Server and method for sending syslog message
By associating logs with groups and authorizing users based on group-specific access, the method addresses the high computing power demands of existing access control systems, enhancing security and efficiency in log access management.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
- Filing Date
- 2025-01-24
- Publication Date
- 2026-07-30
AI Technical Summary
Existing access control systems face challenges in managing access to log entries due to the large number of resources, requiring high computing capacity and power, which complicates the application of the principle of least privilege and increases security risks.
A method and system that utilize a first server to send syslog messages with group indications, enabling a log repository to associate logs with specific groups, and a log viewer device to authorize users based on their interactions, ensuring access control aligns with the principle of least privilege without excessive computing power.
This approach reduces computing power requirements and enhances security by allowing access control based on group associations, ensuring only authorized users can view relevant logs, thus improving overall system security and efficiency.
Smart Images

Figure SE2025050056_30072026_PF_FP_ABST
Abstract
Description
[0001] SERVER AND METHOD FOR SENDING SYSLOG MESSAGE
[0002] TECHNICAL FIELD
[0003] The disclosure relates to at least one first server, a log repository, a log viewer device and methods performed by the first server, the log repository and the log viewer device. Related computer programs and computer readable storage media are also disclosed.
[0004] BACKGROUND
[0005] Logging functions are essential to ensure continuous monitoring of e.g. virtual network functions (VNFs) in a communication network. In cloud-native logging systems, the aggregation, processing and storage of logs can be considered a nonfunctional requirement that is fulfilled by a cloud provider or a tool suite that runs in cooperation with a cloud platform. A typical logging architecture has a secured, dedicated host that includes, for example, local storage of logs or centralized (remote) storage of logs that have a retention period to avoid that the storage capacity limit is reached. In cloud-native logging systems many devices may in general create log data, whereby each device forwards log data to the dedicated host.
[0006] The Internet Engineering Task Force (IETF) Requests For Comments (RFC) 5424 (March 2009) “The Syslog Protocol” relates to a syslog protocol used to convey event notification messages to a storage of log entries. IETF RFC 5424 further refers to a layered architecture allowing use of any number of transport protocols for transmission of syslog messages and a standard format for syslog messages.
[0007] Controlling access to log entries in the log storage may be essential to decrease security risks and ensure protection from unauthorized access in e.g. a cloud platform.
[0008] A Target Based Access Control (TBAC) system is a security model which enables grant of access rights to a user based on a specific resource, such as log entries, which the user is trying to access. An assignment to a resource is identified by a user authorization role. For example, when considering a performance managementfunctionality and the intention to enable the user to handle a function for a specific node type, such as an Ericsson multi-standard (MS) Radio Base Station (RBS), the specific node type is identified as the target. In this example, authorization of the user is handled within the target. A pure role-based access control (RBAC) system, on the other hand, allows access based on a user role, such as admin, user, manager, and grants authorizations based on the user role only.
[0009] Using the TBAC system for controlling access to log entries may enable application of a principle of least privilege and improved security. The principle of least privilege is a security concept stating that a user or entity has access only to specific data, resources and an application needed to complete a required task. According to the principle of least privilege, users of a specific group would be expected to be only allowed to access logs in the dedicated host related to the resources of the target group.
[0010] In access control systems such as the TBAC system, granting access to logs based on a group of resources is challenging, due to challenges such as, e.g., the large number of resources that require high computing capacity, and may cause a demand for unfeasibly high computing power.
[0011] SUMMARY
[0012] An object of the invention is to enable improved security through improved access control to log entries in a digital log repository.
[0013] A first aspect of the invention relates to a method performed by at least one first server providing a service to at least one resource comprised in a group of resources, wherein the at least one first server is communicatively connected to a log repository. The method comprises obtaining information on the group, obtaining information pertaining to at least one event associated with the resource, and sending, to the log repository, a syslog message pertaining to the event, wherein the syslog message comprises an indication of the group. Thereby, the first server is enabled to associate the syslog message to the group.
[0014] A second aspect of the invention relates to a method performed by a log repository, wherein the log repository is communicatively connected to at least one first server,wherein the first server is providing a service to at least one resource comprised in a group of resources. The method comprises receiving, from the first server, a syslog message pertaining to at least one event, wherein the event is associated with the resource, and the syslog message comprises an indication of the group, and saving the syslog message. Thereby, the log repository is enabled to save the syslog message comprising the association to the group.
[0015] A third aspect of the invention relates to a method performed by a log viewer device hosting a first User Interface, III, function, wherein the log viewer device is communicatively connected to a log repository. The method comprises obtaining information related to an interaction caused by a user with a III of the III function, wherein the interaction pertains to a user request by the user to return at least one log to the III, determining that the user is authorized to retrieve at least one log associated with a group of resources, obtaining, from the log repository, the log associated with the user request and associated with the group, returning, to the III, the log associated with the user request and the group. Thereby, the log viewer device is enabled to return the log associated with the user request and the group which the user is authorized to view.
[0016] A fourth aspect of the invention relates to a log system comprising at least one first server providing a service to at least one resource comprised in a group of resources and being configured to perform the method according to the first aspect of the invention, a log repository configured to perform the method according to the second aspect of the invention, and a log viewer device hosting a first III function and being configured to perform the method to the third aspect of the invention.
[0017] A fifth aspect of the invention relates to at least one first server providing a service to at least one resource comprised in a group of resources, wherein the at least one first server is communicatively connected to a log repository, whereby the first server is configured to obtain information on the group, obtain information pertaining to at least one event associated with the resource, and send, to the log repository, a syslog message pertaining to the event, wherein the syslog message comprises an indication of the group.A sixth aspect of the invention relates to at least one first server providing a service to at least one resource comprised in a group of resources, wherein the at least one first server is communicatively connected to a log repository, wherein the at least one first server comprises processing circuitry and a computer readable storage medium, the computer readable storage medium containing instructions executable by the processing circuitry, whereby the at least one first server is configured to obtain information on the group, obtain information pertaining to at least one event associated with the resource, and send, to the log repository, a syslog message pertaining to the event, wherein the syslog message comprises an indication of the group.
[0018] A seventh aspect of the invention relates to a log repository, wherein the log repository is communicatively connected to at least one first server, wherein the first server is providing a service to at least one resource comprised in a group of resources, whereby the log repository is configured to receive, from the first server, a syslog message pertaining to at least one event, wherein the event is associated with the resource, and the syslog message comprises an indication of the group, and save the syslog message.
[0019] An eight aspect of the invention relates to a log repository, wherein the log repository is communicatively connected to at least one first server, wherein the first server s providing a service to at least one resource comprised in a group of resources, wherein the log repository comprises processing circuitry and a computer readable storage medium, the computer readable storage medium containing instructions executable by the processing circuitry, whereby the log repository is configured to receive, from the first server, a syslog message pertaining to at least one event, wherein the event is associated with the resource, and the syslog message comprises an indication of the group, and save the syslog message.
[0020] A ninth aspect of the invention relates to a log viewer device hosting a first III function, wherein the log viewer device is communicatively connected to a log repository, whereby the log viewer device is configured to obtain information related to an interaction caused by a user with a III of the III function, wherein the interaction pertains to a user request by the user to return at least one log to the III, determine that the user is authorized to retrieve at least one log associated with agroup of resources, obtain, from the log repository, the log associated with the user request and associated with the group, and return, to the III, the log associated with the user request and the group.
