Log-based data-change tracking system and method therefor
The log-based data change tracking system addresses the challenge of data lineage management by collecting and analyzing log information to efficiently trace data changes, improving data management and business intelligence services.
Patent Information
- Application Number
- PCT/KR2025/011379
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-30
- Filing Date
- 2025-07-30
- Publication Date
- 2026-02-05
AI Technical Summary
Current systems lack efficient methods for tracking data changes and managing data lineage, which is crucial for identifying the source and impact of data in diverse IT environments, impacting business responsiveness and productivity.
A log-based data change tracking system that collects and stores raw, conversion, and application log information, generating metadata to trace data lineage, and provides business intelligence services by extracting source information and generating query results.
Enables efficient and reliable data management by tracing data changes, enhancing user convenience and reliability in providing desired data and business intelligence services.
Smart Images

Figure KR2025011379_05022026_PF_FP_ABST
Abstract
Description
Log-based data change tracking system and method thereof
[0001] The present disclosure relates to a log-based data change tracking system and method thereof. In particular, the present disclosure relates to a log-based data change tracking system and method thereof capable of tracking data changes by extracting source information for result data based on logs.
[0002] As the current IT environment diversifies and expands, the need for integrated and efficient operations, as well as strengthened data management capabilities to quickly respond to changes in the new business environment and IT technology, is growing.
[0003] Among these, data lineage management refers to the systematic management of information regarding which critical data flows from where, through which transformation processes, and so on. Data lineage management allows business and IT staff to easily identify the source of data and where it is being used, thereby improving productivity.
[0004] Therefore, companies can identify the impact of changes in programs or data and flexibly respond to business changes with minimal risk.
[0005] The matters described as background technology above are only intended to enhance understanding of the background of the present disclosure, and should not be taken as an admission that they correspond to prior art already known to a person of ordinary skill in the art.
[0006] Meanwhile, a prior art document related to the present disclosure is Republic of Korea Patent Publication No. 10-2022-0101787.
[0007] The problem that the present disclosure seeks to solve is to provide a log-based data change tracking system and method therefor.
[0008] The problems to be solved by the present disclosure are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art to which the present disclosure pertains from the description below.
[0009] A log-based data change tracking method according to one embodiment of the present disclosure may include the steps of collecting raw data generated by one or more applications; storing raw log information matching the raw data in a data storage; storing conversion log information matching conversion data analyzed based on the raw data by an operation of an application in the data storage; storing application log information generated based on the raw log information stored in the data storage and the conversion log information in a log storage; and storing matching log information generated by matching the raw log information and the conversion log information based on the application log information as metadata in a lineage storage.
[0010] When a Business Intelligence (BI) service request is received, the method may further include a step of extracting result data corresponding to the received service request from the metadata; a step of extracting source information corresponding to the result data using the matching log information; and a step of generating query result data including the result data and the source information.
[0011] The step of extracting the source information may include a step of tracing and extracting the source information corresponding to the result data in reverse order using the matching log information.
[0012] The step of extracting the source information by tracing it in reverse order may include the step of analyzing the log relationship between the application log information and the result data based on the matching log information and then tracing it in reverse order to extract the first source information; and the step of analyzing the raw log information and the conversion log information corresponding to the first source information based on the application log information and then tracing it in reverse order to extract the second source information.
[0013] The first source information may be based on the conversion log information and include information about the data type, data delimiter, and module delimiter of the conversion data, and the second source information may be based on the raw log information and include information about the data type, data delimiter, and module delimiter of the raw data.
[0014] In one embodiment, the raw log information may include a storage location of the raw data and data identification information of the raw data, the conversion log information may include a storage location of the conversion data, data identification information of the conversion data, and change information of the conversion data, and the application log information may include the raw log information and the conversion log information for each application.
[0015] When a business intelligence service request is received, a step of generating expected data from the metadata before generating result data corresponding to the received service request;
[0016] The method may further include a step of comparing and analyzing the expected data and reference data to calculate a similarity, and then, if the calculated similarity is lower than a preset similarity, extracting additional data from the metadata; and a step of generating the result data in which the additional data is reflected in the expected data.
