes the following steps.

[0085] Step 802: Obtain an interface code identification word of an interface identification code.

[0086] The interface identification code of each function call interface is correspondingly provided with an interface code identification word. For example, the interface identification code of function call interface No. 1 is correspondingly provided with an interface code identification word of "average", "average value" or "average".

[0087] In this step, the interface code identification word of the interface identification code of the function call interface No. 1 is first obtained, that is, "average", "average value" and "average" are obtained.

[0088] Step 804: Perform similarity matching between the main keyword and each interface code identification word of the interface identification code to obtain a sub-similarity value between the main keyword and each interface code identification word.

[0089] Assuming that the current main keyword is "average value", this step performs similarity matching between the main keyword "average value" and each interface code identification word in step 802 to obtain a sub-similarity value between the main keyword "average value" and each interface code identification word. For example, the sub-similarity value between the main keyword "average value" and the first interface code identification word "average" is 80, the sub-similarity value between the main keyword "average value" and the second interface code identification word "average value" is 100, and the sub-similarity value between the main keyword "average value" and the third interface code identification word "average" is 90.

[0090] Step 806: Use the largest sub-similarity value as the similarity value between the main keyword and the interface identification code.

[0091] Next, step 804 is continued. Since the sub-similarity values ​​in step 804 are 80, 100 and 90, 100 is the largest, so 100 is used as the similarity value between the main keyword "average value" and the interface identification code of the function call interface No. 1.

[0092] Similarly, repeat steps 802 to 806, assuming that the similarity between the main keyword "average value" and the interface identification code of the function call interface No. 2 is 77. Then repeat steps 802 to 806 again, assuming that the similarity between the main keyword "average value" and the interface identification code of the function call interface No. 3 is 66.

[0093] At this time, returning to step 702, the log analysis system in this embodiment has obtained the similarity value between the main keyword "average value" and each interface identification code, which are 100 (corresponding to the interface identification code of function call interface No. 1), 77 (corresponding to the interface identification code of function call interface No. 2), and 66 (corresponding to the interface identification code of function call interface No. 3).

[0094] Step 704: The interface identification code with the largest similarity value is used as the interface identification code corresponding to the main keyword.

[0095] Next, step 702 is continued. Since the similarity values ​​in step 702 are 100, 66 and 77, 100 is the largest, the interface identification code corresponding to 100 (ie, XXXXXX1) is used as the interface identification code corresponding to the main keyword "average value".

[0096] Step 706: Determine the corresponding function call interface according to the interface identification code.

[0097] Next, step 704 is performed. Since the function calling interface corresponding to the interface identification code XXXXXX1 is function calling interface No. 1, function calling interface No. 1 is used as the function calling interface corresponding to the main keyword “average value”.

[0098] Returning to step 404 , this step determines that the function call interface corresponding to the log analysis request instruction “calculate the average value of abnormal logs in the past 5 days” is function call interface No. 1 through the main keyword “average value”. Then proceed to step 406 .

[0099] Step 406: Determine the log analysis parameters corresponding to the log analysis request instruction through the primary keyword and / or secondary keyword.

[0100] When the log analysis request instruction is "calculate the average value of abnormal logs in the past 5 days", it can be determined through step 402 that the main keyword of the log analysis request instruction is "average value", and the secondary keywords are "past 5 days" and "abnormal". In this embodiment, the first log analysis parameter can be determined to be T(-5,0) through the secondary keyword "past 5 days", where T represents the time range of log statistics, -5 represents the previous 5 days, and 0 represents the current day. The second log analysis parameter can be determined to be Y through the secondary keyword "abnormal", where Y represents the abnormal value of the statistical log. However, the log analysis parameter cannot be obtained through the main keyword "average value".

[0101] When the log analysis request instruction is "Count logs from the last 8 days to the last 3 days," step 402 can determine that the primary keyword of the log analysis request instruction is "last 8 days to last 3 days," and the secondary keyword is missing. In this embodiment, the primary keyword "last 8 days to last 3 days" can be used to determine the first log analysis parameter as T(-8, -3), where T represents the time range for log statistics, -8 represents the last 8 days, and -3 represents the last 3 days. Because there is no secondary keyword, the log analysis parameter cannot be obtained through the secondary keyword.

