CN102594598A - Log management system and implementation method thereof - Google Patents

Log management system and implementation method thereof Download PDF

Info

Publication number
CN102594598A
CN102594598A CN2012100354702A CN201210035470A CN102594598A CN 102594598 A CN102594598 A CN 102594598A CN 2012100354702 A CN2012100354702 A CN 2012100354702A CN 201210035470 A CN201210035470 A CN 201210035470A CN 102594598 A CN102594598 A CN 102594598A
Authority
CN
China
Prior art keywords
log
daily record
server
module
received
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2012100354702A
Other languages
Chinese (zh)
Inventor
戴文军
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inspur Beijing Electronic Information Industry Co Ltd
Original Assignee
Inspur Beijing Electronic Information Industry Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inspur Beijing Electronic Information Industry Co Ltd filed Critical Inspur Beijing Electronic Information Industry Co Ltd
Priority to CN2012100354702A priority Critical patent/CN102594598A/en
Publication of CN102594598A publication Critical patent/CN102594598A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Debugging And Monitoring (AREA)

Abstract

The invention discloses a log management system and an implementation method thereof, and belongs to the technical field of cluster systems. The method comprises the following steps that: a log generated by each application program on an application server is transmitted to a log client agent through a log database, and the log client agent locally stores the received logs, and transmits the received logs to a log server according to the configured Internet protocol (IP) address and related port numbers of the log server; and a log server agent in the log server receives the logs, a log storage module stores the received logs into a local database in a centralized way, and a log publication module publishes a set number of latest logs in the local database to the Internet for a user to browse and monitor. The invention also discloses the log management system. By the technical scheme, the unified management of the logs is realized, and operation such as log alarming and log viewing is supported on such a basis.

