CN103957133A - Log monitoring method and device - Google Patents

Log monitoring method and device Download PDF

Info

Publication number
CN103957133A
CN103957133A CN201410161849.7A CN201410161849A CN103957133A CN 103957133 A CN103957133 A CN 103957133A CN 201410161849 A CN201410161849 A CN 201410161849A CN 103957133 A CN103957133 A CN 103957133A
Authority
CN
China
Prior art keywords
log recording
website server
monitoring client
configuration file
client
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201410161849.7A
Other languages
Chinese (zh)
Inventor
韩晓铭
郎春青
张宇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
BEIJING LIANJIA ZHONGYING NETWORK TECHNOLOGY CO., LTD.
Original Assignee
Beijing Connection Time-Space Network Communication Facilities Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Connection Time-Space Network Communication Facilities Co Ltd filed Critical Beijing Connection Time-Space Network Communication Facilities Co Ltd
Priority to CN201410161849.7A priority Critical patent/CN103957133A/en
Publication of CN103957133A publication Critical patent/CN103957133A/en
Pending legal-status Critical Current

Links

Landscapes

  • Debugging And Monitoring (AREA)

Abstract

The invention discloses a log monitoring method and device. The method is applied to a monitoring server, and the monitoring server is connected with a plurality of web servers. The method includes the steps that when a log monitoring instruction is received, the log record generated by at least one web server is acquired, whether the number of items of the log record generated by the web servers respectively reaches a preset alarm threshold value or not is judged, and if yes, the alarm information corresponding to the web server is generated. Thus, it can be seen that by the aid of the log monitoring method, the web servers can be monitored.