[0102] Assuming that the log analysis request instruction of this embodiment is "calculate the average value of abnormal logs in the past 5 days", then through the sub-keywords "past 5 days" and "abnormal" in step 406, it can be determined that the log analysis parameters of the log analysis request instruction "calculate the average value of abnormal logs in the past 5 days" are T(-5,0) and Y.

[0103] As shown in FIG1 , the log analysis method of this embodiment further includes the following steps.

[0104] Step 106: Call the function corresponding to the function calling interface in the function library according to the function calling interface, and use the log analysis parameters as input parameters of the function.

[0105] As shown in FIG9 , before step 102 , the log analysis method of this embodiment further includes the following steps.

[0106] Step 901: Create a function call interface. The function call interface is provided with a unique interface identification code, and each interface identification code is provided with an interface code identification word.

[0107] Step 902: Create a function function corresponding to the function function call interface, the function function takes the log analysis parameter as an input parameter, and stores the created function function in the function function library.

[0108] This embodiment provides a function library, in which function functions can be created according to actual usage requirements. After a function is created, a function call interface is created that can directly call the function. After the function call interface is created, a unique interface identification code is set for the function call interface, and finally at least one interface code identification word is set for the interface identification code.

[0109] For example, this embodiment can create an average value function by itself according to usage requirements and store the created average value function in a function function library, and create function function call interface No. 1 for the average value function, and then set the interface identification code XXXXXX1 for function function call interface No. 1, and finally set the interface code identification word "average", "average value", "average number" for the interface identification code XXXXXX1.

[0110] This embodiment can perform any processing on the log as long as the corresponding function and function call interface are created in advance. That is, the log analysis method of this embodiment can perform various forms of analysis and processing on the log and has a wide applicability.

[0111] Return to step 106. When step 104 has determined the function call interface and log analysis parameters based on the main keywords and secondary keywords of the log analysis request instruction, the log analysis system will directly call the corresponding function in the function function library according to the function call interface in step 106, and when calling the corresponding function function, the log analysis parameters will be used as the input parameters of the function function.

[0112] Step 108: Process the logs in the log repository using the function and its input parameters to obtain log processing results corresponding to the log analysis request instruction.

[0113] Next, in step 106, the called function processes the logs in the log repository in combination with the function's input parameters. For example, if the called function is an average function and its input parameters are T(-5, 0) and Y, the function first counts the total number of abnormal logs in the log repository for the past five days, and then divides the total number by 5 to obtain the average value of the abnormal logs for the past five days.

[0114] The log analysis system of this embodiment is further provided with a result display interface, and the log processing result of this step can be displayed through the result display interface.

[0115] According to the log analysis method of this embodiment, when a user needs to analyze a log, he only needs to issue a log analysis request instruction. The log analysis system can automatically obtain the main keywords and secondary keywords based on the natural language large model, and can automatically determine the function function call interface corresponding to the log analysis request instruction through the main keywords, and determine the log analysis parameters corresponding to the log analysis request instruction through the main keywords and / or secondary keywords. It can also automatically call the function function in the function function library through the determined function function call interface and log analysis parameters to analyze and process the log, so as to obtain the log processing result required by the user, making the log analysis operation very simple; in addition, the function functions in the function function library can be created according to usage requirements, so that the log analysis method of this embodiment can perform various forms of analysis and processing on the log, and has a wide applicability.

[0116] Example 2:

[0117] A log analysis system, as shown in FIG10 , includes: a request instruction acquisition module, an interface and parameter determination module, a function calling module and a log processing result acquisition module.