[0017] A log-based data change tracking system according to one embodiment of the present disclosure may include a first database server that stores and manages raw log information of raw data generated by at least one application and conversion log information of analysis data converted from the raw data in a data storage; a second database server that stores and manages application log information generated by collecting the raw log information and the conversion log information in real time; and a third database server that stores and manages matching log information generated by matching the raw log information and the conversion log information based on the application log information as metadata in a lineage storage.
[0018] It may further include a client terminal that requests a Business Intelligence (BI) service and receives query result data corresponding to the service request.
[0019] A non-transitory computer-readable recording medium according to one embodiment of the present disclosure may include instructions that cause a computer to execute a log-based data change tracking method.
[0020] The technical solutions of the present disclosure are not limited to the technical solutions mentioned above, and other technical solutions not mentioned will be clearly understood by those skilled in the art to which the present disclosure pertains from the description below.
[0021] According to embodiments of the present disclosure, by tracking changes in data based on log information for various data performed in at least one application using log information, the user's desired data can be efficiently provided, thereby increasing user convenience and reliability.
[0022] According to embodiments of the present disclosure, a business intelligence service can be used to clearly provide result data for a service desired by a user.
[0023] According to embodiments of the present disclosure, it is possible to provide information desired by a user by tracing back the path through which the information was stored to the current location.
[0024] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art to which the present disclosure pertains from the description below.
[0025] FIG. 1 is a conceptual diagram illustrating a log-based data change tracking system according to one embodiment of the present disclosure.
[0026] FIG. 2 is a diagram illustrating a log-based data change tracking system according to one embodiment of the present disclosure.
[0027] FIG. 3 is a diagram illustrating a log-based data change tracking method according to one embodiment of the present disclosure.
[0028] Figure 4 is a drawing for explaining a method for generating metadata shown in Figure 3.
[0029] FIG. 5 is a diagram illustrating a business intelligence service according to one embodiment of the present disclosure.
[0030] Figure 6 is a drawing for explaining the steps for extracting source information shown in Figure 5.
[0031] Hereinafter, embodiments are described in detail with reference to the attached drawings. However, the embodiments may be modified in various ways, and the scope of the patent application is not limited or restricted by these embodiments. It should be understood that all modifications, equivalents, or alternatives to the embodiments are included within the scope of the patent application.
[0032] Specific structural or functional descriptions of the embodiments are disclosed for illustrative purposes only and may be modified and implemented in various forms. Accordingly, the embodiments are not limited to the specific disclosed form, and the scope of this specification includes modifications, equivalents, or alternatives that fall within the technical concept.
[0033] Although terms such as "first" or "second" may be used to describe various components, these terms should be interpreted solely to distinguish one component from another. For example, a first component may be referred to as a second component, and similarly, a second component may also be referred to as a first component.
[0034] When it is said that a component is "connected" to another component, it should be understood that it may be directly connected or connected to that other component, but there may also be other components in between.
[0035] The terms used in the examples are for illustrative purposes only and should not be construed as limiting. Singular expressions include plural expressions unless the context clearly dictates otherwise. In this specification, terms such as "comprise" or "have" are intended to specify the presence of a feature, number, step, operation, component, part, or combination thereof described in the specification, but should be understood to not preclude the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.
[0036] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by a person of ordinary skill in the art to which the embodiments pertain. Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined herein.
[0037] In addition, when describing with reference to the attached drawings, identical components will be assigned the same reference numerals regardless of the drawing numbers, and redundant descriptions thereof will be omitted. When describing embodiments, if a detailed description of a related known technology is judged to unnecessarily obscure the gist of the embodiment, the detailed description will be omitted.
[0038] The embodiments may be implemented in various forms of products, such as personal computers, laptop computers, tablet computers, smart phones, televisions, smart home appliances, intelligent vehicles, kiosks, and wearable devices.