Description

A kind of daily record monitoring method and device
Technical field
The application relates to monitoring server technical field, especially a kind of daily record monitoring method and device.
Background technology
In Website server, store the data resource corresponding with user's access request, user can send access request to Website server, and then Website server is made corresponding response according to user's access request.But due to sharply increase of visit capacity, assault, treatment effeciency lower etc. various or extraneous or self, cause the Website server cannot be to user's the request action that normally responds.
But, also there is no a kind of scheme of the described abnormal conditions of Website server being carried out to early warning at present.
Summary of the invention
In view of this, the application provides a kind of daily record monitoring method and device, does not also have a kind ofly can not to carry out the technical problem of the scheme of early warning to user's ask normally to respond abnormal conditions of action to Website server in order to solve in prior art.The technical scheme that the application provides comprises:
A kind of daily record monitoring method, is applied to monitor server, and described monitor server is connected with many Website servers, and the method comprises:
Steps A: in the time receiving daily record Monitoring instruction, obtain the log recording that at least one Website server generates;
Step B: whether the item number that judges respectively the log recording of described every each self-generating of Website server meets preset alarm threshold value, if so, performs step C;
Step C: generate the warning message corresponding with this Website server.
Said method, preferred, after described step C, also comprise:
Described warning message is sent to warning message receiving terminal.
Said method, preferred, on described Website server, be provided with monitoring client, and described Website server stores the client configuration file corresponding with described monitoring client; On described monitor server, store and the each self-corresponding service end configuration file of described each monitoring client.
Said method, preferred, described in obtain the log recording that at least one Website server generates, comprising:
Control described multiple monitoring client and determine target website server according to corresponding client configuration file, trigger described monitoring client and send the log recording that described target website server generates, and receive described log recording;
And/or, control described multiple monitoring client and determine target journaling record according to corresponding client configuration file, trigger described monitoring client and send the target journaling record that described Website server generates, and receive described target journaling record.
Said method, preferred, described in obtain the log recording that at least one Website server generates, comprising:
Judge that whether the communication connection between described monitoring client and described monitor server is abnormal;
If so, control described monitoring client the log recording of described Website server generation is put into default message queue; In the time that described communication connection is normal, controls described monitoring client and send the log recording in described message queue;
If not, control described monitoring client and send the log recording that described Website server generates.
Said method, preferred, also comprise:
In the time monitoring described service end configuration file and upgrade, the service end configuration file after described renewal is sent to corresponding monitoring client, taking trigger described monitoring client by described client configuration file update the service end configuration file after described renewal.
Said method, preferred, after obtaining the log recording of at least one Website server generation, also comprise:
According to default burst rule, described log recording is carried out to burst;
Log recording after described burst is stored in many database servers;
In the time receiving log access instruction, generate routing daemon;
Trigger described routing daemon and in described many database servers, obtain the log recording corresponding with described log access instruction.
The application also provides a kind of daily record monitoring device, is applied to monitor server, and described monitor server is connected with many Website servers, and this device comprises:
Acquisition module: in the time receiving daily record Monitoring instruction, obtain the log recording that at least one Website server generates;
Judge module: whether the item number for the log recording that judges respectively described every each self-generating of Website server meets preset alarm threshold value; If so, trigger alarm module;
Alarm module: for generating the warning message corresponding with this Website server;
Sending module, for being sent to warning message receiving terminal by described warning message.
Said apparatus, preferred, on described Website server, be provided with monitoring client, and described Website server stores the client configuration file corresponding with described monitoring client; On described monitor server, store and the each self-corresponding service end configuration file of described each monitoring client; This device also comprises:
Update module, for in the time monitoring described service end configuration file renewal, service end configuration file after described renewal is sent to corresponding monitoring client, taking trigger described monitoring client by described client configuration file update the service end configuration file after described renewal;
Wherein: described acquisition module comprises:
First obtains submodule, determines target website server for controlling described multiple monitoring client according to corresponding client configuration file, triggers described monitoring client and sends the log recording that described target website server generates, and receive described log recording;
Second obtains submodule, determine target journaling record for controlling described multiple monitoring client according to corresponding client configuration file, trigger described monitoring client and send the target journaling record that described Website server generates, and receive described target journaling record;
Whether the 3rd obtains submodule, abnormal for judging the communication connection between described monitoring client and described monitor server; If so, control described monitoring client the log recording of described Website server generation is put into default message queue; In the time that described communication connection is normal, controls described monitoring client and send the log recording in described message queue; If not, control described monitoring client and send the log recording that described Website server generates.
Said apparatus, preferred, also comprise:
Burst module, for according to default burst rule, carries out burst by described log recording;
Memory module, for being stored in many database servers by the log recording after described burst;
Process module, in the time receiving log access instruction, generates routing daemon;
Trigger module, obtains the log recording corresponding with described log access instruction for triggering described routing daemon at described many database servers.
From above technical scheme, the present embodiment provides a kind of daily record monitoring method and device, be applied to monitor server, described monitor server is connected with many Website servers, the method is by the time receiving daily record Monitoring instruction, obtain the log recording that at least one Website server generates, and whether the item number that judges respectively the log recording of described every each self-generating of Website server meets preset alarm threshold value, if, generate the warning message corresponding with this Website server, thereby the log recording that utilizes Website server to generate, realize the monitoring to described Website server.
Brief description of the drawings
The flow chart of the embodiment of a kind of daily record monitoring method that Fig. 1 provides for the application;
The example architecture figure that Fig. 2 provides for the application;
The flow chart of a kind of another embodiment of daily record monitoring method that Fig. 3 provides for the application;
The flow chart of the another embodiment of a kind of daily record monitoring method that Fig. 4 provides for the application;
The part flow chart of the another embodiment of a kind of daily record monitoring method that Fig. 5 provides for the application;
The part flow chart of the another embodiment of a kind of daily record monitoring method that Fig. 6 provides for the application;
The structural representation of the embodiment of a kind of daily record monitoring device that Fig. 7 provides for the application;
The structural representation of a kind of another embodiment of daily record monitoring device that Fig. 8 provides for the application;
The part-structure schematic diagram of the another embodiment of a kind of daily record monitoring device that Fig. 9 provides for the application.
Embodiment
Below in conjunction with the accompanying drawing in the embodiment of the present application, the technical scheme in the embodiment of the present application is clearly and completely described, obviously, described embodiment is only some embodiments of the present application, instead of whole embodiment.Based on the embodiment in the application, those of ordinary skill in the art are not making the every other embodiment obtaining under creative work prerequisite, all belong to the scope of the application's protection.
The Website server of difference in functionality can be realized different web sites function, as shopping, file uploads and download, information search etc.User sends access request to Website server, and the response that Website server responds according to access request, as the submission order in shopping function, confirmation payment etc.
But Website server may cause making normal response action to user's request due to a variety of causes.Described a variety of causes comprises Website server self or from extraneous reason, for example, the user of access websites sharply increases suddenly, the attack of hacker to website etc.
For recording above-mentioned abnormal conditions, Website server can generate corresponding log recording, stores the data message that abnormal conditions are relevant in described log recording, as produced time, the time that receives access request, the content of access request etc. of abnormal conditions.Described log recording can be used as the foundation of analyzing web site server health.Therefore, the described log recording that the application utilizes Website server to generate, realizes the monitoring function to Website server.
Embodiment of the method one:
Refer to Fig. 1, it shows the flow chart of a kind of daily record monitoring method embodiment mono-that the application provides, and the present embodiment can comprise:
Step 101: in the time receiving daily record Monitoring instruction, obtain the log recording that at least one Website server generates.
Wherein, described daily record Monitoring instruction, for triggering the execution of the present embodiment,, in the time receiving described daily record Monitoring instruction, starts to carry out the operation of obtaining log recording in this step.Described daily record Monitoring instruction can be according to extraneous manual operation triggering for generating, and when Website server monitoring as needs, people is for carrying out clicking operation, thereby generates described daily record Monitoring instruction.
Concrete, described acquisition process, can be to receive the log recording that described Website server sends voluntarily, can be also to send control command to described Website server, to trigger described Website server, the log recording of generation is sent to described monitor server.