[0118] The request instruction acquisition module is used to obtain log analysis request instructions. The interface and parameter determination module is used to input the log analysis request instructions into the natural language large model, determine the function function call interface corresponding to the log analysis request instruction based on the natural language large model, and determine the log analysis parameters corresponding to the log analysis request instruction. The function function call module is used to call the function function corresponding to the function function call interface in the function function library according to the function function call interface, and use the log analysis parameters as the input parameters of the function function. The log processing result acquisition module is used to process the logs in the log storage library through the function function and the input parameters of the function function to obtain the log processing results corresponding to the log analysis request instruction.

[0119] The appeal instruction acquisition module includes: a start signal acquisition unit, an initial instruction acquisition unit, an end signal acquisition unit and an appeal instruction determination unit.

[0120] The start signal acquisition unit is used to acquire a command input start signal. The initial command acquisition unit is used to determine the input command type and acquire an initial log analysis request command corresponding to the input command type. The end signal acquisition unit is used to acquire a command input end signal. The request command determination unit is used to process the initial log analysis request command to obtain a log analysis request command.

[0121] The demand instruction determination unit includes: a first instruction determination processing subunit, a second instruction determination processing subunit and an instruction splicing subunit.

[0122] The first instruction determination processing subunit is used to determine whether there is an initial log analysis request instruction with an input instruction type of picture type. When an initial log analysis request instruction with an input instruction type of picture type exists, the initial log analysis request instruction with picture type is converted into an initial log analysis request instruction with text type. The second instruction determination processing subunit is used to determine whether there is an initial log analysis request instruction with an input instruction type of voice type. When an initial log analysis request instruction with an input instruction type of voice type exists, the initial log analysis request instruction with voice type is converted into an initial log analysis request instruction with text type. The instruction splicing subunit is used to splice the initial log analysis request instructions with text type to obtain a log analysis request instruction.

[0123] The interface and parameter determination module includes: a primary and secondary keyword acquisition unit, an interface determination unit and a parameter determination unit.

[0124] The primary and secondary keyword acquisition unit is used to acquire the primary and secondary keywords in the log analysis request instruction using a large natural language model. The interface determination unit is used to determine the function call interface corresponding to the log analysis request instruction using the primary keyword. The parameter determination unit is used to determine the log analysis parameters corresponding to the log analysis request instruction using the primary keyword and / or secondary keyword.

[0125] The log analysis system of this embodiment also includes: a model training module.

[0126] The model training module is used to obtain log analysis request history instructions, mark the log analysis request history instructions with primary keywords and secondary keywords, and train the natural language model by completing the log analysis request history instructions with primary keyword marking and secondary keyword marking.

[0127] The primary and secondary keyword acquisition unit includes: a keyword acquisition subunit and an intention matching score value acquisition subunit.

[0128] The keyword acquisition subunit is used to obtain keywords from the log analysis request instructions. The intent match score acquisition subunit is used to obtain the intent match score of each keyword, determine the keyword with the highest intent match score as the primary keyword of the log analysis request instruction, and determine the remaining keywords as secondary keywords of the log analysis request instruction. The intent match score acquisition subunit uses a large natural language model to obtain the probability that the keyword is the primary intent of the log analysis request instruction, and determines the keyword's intent match score based on this probability.

[0129] The interface determination unit includes: a similarity value acquisition subunit, an interface identification code determination subunit and an interface determination subunit.

[0130] The similarity value acquisition subunit is used to obtain the similarity value between the main keyword and each interface identification code. The interface identification code determination subunit is used to use the interface identification code with the largest similarity value as the interface identification code corresponding to the main keyword. The interface determination subunit is used to determine the corresponding function call interface based on the interface identification code.

[0131] The similarity value acquisition subunit includes: an interface code identification word acquisition subunit, a sub-similarity value acquisition subunit and a similarity value determination subunit.

[0132] The interface code identification word acquisition subunit is used to obtain the interface code identification word of an interface identification code. The sub-similarity value acquisition subunit is used to perform similarity matching between the main keyword and each interface code identification word of the interface identification code to obtain a sub-similarity value between the main keyword and each interface code identification word. The similarity value determination subunit is used to use the largest sub-similarity value as the similarity value between the main keyword and the interface identification code.

