A kind of self-defined daily record resolution rules the Method and kit for of parsing daily record automatically
First, technical field
The analysis parsing of software Development Automation computer network machine intelligence big data and enforcement engine
2nd, background technology
For the purpose simplifying description, herein will be using some special concepts.When present disclosure is related to related notion, involved
And the implication of concept refer to and is defined as below:
[defining 1] instrument
Instrument mentioned here refers to self-defined daily record resolution rules and automatically parses the Method and kit for of daily record.
[defining 2] etc.
Etc. be illustrate item, content comprise but be not limited to this invention scope.
[defining 3] canonical magic square
Canonical magic square is the general designation of the regular expression label that instrument is capable of automatic identification, and instrument internal portion is just commonly used
Then expression formula tag library, user passes through visualized graph interface can self-defined expansion canonical magic square storehouse.For using user,
User is added dynamically to canonical magic square label to prepare in rule, without implementing of care regular expression label.
[defining 4] wizard-like is prepared
Wizard-like is prepared and is referred under visualized operation, and the preparation page elements of next step are the preparation institutes according to previous step
Determine.
With the fast development of computer network and communication network, the production of all trades and professions and the number of devices of management system
Also increase sharply, increased maintenance cost to the system operation of every profession and trade, when certain device node breaks down or during hidden danger, past
The substantial amounts of time go to check toward attendant to be expended and carry out orientation problem with the specifying information in the alarm and daily record of analysis system.
At present, attendant is after receiving fault warning information, and attendant typically first passes through webmaster and checks that equipment is accused
The alert situation with various performance indications, rule of thumb investigates suspected fault point step by step, also needs to logging device simultaneously and passes through people
Machine instruction interaction obtains just finding problem points after logged result is further analyzed again.Generally, attendant is in solution
The time that certainly often first will expend more than 70% when potential faults goes orientation problem, and time-consuming link mainly has man-machine friendship
Mutually, log analysis, data analysis, logic judgment etc..During positioning problems, the log analysis ability of technical staff and experience
Decisive role is served to the time control of issue handling.
In order to be able to lift system daily record analytic ability, it is typically necessary the function of increasing some expert systems in system,
Allow expert system can carry out the function that daily record parses automatically, but the exploitation of current expert system generally requires system equipment producer and props up
Hold, and the built-in expert system daily record analytical capabilities of system suffer from equipment manufacturer and develop the restriction of working days it is impossible in time
Meet the personalization of plant maintenance personnel and interim demand.
Also the daily record analytical tool that some non-original equipment manufacturers provide, such as " daily record is easy " etc. are occurred in that at this stage, but daily record
Easy daily record analytic method is mainly realized by regular expression.Regular expression is that one kind is retouched using single character string
State, mate a series of rules meeting certain grammer, in a lot of text editors, regular expression be usually used to retrieval,
Replace the text that those meet certain pattern.It is intended to through special training using regular expression and have a set threshold, one
As have Basis of Computer Engineering people learn to get up to be easier, but for Non-computer Majors people use just relatively difficult,
If the plant maintenance personnel wanting all trades and professions will learn regular expression and could parse daily record, thus being used for subsequent operation,
So not only workload is big but also more difficult popularization.
In order to allow plant maintenance personnel more easily analyzing device daily record, and it is applied to expert system (outside system
System) intelligent operation in, it is a kind of simple to operate, visual, sharp that we are that plant maintenance personnel and equipment manufacturer provide
In think tank's construction, wizard-like mode of operation, and being capable of self-defined daily record resolution rules the method that automatically parses daily record
And instrument.The internal external system of this instrument provides multiple access interfaces, can be independently developed specially as plant maintenance personnel
Family system assembly it is also possible to as equipment genuine man provide expert system in assembly.
This instrument be applicable not only in real time with quasi real time daily record, apply also for each class text (for example: txt, xls, xlsx,
Log file, relation and non-relational database storage etc.), structuring and unstructured data.