In addition, the present embodiment does not limit the particular type of described Website server, as long as generating to abnormal conditions the Website server of log recording.
Step 102: whether the item number that judges respectively the log recording of described every each self-generating of Website server meets preset alarm threshold value; If so, perform step 103.
Wherein, in described log recording, can include the mark of Website server, generate the Website server of log recording in order to record.Concrete, described deterministic process is, adds up the item numerical value of the log recording of described every each self-generating of Website server, generated the log recording of how many, and described each quantitative value and default threshold value of warning are compared.When the quantitative value of the log recording generating when certain Website server meets preset alarm threshold value, execution step 103.
It should be noted that, described preset alarm threshold value, can be same numerical value, and the quantitative value of the log recording that described each Website server generates is all compared with same preset alarm threshold value; Also can be different numerical value, be each Website server different alarm threshold values is set.In addition, further say, for same Website server, described preset alarm threshold value can be also different numerical value, be that same Website server can send dissimilar log recording, described preset alarm threshold value can be corresponding with the type of log recording, the i.e. each self-corresponding alarm threshold value of log recording of default every type, for example, warning predetermined threshold value corresponding to log recording generating in payment process is 10, and submitting preset alarm threshold value corresponding to log recording generating in order process to is 20.
It should be noted that, described acquisition process carries out in real time, it is the log recording that Website server generates described in Real-time Obtaining, described preset alarm threshold value can include time period factor, be that described preset alarm threshold value is the threshold value in Preset Time section, for example, one minute 10, one minute 20.Corresponding, described deterministic process is specially, and judges whether the item number of the log recording in described Preset Time section meets preset alarm threshold value.For example, judge whether the item number that pays log recording in a minute meets 10, judge whether the quantitative value that pays log recording in a minute meets 20.
Step 103: generate the warning message corresponding with this Website server.
Concrete, if the quantitative value of the log recording that in step 102, certain Website server of judgement generates meets preset alarm threshold value, generate the warning message corresponding with this Website server.In described log recording, can include the mark of Website server, can set up according to the mark of Website server the corresponding relation of warning message and Website server.
In addition, the form of described warning message can be including but not limited to mail warning message, SMS alarm information, interface warning message.
It should be noted that, above-mentioned steps 101, step 102 and step 103 are corresponding with steps A, step B and step C in claim 1 respectively.
From above technical scheme, the present embodiment provides a kind of daily record monitoring method, described method is applied to monitor server, described monitor server is connected with many Website servers, the method is by the time receiving daily record Monitoring instruction, obtain the log recording that at least one Website server generates, and whether the item number that judges respectively the log recording of described every each self-generating of Website server meets preset alarm threshold value, if, generate the warning message corresponding with this Website server, thereby the log recording that utilizes Website server to generate, realize the monitoring to described Website server.
Further, described warning message is corresponding with described Website server, can determine the concrete Website server that produces access exception situation according to described warning message.Use at Website server under the scene of distributed collaboration treatment technology, can position the Website server that occurs abnormal conditions rapidly, effectively improved monitoring efficiency and monitoring accuracy.
Refer to Fig. 1, after said method embodiment mono-step 103, this embodiment also comprises:
Step 104: described warning message is sent to warning message receiving terminal.
Concrete, according to the concrete form of described warning message, described warning message is sent to warning message receiving terminal, to remind related personnel to process the abnormal conditions of described Website server.Wherein, described warning message receiving terminal can be one or more.For example, one or more in mail reception terminal, short message receiving terminal, interface display terminal.
Embodiment of the method two:
Refer to Fig. 2, on many Website servers 201 to 204, be provided with separately monitoring client, described Website server is connected with described monitor server, and on described Website server 205, stores the client configuration file corresponding with described monitoring client; On described monitor server, store and the each self-corresponding service end configuration file of described each monitoring client.It should be noted that, described monitoring client and described monitor server 205 use HTTP and tcp/ip communication agreement, so that described monitoring client is widely used under various operating system environment, improve the application of each embodiment in the application.
On the basis of the Organization Chart showing at described Fig. 2, refer to Fig. 3, it shows the flow chart of a kind of daily record monitoring method embodiment bis-that the application provides, and this enforcement can comprise:
Step 301: in the time receiving daily record Monitoring instruction, control described multiple monitoring client and determine target website server according to corresponding client configuration file, trigger described monitoring client and send the log recording that described target website server generates, and receive described log recording.
Wherein, described control procedure can be, in the time that described monitor server receives daily record Monitoring instruction, described monitor server sends control information to described monitoring client, in the time that described monitoring client arrives described control information, determine target website server according to corresponding client configuration file.Concrete, in described Website server, store client configuration file, in described client configuration file, include the right configuration information of monitoring client, as whether sent log recording, send in which way log recording etc.Described monitoring client determines whether to send according to the configuration information in described client configuration file the log recording that the Website server corresponding with this monitoring client generates.If so, this Website server is defined as to target website server.It should be noted that, described target website server can be one, can be also multiple, and concrete quantity is to determine according to the configuration information in described each client configuration file.
In addition, the log recording that described monitoring client generates described target website server according to trigger command sends to described monitor server, and described monitor server receives described log recording.In addition, can also control described monitoring client the log recording of generation is kept in Website server simultaneously, carry out the inquiry of history log data for related personnel.
Step 302: whether the item number that judges respectively the log recording of described every each self-generating of Website server meets preset alarm threshold value; If so, perform step 303.
Step 303: generate the warning message corresponding with this Website server.
Wherein, step 302 and 303 identical with step 102 in embodiment of the method one and 103, is not repeated herein.
Embodiment of the method three:
On the basis of the Organization Chart showing at described Fig. 2, refer to Fig. 4, it shows the flow chart of a kind of daily record monitoring method embodiment tri-that the application provides, and this enforcement can comprise:
Step 401: in the time receiving daily record Monitoring instruction, control described multiple monitoring client and determine target journaling record according to corresponding client configuration file, trigger described monitoring client and send the target journaling record that described Website server generates, and receive described target journaling record.
Wherein, on described Website server, store client configuration file, configuration information in described client configuration file can include the log recording that sends which kind of type, described monitoring client can be determined the type that sends log recording according to described configuration information, described definite log record types is defined as to target journaling record.In the time receiving trigger command, described monitoring client can send target journaling record to described monitor server, and described monitor server receives described log recording.
Step 402: whether the item number that judges respectively the log recording of described every each self-generating of Website server meets preset alarm threshold value; If so, perform step 403.
Step 403: generate the warning message corresponding with this Website server.
Wherein, step 402 and 403 identical with step 102 in embodiment of the method one and 103, is not repeated herein.
Certainly, in described client configuration file, can include and whether send log recording, send the information such as the log recording of which kind of type, the step 101 in embodiment of the method one can be by the step 201 in two and the step 301 in embodiment tri-realize in conjunction with the embodiments, in the time receiving daily record Monitoring instruction, control described monitoring client and determine target website server and target journaling record according to corresponding client configuration file, trigger described monitoring client and send the target journaling record that described target website server generates, and receive described target journaling record.
Embodiment of the method four:
On the framework basis shown in Fig. 2, refer to Fig. 5, it shows the part flow chart of a kind of daily record monitoring method embodiment tetra-that the application provides, and the step 101 of said method embodiment mono-can realize by following steps:
Step 501: judge that whether the communication connection between described monitoring client and described monitor server is abnormal; If so, perform step 502; If not, execution step 503.
Wherein, in the time that the communication connection between described monitoring client and described monitor server is abnormal, can cause described log recording can not be sent to described monitor server, need to judge that whether described communication connection is normal.
Step 502: control described monitoring client the log recording of described Website server generation is put into default message queue; In the time that described communication connection is normal, controls described monitoring client and send the log recording in described message queue.
Wherein, include all log recordings that successfully do not sent in described message queue, and described log recording has sequencing, the time that generates described log recording by described Website server arranges.In the time that described communication connection is normal, triggers described monitoring client and in chronological sequence sequentially the log recording in described message queue is sent to described monitor server.