[0039] First, the configuration of a log-based data transformation tracking system according to one embodiment of the present disclosure will be described with reference to FIGS. 1 and 2.
[0040] FIG. 1 is a conceptual diagram for explaining a log-based data change tracking system according to one embodiment of the present disclosure, and FIG. 2 is a diagram for explaining a log-based data change tracking system according to one embodiment of the present disclosure.
[0041] As illustrated in FIGS. 1 and 2, a log-based data change tracking system (1) according to one embodiment of the present disclosure may include a client terminal (10), a first database server (20), a second database server (30), and a third database server (40).
[0042] Here, the client terminal (10) may refer to a node(s) in a database system having a mechanism for communicating over a network. For example, the client terminal (10) may include a personal computer (PC), a laptop computer, a workstation, a terminal, and / or any electronic device having network connectivity. In addition, the client terminal (10) may include any server implemented by at least one of an agent, an application programming interface (API), and a plug-in.
[0043] For example, a client terminal (10) may be associated with a user using a third database server (30).
[0044] In this embodiment, the client terminal (10) can request a business intelligence service and receive query result data corresponding to the service request in real time from a third database server (30).
[0045] Specifically, the client terminal (10) can request a business intelligence service through a network and receive result data corresponding to the service request, along with source information about the path through which the result data was stored at the current location.
[0046] For example, if a client terminal (10) is a business and requests information on next year's projected sales, the client terminal (10) can be provided with supporting source information for the projected sales. Accordingly, the client terminal (10) can receive more accurate data.
[0047] The client terminal (10) may, but is not limited to, pre-registering as a member using user information to perform business intelligence services. Here, user information may include, but is not limited to, one or more of job-specific, individual, and company-specific information.
[0048] According to an embodiment, the client terminal (10) may generate a feedback signal for the business intelligence service after or during use of the business intelligence service.
[0049] The first to third database servers (20, 30, 40) may include any type of computer system or computer device, such as, for example, a microprocessor, a mainframe computer, a digital single processor portable device, and a device controller. Here, the first to third database servers (20, 30, 40) may each include a database management system (DBMS) and persistent storage.
[0050] The first to third database servers (20, 30, 40) may include one or more memories including a buffer cache. In addition, the first to third database servers (20, 30, 40) may include one or more processors (not shown). Accordingly, the DBMS may be operated on the memory by the processors.
[0051] Here, memory may refer to, but is not limited to, a volatile storage device in which stored information is instantly erased when power is turned off, such as random access memory (RAM) such as dynamic random access memory (DRAM) and static random access memory (SRAM), which is the primary storage device directly accessed by the processor. Such memory may be operated by the processor. The memory may temporarily store a data table. The data table may include data values. In one aspect, the data values of the data table may be written from the memory to a permanent storage medium. Specifically, data may be stored in a data block of a buffer cache included in the memory. The data stored in the data block of the buffer cache may be written to a permanent storage medium by a background process.
[0052] Permanent storage media include non-volatile storage media capable of persistently storing arbitrary data, such as magnetic disks, optical disks, and magneto-optical storage devices, as well as storage devices based on flash memory and / or battery-backed memory. In this case, the persistent storage media can communicate with the processors and memories of the first to third database servers (20, 30, 40) via various communication means.
[0053] Depending on the embodiment, the persistent storage medium may be located externally to the first to third database servers (20, 30, 40) and may be capable of communicating with the first to third database servers (20, 30, 40).
[0054] The DBMS is a program that allows operations such as searching, inserting, modifying, and / or deleting necessary data in the first to third database servers (20, 30, 40), and, as described above, can be implemented by a processor in the memory of the first to third database servers (20, 30, 40).
[0055] The client terminal (10) and the first to third database servers (20, 30, 40) can communicate with each other via a network. In addition, the first to third database servers (20, 30, 40) can also communicate with each other via a network.
[0056] The network presented in this embodiment may include various wired communication systems such as Public Switched Telephone Network (PSTN), xDSL (x Digital Subscriber Line), Rate Adaptive DSL (RADSL), Multi Rate DSL (MDSL), Very High Speed DSL (VDSL), Universal Asymmetric DSL (UADSL), High Bit Rate DSL (HDSL), and Local Area Network (LAN).