Description

A kind of Log Administration System and its implementation
Technical field
The present invention relates to NOWs, relate in particular to a kind of Log Administration System and its implementation.
Background technology
Along with the development of cloud computing, IT system presents the polymerization trend of concentrating.Single service management is substituted by the complicated service crowd.Relate to application software in the IT environment and comprise dozens or even hundreds of thousands of kinds, therefore management becomes the problem that present NOWs presses for solution.An important component part in the management of group of planes services sets is a log system.The Log Administration System of disperseing does not utilize NOWs condition monitoring and daily record to check.
Summary of the invention
Technical problem to be solved by this invention is a kind of Log Administration System and its implementation to be provided, with the unified management daily record.
In order to address the above problem, the invention discloses a kind of implementation method of Log Administration System, comprising:
Each application log sends to the daily record Client Agent through log database on the application server; Said daily record Client Agent is preserved the daily record of being received in this locality; According to the log server ip address and the associated port number of configuration, the daily record of being received is sent to log server again;
Log services end agency receives said daily record in the said log server; The log store module is saved in received daily record unification in the local data base; The daily record release module is published to the daily record of setting number up-to-date in the local data base on the network, supplies the user to browse and monitor.
Preferably, said method also comprises: when log services end agency received new daily record in the said log server, said daily record release module was upgraded the issue daily record, and making the daily record of being issued is the daily record of up-to-date setting number.
Preferably, said method comprises that also said log server also carries out daily record through the log services subscribing module and reports to the police when particular log takes place.
Preferably; The subscribing module of log services described in the said method according to user instruction to the one or more daily record filters of said log services agency of trademark registration; The corresponding at least log processing instance of each daily record filter of being registered; Each daily record filter filters out the daily record with characteristic information; The log processing instance corresponding through this daily record filter sends to corresponding message recipient with the daily record that is filtered out, and said message recipient gives the daily record receiver with Real-time Alarm this Log Report again.
The invention also discloses a kind of Log Administration System, comprise application server and log server, wherein, said application server comprises log database and daily record Client Agent at least:
Said log database sends to said daily record Client Agent with each application log;
Said daily record Client Agent is preserved the daily record of being received, and according to the log server ip address and the associated port number that dispose, the daily record of being received is sent to log server in this locality;
Said log server comprises log services end agency, log store module and daily record release module at least:
Said log services end agency receives the daily record that said application server sends;
Said log store module is saved in received daily record unification in the local data base;
Said daily record release module is published to the daily record of setting number up-to-date in the local data base on the network, supplies the user to browse and monitor.
Preferably, in the said system, when said log services end agency received new daily record, said daily record release module was also upgraded the issue daily record, and making the daily record of being issued is the daily record of up-to-date setting number.
Preferably, in the said system, said log server also comprises the log services subscribing module, and this module is carried out daily record and reported to the police when particular log takes place.
Preferably; In the said system; Said log services subscribing module is included in one or more daily record filters of said log services agency of trademark registration; The corresponding at least log processing instance of each daily record filter of being registered, the daily record that each daily record filter filters out with characteristic information, the log processing instance corresponding through this daily record filter sends to corresponding message recipient with Real-time Alarm with the daily record that is filtered out.
The present techniques scheme has realized the unified management of daily record, and can support various daily records to report to the police on this basis, and daily record such as checks at operation.
Description of drawings
The structural representation of the Log Administration System that Fig. 1 provides for present embodiment 1.
Embodiment
For the purpose, technical scheme and the advantage that make the application is clearer, hereinafter will combine accompanying drawing and embodiment that the present techniques scheme is done further explain.Need to prove, under the situation of not conflicting, the combination each other arbitrarily of the application's embodiment and the characteristic of embodiment.
Embodiment 1
Present embodiment provides a kind of Log Administration System, can carry out unified log management.Particularly, this system comprises the two large divisions at least, and is as shown in Figure 1, is respectively application server and log server.
In the present embodiment, application server comprises log database and daily record Client Agent again.
Log database (Lib storehouse) mainly is that each application log is sent to the daily record Client Agent;
Above-mentioned daily record Lib can use in the storehouse multilingual to develop as required, specifically can comprise the Lib storehouse of C language, Java language exploitation, and application program is directly quoted relevant Lib built-in function and carried out the daily record transmission.Other also can use step language such as PHP, Perl to develop.Daily record lib storehouse comprises Log Types, daily record grade, daily record at least to every daily record and produces in a hurry, time time of reception, produces log pattern, log content and daily record numbering.