Step 503: control described monitoring client and send the log recording that described Website server generates.
In the time that the communication connection between monitoring client and described monitor server is abnormal, can be realized the caching function of the log recording that Website server is generated by above technical scheme, thereby can ensure the fail safe of described log recording, and then monitoring accuracy is provided.
On the framework basis shown in Fig. 2, in the time that monitoring personnel need to modify to configuration information, only need upgrade the service end configuration file on described monitor server., on the basis of above-mentioned each embodiment of the method, can also comprise:
In the time monitoring described service end configuration file and upgrade, the service end configuration file after described renewal is sent to corresponding monitoring client, taking trigger described monitoring client by described client configuration file update the service end configuration file after described renewal.
Wherein, described in monitor the mode that described service end configuration file upgrades, can be to generate and upgrade instruction according to monitoring personnel's renewal operation, by monitor server described in described renewal instruction triggers; Can also be to preserve once described service end configuration file every Preset Time section, and by the current service end configuration file of preservation and the last comparing, in the time there are differences, can determine that described service end configuration file upgrades.
The service end configuration file after described renewal is sent to corresponding monitoring client by described monitor server.Wherein, can be only to send the part of upgrading, can be also the whole service end configuration files that send after upgrading.Triggering described monitoring client is the service end configuration file after described renewal by described client configuration file update, thereby realizes the renewal to the client configuration file of storing in Website server.
In the time that described Website server quantity is more, the configuration file of revising in described each Website server need to expend the more time of related personnel, and because quantity is more, the renewal of configuration file is slower, and then the monitoring that causes Website server not in time, finally causes Website server to occur serious access exception problem.The technical scheme being provided from the present embodiment, in described monitor server, store and the each self-corresponding service end configuration file of each monitoring client, only need upgrade each service end configuration file on described monitor server, the service end configuration file after upgrading is sent to described Website server by described monitor server, trigger described monitoring client configuration file is upgraded, improved monitoring efficiency and monitoring promptness.
In addition, the present embodiment does not limit the execution sequence of this step, can be to carry out before or after the arbitrary steps in each said method embodiment.
Embodiment of the method five:
Log recording need to be stored in database, in the time that the quantity of log recording is larger, described log recording effectively need to be stored.Refer to Fig. 6, the part flow chart that it shows a kind of daily record monitoring method embodiment five that the application provides, after the step 101 of embodiment of the method one, can also comprise:
Step 601: according to default burst rule, described log recording is carried out to burst.
Wherein, described burst is by the process of log recording Data Division, or can be referred to as subregion.Described default burst rule can be time allocation rule, by the rise time of log recording, each log recording is carried out to burst, can be maybe Website server mark rule, by different web sites server identification, each log recording is carried out to burst.Log recording data after burst and the corresponding relation of described are stored in burst configuration file.
Concrete, be fritter by the cutting of log recording data acquisition system, these fritters are formed to multiple bursts, the each part only comprising in log recording data acquisition system.
Step 602: the log recording after described burst is stored in many database servers.
Wherein, the log recording after described burst is stored in many database servers and can realizes load distribution.Refer to Fig. 2, the log recording after burst can disperse to be stored in each database server 206 to 208.
Step 603: in the time receiving log access instruction, generate routing daemon.
Wherein, in the time that application program need to conduct interviews to the log recording of storage, trigger and generate log access instruction, in the time receiving described log access instruction, generate routing daemon.Thereby the concrete memory location that described application program needn't log records concrete burst information and described fragment data, is connected with described routing daemon, only access request need be sent to described routing daemon.
Step 604: trigger described routing daemon and obtain the log recording corresponding with described log access instruction in described many database servers.
Wherein, described routing daemon can be according to the information in described burst configuration file, accurately determine the concrete memory location after the log recording burst corresponding with described access request, and obtain, and the log recording data after obtaining are returned to described application program.
From above technical scheme, described log recording data are disperseed to be stored in many database servers, thereby do not need powerful large database server just can realize the storage of a large amount of daily record datas.
Device embodiment mono-:
Refer to Fig. 7, it shows the structural representation of a kind of daily record monitoring device embodiment mono-that the application provides, this application of installation is in monitor server, described monitor server is connected with many Website servers, and this device comprises: acquisition module 701, judge module 702, alarm module 703 and sending module 704.Wherein:
Described acquisition module 701, in the time receiving daily record Monitoring instruction, obtains the log recording that at least one Website server generates.
Wherein, described daily record Monitoring instruction, for triggering the execution of the present embodiment,, in the time receiving described daily record Monitoring instruction, starts to carry out the operation of obtaining log recording in this step.Described daily record Monitoring instruction can be according to extraneous manual operation triggering for generating, and when Website server monitoring as needs, people is for carrying out clicking operation, thereby generates described daily record Monitoring instruction.
Concrete, described acquisition module 701 acquisition processs, can be to receive the log recording that described Website server sends voluntarily, can be also to send control command to described Website server, to trigger described Website server, the log recording of generation is sent to described monitor server.
In addition, the present embodiment does not limit the particular type of described Website server, as long as generating to abnormal conditions the Website server of log recording.
Whether described judge module 702, meet preset alarm threshold value for the item number of the log recording that judges respectively described every each self-generating of Website server; If so, trigger alarm module 703.
Wherein, in described log recording, can include the mark of Website server, generate the Website server of log recording in order to record.Concrete, described judge module 702 deterministic processes are, add up the item number of the log recording of described every each self-generating of Website server, generated the log recording of how many, and described each quantitative value and default threshold value of warning are compared.When the quantitative value of the log recording generating when certain Website server meets preset alarm threshold value, trigger alarm module 703.
It should be noted that, described preset alarm threshold value, can be same numerical value, and the quantitative value of the log recording that described each Website server generates is all compared with same preset alarm threshold value; Also can be different numerical value, be each Website server different alarm threshold values is set.In addition, further say, for same Website server, described preset alarm threshold value can be also different numerical value, be that same Website server can send dissimilar log recording, described preset alarm threshold value can be corresponding with the type of log recording, the i.e. each self-corresponding alarm threshold value of log recording of default every type, for example, warning predetermined threshold value corresponding to log recording generating in payment process is 10, and submitting preset alarm threshold value corresponding to log recording generating in order process to is 20.
It should be noted that, described acquisition module 701 acquisition processs carry out in real time, it is the log recording that Website server generates described in Real-time Obtaining, described preset alarm threshold value can include time period factor, be that described preset alarm threshold value is the threshold value in Preset Time section, for example, one minute 10, one minute 20.Corresponding, described deterministic process is specially, and judges whether the item number of the log recording in described Preset Time section meets preset alarm threshold value.For example, judge whether the item number that pays log recording in a minute meets 10, judge whether the quantitative value that pays log recording in a minute meets 20.
Described alarm module 703, for generating the warning message corresponding with this Website server.
Concrete, if the quantitative value of the log recording that certain Website server that described judge module 702 judges generates meets preset alarm threshold value, described alarm module 703 generates the warning message corresponding with this Website server.In described log recording, can include the mark of Website server, can set up according to the mark of Website server the corresponding relation of warning message and Website server.
In addition, the form of described warning message can be including but not limited to mail warning message, SMS alarm information, interface warning message.
Described sending module 704, for being sent to warning message receiving terminal by described warning message.
Concrete, according to the concrete form of described warning message, described warning message is sent to warning message receiving terminal, to remind related personnel to process the abnormal conditions of described Website server.Wherein, described warning message receiving terminal can be one or more.For example, one or more in mail reception terminal, short message receiving terminal, interface display terminal.
From above technical scheme, the present embodiment provides a kind of daily record monitoring device, described application of installation is in monitor server, described monitor server is connected with many Website servers, the method is by the time receiving daily record Monitoring instruction, obtain the log recording that at least one Website server generates, and whether the item number that judges respectively the log recording of described every each self-generating of Website server meets preset alarm threshold value, if, generate the warning message corresponding with this Website server, thereby the log recording that utilizes Website server to generate, realize the monitoring to described Website server.