[0021] A tenth aspect of the invention relates to a log viewer device hosting a first III function, wherein the log viewer device is communicatively connected to a log repository, wherein the log viewer device comprises processing circuitry and a computer readable storage medium, the computer readable storage medium containing instructions executable by the processing circuitry, whereby the log viewer device is configured to obtain information related to an interaction caused by a user with a III of the III function, wherein the interaction pertains to a user request by the user to return at least one log to the III, determine that the user is authorized to retrieve at least one log associated with a group of resources, obtain, from the log repository, the log associated with the user request and associated with the group, and return, to the III, the log associated with the user request and the group.
[0022] A eleventh aspect of the invention relates to a computer program comprising instructions which, when executed on processing circuitry of at least one first server, cause the processing circuitry of the first server to carry out the method according to the first aspect, processing circuitry of a log repository, cause the processing circuitry of the log repository to carry out the method according to the second aspect, and processing circuitry of a log viewer device, cause the processing circuitry of the log viewer device to carry out the method according to the third aspect.
[0023] A twelfth aspect of the invention relates to a tangible, non-volatile computer readable medium comprising instructions that, when executed on processing circuitry of at least one first server, cause the processing circuitry of the first server to carry out the method according to the first aspect, processing circuitry of a log repository, cause the processing circuitry of the log repository to carry out the method according to the second aspect, and processing circuitry of a log viewer device, cause the processing circuitry of the log viewer device to carry out the method according to the third aspect.
[0024] BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 is a schematic diagram illustrating an example of an environment.Figure 2 is a flowchart illustrating a method 200 performed by the at least one first server.
[0026] Figure 3 is a flowchart illustrating a method 300 performed by the log repository.
[0027] Figure 4 is a flowchart illustrating a method 400 performed by the log viewer device.
[0028] Figures 5 is a signaling diagram of an embodiment of an interaction between the at least one first server, the log viewer device, and the log repository.
[0029] Figure 6 illustrates a block diagram illustrating embodiments of the first server.
[0030] Figure 7 illustrates a block diagram illustrating embodiments of the log repository.
[0031] Figure 8 illustrates a block diagram illustrating embodiments of the log viewer device.
[0032] DETAILED DESCRIPTION
[0033] Figure 1 shows a schematic diagram illustrating an example setup of an environment in which embodiments presented herein can be applied. Figure 1 illustrates at least one first server 100, a log repository 110, a log viewer device 120, at least one second server 130, a user 140, an administrative user 150, a User Interface (III) 160, and a second III 170. The first server 100 may in practice be only one first server host 100a, or two or more server hosts 100a-c. The log viewer device 120 optionally hosts a III function. The III function is for causing the log viewer device to output the III 160, wherein the user 140 is enabled to interact with the III 160. The III 160 may correspond to a first III and the III function to a first III function. The second server 130 comprises one second server host 130a, or more than one second server hosts 130a-c. The second server 130 optionally hosts a second III function. The second III function is for causing the second server to output the second III 170, wherein the administrative user 150 is enabled to interact with the second III 170. The log repository 110 is communicatively connected with the first server 100 and with the log viewer device 120. The first server 100 is optionally communicativelyconnected with the second server 130. The log viewer device 120 is optionally communicatively connected with the second server 130 such as via external and / or internal entities using wired communications, e.g., based on Ethernet, and / or wireless communications, e.g., Wi-Fi, and / or a cellular network corresponding to one of or a combination of 5G cellular networks, Long Term Evolution (LTE) and Evolved Packet System (EPS), LTE-advanced, Universal Mobile Telecommunications System (UMTS), or any other current or future wireless network, such as a future 3GPP 6G network.
[0034] The first server 100 provides a service to at least one resource comprised in a group of resources. The first server 100 is configured to obtain information on the group, obtain information pertaining to at least one event associated with the resource and send, to the log repository 110, a syslog message pertaining to the event. The syslog message comprises an indication of the group. The log repository 110 is configured to receive, from the first server 100, the syslog message and save the syslog message. The log viewer device 120 obtains information related to an interaction caused by the user 140 with the first Ul of the first Ul function. The interaction pertains to a user request by the user 140 to return at least one log to the first Ul 160. The log viewer device 120 is further configured to determine that the user 140 is authorized to retrieve at least one log associated with the user request, obtain, from the log repository 110, the log associated with the user request, and return, to the first Ul, the log associated with the user request.
[0035] The solution presented herein addresses the above-mentioned challenges of enabling decreased computing power and signaling when granting access to least one log based on the group. The solution presented herein allows to comply with the principle of least privilege, ensuring a high level of security. Further, the solution presented herein may enable access control based on the logs associated with the group without a need of post- processing and thus may not interfere with an access control performance of an access control system.
[0036] Referring to Figure 1 , the first server 100 provides a function and / or task to at least one resource of the group of resources. The first server 100 may host and / or manage an execution of an application.The at least one resource of the group of resources may be at least one object whose content may be accessible by a user such as the user 140 and / or an application. For example, the resource may correspond to a tool e.g. run by a computer such as an application, data or a functionality / computer operation. The at least one resource may be at least one explicit object. The explicit object may be generated inside a network management as a result of user operation(s), such as one or more subscriptions, administrative information, user data and procedure information. The network management may refer to a functionality run by the computer responsible for monitoring, controlling, configuring the resource.
[0037] Alternatively, or additionally, the at least one resource may be at least one object of a spontaneous and / or unsolicited event. The object of the spontaneous and / or unsolicited event is generated as a result of a system and / or network activity on resources. For example, the object is performance data, one or more log records and alarm data. Alternatively, or additionally, the at least one resource may be at least one implicit object. The implicit object may represent a physical or logical entity of the managed network such as Managed Object Instances (MOIs), e.g. network elements, cells and topology info. The resource may correspond to a resource of managing Key performance Indicators (KPIs) resource including data dashboard or systems for tracking the performance metrics for the communication network; a node monitor resource for monitoring individual network nodes of the communication network, such as switches, routers or servers; a network health monitor resource for tracking and monitoring the overall health of the communication network such as bandwidth usage, latency, error rates and other performance metrics; Network Health Analysis resource for analyzing network health data gathered from monitoring for e.g. troubleshooting or performance optimization; and / or Flow Automation resource for automating network flow management such as adjusting traffic routes or applying bandwidth policies automatically in the communication network. In an example, the resource corresponds both to the node monitor resource and the resource of managing KPIs resource, wherein access to the node monitor resource and resource of managing KPIs resource involve ability to view and / or analyze performance and status of network nodes. Additionally, and / or alternatively the resource corresponds to a resource of managing network links; a Network Privileged Access Management resource; a network viewer resource; a network explorer resource for e.g. exploring or discovering different network devices, nodes orelements on the communication network for management diagnostics or analysis; and / or a parameter management resource for e.g. for managing and configuring various parameters or settings within network devices such as routing protocols, IP settings or firewall configurations in the communication network. Additionally, or alternatively, the resource corresponds to at least one facility management (FM) application such as an Alarm Monitor resource, Alarm Search resource, Alarm Overview resource, Alarm Supervision Status and / or a Command Line Interface for Ericsson Network Manager (ENM CLI) resource. A function of the Alarm Monitor resource, Alarm Search resource, Alarm Overview resource, or Alarm Search resource may be a Network Management (NM) functionality to e.g. acquire alarm data such as for one or more active alarms in the communication network, e.g. to give the authorized user an overview of active alarms.