Be noted that also log database uses udp protocol to carry out the daily record transmission in the present embodiment, but in practical application, be not limited to use udp protocol to send.
The daily record Client Agent is preserved the daily record of being received, and according to the log server ip address and the associated port number that dispose, the daily record of being received is sent to log server in this locality.Wherein, can use TCP/IP procotols such as HTTP, HTTPS to carry out information exchange between daily record Client Agent and the log server.
And adopt consistent communications protocol to get final product between daily record Lib storehouse in the application server and the daily record Client Agent.The local Socket (socket) that present embodiment uses, but in practical application, be not limited to use local Socket, can use other any Inter-Process Communication mode to carry out communication.
Introduce the log server in the present embodiment below again, as shown in Figure 1, this log server comprises log services end agency, log store module and daily record release module.
Log services end agency receives the daily record that application server sends;
The log store module is saved in received daily record unification in the local data base;
The daily record release module is published to the daily record of setting number up-to-date in the local data base on the network, supplies the user to browse and monitor.Wherein, the user can carry out log searching through the log services release module, and preserves search condition, realizes the real-time tracking to the daily record of certain application on the specific application servers through the automatic update system of log services issue browsing client.The user can pass through the condition of the different retrieval of combination, thereby obtains different result for retrieval.
In addition, when having the arrival of new daily record, the daily record release module will be upgraded content distributed, and the oldest data are replaced, and guarantee that promptly the daily record of being issued is up-to-date daily record.
On the basis of above-mentioned log server, preferred version propose to increase by a log services subscribing module, and the main effect of this module is when particular log takes place, to carry out daily record to report to the police, and like this, the user can learn daily record and handles in the very first time.Particularly, the log services subscribing module according to user instruction to log services agency of trademark registration daily record filter, to carry out the subscription of different characteristic daily record.Need to prove, can register a plurality of daily record filters simultaneously, and the corresponding at least log processing instance of each daily record filter.After filtering out the particular log with characteristic information when the daily record filter, the log processing instance that this daily record filter is corresponding can send to message recipient with the particular log that filters out; Message recipient then with this particular log report mail server, note receiving terminal, TRAP server, etc. specific daily record receiver to realize Real-time Alarm.
Embodiment 2
Present embodiment is introduced the implementation method of Log Administration System in the foregoing description 1.
Each application log sends to the daily record Client Agent through log database on the application server; The daily record Client Agent is preserved the daily record of being received in this locality; According to the log server ip address and the associated port number of configuration, the daily record of being received is sent to log server again;
Log services end agency receives above-mentioned daily record in the log server; The log store module is saved in received daily record unification in the local data base; The daily record release module is published to the daily record of setting number up-to-date in the local data base on the network, supplies the user to browse and monitor.
In said method, when log services end agency receives new daily record in the log server, the daily record release module also will be upgraded and issue daily record, and making the daily record of being issued is the daily record of up-to-date setting number.
In addition, log server also carries out the daily record warning through the log services subscribing module when particular log takes place.Particularly; The user can self-demand; Through the log services subscribing module to the one or more daily record filters of log services agency of trademark registration, corresponding at least log processing instance of each daily record filter of being registered, and after the daily record filter filters out daily record with some concrete characteristic (this daily record is the particular log of the needs alarm that user self is provided with); Can this particular log be sent to the corresponding log processing instance of this daily record filter; The log processing instance is handled daily record according to concrete instantiation parameter, is about to daily record and sends to specific daily record receiving terminal, thereby realize Real-time Alarm.
One of ordinary skill in the art will appreciate that all or part of step in the said method can instruct related hardware to accomplish through program, said program can be stored in the computer-readable recording medium, like read-only memory, disk or CD etc.Alternatively, all or part of step of the foregoing description also can use one or more integrated circuits to realize.Correspondingly, each the module/unit in the foregoing description can adopt the form of hardware to realize, also can adopt the form of software function module to realize.The application is not restricted to the combination of the hardware and software of any particular form.
Can find out from the foregoing description, the present techniques scheme constructs a unified group of planes Log Administration System, but efficient real time is checked daily record, and when system's generation anomalous event, can report to the police through unified Log Administration System.
The above is merely the application's preferred embodiments, is not the protection range that is used to limit the application.All within the application's spirit and principle, any modification of being made, be equal to replacement, improvement etc., all should be included within the application's the protection range.