Further, described warning message is corresponding with described Website server, can determine the concrete Website server that produces access exception situation according to described warning message.Use at Website server under the scene of distributed collaboration treatment technology, can position the Website server that occurs abnormal conditions rapidly, effectively improved monitoring efficiency and monitoring accuracy.
Device embodiment bis-:
On the basis of the Organization Chart showing at described Fig. 2, refer to Fig. 8, it shows the structural representation of a kind of daily record monitoring device embodiment bis-that the application provides, and this enforcement can comprise: first obtains submodule 7011, second obtains submodule 7012, the 3rd and obtain submodule 7013, judge module 702, alarm module 703, sending module 704 and update module 705.Wherein:
Described first obtains submodule 7011, for in the time receiving daily record Monitoring instruction, control described multiple monitoring client and determine target website server according to corresponding client configuration file, trigger described monitoring client and send the log recording that described target website server generates, and receive described log recording.
Wherein, described first obtains submodule 7011 control procedures can be, in the time that described monitor server receives daily record Monitoring instruction, described monitor server sends control information to described monitoring client, in the time that described monitoring client arrives described control information, determine target website server according to corresponding client configuration file.Concrete, in described Website server, store client configuration file, in described client configuration file, include the right configuration information of monitoring client, as whether sent log recording, send in which way log recording etc.Described monitoring client determines whether to send according to the configuration information in described client configuration file the log recording that the Website server corresponding with this monitoring client generates.If so, this Website server is defined as to target website server.It should be noted that, described target website server can be one, can be also multiple, and concrete quantity is to determine according to the configuration information in described each client configuration file.
In addition, the log recording that described monitoring client generates described target website server according to trigger command sends to described monitor server, and described first obtains submodule 7011 receives described log recording.In addition, described first obtains submodule 7011 can also control described monitoring client the log recording of generation is kept in Website server simultaneously, carries out the inquiry of history log data for related personnel.
Described second obtains submodule 7012, for in the time receiving daily record Monitoring instruction, control described multiple monitoring client and determine target journaling record according to corresponding client configuration file, trigger described monitoring client and send the target journaling record that described Website server generates, and receive described target journaling record.
Wherein, on described Website server, store client configuration file, configuration information in described client configuration file can include the log recording that sends which kind of type, described monitoring client can be determined the type that sends log recording according to described configuration information, described definite log record types is defined as to target journaling record.In the time receiving trigger command, described monitoring client can send target journaling record to described monitor server, and described second obtains submodule 7012 receives described log recording.
Whether the described the 3rd obtains submodule 7013, abnormal for judging the communication connection between described monitoring client and described monitor server; If so, control described monitoring client the log recording of described Website server generation is put into default message queue; In the time that described communication connection is normal, controls described monitoring client and send the log recording in described message queue; If not, control described monitoring client and send the log recording that described Website server generates.
Wherein, in the time that the communication connection between described monitoring client and described monitor server is abnormal, can cause described log recording can not be sent to described monitor server, need to judge that whether described communication connection is normal.
Wherein, include all log recordings that successfully do not sent in described message queue, and described log recording has sequencing, the time that generates described log recording by described Website server arranges.In the time that described communication connection is normal, the described the 3rd obtain submodule 7013 trigger described monitoring client in chronological sequence order the log recording in described message queue is sent to described monitor server.
In the time that the communication connection between monitoring client and described monitor server is abnormal, the technical scheme being provided by the present embodiment can realize the caching function of the log recording that Website server is generated, thereby can ensure the fail safe of described log recording, and then monitoring accuracy is provided.
Whether described judge module 702, meet preset alarm threshold value for the item number of the log recording that judges respectively described every each self-generating of Website server; If so, trigger alarm module 703.
Described alarm module 703, for generating the warning message corresponding with this Website server.
Described sending module 704, for being sent to warning message receiving terminal by described warning message.
Wherein, the module 702 to 704 in the present embodiment is identical with module 702 to 704 in device embodiment mono-, and therefore not to repeat here.
Described update module 705, for in the time monitoring described service end configuration file renewal, service end configuration file after described renewal is sent to corresponding monitoring client, taking trigger described monitoring client by described client configuration file update the service end configuration file after described renewal.
Wherein, described update module 705 monitors the mode that described service end configuration file upgrades, and can be to generate and upgrade instruction according to monitoring personnel's renewal operation, by monitor server described in described renewal instruction triggers; Can also be to preserve once described service end configuration file every Preset Time section, and by the current service end configuration file of preservation and the last comparing, in the time there are differences, can determine that described service end configuration file upgrades.
The service end configuration file after described renewal is sent to corresponding monitoring client by described update module 705.Wherein, can be only to send the part of upgrading, can be also the whole service end configuration files that send after upgrading.It is the service end configuration file after described renewal by described client configuration file update that described update module 705 triggers described monitoring client, thereby realizes the renewal to the client configuration file of storing in Website server.
In the time that described Website server quantity is more, the configuration file of revising in described each Website server need to expend the more time of related personnel, and because quantity is more, the renewal of configuration file is slower, and then the monitoring that causes Website server not in time, finally causes Website server to occur serious access exception problem.The technical scheme being provided from the present embodiment, in described monitor server, store and the each self-corresponding service end configuration file of each monitoring client, only need upgrade each service end configuration file on described monitor server, the service end configuration file after upgrading is sent to described Website server by described monitor server, trigger described monitoring client configuration file is upgraded, improved monitoring efficiency and monitoring promptness.
Device embodiment tri-:
Log recording need to be stored in database, in the time that the quantity of log recording is larger, described log recording effectively need to be stored.Refer to Fig. 9, it shows the part-structure schematic diagram of a kind of daily record monitoring device embodiment tri-that the application provides, on the basis of device embodiment mono-, the present embodiment can also comprise: burst module 801, memory module 802, process module 803 and trigger module 804.Wherein:
Described burst module 801, after obtaining the log recording of at least one Website server generation, according to default burst rule, carries out burst by described log recording.
Wherein, described burst module 801 bursts are by the process of log recording Data Division, or can be referred to as subregion.Described default burst rule can be time allocation rule, by the rise time of log recording, each log recording is carried out to burst, can be maybe Website server mark rule, by different web sites server identification, each log recording is carried out to burst.Log recording data after burst and the corresponding relation of described are stored in burst configuration file.
Concrete, described burst module 801 is fritter by the cutting of log recording data acquisition system, and these fritters are formed to multiple bursts, the each part only comprising in log recording data acquisition system.
Described memory module 802, for being stored in many database servers by the log recording after described burst.
Wherein, described memory module 802 is stored in the log recording after described burst in many database servers and can realizes load distribution.
Described process module 803, in the time receiving log access instruction, generates routing daemon.
Wherein, in the time that application program need to conduct interviews to the log recording of storage, trigger and generate log access instruction, in the time that described process module 803 receives described log access instruction, generate routing daemon.Thereby the concrete memory location that described application program needn't log records concrete burst information and described fragment data, is connected with described routing daemon, only access request need be sent to described routing daemon.
Described trigger module 804, obtains the log recording corresponding with described log access instruction for triggering described routing daemon at described many database servers.
Wherein, described routing daemon can be according to the information in described burst configuration file, accurately determine the concrete memory location after the log recording burst corresponding with described access request, and obtain, and the log recording data after obtaining are returned to described application program.
From above technical scheme, described log recording data are disperseed to be stored in many database servers, thereby do not need powerful large database server just can realize the storage of a large amount of daily record datas.
It should be noted that, each embodiment in this specification all adopts the mode of going forward one by one to describe, and what each embodiment stressed is and the difference of other embodiment, between each embodiment identical similar part mutually referring to.
To the above-mentioned explanation of the disclosed embodiments, make professional and technical personnel in the field can realize or use the present invention.To be apparent for those skilled in the art to the multiple amendment of these embodiment, General Principle as defined herein can, in the situation that not departing from the spirit or scope of the present invention, realize in other embodiments.Therefore, the present invention will can not be restricted to these embodiment shown in this article, but will meet the widest scope consistent with principle disclosed herein and features of novelty.