[0038] The group of resources may be a set of resources of the at least one resource that are grouped together based on e.g. similar functionality, characteristics, or attributes of the resource comprised in the group. Alternatively, or additionally, the group may be a set of resources with similar access policies. In an example, the group of resources is including monitoring resources such as the Node Monitor, Network Health Monitor and / or Flow Automation. In an alternative example, the group of resource comprises managing resources such as KPI Management, and / or Parameter Management. In an example, the group of resources can be a table or list of resources, saved in a memory comprised in the communication network, e.g in a memory in the log repository or a communication node comprising a database. In an example, the group of recourses may be saved in a JavaScript Object Notation (JSON) syntax such as
[0039] “TargetGroupName”: “TargetGroup 1”,
[0040] Resources : [
[0041] {TesourceName” : “resource 1”,
[0042] “value” : “valuer
[0043] }
[0044] {’TesourceName” : “resource ”N,
[0045] “value” : “valueN”
[0046] }
[0047] Figure 2 is a flowchart illustrating a method 200 performed by the at least one first server 100, as shown in Figure 1 and described in the text thereto.The method 200 comprises a first step 210, where the first server 100 obtains information on the group. Optionally, the first step 210 comprises a step 212. In the optional step 212, the first server 100 receives, from the log viewer device 120, the information on the group. The first server 100 obtains in a step 220 information pertaining to at least one event associated with the resource. Optionally, the step 210 is performed in response to step 220, i.e. after step 220. Further, the first server 100 sends in a step 230, to the log repositor, a syslog message pertaining to the event. The syslog message comprises an indication of the group.
[0048] By obtaining the information on the group in step 210, the first server 100 may be enabled to determine which resource is corresponding to the group. By obtaining the event in step 220, the first server 100 may be enabled to determine that the resource associated with the event is comprised in the group. By sending the syslog message comprising the indication of the group in step 230, the first server 100 is enabled to indicate the group in the syslog message pertaining to the event.
[0049] Figure 3 is a flowchart illustrating a method 300 performed by the log repository 110, as shown in Figure 1 and described in the text thereto.
[0050] The method 300 comprises a step 310, where the log repository 110 is receiving, from the first server 100, the syslog message. In a step 320, the log repository 110 saves the syslog message. In an optional step 322, the log repository 110 receives, from the log viewer device 120, a request. The request is associated with a user request by the user 140 to return at least one log to the first III and associated with the group. An interaction caused by the user 140 with the first III of the first III function pertains to the user request. In an optional step 324 the log repository 110 sends, to the log viewer device 120, at least one log associated with the user request and the group.
[0051] By receiving the syslog message in step 310, the log repository 110 is enabled to save the syslog message comprising the indication of the group. By saving the syslog message comprising the indication of the group in step 320, the log repository 110 may be enabled to link a log entry to the group. By receiving the request in step 322, the log repository 110 may be enabled to filter log entries after requestedparameters comprised in the user request, e.g. after the identifier of the group and send at least one log associated with the user request and the group.
[0052] Figure 4 is a flowchart illustrating a method 400 performed by the log viewer device 120 as shown in Figure 1 and described in the text thereto.
[0053] The method 400 comprises a step 410, wherein the log viewer device 120 obtains information related to the interaction caused by the user 140 with the first III. In an optional step 412 the log viewer device 120 obtains the information on the group. The step 412 may optionally comprise a step 414, wherein the log viewer device 120 receives from the second server 130 the information on the group. The method 400 further comprises a step 420, wherein the log viewer device 120 determines that the user 140 is authorized to retrieve at least one log associated with the group. The step 420 optionally comprises a step 422 of obtaining the user information of the user 140. The user information comprises at least one of a user role information associated with the user 140 and an identity of the user 140. In a step 430, the log viewer device 120 obtains the log associated with the user request and associated with the group. Optionally step 430 comprises a step 432 and a step 434. In the optional step 432 the log viewer device 120 sends to the log repository 110 a request associated with the user request and the group. In the optional step 434, the log viewer device 120, receives, from the log repository 110, the at least one log associated with the user request and the group. The method 400 further comprises returning to the III, the log associated with the user request and the group.
[0054] By obtaining the information related to the interaction in step 410, the log viewer device 120 may be triggered to perform step 420 of determining that the user 140 is authorized to retrieve the log associated with the group. By performing step 420 the log viewer device 120 may be enabled to obtain only those logs in step 430 which the user 140 is authorized to access. By obtaining the log associated with the group and the user request in step 430, the log viewer device 120 may be enabled to filter the logs according to the user request and the logs associated with the group, and return the logs requested by the user 140 to which the user 140 is authorized in step 440.Figure 5 depicts a signaling diagram of an embodiment of the exemplary interaction between the at least one first server 100, the log viewer device 120, the log repository 110, and optionally the at least one second server 130 as shown in Figure 1. In Figure 5 at least one first server 100, the log viewer device 120, the log repository 110, and optionally the at least one second server 130, the user 140 and the administrative user 150 (as shown in Figure 1 and described in the text thereto) are depicted for illustration.
[0055] In an optional step 501 of Figure 5 the administrative user 150 interacts with the second III 170. The second server 130 may obtain information related to an interaction caused by the administrative user 150 with the second III 170, and during the interaction, determine the information on the group and information on the user 140. The interaction, by the user 140 with the second III 170, may be for configuring a group of resource, at least one user role associated with the group of resources and / or at least one user role associated with the user 140.
[0056] In a step 502, the first server 100 obtains the information pertaining to at least one event with at least one resource. The step 502 corresponds to step 220 of the method 200.
[0057] In an optional step 503, the first server 100, sends a request for information on the group to the second server 130. The second server 130 retrieves the request for information on the group.
[0058] In an optional step 504, the first server 100, receives, from the second server 130, the information on the group. The second server 130 sends the information on the group to the first server 100. The step 504 corresponds to step 212 of method 200.
[0059] Optionally steps 503 and 504 are performed before step 502.
[0060] In a step 505, the first server 100, sends, to the log repository 110, a syslog message pertaining to the event. The syslog message comprises the indication of the group. The log repository 110 receives the syslog message. The step 505 corresponds to step 230 of method 200 and step 310 of method 300.In a step 506, the log repository 110 saves the syslog message. The step 506 corresponds to step 320 of method 300. Saving the syslog message may comprise saving the syslog message in a memory comprised in the log repository 110 and / or in an external (to the log repository) memory device in the communication network.
[0061] In an optional step 507, the user 140 interacts with the first III. The log viewer device 120 may obtain information related to the interaction caused by the user 140 with the first III. During the interaction caused by the user 140, the log viewer device 120 obtains the user request to return at least one log to the III. The step 507 corresponds to step 410 of the method 400.
[0062] In an optional step 508, the log viewer device 120, sends a request associated with the user request to the second server 130. The second server 130 receives the request.
[0063] In an optional step 509, the log viewer device 120 receives, from the second server 130, the information on the group. The step 509 corresponds to step 414 of method 400.
[0064] In a step 510, the log viewer device 120, determines that the user 140 is authorized. The step 510 corresponds to step 420 of method 400. Determining may optionally comprise determining the user role associated with the user 140 from an authentication function hosted by the second server 130. The authentication function may optionally authenticate the user 140.
[0065] In an optional step 511 , the log viewer device 120, sends, to the log repository 110, the request to return at least one log to the III associated with the user request and associated with the group. In an example, the request comprises the identifier of the group. The log repository 110 receives the request from the log viewer device 120. The step 522 corresponds to step 432 of method 400 and step 322 of method 300.