[0057] Additionally, the network presented in this embodiment may include various wireless communication systems such as CDMA (Code Division Multi Access), TDMA (Time Division Multi Access), FDMA (Frequency Division Multi Access), OFDMA (Orthogonal Frequency Division Multi Access), SCFDMA (Single Carrier-FDMA) and other systems.
[0058] Additionally, the network presented in this embodiment may include a database link. Accordingly, the first to third database servers (20, 30, 40) may communicate with each other via this database link to retrieve data from other database servers.
[0059] For example, the database link may include a database link between the first to third database servers (20, 30, 40). The techniques described herein may be used in other networks as well as the networks mentioned above.
[0060] Specifically, the first database server (20) can generate raw data generated by application execution and converted data obtained by converting the raw data, and then store them in real time in the data storage (22).
[0061] More specifically, the first database server (20) can read raw data, analyze the raw data, convert the raw data, store the converted data, raw log information matching the raw data, and convert log information matching the converted data in real time in the data storage (22) according to the execution of the application.
[0062] For example, the first database server (20) can continuously update and store the storage location of raw data and raw log information including data identification information of the raw data in the data storage (22) according to application execution, and can store the storage location of analysis data and conversion log information including data identification information of the analysis data.
[0063] According to an embodiment, the first database server (20) can record and store the storage time and data capacity of raw data in raw log information, and can record and store the storage time and data capacity of analysis data in conversion log information.
[0064] The second database server (30) can collect raw log information and converted log information generated by the execution of one or more applications based on the application, generate application log information, and store the generated application log information in a log storage (32).
[0065] In this embodiment, the second database server (30) can perform the function of a log processor that collects and stores application log information on behalf of the application.
[0066] For example, the second database server (30) can collect raw log information and conversion log information generated based on input data, application identifier, module identifier, and output data, and store the collected information as application log information.
[0067] The third database server (40) can generate matching log information by matching raw log information and converted log information based on application log information, and store the generated matching log information as metadata in the lineage storage (42) in real time.
[0068] Specifically, the third database server (40) can generate matching log information by matching the raw log information corresponding to the raw data and the change log information corresponding to the converted data so that it can know through which path the raw data and the converted data were stored in the current location according to the execution of the application, and can store the generated matching log information as metadata.
[0069] In addition, when a business intelligence service is requested by a client terminal (10), the third database server (40) can extract result data corresponding to the service request from metadata and then extract source information for the result data to generate query result data.
[0070] Specifically, when a business intelligence service is requested by a client terminal (10), the third database server (40) preprocesses service request data included in the business intelligence service. Thereafter, the third database server (40) extracts keywords from the preprocessed service request data and can use the extracted keywords to generate result data corresponding to the service request from metadata.
[0071] For example, a third database server (40) performs a tokenization process to filter text-based service request data. Next, the third database server (40) performs a purification process to remove noise data contained in the tokenized text data. Subsequently, the third database server (40) can normalize the purified text.
[0072] According to an embodiment, the third database server (40) can automatically check for typos in text and convert the typos, or automatically remove duplicate data.
[0073] The third database server (40) extracts keywords from the service request data and then classifies the service request data by field using the extracted keywords. Thereafter, the third database server (40) can generate result data corresponding to the keywords classified by field.
[0074] Meanwhile, the third database server (40) can provide result data corresponding to service request data according to a pre-entered algorithm, but in contrast, as natural language analysis and processing technology develops along with big data processing technology, it can also provide optimal result data by considering various variables.
[0075] In this embodiment, the third database server (40) can provide result data using various algorithms such as a large language model (LLM), retrieval-augmented generation (RAG), explainable AI (XAI), machine learning, etc. for big data analysis. Since training for LLM uses a large amount of input and requires a large amount of computation, a high-throughput GPU (Graphics Processing Unit) can be used to efficiently process multi-device-based computation.