[content of the invention]
The self-defined daily record resolution rules of energy the Method and kit for of parsing daily record automatically, the purpose of its invention is, can be
User provide a kind of simple to operate, visual, be beneficial to think tank's construction, wizard-like mode of operation, and can make by oneself
Adopted daily record resolution rules the Method and kit for of parsing daily record automatically, thus improve the efficiency of daily record parsing.
The chief component of this instrument has: think tank's management module, rule prepare module, condition custom block, canonical
Magic square module, rule parsing engine, regular enforcement engine etc..
1st, think tank's management module
Based on big data analytical calculation, instrument, according to user's history service condition, is automatically advised use than more frequently
Then masterplate and canonical magic square are marked, and the professional knowledge that carries out of intelligence with the shared of experience and reduces repeated construction.
2nd, rule prepares module
Based on the rule preparation of wizard-like, carry out journal formatting configuration by step guiding user and join with daily record resolution rules
Put.During preparing, user can carry out to sample data parsing preview, reduces error, improve operating efficiency and (facilitate user
In real time preparation rule is verified).
3rd, condition custom block
Instrument automatically according to regular masterplate, dynamic load alternative Rule of judgment list.User can be in alternative conditions list
Condition freely combined judgement, with reach parsing logged result purpose.
4th, canonical magic square module
Canonical tag library in canonical magic square, is to have carried out encapsulation and labeling to conventional regular expression, and realizes
Unified management.Canonical magic square is built-in partly to commonly use canonical label, and supports User Defined canonical label.Canonical magic square can spirit
Work is applied to the scene of any text resolution.
5th, rule parsing engine
Automatically the rule template configuring in the 2nd point of parsing, rule template is converted into the execution code of backstage parsing, and will
The regular enforcement engine that code is transmitted at the 6th point goes to execute.
6th, regular enforcement engine
The daily record parsing execution code being generated based on the 5th step, is carried out daily record parsing, and returns analysis result.
[brief description]
Fig. 1 is rule base preparation process schematic diagram:
Fig. 2 is self-defined log-structured and automatically parses the functional frame composition of logging tools:
[specific embodiment]
Below by example in detail specific embodiment, the most frequently used preparation resolution rules are selected to illustrate.
Involved example is only used for parsing the present invention, is not intended to limit the scope of the present invention.The scope of application of the present invention include but not
It is limited to the scope involved by example.
Instantiation mode is related to the process for preparation of 2 scenes: " judgement of bivariate table result " and " coupling keyword judges ".
[preparation process a] self-defined syslog structure-bivariate table result judges
Step 1:
User's newly-built rule masterplate on instrument, enters resolution rules template configuration guide interface.
Step 2:
Preparing resolution rules interface, (acquiescence is not selected, and does not select representative to be not required to format day to select " judgement of bivariate table result "
Will result.)
Step 3:
Prepare interface formatting bivariate table, prepare the rule formatting bivariate table, prepare which row item specifically includes that from
Start parsing, altogether how many row, Column Cata Format, whether to sort result, whether enable senior preparation, effect preview etc..
Step 4:
In judgment rule selection interface, system, according to the selection result of step 2, automatically selects " judging bivariate table result " and makees
For judgment rule.
Step 5:
Preparing bivariate table result interface, preparing the judgment rule of bivariate table result, main item of preparing is being: variable preparation,
Output preparation, analysis result preview etc. when DP is prepared, condition meets.
Step 6:
Preserve warehouse-in and complete the rule masterplate configuration of bivariate table result.
[preparation process b] self-defined syslog structure-coupling keyword judges
Step 1:
User's newly-built rule masterplate on instrument, enters resolution rules template configuration guide interface.
Step 2:
Preparing resolution rules interface, preparing journal formatting rule, do not choose and (give tacit consent to and do not select, do not select representative to be not required to lattice
Formula logged result.)
Step 3:
In judgment rule selection interface, select " coupling keyword judges ".
Step 4:
Judge interface in coupling keyword, prepare coupling keyword judgment rule, main item of preparing is: keyword, sample
Output preparation etc. when data, matching result, condition meet.
Step 5:
Preservation warehouse-in completes coupling keyword and judges that masterplate configures.
Said process refers to Fig. 1.