[0066] In a step 512, the log viewer device 120 receives the at least one log associated with the user request. The log repository 110 sends to the log viewer device 120 the log associated with the user request. The step 512 corresponds to step 434 of method 400 and step 324 of method 300.In a step 513, the log viewer device 120 returns, to the first III, the log associated with the user request and the group. The user 140 may interact with the first III to retrieve the log. The step 513 corresponds to step 440 of method 400.
[0067] In a first embodiment, the second server 130 is the one first server host 100a comprised in the first server 100. The first server host 100a hosts the software which applies a TBAC system. The first server host 100a and the log viewer device 120 are deployed in a cloud environment.
[0068] In the first embodiment, the step 501 is performed. The administrative user 150 interacts with the second III 170 being a Security III, which provides information or triggers a configuration of e.g. which user roles are associated with the group and which resources are associated with the group. The information is obtained by the second server 130 and is based on the interaction. The information obtained based on the interaction corresponds to the user role associated with the group, a list of resources which are comprised in the group and / or user roles associated with users. The first server host 100a uses the TBAC system to configure the user role of the group and configure the list of resources comprised in the group based on the information obtained. The first server host 100a creates and / or updates at least one TBAC role-based access control policy linking user roles to the group to obtain the user roles associated with the group and linking the user roles associated with the group to the user roles associated with users. Based on the information obtained, the first server host 100a modifies a service interface for configuring the group. In an example, the first server host 100a configures the group by gathering the at least one resource with a filter, such as a first group of nodes located in Europe, a second group of nodes located in the US. To extend the service interface, the first server host 100a defines an Application Programming Interface (API), such as a TBAC configuration API managed by the administrative user 150, and / or endpoint to include operations for managing the group. In an example the second user uses Hypertext Transfer Protocol (HTTP) requests in a Representational State Transfer (REST)ful API such as GET / group / {id} to retrieve target group details, POST / group to create a new group, PATCH / group / {id} to update target group attributes and DELETE / group / {id} to remove a target group. In an example, the at least one resource comprised in the group corresponds to documents such as reports, teamdata and internal communications located in Europe. In the example, the first server host 100a configures the user role associated with the group to the European network manager role based on the information obtained. The first server host 100a further links the user roles associated with users with the user role associated with the group by e.g. defining the user role associated with the user 140 with privileges on the at least one resource of the group. For example, the European manager role may be linked to the user roles associated with European managing, such as a German network manager role, a Swedish network manager role, an Italian network manager role and / or a Greek network manager role.
[0069] In the first embodiment, the step 502 is performed. In the example, the event associated with the resource is “accessing a resource” such as a network node. In the example, obtaining the event corresponds to obtaining an accessing of a document such as a report, team data and / or an internal communication document. In an example, the first server provides to service to “access a resource”. In the example, the first server receives an access request from the user for accessing a resource. In response to request, the first server in turn acts as a client towards the resource.
[0070] In the first embodiment, alternative to the steps 503 and 504, the first server host 100a acquires the information on the group. The information on the group comprises the identifier of the group, which identifier is used to, e.g., inform the first server host 100a which group the resource is comprised in. In the first embodiment, the information on the group comprises further at least one parameter of the resource comprised in the group. In an example, the parameter is a cell identifier of a network node (e.g. a cell identifier between 1000-2000), wherein the resource is the network node. The resource is pertaining to the event. In the example, the resource pertaining to the event is the document, team data and / or internal communication document which had been accessed. The first server host 100a may filter the information by requesting the service comprising the service interface to retrieve the identifier of the group the resource is corresponding to.
[0071] The steps 502 to 504 may be performed during a period wherein logging is enabled for various type of recourse and various type of events. In the example, the various type of events may correspond to reading, writing, and / or updating a resource.In the first embodiment, the steps 505 and 506 are performed, wherein the indication of the group comprises the identifier of the group comprised in a structured data identifier (SD-ID) of the syslog message. The syslog message may be sent via a log shipper comprised in the first server host 100a.
[0072] In the first embodiment, the step 507 is performed, wherein the user request to return at least log comprises an identifier of the resource. The user interacts with the first III being the log viewer to request returning the log associated with the resource. The resource the log is associated with corresponds e.g. to a document located in Europe comprised in the group of resources as configured in step 501.
[0073] In the first embodiment, alternatively to the steps 508 and 509, the second server 130 retrieves in a step 508a updates on the information on the group. The first server host 100a subscribes to changes in the configuration and acquires the information on the group from the service interface if the group is updated in step 501. The updates received may be comprised in a HTTP message. In an example, the updates received may be in the following message structure, wherein the UserName corresponds to the identity of the first user and the TargetGroupName corresponds to the identity of the group:
[0074] “UserName”: “UserNamel”,
[0075] ValidTargetGroups : [
[0076] ’’TargetGroupName” : “TargetGroupNamel”,
[0077] ’’TargetGroupName” : “TargetGroupNameN”,
[0078] In the first embodiment, the step 510 is performed, wherein the log viewer device 120 verifies that the user role associated with the user 140 matches with the user role associated with the group. In the example, the log viewer device 120 determines the user role associated with the user 140 being e.g. a German managing role from an authentication function hosted by the log viewer device 120 authenticating the user 140. The log viewer device 120 further determines that the German managing role is linked to the user role associated with the group being the European managing role. In an example, step 510 further comprises, determining that the user role associated with the group is only authorized to access logs of the group ofresources that include the at least one parameter, such as the cell identifier between 1000 and 2000.
[0079] In the first embodiment, the steps 511 and 512 are performed via a north bound API hosted by the log viewer device 120, wherein the log associated with the user request and the group received by the log viewer device 120 corresponds to the log associated with the resource. The request for the log may be a database query such as a Structured Query Language (SQL) query, wherein the log repository 110 is a log database. The log associated with the resource and e.g. the at least one parameter may correspond to log entries of the events pertaining to the document located in Europe.
[0080] In the first embodiment, the step 513 is performed, wherein the log viewer device 120 returns to the log viewer the log associated with the resource and e.g. the at least one parameter. In an example, the first Ul is displayed on a device which the user 140 is interacting with, wherein the user 140 may obtain the log associated with the resource via the device.
[0081] In a second embodiment, the log repository 110, the second server 130 and the log viewer device 120 are comprised in the at least one first server 100 comprising two or more first server hosts 100a-c. The first server 100 is comprised in the communication network. The log viewer device 120 hosts a microservice.
[0082] In the second embodiment, step 501 is performed, wherein the administrative user 150 interacts with the second Ul 170 to trigger configuration of the group and the user role associated with the group. In an example, the user role associated with the group is an analyst, wherein the group comprises a plurality of resources corresponding to the Network Health Analysis resource, Network Viewer resource and KPI Management resource. The group comprising the resources, a name of the group, and the user role associated with the group is saved in a table as the information on the group in a memory comprised in the first server 100.
[0083] In the second embodiment, step 502 is performed, wherein obtaining the event comprises receiving a notification from an entity hosting a resource comprised in the group such as the Network Health analysis resource. The event corresponds to e.g. a modification of an alert threshold, and / or an adjustment of metrics andconfiguration of at least one of resources such as the Network Health Analysis resource.
[0084] In the second embodiment, alternative to step 503, the information on the group is retrieved in a retrieving step, by the first server 100, from the memory comprised in the first server 100. The retrieving further comprised determining by the first server 100 that the resource the event is pertaining to is comprised in the group. In the example, the first server 100 determined that the Network Health analysis resource is comprised in the group by e.g. determining that the resource includes attributes matching the group criteria, that the resource is linked to the group through a policy specifying allowed roles and actions for that group, that the resource is contained in the list of resources of the group, that the resource is tagged with attributes that are linked to the group, and / or that the resource explicitly references the groups unique identifier in its metadata or configuration.