Claims (8)

1. the implementation method of a Log Administration System is characterized in that,
Each application log sends to the daily record Client Agent through log database on the application server; Said daily record Client Agent is preserved the daily record of being received in this locality; According to the log server ip address and the associated port number of configuration, the daily record of being received is sent to log server again;
Log services end agency receives said daily record in the said log server; The log store module is saved in received daily record unification in the local data base; The daily record release module is published to the daily record of setting number up-to-date in the local data base on the network, supplies the user to browse and monitor.
2. the method for claim 1 is characterized in that, this method also comprises:
When log services end agency received new daily record in the said log server, said daily record release module was upgraded the issue daily record, and making the daily record of being issued is the daily record of up-to-date setting number.
3. according to claim 1 or claim 2 method is characterized in that this method also comprises:
Said log server also carries out daily record through the log services subscribing module and reports to the police when particular log takes place.
4. method as claimed in claim 3 is characterized in that,
Said log services subscribing module according to user instruction to the one or more daily record filters of said log services agency of trademark registration; The corresponding at least log processing instance of each daily record filter of being registered; Each daily record filter filters out the daily record with characteristic information; The log processing instance corresponding through this daily record filter sends to corresponding message recipient with the daily record that is filtered out, and said message recipient gives the daily record receiver with Real-time Alarm this Log Report again.
5. a Log Administration System is characterized in that, this system comprises application server and log server, and wherein, said application server comprises log database and daily record Client Agent at least:
Said log database sends to said daily record Client Agent with each application log;
Said daily record Client Agent is preserved the daily record of being received, and according to the log server ip address and the associated port number that dispose, the daily record of being received is sent to log server in this locality;
Said log server comprises log services end agency, log store module and daily record release module at least:
Said log services end agency receives the daily record that said application server sends;
Said log store module is saved in received daily record unification in the local data base;
Said daily record release module is published to the daily record of setting number up-to-date in the local data base on the network, supplies the user to browse and monitor.
6. system as claimed in claim 5 is characterized in that,
When said log services end agency received new daily record, said daily record release module was also upgraded the issue daily record, and making the daily record of being issued is the daily record of up-to-date setting number.
7. like claim 5 or 6 described systems, it is characterized in that,
Said log server also comprises the log services subscribing module, and this module is carried out daily record and reported to the police when particular log takes place.
8. system as claimed in claim 7 is characterized in that,
Said log services subscribing module is included in one or more daily record filters of said log services agency of trademark registration; The corresponding at least log processing instance of each daily record filter of being registered; The daily record with characteristic information that each daily record filter filters out, the log processing instance corresponding through this daily record filter sends to corresponding message recipient with Real-time Alarm with the daily record that is filtered out.
CN2012100354702A 2012-02-16 2012-02-16 Log management system and implementation method thereof Pending CN102594598A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2012100354702A CN102594598A (en) 2012-02-16 2012-02-16 Log management system and implementation method thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2012100354702A CN102594598A (en) 2012-02-16 2012-02-16 Log management system and implementation method thereof

Publications (1)

Publication Number Publication Date
CN102594598A true CN102594598A (en) 2012-07-18

Family

ID=46482818

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2012100354702A Pending CN102594598A (en) 2012-02-16 2012-02-16 Log management system and implementation method thereof

Country Status (1)

Country Link
CN (1) CN102594598A (en)

Cited By (20)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102981943A (en) * 2012-10-29 2013-03-20 新浪技术(中国)有限公司 Method and system for monitoring application logs
CN103580899A (en) * 2012-08-01 2014-02-12 中兴通讯股份有限公司 Method and system for managing event logs, cloud service client side and virtualization platform
CN103856353A (en) * 2014-03-06 2014-06-11 上海爱数软件有限公司 Service log data access and statistic analysis method and device
CN103973785A (en) * 2014-05-07 2014-08-06 Tcl集团股份有限公司 Log reading system based on P2P and method thereof
CN104375928A (en) * 2013-08-12 2015-02-25 鸿富锦精密工业(深圳)有限公司 Abnormal log management method and system
CN104408136A (en) * 2014-11-26 2015-03-11 合肥晶奇电子科技有限公司 Log treatment method for public medical system
CN104461820A (en) * 2014-10-29 2015-03-25 中国建设银行股份有限公司 Equipment monitoring method and device
CN104579767A (en) * 2014-12-29 2015-04-29 山石网科通信技术有限公司 Method and system for sending gateway log information
CN104598622A (en) * 2015-02-02 2015-05-06 浪潮软件股份有限公司 Method and system for implementing data modification log as well as application server
CN104699592A (en) * 2012-09-25 2015-06-10 北京奇虎科技有限公司 Log data transmission method and log data transmission system
CN104714880A (en) * 2012-09-25 2015-06-17 北京奇虎科技有限公司 Log data transmission method and system as well as log server
CN105099740A (en) * 2014-05-15 2015-11-25 中国移动通信集团浙江有限公司 Log management system and log collection method
CN105183609A (en) * 2015-09-16 2015-12-23 焦点科技股份有限公司 Real-time monitoring system and method applied to software system
CN105229605A (en) * 2012-11-26 2016-01-06 谷歌股份有限公司 The concentrated distribution that application program is analyzed
CN106385331A (en) * 2016-09-08 2017-02-08 努比亚技术有限公司 Method and system for monitoring alarm based on log
CN106657408A (en) * 2017-02-24 2017-05-10 深圳市中博睿存信息技术有限公司 Cross-platform log collecting and processing framework
CN107231245A (en) * 2016-03-23 2017-10-03 阿里巴巴集团控股有限公司 Report method and device, the method and device of processing monitoring daily record of monitoring daily record
CN107463602A (en) * 2017-06-15 2017-12-12 努比亚技术有限公司 A kind of log processing method and server, client
CN111416767A (en) * 2020-03-16 2020-07-14 广东科徕尼智能科技有限公司 Log output method, device and storage medium of edge intelligent gateway
CN113342748A (en) * 2021-07-05 2021-09-03 北京腾云天下科技有限公司 Log data processing method and device, distributed computing system and storage medium