[0133] The log analysis system of this embodiment further includes: an interface creation module and a function creation module.

[0134] The interface creation module is used to create a function call interface. The function call interface has a unique interface identification code, and each interface identification code has an interface code identification word. The function creation module is used to create a function corresponding to the function call interface. The function function uses log analysis parameters as input parameters and stores the created function in the function library.

[0135] The log analysis system of this embodiment, when the user needs to analyze the log, only needs to issue a log analysis request instruction. The log analysis system can automatically obtain the main keywords and secondary keywords based on the natural language large model, and can automatically determine the function function call interface corresponding to the log analysis request instruction through the main keywords, and determine the log analysis parameters corresponding to the log analysis request instruction through the main keywords and / or secondary keywords. It can also automatically call the function function in the function function library through the determined function function call interface and log analysis parameters to analyze and process the log, so as to obtain the log processing results required by the user, making the log analysis operation very simple; in addition, the function functions in the function function library can be created according to usage requirements, so that the log analysis system of this embodiment can perform various forms of analysis and processing on the log, and has a wide applicability.

[0136] Example 3:

[0137] An electronic device, as shown in FIG11 , includes a memory and a processor. The memory is used to store programs. The processor is used to run the programs stored in the memory to execute the log analysis method in Example 1.

[0138] Specifically, the electronic device of this embodiment may include: at least one processor, at least one network interface, a user interface, a memory, and at least one communication bus.

[0139] The communication bus can be used to realize the connection and communication among the above components.

[0140] The customer interface may include buttons, and the optional customer interface may also include a standard wired interface or a wireless interface.

[0141] The network interface may include, but is not limited to, a Bluetooth module, an NFC module, a Wi-Fi module, and the like.

[0142] The processor may include one or more processing cores. The processor uses various interfaces and lines to connect the various parts of the entire electronic device, and performs various functions of the routing device and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory, and calling data stored in the memory. Optionally, the processor can be implemented in at least one hardware form of DSP, FPGA, PLA. The processor can integrate one or a combination of CPU, GPU and modem. Among them, the CPU mainly processes the operating system, customer interface and application programs; the GPU is responsible for rendering and drawing the content to be displayed on the display; the modem is used to handle wireless communications. It is understandable that the above-mentioned modem may not be integrated into the processor, but may be implemented separately through a chip.

[0143] The memory may include RAM or ROM. Optionally, the memory includes a non-transitory computer-readable medium. The memory may be used to store instructions, programs, codes, code sets, or instruction sets. The memory may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory may also optionally be at least one storage device located away from the aforementioned processor.

[0144] Example 4:

[0145] A computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, implement the log analysis method of Example 1. If the components of the electronic device of Example 3 are implemented as software functional units and sold or used as independent products, they can be stored in the computer-readable storage medium of this embodiment.

[0146] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of this specification is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted via a computer-readable storage medium. The computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. Available media may be magnetic media (eg, floppy disks, hard disks, tapes), optical media (eg, digital versatile discs (DVDs)), or semiconductor media (eg, solid state disks (SSDs)).

[0147] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When executed, the program can include the processes of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks. The technical features of this embodiment and the implementation scheme can be combined in any manner unless they conflict.

[0148] The embodiments described above are merely preferred embodiments of this specification and are not intended to limit the scope of this specification. Without departing from the design spirit of this specification, various modifications and improvements made to the technical solutions of this specification by ordinary technicians in this field should fall within the scope of protection determined by the claims of this specification.

Claims

1. A log analysis method, comprising: Get log analysis request instructions; Input the log analysis request instruction into a natural language big model, and determine a function call interface corresponding to the log analysis request instruction and a log analysis parameter corresponding to the log analysis request instruction based on the natural language big model; Calling a function corresponding to the function calling interface in a function library according to the function calling interface, and using the log analysis parameter as an input parameter of the function; The logs in the log repository are processed through the function function and the input parameters of the function function to obtain a log processing result corresponding to the log analysis request instruction.