[0085] In the second embodiment, the steps 505 and 506 are performed, wherein the syslog message comprises information on the event. In the example, syslog message may comprise the information on the event and a name of the group in the SD-ID field of the syslog message.
[0086] In the second embodiment, the step 507 is performed, wherein the user 140 interacts with the log viewer device 120. In the example, the user 140 intents to request the log associated with the Network Health analysis resource. The log viewer device 120 obtains, during the interaction caused by the user 140 with the first III, the user request requesting the log associated with the resource.
[0087] In the second embodiment, alternatively to the step 508 and 509, the log viewer device 120 retrieves in a step the information on the group from the memory and determines that the resource with which the requested log is associated with is comprised in the group.
[0088] In the second embodiment, step 510 is performed, wherein determining comprises checking that the user 140 has been authenticated, retrieving the user role information associated with the user 140 from an authentication function hosted by the first server 100 and determining that the user role associated with the user 140 corresponding to an analysist role and the user role associated with the groupmatches. In an example, authentication of the user, by the authentication function, is performed using username and password, Multi-Factor Authentication (MFA), a certificate, and / or a token.
[0089] In the second embodiment, step 511 and 512, wherein the at least one log associated with the user request and the group corresponds to the at least one log associated with the resource. In the example, the log viewer device 120 receives the at least one log associated with the Network health analysis resource from the log repository 110. The request associated with the user request may be an Open Source based Message, such as an OpenSearch message in the form of a SQL message ora Piped Processing Language (PPL) message, comprising the identifier of the group and the response comprising the log associated with the resource may be an Open Source based message such as an OpenSearch message.
[0090] In the second embodiment, step 513 is performed.
[0091] In a third embodiment, the first server 100 corresponds to the two or more first server hosts 100a-c. The second server 130 and the log viewer device 120 are separate from the first server. The first server 100, the second server 130 and log viewer device 120 are deployed e.g. in a data center, wherein the first server 100 provides cloud hosting services.
[0092] In the third embodiment, the step 501 is performed, wherein the administrative user 150 configures which resources correspond to the group and the user role associated with the group. The second server 130 configures the service indication as described in the first embodiment based on the information obtained based on the interaction caused by the user 140 with the second Ul 170. In an example, the at least one resource comprised in the group of resources are the Alarm Monitor resource, Alarm Overview resource and Alarm Search resource. In the example the user role associated with the group is an engineer or technician.
[0093] In the third embodiment, the steps 503 and 504 are performed, wherein the information on the group comprises user role information associated with the group and an indication which resource is comprised in the group comprising a confirmation of each resource. In the example the user role information associated with the group indicate that the user role associated with the group is the engineer ortechnician. The request may be a HTTP request and a response comprising the identifier of the group may correspond to a HTTP response. An example, of the HTTP request related to a group is:
[0094] GET / ... / targetGroup {targetGroupI}.
[0095] An example of the HTTP response is:
[0096] HTTP body :
[0097] {
[0098] Resources : [
[0099] {TesourceName” : “resource 1”,
[0100] “value” : “valuer
[0101] }
[0102] {’TesourceName” : “resource ”N,
[0103] “value” : “valueN”
[0104] }
[0105] }
[0106] In the third embodiment, the step 502 is performed, wherein a plurality of events is obtained. In the example, the plurality of events is that an alarm is created by the Alarm Monitor comprising the issue such as high latency, packet loss or device unreachability, that the alarm is acknowledged by an administrator, and that the alarm is marked as cleared.
[0107] In the third embodiment, the steps 505 and 506 are performed, wherein the syslog message comprises the identifier of the group and information on the events.
[0108] Steps 505 and 506 are performed periodically within a time period being predefined in the first server 100.
[0109] In the third embodiment, the step 507 is performed, wherein the user authenticates with the log viewer device 120. From authentication the log viewer device 120 determines the user role associated with the user 140 being a technician. The log viewer device 120 obtains the user request from the interaction caused by the user 140 with the first III. The user request comprises a request to display the logs associated with Alarm Monitor and Alarm Supervision Status.
[0110] In the third embodiment, the steps 508 and 509 are performed, wherein the request associated with the user request corresponds to an API query for requesting anindication on which group the resources such as the Alarm Monitor and Alarm Supervision Status correspond to, the identifier of the group and the user role associated with the group. The information on the group may comprise the indication that the Alarm Monitor is comprised in the group, the name of the group and the user role associated with the group being the technician or engineer.
[0111] In the third embodiment, the step 510 is performed, wherein determining comprises e.g. verifying that the user 140 is authorized to access the Alarm Monitor resource only but not the Alarm Supervision, as the user role associated with the group matched the user role associated with the user 140.
[0112] In the third embodiment, alternatively to steps 511 and step 512, the log viewer device 120 retrieves the at least one log associated with the e.g. Alarm Monitor resource from the log repository 110. Retrieving may optionally comprise filtering log entries in the log repository 110 after the Alarm Monitor resource and the identifier of the group.
[0113] In the third embodiment, step 513 is performed, wherein the at least one log associated with the Alarm Monitor may be returned to the first III. Optionally, in the first III it may be indicated that access to the logs associated with the Alarm Supervision resource are denied.
[0114] A user role associated with the user 140 may correspond to a permission assigned to the user 140. In other words, the user role may determine what actions the user 140 can perform and what viewing / reading rights the user has with respect to and via the log viewer device 120. In an example, the user role associated with the user 140 corresponds to a category of functions such as an administrator, engineer, or analyst influencing the access the user 140 has. In an example, the user role associated with the group may further correspond to a permission linked to the group of resources comprising the at least one parameter. In example, the parameter may be a range of cell identities, such as a group of resources corresponding to network cells. The user role associated with the user may correspond to a user role defined in Role-Based Access Control (RBAC).
[0115] A user role associated with the group may correspond to a permission linked to the group of resources based on e.g. access policies. In an example, the user roleassociated with the group corresponds to the category of functions such as administrators, engineers or analysts influencing the access. In an example, the user role associated with the group is a network administrator, wherein the user 140 having the user role of the network administrator has access to the group. In the example, the group may comprise KPI Management, Node Monitor and Link Management. In an alternative example, the user role associated with the group is a network engineer, wherein the user 140 having the user role associated with the user 140 of the network engineer has access to the group. In the example the group may be a monitoring resource group comprising a Node Monitor and Network Health Monitor, but no KPI Management or high-level analysis tools. In an alternative example, the user role associated with the group is a support staff, wherein the user 140 having the user role associated with the user 140 of the support staff may have access to the group comprising a Network Viewer and Network Explorer. In an example, the user role associated with the group may further correspond to the permission linked to the group of resources comprising the parameter. The user role associated with the group may correspond to a user role defined in TBAC.
[0116] The user role information associated with the group, and / or the user role information associated with the user 140 may correspond to a name, a unique numeric or alphanumeric identifier, a domain or tag, and / or an access policy identifier.
[0117] The service is a software component providing a functionality or a task. For example, the service may correspond to collect alarms, reading resources, writing resources, and / or updating resources.