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1642104A (en) * 2004-01-05 2005-07-20 华为技术有限公司 Method and device for realizing system journal
CN1852309A (en) * 2005-11-16 2006-10-25 华为技术有限公司 Data synchronizing processing method and its client end
CN101197700A (en) * 2006-12-05 2008-06-11 阿里巴巴公司 Method and system for providing log service
CN101291256A (en) * 2008-06-02 2008-10-22 杭州华三通信技术有限公司 Method and system for upgrading system log to alarm
CN101969386A (en) * 2010-11-09 2011-02-09 道有道(北京)科技有限公司 Log acquisition device and log acquisition method
CN102209134A (en) * 2010-03-30 2011-10-05 深圳富泰宏精密工业有限公司 System and method for automatically retrieving log

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1642104A (en) * 2004-01-05 2005-07-20 华为技术有限公司 Method and device for realizing system journal
CN1852309A (en) * 2005-11-16 2006-10-25 华为技术有限公司 Data synchronizing processing method and its client end
CN101197700A (en) * 2006-12-05 2008-06-11 阿里巴巴公司 Method and system for providing log service
CN101291256A (en) * 2008-06-02 2008-10-22 杭州华三通信技术有限公司 Method and system for upgrading system log to alarm
CN102209134A (en) * 2010-03-30 2011-10-05 深圳富泰宏精密工业有限公司 System and method for automatically retrieving log
CN101969386A (en) * 2010-11-09 2011-02-09 道有道(北京)科技有限公司 Log acquisition device and log acquisition method