Claims (10)

1. a daily record monitoring method, is characterized in that, is applied to monitor server, and described monitor server is connected with many Website servers, and the method comprises:
Steps A: in the time receiving daily record Monitoring instruction, obtain the log recording that at least one Website server generates;
Step B: whether the item number that judges respectively the log recording of described every each self-generating of Website server meets preset alarm threshold value, if so, performs step C;
Step C: generate the warning message corresponding with this Website server.
2. method according to claim 1, is characterized in that, after step C, also comprises:
Described warning message is sent to warning message receiving terminal.
3. method according to claim 1, is characterized in that, is provided with monitoring client on described Website server, and described Website server stores the client configuration file corresponding with described monitoring client; On described monitor server, store and the each self-corresponding service end configuration file of described each monitoring client.
4. method according to claim 3, is characterized in that, described steps A comprises:
Control described multiple monitoring client and determine target website server according to corresponding client configuration file, trigger described monitoring client and send the log recording that described target website server generates, and receive described log recording;
And/or, control described multiple monitoring client and determine target journaling record according to corresponding client configuration file, trigger described monitoring client and send the target journaling record that described Website server generates, and receive described target journaling record.
5. method according to claim 3, is characterized in that, described steps A comprises:
Judge that whether the communication connection between described monitoring client and described monitor server is abnormal;
If so, control described monitoring client the log recording of described Website server generation is put into default message queue; In the time that described communication connection is normal, controls described monitoring client and send the log recording in described message queue;
If not, control described monitoring client and send the log recording that described Website server generates.
6. method according to claim 3, is characterized in that, also comprises:
In the time monitoring described service end configuration file and upgrade, the service end configuration file after described renewal is sent to corresponding monitoring client, taking trigger described monitoring client by described client configuration file update the service end configuration file after described renewal.
7. method according to claim 1, is characterized in that, after steps A, also comprises:
According to default burst rule, described log recording is carried out to burst;
Log recording after described burst is stored in many database servers;
In the time receiving log access instruction, generate routing daemon;
Trigger described routing daemon and in described many database servers, obtain the log recording corresponding with described log access instruction.
8. a daily record monitoring device, is characterized in that, is applied to monitor server, and described monitor server is connected with many Website servers, and this device comprises:
Acquisition module: in the time receiving daily record Monitoring instruction, obtain the log recording that at least one Website server generates;
Judge module: whether the item number for the log recording that judges respectively described every each self-generating of Website server meets preset alarm threshold value; If so, trigger alarm module;
Alarm module: for generating the warning message corresponding with this Website server;
Sending module, for being sent to warning message receiving terminal by described warning message.
9. device according to claim 8, is characterized in that, is provided with monitoring client on described Website server, and described Website server stores the client configuration file corresponding with described monitoring client; On described monitor server, store and the each self-corresponding service end configuration file of described each monitoring client; This device also comprises:
Update module, for in the time monitoring described service end configuration file renewal, service end configuration file after described renewal is sent to corresponding monitoring client, taking trigger described monitoring client by described client configuration file update the service end configuration file after described renewal;
Wherein: described acquisition module comprises:
First obtains submodule, determines target website server for controlling described multiple monitoring client according to corresponding client configuration file, triggers described monitoring client and sends the log recording that described target website server generates, and receive described log recording;
Second obtains submodule, determine target journaling record for controlling described multiple monitoring client according to corresponding client configuration file, trigger described monitoring client and send the target journaling record that described Website server generates, and receive described target journaling record;
Whether the 3rd obtains submodule, abnormal for judging the communication connection between described monitoring client and described monitor server; If so, control described monitoring client the log recording of described Website server generation is put into default message queue; In the time that described communication connection is normal, controls described monitoring client and send the log recording in described message queue; If not, control described monitoring client and send the log recording that described Website server generates.
10. device according to claim 8, is characterized in that, also comprises:
Burst module, for according to default burst rule, carries out burst by described log recording;
Memory module, for being stored in many database servers by the log recording after described burst;
Process module, in the time receiving log access instruction, generates routing daemon;
Trigger module, obtains the log recording corresponding with described log access instruction for triggering described routing daemon at described many database servers.
CN201410161849.7A 2014-04-22 2014-04-22 Log monitoring method and device Pending CN103957133A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410161849.7A CN103957133A (en) 2014-04-22 2014-04-22 Log monitoring method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410161849.7A CN103957133A (en) 2014-04-22 2014-04-22 Log monitoring method and device