[0118] The log repository 110 may be a database or configured in a streaming log comprised in e.g. the first server 100 and / or log viewer device 120 such as OpenSearch. In an example, the log repository 110 corresponds to a device hosting a collector to receive, aggregate and store logs from at least one log shipper comprised in the first server 100. The log shipper may e.g. a lightweighted agent or component residing in each container in a component stack capturing logs generated by the service and sending the logs to the collector.
[0119] The at least one first server 100, second server 130 and / or the log viewer device 120 correspond to at least one hardware based apparatus running a server as a softwaresuch as a web server, e.g. hosting websites and delivering web pages via e.g.
[0120] HTTP / HTTPS; a file server, e.g. storing and managing access files; a database server, e.g. providing database services to applications or users; an application server, e.g. hosting and running application logic; a proxy server, e.g. acting as intermediary for client requests to other servers; a cloud server; or a combination thereof. The web server may be e.g. Apache, Nginz, the database server may be a SQL server such as MySQL and Post lngres(Postgre)SQL. In an example, the at least one first server 100, second server 130 and / or the log viewer device 120 may correspond to a combination of the web server and a database server. In an example the first server 100 and / or the second server 130 may be an Identity-Aware Proxy (IAP) based server and / or a Cloud Information Rights Management (IRM) based server and / or an Orchestrator based server. Alternatively, the log viewer device 120 may correspond to a device hosting a microservice for the first Ul and / or device hosting a functionality being managed by e.g. specific operators. The log viewer device 120 may host two interfaces, the first Ul and optionally the north bound API where a log analyzer product may acquire logs for post-processing from e.g. the log repository 110. In an example the log repository 110 and / or the log viewer device 120 is comprised in the first server 100 and / or second server 130.
[0121] The user 140 and / or the administrative user 150 may be human, or a service or a bot interacting with the first and / or second Ul 170.
[0122] The first Ul and / or the second Ul 170 may be displayed using a display device. The second Ul 170 may be a Security Ul. In an example, the Security Ul is a management interface used by the administrative user, e.g. to set security parameters via e.g. highly privileged roles such as creating users, roles, associate user to roles, create groups and / or associated groups to users. In an alternative or additional example the second and / or first Ul is built on top of a REST interface exposed by a cloud native Identity and Access Management (IAM) server component e.g. implemented by the Keycloack 3PP. The administrator user may interact with the second Ul 170. The first Ul may be a log viewer. The user 140 may interact with the first Ul 160. For example, the first Ul and / or the second Ul 170 is a Graphical User Interface (GUI), a Command line interact (CLI), a Menu-driven Ul, a Touch Ul, a Voice Ul, and / or a Form-based Ul a Natural language Ul. The displaydevice may be a video device, a non-video device, a three dimensional (3D) based device and / or a static media device. The video device may be a display such as a Liquid-crystal display (LCD) or light-emitting diode (LED) display. The non-video device may be a Vacuum fluorescent display (VFD), a segment-based display and / or a Light-emitting electrochemical cell (LEC) based display. The 3D based device may be a hologram-based display, a volumetric display and / or a fog display. The static media device may be a movie projector, a transparency-based display, a laser beam based display. The second Ul 170 may e.g. be a third party (3PP) Ul for e.g.
[0123] Keycloak and / or ForgeRocks.
[0124] The first Ul function hosted by log viewer device 120 may output the first Ul . The second Ul function hosted by the second server 130 may output the second Ul 170. During an interaction caused by the user 140 and / or the administrative user 150 with the first Ul and / or second Ul 170, may the first and / or second Ul function obtain input from the user 140 and / or the administrative user 150. The input is processed and send to the first and / or log viewer device 120 as information related to the interaction. When the server returns information to the first Ul, the server inputs the information to the first and / or second Ul function, which outputs the information in the first and / or second Ul 170 using the display.
[0125] The at least one event may be an occurrence or change to at least one resource such a application or in a network that is recorded in a log entry. In an example the event corresponds to a system event such as server startup or shutdown, software update, resource utilization spike and / or a hardware failure or a hardware error. In an alternative or additional example, the event corresponds to a security event such as a successful, or failed login attempt to a resource, an unauthorized access attempt to a resource, a privileged escalation, and / or firewall or intrusion detection alter. In an alternative and / or additional example the event corresponds to a communication network event such as a connection request e.g. via Secure Socket Shell (SSH), HTTP, a packet drop or a timeout, a network device configuration change and / or an unusual traffic pattern. In an alternative and / or additional example the event corresponds to an application event such as a user action, an error or exception in the application, an API call, and / or an application deployment or an update. In an alternative and / or additional example the event corresponds to a database eventsuch as a query executed, data change, a database connection issue and / or a backup or restore operation. In an alternative and / or additional example the event corresponds to an operational event such as a task completion, or configuration change. In an alternative or additional example the event may correspond to a management operation on a resource such as create, update or delete.
[0126] The syslog message is a standardized message following the standard defined by the IETF RFC 5424. The syslog message may be transmitted using e.g. a User Datagram Protocol (UDP), a transmission control protocol (TCP) and / or Transport Layer Security (TLS). The syslog message may comprise the information pertaining to the event such as a Message (MSG) body part, an identifier of the first server 100 such as a hostname, an identifier of an application hosted by the first server 100 such as an app name, a severity level indication, wherein the severity level pertains to an importance of the syslog message, and / or a timestamp indicating when the syslog message is generated e.g. by the application. The seventy level indication may be a value or string indicating the importance of the syslog message. Further the syslog message may comprise an indication of the group comprising an SD-ID. In an example, the structured data identifier, SD-ID comprises an identifier of the group. The identifier of the group may be a name of the group, a unique numeric or alphanumeric identifier, a domain or tag wherein the group may be identified by a shared attribute, and / or an access policy identifier. The identifier of the group may correspond to any name defined by the administrative user via the second III. In an example the syslog message may be:
[0127] <34>1 2024-07-08T15:04:05.000Z myserver.com myApp - ID47 - [targetGroup@193 name= targetGroupA”] Resource A read
[0128] wherein “<34>” corresponds to a priority (PRI) (Priority, 34 = Facility 4 (auth) + Severity 2 (warning)); “1” corresponds to a Protocol version (1); “2024-07-08T15:04:05.000Z” corresponds to a Timestamp in an International Organization for Standardization (ISO) 8601 format; “myserver.com” corresponds to a Hostname of a source machine; “myApp:” corresponds to a name of the application generating the syslog message; ID47 corresponds to a message identifier (MsgID);
[0129] “[targetGroup@193 name= targetGroupA”]” corresponds to structured data with a unique identity of the group such as ID targetGroup@193 with its field; and“Resource A read” corresponds to a Log message. The information on the group may comprise an indication that the resource is comprised in the group. The indication that the resource is comprised in the group may be a confirmation that the resource is comprised in the group. In an example, the confirmation indicates that the resource includes attributes matching the group criteria, that the resource is linked to the group through a policy specifying allowed roles and actions for that group, that the resource is contained in the list of resources of the group, that the resource is tagged with attributes that are linked to the group, and / or that the resource explicitly references the groups unique identifier in its metadata or configuration. Alternatively, and / or additionally the information on the group may comprise the identifier of the group. Alternatively, and / or additionally the information on the group comprises the at least one user role information associated with the group. In an example the information on the group comprises information on how to filter the at least one resource of the group, such as how to filter resources located in Europe.
[0130] The at least one log may correspond to at least one record of the at least one event. The at least one log may be a log entry. The at least one log is e.g. a system log for e.g. tracking changes in an operating system, an application log for e.g., recording user activities and errors in a software and / or a web server log e.g. for storing data about website visits.