2. According to the log analysis method of claim 1, obtaining the log analysis request instruction comprises: Get the command input start signal; Determine the input instruction type, and obtain the initial log analysis request instruction corresponding to the input instruction type; Get the instruction input completion signal; The initial log analysis request instruction is processed to obtain the log analysis request instruction.

3. The log analysis method according to claim 2, wherein processing the initial log analysis request instruction to obtain the log analysis request instruction comprises: Determining whether there is an initial log analysis request instruction of an image type, and if there is an initial log analysis request instruction of an image type, converting the initial log analysis request instruction of the image type into an initial log analysis request instruction of a text type; Determining whether there is an initial log analysis request instruction of a voice type input instruction type, and if there is an initial log analysis request instruction of a voice type input instruction type, converting the initial log analysis request instruction of the voice type into an initial log analysis request instruction of a text type; The initial log analysis request instructions of the text type are spliced to obtain the log analysis request instruction.

4. The log analysis method according to claim 1, wherein determining the function call interface corresponding to the log analysis request instruction and determining the log analysis parameters corresponding to the log analysis request instruction based on the natural language large model comprises: Obtaining the primary keywords and secondary keywords in the log analysis request instruction through a large natural language model; Determine the function call interface corresponding to the log analysis request instruction through the main keyword; The log analysis parameters corresponding to the log analysis request instruction are determined using the primary keyword and / or the secondary keyword.

5. The log analysis method according to claim 4, further comprising: Obtain log analysis request history instructions, perform primary keyword tagging and secondary keyword tagging on the log analysis request history instructions, and train the natural language large model by completing the primary keyword tagging and secondary keyword tagging of the log analysis request history instructions.

6. The log analysis method according to claim 4, wherein obtaining the primary keywords and secondary keywords in the log analysis request instruction through a natural language large model comprises: Obtaining keywords in the log analysis request instruction; Obtain the intention matching score value of each keyword, determine the keyword with the highest intention matching score value as the main keyword of the log analysis request instruction, and determine the remaining keywords as secondary keywords of the log analysis request instruction.

7. The log analysis method according to claim 6 obtains the probability that the keyword is the main intention of the log analysis request instruction through a large natural language model, and determines the intention matching score value of the keyword through the probability.

8. The log analysis method according to claim 4, wherein determining the function call interface corresponding to the log analysis request instruction using the primary keyword comprises: Obtaining a similarity value between the main keyword and each interface identification code; The interface identification code with the largest similarity value is used as the interface identification code corresponding to the main keyword; The corresponding function calling interface is determined according to the interface identification code.

9. The log analysis method according to claim 8, wherein obtaining the similarity value between the main keyword and each interface identification code comprises: Obtaining an interface code identification word of the interface identification code; Performing similarity matching between the main keyword and each interface code identification word of the interface identification code to obtain a sub-similarity value between the main keyword and each interface code identification word; The largest sub-similarity value is used as the similarity value between the main keyword and the interface identification code.

10. The log analysis method according to claim 1, further comprising: Creating a function call interface, wherein the function call interface is provided with a unique interface identification code, and each interface identification code is provided with an interface code identification word; A function function corresponding to the function function calling interface is created, the function function takes the log analysis parameter as an input parameter, and the created function function is stored in the function function library.

11. A log analysis system, comprising: The request instruction acquisition module is used to obtain log analysis request instructions; An interface and parameter determination module, configured to input the log analysis request instruction into a natural language macro model, and determine a function call interface corresponding to the log analysis request instruction and a log analysis parameter corresponding to the log analysis request instruction based on the natural language macro model; A function calling module, configured to call a function corresponding to the function calling interface in a function library according to the function calling interface, and use the log analysis parameter as an input parameter of the function; The log processing result acquisition module is used to process the logs in the log storage repository through the function function and the input parameters of the function function to obtain the log processing results corresponding to the log analysis request instruction.

12. The log analysis system according to claim 11, wherein the request instruction acquisition module comprises: A start signal acquisition unit, used for acquiring a command input start signal; An initial instruction acquisition unit, configured to determine an input instruction type and acquire an initial log analysis request instruction corresponding to the input instruction type; An end signal acquisition unit, used for acquiring an instruction input end signal; The request instruction determining unit is configured to process the initial log analysis request instruction to obtain the log analysis request instruction.