Publications (1)

Publication Number Publication Date
CN103957133A true CN103957133A (en) 2014-07-30

Family

ID=51334363

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410161849.7A Pending CN103957133A (en) 2014-04-22 2014-04-22 Log monitoring method and device

Country Status (1)

Country Link
CN (1) CN103957133A (en)

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104202201A (en) * 2014-09-16 2014-12-10 广州金山网络科技有限公司 Log processing method and device and terminal
CN104281684A (en) * 2014-09-30 2015-01-14 东软集团股份有限公司 Method and system for storing and querying mass logs
CN104298586A (en) * 2014-10-15 2015-01-21 青岛海尔软件有限公司 Web system exception analytical method and device based on system log
CN104363113A (en) * 2014-10-29 2015-02-18 中国建设银行股份有限公司 Business continuity detection method
CN104993952A (en) * 2015-06-19 2015-10-21 成都艾尔普科技有限责任公司 Network user behavior audit and responsibility management system
CN105049232A (en) * 2015-06-19 2015-11-11 成都艾尔普科技有限责任公司 Network information log audit system
CN106411563A (en) * 2016-06-30 2017-02-15 北京小米移动软件有限公司 Log recording method and device and router
CN107273263A (en) * 2017-05-26 2017-10-20 努比亚技术有限公司 A kind of analysis method of misoperation, application terminal and monitoring server
CN109560977A (en) * 2017-09-25 2019-04-02 北京国双科技有限公司 Web site traffic monitoring method, device, storage medium, processor and electronic equipment
CN110502581A (en) * 2019-08-27 2019-11-26 中国联合网络通信集团有限公司 Distributed data base system monitoring method and device
CN112764986A (en) * 2021-01-05 2021-05-07 北京汽车研究总院有限公司 Vehicle log obtaining method and device, electronic equipment and vehicle

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101540681A (en) * 2008-10-28 2009-09-23 厦门市美亚柏科资讯科技有限公司 Method and system for monitoring computer network connection statuses
CN102857387A (en) * 2011-06-30 2013-01-02 北京新媒传信科技有限公司 Online website monitoring system and method
CN102981943A (en) * 2012-10-29 2013-03-20 新浪技术(中国)有限公司 Method and system for monitoring application logs
CN103428186A (en) * 2012-05-24 2013-12-04 中国移动通信集团公司 Method and device for detecting phishing website