[0076] Additionally, the third database server (40) can extract source information corresponding to the result data using matching log information.
[0077] Specifically, the third database server (40) can use matching log information to trace back and extract source information corresponding to the result data.
[0078] For example, the third database server (40) can extract the first source information by analyzing the log relationship between the application log information and the result data based on the matching log information and then tracing in reverse order. Then, the third database server (40) can extract the second source information by analyzing the raw log information and the converted log information corresponding to the first source information based on the application log information and then tracing in reverse order. In other words, the third database server (40) can extract the source information from the converted data in the order of the raw data.
[0079] In some embodiments, when a business intelligence service request is received, the third database server (40) may extract and generate expected data from metadata before generating result data corresponding to the service request.
[0080] That is, the third database server (40) compares and analyzes the expected data and the reference data to calculate the similarity between the expected data and the reference data. Thereafter, if the calculated similarity is lower than the preset similarity, the third database server (40) can extract additional data from the metadata and then generate result data reflecting the additional data. Depending on the embodiment, the third database server (40) may also generate result data without reflecting the additional data.
[0081] Next, the operation of a log-based data change tracking system (1) according to one embodiment of the present disclosure will be described with reference to FIGS. 3 and 4. Hereinafter, for convenience of explanation, the log-based data change tracking system will be abbreviated as "system."
[0082] FIG. 3 is a diagram for explaining a log-based data change tracking method according to one embodiment of the present disclosure, and FIG. 4 is a diagram for explaining a method for generating metadata illustrated in FIG. 3.
[0083] Referring to FIG. 3, the system (1) can collect raw data generated by application operation and then store raw log information corresponding to the raw data (S100).
[0084] Specifically, the first database server (20) can collect raw data generated by one or more applications and then store raw log information matching the raw data in a data storage (22).
[0085] For example, referring to FIG. 4, the first database server (20) can generate raw log information based on the data type, data delimiter, and data location of the raw data, and store the generated raw log information in the data storage (22).
[0086] Next, the system (1) can analyze the raw data generated by application operation to generate conversion data, and then store conversion log information corresponding to the generated conversion data in a data storage (22) (S110).
[0087] Specifically, the first database server (20) can analyze raw data generated by one or more applications to generate converted data, and then store converted log information matching the generated converted data in a data storage (22).
[0088] For example, referring to FIG. 4, the first database server (20) can generate conversion log information based on the data type, data delimiter, and data location for the conversion data, and store the generated conversion log information in the data storage (22).
[0089] Next, the system (1) can collect raw log information and conversion log information stored in the data storage (22), generate application log information including raw log information and conversion log information for each application, and store the generated application log information in the log storage (32) (S120).
[0090] Specifically, the second database server (30) can generate application log information by merging and / or filtering raw log information and converted log information for each running application.
[0091] For example, referring to FIG. 4, the second database server (30) may merge and / or filter raw log information and converted log information collected from the data storage (22), and then generate application log information based on input data, application identifier, module identifier, and output data, and store the generated application log information in the log storage (32).
[0092] Finally, the system (1) can match raw log information and converted log information to generate matching log information, and store the generated matching log information as metadata in the lineage storage (42) (S130).
[0093] Specifically, the third database server (40) can generate matching log information by matching raw log information and converted log information based on application log information.
[0094] For example, referring to FIG. 4, the third database server (40) can store metadata based on input data, application identifier, module identifier, and output data.
[0095] Next, a method for providing a business intelligence service by the system (1) is described with reference to FIG. 5. FIG. 5 is a drawing for explaining a business intelligence service according to one embodiment of the present disclosure, and FIG. 6 is a drawing for explaining a step of extracting source information illustrated in FIG. 5.
[0096] Referring to FIG. 5, the system (1) can receive a business intelligence (BI) service request from a client terminal (10) (S200).
[0097] After this, the system (1) can preprocess the service request data included in the service request and then extract keywords from the preprocessed service request data (S210).
[0098] Specifically, the third database server (40) can sequentially perform tokenization, cleaning, and normalization tasks to ensure that service request data is accurately recognized.