Cited By (29)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103580899A (en) * 2012-08-01 2014-02-12 中兴通讯股份有限公司 Method and system for managing event logs, cloud service client side and virtualization platform
CN103580899B (en) * 2012-08-01 2018-11-30 南京中兴新软件有限责任公司 Event log management method, system, cloud service client and virtual platform
CN104714880B (en) * 2012-09-25 2018-07-27 北京奇虎科技有限公司 Daily record data transmission method, system and log server
CN104714880A (en) * 2012-09-25 2015-06-17 北京奇虎科技有限公司 Log data transmission method and system as well as log server
CN104699592A (en) * 2012-09-25 2015-06-10 北京奇虎科技有限公司 Log data transmission method and log data transmission system
CN104699592B (en) * 2012-09-25 2018-09-04 北京奇虎科技有限公司 A kind of method and system of daily record data transmission
CN102981943B (en) * 2012-10-29 2016-05-11 新浪技术(中国)有限公司 The method and system of monitoring application daily record
CN102981943A (en) * 2012-10-29 2013-03-20 新浪技术(中国)有限公司 Method and system for monitoring application logs
US10331539B2 (en) 2012-11-26 2019-06-25 Google Llc Centralized dispatching of application analytics
CN105229605B (en) * 2012-11-26 2018-10-02 谷歌有限责任公司 The concentration distribution of application program analysis
CN105229605A (en) * 2012-11-26 2016-01-06 谷歌股份有限公司 The concentrated distribution that application program is analyzed
CN104375928A (en) * 2013-08-12 2015-02-25 鸿富锦精密工业(深圳)有限公司 Abnormal log management method and system
CN103856353A (en) * 2014-03-06 2014-06-11 上海爱数软件有限公司 Service log data access and statistic analysis method and device
CN103973785B (en) * 2014-05-07 2018-06-19 Tcl集团股份有限公司 A kind of log read system and method based on P2P
CN103973785A (en) * 2014-05-07 2014-08-06 Tcl集团股份有限公司 Log reading system based on P2P and method thereof
CN105099740A (en) * 2014-05-15 2015-11-25 中国移动通信集团浙江有限公司 Log management system and log collection method
CN104461820A (en) * 2014-10-29 2015-03-25 中国建设银行股份有限公司 Equipment monitoring method and device
CN104408136A (en) * 2014-11-26 2015-03-11 合肥晶奇电子科技有限公司 Log treatment method for public medical system
CN104579767A (en) * 2014-12-29 2015-04-29 山石网科通信技术有限公司 Method and system for sending gateway log information
CN104579767B (en) * 2014-12-29 2018-01-02 山石网科通信技术有限公司 The sending method and system of gateway log information
CN104598622A (en) * 2015-02-02 2015-05-06 浪潮软件股份有限公司 Method and system for implementing data modification log as well as application server
CN105183609A (en) * 2015-09-16 2015-12-23 焦点科技股份有限公司 Real-time monitoring system and method applied to software system
CN105183609B (en) * 2015-09-16 2017-03-15 焦点科技股份有限公司 A kind of real-time monitoring system for being applied to software system and method
CN107231245A (en) * 2016-03-23 2017-10-03 阿里巴巴集团控股有限公司 Report method and device, the method and device of processing monitoring daily record of monitoring daily record
CN106385331A (en) * 2016-09-08 2017-02-08 努比亚技术有限公司 Method and system for monitoring alarm based on log
CN106657408A (en) * 2017-02-24 2017-05-10 深圳市中博睿存信息技术有限公司 Cross-platform log collecting and processing framework
CN107463602A (en) * 2017-06-15 2017-12-12 努比亚技术有限公司 A kind of log processing method and server, client
CN111416767A (en) * 2020-03-16 2020-07-14 广东科徕尼智能科技有限公司 Log output method, device and storage medium of edge intelligent gateway
CN113342748A (en) * 2021-07-05 2021-09-03 北京腾云天下科技有限公司 Log data processing method and device, distributed computing system and storage medium

Similar Documents

Publication Publication Date Title
CN102594598A (en) Log management system and implementation method thereof
CN114143203B (en) Method and system for collecting network data packet indexes of Kubernetes container based on dynamic service topology mapping
CN109245931B (en) Log management and monitoring alarm realization method of container cloud platform based on kubernets
CN106571960B (en) Log collection management system and method
US7680907B2 (en) Method and system for identifying and conducting inventory of computer assets on a network
CN102918534B (en) Inquiry pipeline
CN106612199B (en) A kind of network monitoring data is collected and analysis system and method
CN103731298A (en) Large-scale distributed network safety data acquisition method and system
US20070124437A1 (en) Method and system for real-time collection of log data from distributed network components
US20180287920A1 (en) Intercepting application traffic monitor and analyzer
JP2014528126A (en) Distributing multi-source push notifications to multiple targets
CN102148827B (en) Security event management method, device and security management platform
CN103546343B (en) The network traffics methods of exhibiting of network traffic analysis system and system
CN103326896B (en) The system and method for the information data that a kind of user of collection produces on the internet
CN103152352A (en) Perfect information security and forensics monitoring method and system based on cloud computing environment
CN107864056A (en) A kind of distributed event acquisition probe, distributed event high speed acquisition system and method
CN105429791A (en) Distributed service state detection device and method
JP2008263581A (en) Method and apparatus for clustered filtering in rfid infrastructure
CN104834582A (en) Monitoring event display method
CN114328124A (en) Method and device for business monitoring, storage medium and electronic device
CN102130759A (en) Data collection method, data collection device cluster and data collection devices
CN111131079B (en) Policy query method and device
CN111740868A (en) Alarm data processing method and device and storage medium
US20120109663A1 (en) Advanced Metering Infrastructure Event Filtering
CN108877188B (en) Environment-friendly data concurrent acquisition and multi-network publishing method and device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20120718