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101540681A (en) * 2008-10-28 2009-09-23 厦门市美亚柏科资讯科技有限公司 Method and system for monitoring computer network connection statuses
CN102857387A (en) * 2011-06-30 2013-01-02 北京新媒传信科技有限公司 Online website monitoring system and method
CN103428186A (en) * 2012-05-24 2013-12-04 中国移动通信集团公司 Method and device for detecting phishing website
CN102981943A (en) * 2012-10-29 2013-03-20 新浪技术(中国)有限公司 Method and system for monitoring application logs

Cited By (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104202201A (en) * 2014-09-16 2014-12-10 广州金山网络科技有限公司 Log processing method and device and terminal
CN104202201B (en) * 2014-09-16 2018-01-23 广州金山网络科技有限公司 A kind of log processing method, device and terminal
CN104281684A (en) * 2014-09-30 2015-01-14 东软集团股份有限公司 Method and system for storing and querying mass logs
CN104281684B (en) * 2014-09-30 2017-08-25 东软集团股份有限公司 Massive logs are stored and querying method and system
CN104298586A (en) * 2014-10-15 2015-01-21 青岛海尔软件有限公司 Web system exception analytical method and device based on system log
CN104363113A (en) * 2014-10-29 2015-02-18 中国建设银行股份有限公司 Business continuity detection method
CN104993952A (en) * 2015-06-19 2015-10-21 成都艾尔普科技有限责任公司 Network user behavior audit and responsibility management system
CN105049232A (en) * 2015-06-19 2015-11-11 成都艾尔普科技有限责任公司 Network information log audit system
CN106411563B (en) * 2016-06-30 2019-11-15 北京小米移动软件有限公司 Log recording method, device and router
CN106411563A (en) * 2016-06-30 2017-02-15 北京小米移动软件有限公司 Log recording method and device and router
CN107273263A (en) * 2017-05-26 2017-10-20 努比亚技术有限公司 A kind of analysis method of misoperation, application terminal and monitoring server
CN107273263B (en) * 2017-05-26 2020-11-17 努比亚技术有限公司 Abnormal operation analysis method, application terminal and monitoring server
CN109560977A (en) * 2017-09-25 2019-04-02 北京国双科技有限公司 Web site traffic monitoring method, device, storage medium, processor and electronic equipment
CN110502581A (en) * 2019-08-27 2019-11-26 中国联合网络通信集团有限公司 Distributed data base system monitoring method and device
CN112764986A (en) * 2021-01-05 2021-05-07 北京汽车研究总院有限公司 Vehicle log obtaining method and device, electronic equipment and vehicle
CN112764986B (en) * 2021-01-05 2024-08-13 北京汽车研究总院有限公司 Vehicle log acquisition method and device, electronic equipment and vehicle

Similar Documents

Publication Publication Date Title
CN103957133A (en) Log monitoring method and device
CN109412870B (en) Alarm monitoring method and platform, server and storage medium
JP2019501551A5 (en) Cloud-based system and method for managing messages related to operation of cable test devices and computing devices
CN108809702B (en) Equipment management method and equipment management platform
CN110674440A (en) Buried point data processing method, system, computer device and readable storage medium
CN105100708A (en) Request processing method and device
CN111654408B (en) Device monitoring method, device, computer device and storage medium
CN110532077B (en) Task processing method and device and storage medium
CN106790131B (en) Parameter modification method and device and distributed platform
CN110990233A (en) Method and system for displaying SOAR by using Gantt chart
CN113472787A (en) Alarm information processing method, device, equipment and storage medium
CN108512869A (en) A kind of method and system handling concurrent data using asynchronization mode
CN114465741A (en) Anomaly detection method and device, computer equipment and storage medium
CN107241385B (en) Internet of things data acquisition system and method
CN110661851A (en) Data exchange method and device
CN107846322A (en) A kind of monitoring system of self-service device
CN108173889A (en) User data processing method and user data processing unit
CN111835583B (en) Attribute inspection method and device for products of Internet of things and computer equipment
CN108023740B (en) Risk prompting method and device for abnormal information in monitoring
CN112883253A (en) Data processing method, device, equipment and readable storage medium
CN117493370A (en) Data acquisition method, apparatus, device, readable storage medium, and program product
CN111124547B (en) Task processing method and device
CN109921920A (en) A kind of failure information processing method and relevant apparatus
CN116911778A (en) Hotel project development management method and system
KR20180065839A (en) Method and apparatus for reporting job performance through analysis of job and job log data

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
ASS Succession or assignment of patent right

Owner name: BEIJING LIANJIA ZHONGYING NETWORK TECHNOLOGY CO.,

Free format text: FORMER OWNER: NETWORK COMMUNICATIONS EQUIPMENT CO., LTD., BEIJING UNISPACE

Effective date: 20141102

C41 Transfer of patent application or patent right or utility model
COR Change of bibliographic data

Free format text: CORRECT: ADDRESS; FROM: 100029 CHAOYANG, BEIJING TO: 100022 CHAOYANG, BEIJING

TA01 Transfer of patent application right

Effective date of registration: 20141102

Address after: 100022 Beijing City, Chaoyang District No. 39 East Third Ring Road, North SOHO office building A Room 302

Applicant after: BEIJING LIANJIA ZHONGYING NETWORK TECHNOLOGY CO., LTD.

Address before: 100029, E, room 705, block 6, North Fourth Ring Road, Chaoyang District, Beijing

Applicant before: Beijing connection time-space network communication facilities company limited

WD01 Invention patent application deemed withdrawn after publication
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20140730