[0131] The user request to return at least log may correspond to the input made by the user 140 into the first III during the interaction caused by the user with the first III. The input comprises requested parameters on at least one log to return. The requested parameters may be for example at least one identifier of a resource and / or the identifier of the group. The interaction caused by the user 140 with the first III pertains to the user request, wherein the user inputs e.g. requested parameters during the interaction.
[0132] The information related to the interaction may correspond to input data obtained by the first III function during the interaction caused by the user 140 with the III. The information may comprise the requested parameters and the user request to return the at least one log comprising the requested parameters. The at least one log associated with the user request and the group may be at least one log entry comprising and / or linked to the requested parameters.The request associated with the user request and the group may comprise the requested parameters.
[0133] Figure 6 illustrates a block diagram illustrating embodiments of the first server 100 in further detail. In practice, the steps 210 to 230 of the method 200 performed by the first server 100 are performed by processing circuitry 604, embodied in one or more processors and / or microprocessors arranged to execute a computer program 601 that is downloaded to a computer program product 605, here in the form of a computer readable storage medium 602. The computer readable storage medium 602 may be a memory, such as a read-only memory (ROM), or a tangible nonvolatile computer readable storage medium, such as flash memory or a hard disk drive, or any combination thereof. The computer program 601 comprises computerexecutable instructions stored or downloaded to the computer readable storage medium 602 and are executable by the processing circuitry 604. Alternatively, the computer program 601 may be transferred to the computer readable storage medium 602 using a suitable computer program product, such as a memory stick or in a memory of a device. Thus, the computer program 601 may be stored in any suitable manner in the computer program product. The processing circuity 604 is arranged to cause the first server 100 to carry out the steps 210 to 230 of method 200 in accordance with any of the of the described embodiments for steps 210 to 230. The processing circuitry 604 is in one embodiment one or more general-purpose processors wherein each one of the general purpose processors includes one or more cores, but may alternatively be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), etc. An I / O interface 603 is provided for communicating with external and / or internal entities using wired communications, e.g., based on Ethernet, and / or wireless communications, e.g., WiFi, and / or a cellular network corresponding to one or a combination of 5G cellular networks, LTE, LTE-advanced, UMTS, or any other current or future wireless network, such as a future 3GPP 6G network, as long as the principles described below are applicable.
[0134] Figure 7 illustrates a block diagram illustrating embodiments of the log repository 110 in further detail. In practice, the steps 310 to 324 of the method 300 performed by thelog repository 110 are performed by processing circuitry 704, embodied in one or more processors and / or microprocessors arranged to execute a computer program 701 that is downloaded to a computer program product 705, here in the form of a computer readable storage medium 702. The computer readable storage medium 702 may be a memory, such as aa ROM, or a tangible non-volatile computer readable storage medium, such as flash memory or a hard disk drive, or any combination thereof. The computer program 701 comprises computer-executable instructions stored or downloaded to the computer readable storage medium 702 and are executable by the processing circuitry 704. Alternatively, the computer program 701 may be transferred to the computer readable storage medium 702 using a suitable computer program product, such as a memory stick or in a memory of a device. Thus, the computer program 701 may be stored in any suitable manner in the computer program product. The processing circuity 704 is arranged to cause the log repository 110 to carry out the steps 310 to 324 of method 300 in accordance with any of the of the described embodiments for steps 310 to 324. The processing circuitry 704 is in one embodiment one or more general-purpose processors wherein each one of the general purpose processors includes one or more cores, but may alternatively be a DSP, an ASIC, an FPGA, a CPLD, etc. An I / O interface 703 is provided for communicating with external and / or internal entities using wired communications, e.g., based on Ethernet, and / or wireless communications, e.g., WiFi, and / or a cellular network corresponding to one or a combination of 5G cellular networks, LTE, LTE-advanced, UMTS, or any other current or future wireless network, such as a future 3GPP 6G network, as long as the principles described below are applicable.
[0135] Figure 8 illustrates a block diagram illustrating embodiments of the log viewer device 120 in further detail. In practice, the steps 410 to 440 of the method 400 performed by the log viewer device 120 are performed by processing circuitry 804, embodied in one or more processors and / or microprocessors arranged to execute a computer program 801 that is downloaded to a computer program product 805, here in the form of a computer readable storage medium 802. The computer readable storage medium 802 may be a memory, such as a ROM, or a tangible non-volatile computer readable storage medium, such as flash memory or a hard disk drive, or any combination thereof. The computer program 801 comprises computer-executableinstructions stored or downloaded to the computer readable storage medium 802 and are executable by the processing circuitry 804. Alternatively, the computer program 801 may be transferred to the computer readable storage medium 802 using a suitable computer program product, such as a memory stick or in a memory of a device. Thus, the computer program 801 may be stored in any suitable manner in the computer program product. The processing circuity 804 is arranged to cause the log viewer device 120 to carry out the steps 410 to 440 of method 400 in accordance with any of the of the described embodiments for steps 410 to 440. The processing circuitry 804 is in one embodiment one or more general-purpose processors wherein each one of the general purpose processors includes one or more cores, but may alternatively be a DSP, an ASIC, an FPGA, a CPLD, etc. An I / O interface 803 is provided for communicating with external and / or internal entities using wired communications, e.g., based on Ethernet, and / or wireless communications, e.g., Wi-Fi, and / or a cellular network corresponding to one or a combination of 5G cellular networks, LTE, LTE-advanced, UMTS, or any other current or future wireless network, such as a future 3GPP 6G network, as long as the principles described below are applicable.
[0136] While the first server 100, log repository 110 and log viewer 120 have been disclosed with the help of Figs. 6-8 as configured with computer programs 601 , 701 and 801 respectively, they are in alternative embodiments implemented in pure hardware, e.g. through one or more ASICs.
Claims
CLAIMS1. A method (200) performed by at least one first server (100) providing a service to at least one resource comprised in a group of resources, wherein the at least one first server (100) is communicatively connected to a log repository (110), and wherein the method comprises:obtaining (210) information on the group;obtaining (220) information pertaining to at least one event associated with the resource; andsending (230), to the log repository (110), a syslog message pertaining to the event, wherein the syslog message comprises an indication of the group.
2. The method (200) according to claim 1 , wherein obtaining (210) information on the group comprisesreceiving (212) the information on the group from a second server (130)3. The method (200) according to any one of the preceding claims, wherein the syslog message comprises at least one of:the information pertaining to the event,an identifier of the first server (100);an identifier of an application hosted by the first server (100);a severity level indication, wherein the severity level pertains to an importance of the syslog message; anda timestamp indicating when the syslog message is generated.
4. The method (200) according to any one of the preceding claims, wherein the information on the group comprises at least one of:an indication that the resource is comprised in the group; an identifier of the group; andat least one user role information associated with the group.
5. The method (200) according to any one of the preceding claims, wherein the indication of the group comprises a structured data identifier, SD-ID, which comprises an identifier of the group.
6. A method (300) performed by a log repository (110), wherein the log repository (110) is communicatively connected to at least one first server (100) , wherein the first server (100) is providing a service to at least one resource comprised in a group of resources, and wherein the method comprises:receiving (310), from the first server (100), a syslog message pertaining to at least one event, wherein the event is associated with the resource, and the syslog message comprises an indication of the group; and saving (320) the syslog message.