13. The log analysis system according to claim 12, wherein the request instruction determination unit comprises: a first instruction determination processing sub-unit, configured to determine whether there is an initial log analysis request instruction of an image type, and, if there is an initial log analysis request instruction of an image type, convert the image type initial log analysis request instruction into a text type initial log analysis request instruction; a second instruction determination processing sub-unit, configured to determine whether there is an initial log analysis request instruction of a voice type input instruction type, and when there is an initial log analysis request instruction of a voice type input instruction type, convert the initial log analysis request instruction of the voice type into an initial log analysis request instruction of a text type; The instruction splicing subunit is used to splice the initial log analysis request instructions of the text type to obtain the log analysis request instructions.

14. The log analysis system according to claim 11, wherein the interface and parameter determination module comprises: A primary and secondary keyword acquisition unit, configured to acquire primary and secondary keywords in the log analysis request instruction through a large natural language model; An interface determining unit, configured to determine a function call interface corresponding to the log analysis request instruction using the primary keyword; A parameter determination unit is used to determine the log analysis parameter corresponding to the log analysis request instruction through the main keyword and / or the secondary keyword.

15. The log analysis system according to claim 14, further comprising: The model training module is used to obtain log analysis request history instructions, mark the log analysis request history instructions with primary keywords and secondary keywords, and train the natural language model by completing the log analysis request history instructions with primary keyword marking and secondary keyword marking.

16. The log analysis system according to claim 14, wherein the primary and secondary keyword acquisition unit comprises: A keyword acquisition subunit, configured to acquire keywords in the log analysis request instruction; The intention matching score value acquisition subunit is used to obtain the intention matching score value of each keyword, determine the keyword with the highest intention matching score value as the main keyword of the log analysis request instruction, and determine the remaining keywords as secondary keywords of the log analysis request instruction.

17. A log analysis system according to claim 16, wherein the intention matching score value acquisition subunit obtains the probability that the keyword is the main intention of the log analysis request instruction through a natural language large model, and determines the intention matching score value of the keyword through the probability.

18. The log analysis system according to claim 14, wherein the interface determination unit comprises: A similarity value obtaining subunit, configured to obtain a similarity value between the main keyword and each interface identification code; an interface identification code determination subunit, configured to use the interface identification code with the largest similarity value as the interface identification code corresponding to the primary keyword; The interface determination subunit is used to determine the corresponding function call interface according to the interface identification code.

19. The log analysis system according to claim 18, wherein the similarity value obtaining subunit comprises: An interface code identification word acquisition subunit, used to acquire an interface code identification word of the interface identification code; a sub-similarity value obtaining sub-unit, configured to perform similarity matching between the main keyword and each of the interface code identification words of the interface identification code, so as to obtain a sub-similarity value between the main keyword and each of the interface code identification words; The similarity value determining sub-unit is configured to use the maximum sub-similarity value as the similarity value between the main keyword and the interface identification code.

20. The log analysis system according to claim 11, further comprising: An interface creation module is used to create a function call interface, wherein the function call interface is provided with a unique interface identification code, and each interface identification code is provided with an interface code identification word; A function creation module is used to create a function corresponding to the function call interface, the function takes the log analysis parameter as an input parameter, and stores the created function in the function library.

21. An electronic device comprising: Memory, used to store programs; A processor, configured to run the program stored in the memory to execute the log analysis method according to any one of claims 1 to 10.

22. A computer-readable storage medium having computer program instructions stored thereon, wherein the computer program instructions, when executed by a processor, implement the log analysis method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Log analysis method and analysis device for component

    CN103544298A

  • Log analysis method and device

    CN110704290A

  • Log processing method and device, computer equipment and storage medium

    CN114968960A

  • Voice control method, computing device and readable storage medium

    CN117334194A

  • Log analysis method and system

    CN117950950A