[0099] Furthermore, the third database server (40) can classify the preprocessed service request data by requested service based on the words contained in the preprocessed service request data. Specifically, the third database server (40) can extract keywords from the preprocessed service request data and then use the extracted keywords to classify the preprocessed service request data by requested service.
[0100] Next, the system (1) can extract result data corresponding to the received service request from metadata (S220), and then extract source information corresponding to the result data from metadata (S230).
[0101] Specifically, the third database server (40) can use matching log information to trace back and extract source information corresponding to the result data.
[0102] For example, the third database server (40) can analyze the log relationship between application log information and result data based on matching log information, and then trace in reverse order to extract first source information. Next, the third database server (40) can analyze the raw log information and converted log information corresponding to the first source information based on the application log information, and then trace in reverse order to extract second source information. For a more detailed explanation of source information extraction, reference will be made to FIG. 6.
[0103] Fig. 6 illustrates a case where the result data is 'data_b.1'. In this case, the third database server (40) can extract the first source information of the result data 'data_b.1'. The first source information can include the generation path of the result data 'data_b.1'. For example, the generation path can be "data_a.1 - application #2 - field change module". This generation path means that the result data 'data_b.1' was generated as a result of the transformation data 'data_a.1' being processed by the module identifier 'field change module' of the application identifier 'application #2'.
[0104] Next, the third database server (40) can extract the second source information of the converted data 'data_a.1' when the first source information is the converted data 'data_a.1'. The second source information can include the generation path of the converted data 'data_a.1'. For example, the generation path can be "data_1.1 - application #1 - field merge module". This generation path means that the converted data 'data_a.1' was generated as a result of the raw data 'data_1.1' and the raw data 'data_2.1' being processed in the module separator 'field merge module' of the application separator 'application #1'.
[0105] In other words, the third database server (40) can trace the data transformation path in reverse order from the result data. That is, the third database server (40) can extract the source information including the first source information from 'data_a.1' and the second source information from 'data_1.1' and 'data_1.2' for the result data called 'data_b.1'.
[0106] In this embodiment, the step of generating source information is initiated in two steps, but is not limited thereto, and if data is modified, a step of extracting multiple source information may be further included.
[0107] Referring again to FIG. 5, the system (1) can generate query result data including result data and source information (S240).
[0108] Specifically, the third database server (40) can generate query result data by matching result data and source information.
[0109] For example, the third database server (40) can synchronize result data and source information using a query engine to generate query result data corresponding to the service request received in step S200. The generated query result data can be transmitted to the client unit (10).
[0110] The embodiments described above may be implemented using hardware components, software components, and / or a combination of hardware components and software components. For example, the devices, methods, and components described in the embodiments may be implemented using one or more general-purpose computers or special-purpose computers, such as, for example, a processor, a controller, an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable gate array (FPGA), a programmable logic unit (PLU), a microprocessor, or any other device capable of executing instructions and responding to them. The processing device may execute an operating system (OS) and software applications running on the operating system. The processing device may also access, store, manipulate, process, and generate data in response to the execution of the software. For ease of understanding, the processing device is sometimes described as being used alone; however, one of ordinary skill in the art will recognize that the processing device may include multiple processing elements and / or multiple types of processing elements. For example, a processing unit may include multiple processors, or a processor and a controller. Other processing configurations, such as parallel processors, are also possible.
[0111] Software may include computer programs, codes, instructions, or any combination thereof, which may configure a processing device to perform a desired operation or, independently or collectively, command the processing device. The software and / or data may be permanently or temporarily embodied in any type of machine, component, physical device, virtual equipment, computer storage media or devices, or transmitted signal waves, for interpretation by the processing device or for providing instructions or data to the processing device. The software may also be distributed over networked computer systems and stored or executed in a distributed manner. The software and data may be stored on a computer-readable recording medium.