7. The method (300) according to claim 6, wherein the method comprises: receiving (322), from a log viewer device (120) hosting a first User Interface, III, function, a request associated with a user request by a user (140) to return at least one log to a III (160) of the III function and associated with the group, wherein an interaction caused by a user (140) with the III (160) pertains to the user request;sending (324), to the log viewer device (120), at least one log associated with the user request and the group.
8. The method (300) according to any of claims 6 to 7, wherein the syslog message comprises at least one of:the information pertaining to the event,an identifier of the first server (100);an identifier of an application hosted by the first server (100);a severity level indication, wherein the severity level pertains to an importance of the syslog message; anda timestamp indicating when the syslog message is generated.
9. The method (300) according to any one of claims 6 to 8, wherein the indication of the group comprises a structured data identifier, SD-ID, which comprises an identifier of the group.
10. A method (400) performed by a log viewer device (120) hosting a first User Interface, function, wherein the log viewer device (120) is communicatively connected to a log repository (110), and the method comprises:obtaining (410) information related to an interaction caused by a user (140) with a III (160) of the III function, wherein the interaction pertains to a user request by the user (140) to return at least one log to the III (160); determining (420) that the user (140) is authorized to retrieve at least one log associated with a group of resources;obtaining (430), from the log repository (110), the log associated with the user request and associated with the group;returning (440), to the III (160), the log associated with the user request and the group.
11. The method (400) according to claim 10, wherein the method comprises obtaining (412) information on the group.
12. The method (400) according to claim 11, wherein obtaining (412) the information on the group comprisesreceiving (414), from at least one second server (130), the information on the group.
13. The method (400) according to any of the claims 11 to 12, wherein the information on the group comprises at least one of:an indication that the at least one resource is comprised in the group; an identifier of the group; andat least one user role information associated with the group.
14. The method (400) according to any one of claims 10 to 13, wherein obtaining (430) the log associated with the user request comprises:sending (432), to the log repository (110), a request associated with the user request and the group; andreceiving (434), from the log repository (110), the at least one log associated with the user request and the group.
15. The method (400) according to any one of claims 10 to 14, wherein determining (430) that the user (140) is authorized to retrieve the log associated with the group comprisesobtaining (422) user information of the user (140), wherein the user information comprises at least one of a user role information associated with the user (140) and an identity of the user (140).
16. The method (400) according to any one of claims 10 to 15, wherein the user request comprises a request to access the log associated with the group.
17. A log system comprising:at least one first server (100) providing a service to at least one resource comprised in a group of resources and being configured to perform the method according to any one of claims 1 to 5;a log repository (110) configured to perform the method according to any one of claims 6 to 9; anda log viewer device (120) hosting a first User Interface function and being configured to perform the method according to any one of claims 10 to 16.
18. At least one first server (100) providing a service to at least one resource comprised in a group of resources, wherein the at least one first server (100)is communicatively connected to a log repository (110), whereby the first server (100) is configured to:obtain information on the group;obtain information pertaining to at least one event associated with the resource; andsend, to the log repository (110), a syslog message pertaining to the event, wherein the syslog message comprises an indication of the group.
19. The at least one first server (100) according to claim 18, configured to perform the method according to any of claims 2 to 5.
20. At least one first server (100) providing a service to at least one resource comprised in a group of resources, wherein the at least one first server (100) is communicatively connected to a log repository (110), wherein the at least one first server (100) comprises processing circuitry (604) and a computer readable storage medium (602), the computer readable storage medium (602) containing instructions executable by the processing circuitry (604), whereby the at least one first server (100) is configured toobtain information on the group;obtain information pertaining to at least one event associated with the resource; andsend, to the log repository (110), a syslog message pertaining to the event, wherein the syslog message comprises an indication of the group.21.The at least one first server (100) according to claim 20, configured to perform the method according to any of claims 2 to 5.
22. A log repository (110), wherein the log repository (110) is communicatively connected to at least one first server (100), wherein the first server (100) isproviding a service to at least one resource comprised in a group of resources, whereby the log repository (110) is configured to:receive, from the first server (100), a syslog message pertaining to at least one event, wherein the event is associated with the resource, and the syslog message comprises an indication of the group; andsave the syslog message.
23. The log repository (110) according to claim 22, configured to perform the method according to any of claims 7 to 9.
24. A log repository (110), wherein the log repository (110) is communicatively connected to at least one first server (100), wherein the first server (100) is providing a service to at least one resource comprised in a group of resources, wherein the log repository (110) comprises processing circuitry (704) and a computer readable storage medium (702), the computer readable storage medium (702) containing instructions executable by the processing circuitry (704), whereby the log repository (110) is configured to:receive, from the first server (100), a syslog message pertaining to at least one event, wherein the event is associated with the resource, and the syslog message comprises an indication of the group; andsave the syslog message.
25. The log repository (110) according to claim 24, configured to perform the method according to any of claims 7 to 9.
26. A log viewer device (120) hosting a first User Interface, function, wherein the log viewer device (120) is communicatively connected to a log repository (110); whereby the log viewer device (120) is configured to:obtain information related to an interaction caused by a user (140) with a III (160) of the III function, wherein the interaction pertains to a user request by the user (140) to return at least one log to the III (160);determine that the user (140) is authorized to retrieve at least one log associated with a group of resources;obtain, from the log repository (110), the log associated with the user request and associated with the group; andreturn, to the III (160), the log associated with the user request and the group.
27. The log viewer device (120) according to claim 26, configured to perform the method according to any of claims 11 to 16.
28. A log viewer device (120) hosting a first User Interface, function, wherein the log viewer device (120) is communicatively connected to a log repository (110), wherein the log viewer device (120) comprises processing circuitry (804) and a computer readable storage medium (802), the computer readable storage medium (802) containing instructions executable by the processing circuitry (804), whereby the log viewer device (120) is configured to:obtain information related to an interaction caused by a user (140) with a III (160) of the III function, wherein the interaction pertains to a user request by the user (140) to return at least one log to the III (160);determine that the user (140) is authorized to retrieve at least one log associated with a group of resources;obtain, from the log repository (110), the log associated with the user request and associated with the group; andreturn, to the III (160), the log associated with the user request and the group.
29. The log viewer device (120) according to claim 28, configured to perform the method according to any of claims 11 to 16.
30. A computer program (601) comprising instructions which, when executed on processing circuitry (604) of at least one first server (100), cause the processing circuitry (604) of the first server (100) to carry out the method according to any one of claims 1 to 5.
31. A computer program (701 ) comprising instructions which, when executed on processing circuitry (704) of a log repository (110), cause the processing circuitry (704) of the log repository (110) to carry out the method according to any one of claims 6 to 9.
32. A computer program (801) comprising instructions which, when executed on processing circuitry (804) of a log viewer device (120), cause the processing circuitry (804) of the log viewer device (120) to carry out the method according to any one of claims 10 to 16.
33. A tangible, non-volatile computer readable medium (602) comprising instructions that, when executed onprocessing circuitry (604) of at least one first server (100), cause the processing circuitry (604) of the first server (100) to carry out the method according to any one of claims 1 to 5.
34. A tangible, non-volatile computer readable medium (702) comprising instructions that, when executed onprocessing circuitry (704) of a log repository (110), cause the processing circuitry (704) of the log repository (110) to carry out the method according to any one of claims 6 to 9.
35. A tangible, non-volatile computer readable medium (802) comprising instructions that, when executed onprocessing circuitry (804) of a log viewer device (120), cause the processing circuitry (804) of the log viewer device (120) to carry out the method according to any one of claims 10 to 16.