[0112] The method according to the embodiment may be implemented in the form of program commands that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program commands, data files, data structures, etc., alone or in combination. The program commands recorded on the medium may be those specially designed and configured for the embodiment or may be those known and available to those skilled in the art of computer software. Examples of the computer-readable recording medium include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specially configured to store and execute program commands such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc.
[0113] Although the embodiments described above have been described with limited drawings, those skilled in the art will appreciate that various technical modifications and variations can be applied based on the above. For example, appropriate results can still be achieved even if the described techniques are performed in a different order than described, and / or components of the described systems, structures, devices, circuits, etc. are combined or combined in a different manner than described, or are replaced or substituted with other components or equivalents.
[0114] Therefore, other implementations, other embodiments, and equivalents to the claims also fall within the scope of the claims described below.
[0115] The log-based data change tracking system and method described above can be applied to the business intelligence service field.
Claims
1. In the log-based data change tracking method, A step of collecting raw data generated by one or more applications; A step of storing raw log information matching the above raw data in a data storage; A step of storing conversion log information matching the conversion data analyzed based on the raw data by the operation of the application in the data storage; A step of storing application log information generated based on the raw log information and the converted log information stored in the data storage in a log storage; and A step of storing matching log information generated by matching the raw log information and the converted log information based on the application log information as metadata in a lineage storage, A log-based data change tracking method.
2. In paragraph 1, When a Business Intelligence (BI) service request is received, a step of extracting result data corresponding to the received service request from the metadata; A step of extracting source information corresponding to the result data using the above matching log information; and Further comprising a step of generating query result data including the result data and the source information. A log-based data change tracking method.
3. In paragraph 2, The steps for extracting the above source information are: A step of extracting the source information corresponding to the result data by tracing it in reverse order using the matching log information, A log-based data change tracking method.
4. In paragraph 3, The step of extracting the above source information in reverse order is: A step of analyzing the log relationship between the application log information and the result data based on the matching log information and then tracing in reverse order to extract the first source information; and A step of analyzing the raw log information and the converted log information corresponding to the first source information based on the application log information and then tracing in reverse order to extract the second source information, A log-based data change tracking method.
5. In paragraph 4, The above first source information is based on the conversion log information and includes information about the data type, data delimiter, and module delimiter of the conversion data, The second source information is based on raw log information and includes information about the data type, data delimiter, and module delimiter of the raw data. A log-based data change tracking method.
6. In paragraph 4, The above raw log information includes the storage location of the raw data and data identification information of the raw data, The above conversion log information includes the storage location of the conversion data, data identification information of the conversion data, and change information of the conversion data. The above application log information includes the raw log information and the conversion log information for each application. A log-based data change tracking method.
7. In paragraph 1, When a business intelligence service request is received, a step of generating expected data from the metadata before generating result data corresponding to the received service request; A step of comparing and analyzing the above expected data and reference data to calculate a similarity, and then, if the calculated similarity is lower than the preset similarity, extracting additional data from the metadata; and Further comprising a step of generating the result data in which the additional data is reflected in the expected data. A log-based data change tracking method.
8. A first database server that stores and manages raw log information of raw data generated by one or more applications and converted log information of analysis data converted from the raw data in a data storage; A second database server that collects the raw log information and the converted log information in real time and stores and manages the generated application log information in a log storage; and A third database server that stores and manages matching log information generated by matching the raw log information and the converted log information based on the application log information as metadata in the lineage storage. Log-based data change tracking system.
9. In paragraph 8, Further comprising a client terminal that requests a Business Intelligence (BI) service and receives query result data corresponding to the service request. Log-based data change tracking system.
10. A non-transitory computer-readable recording medium containing instructions for causing a computer to execute the method according to claim 1.
Citation Information
Patent Citations
System log data classification processing method and device and intelligent electronic equipment
CN111736978A
Log data processing method and device, storage medium and electronic equipment
CN113868215A
Measuring User Behavior and Engagement Using User Interfaces in Terminal Devices
JP2017504121A
Data management device, data management method and a computer-readable storage medium for storing data management program
KR102669472B1
Data change tracking system baed on log and method thereof
KR102818444B1