CN107564584A - A kind of log analysis method and system - Google Patents

A kind of log analysis method and system Download PDF

Info

Publication number
CN107564584A
CN107564584A CN201710857751.9A CN201710857751A CN107564584A CN 107564584 A CN107564584 A CN 107564584A CN 201710857751 A CN201710857751 A CN 201710857751A CN 107564584 A CN107564584 A CN 107564584A
Authority
CN
China
Prior art keywords
conclusion
analysis
information
phenomenon
phenomenon information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201710857751.9A
Other languages
Chinese (zh)
Inventor
乔茹虹
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shanghai United Imaging Healthcare Co Ltd
Original Assignee
Shanghai United Imaging Healthcare Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shanghai United Imaging Healthcare Co Ltd filed Critical Shanghai United Imaging Healthcare Co Ltd
Priority to CN201710857751.9A priority Critical patent/CN107564584A/en
Publication of CN107564584A publication Critical patent/CN107564584A/en
Pending legal-status Critical Current

Links

Abstract

The invention discloses a kind of log analysis method and system.Methods described includes:The journal file of measurement equipment to be checked is obtained, event information and data characteristic information are included in the journal file;Event information and corresponding data characteristic information in the journal file, collect the phenomenon information in the journal file, and the phenomenon information is the combination that event information and corresponding data characteristic information are formed;And the analysis phenomenon information, and conclusion corresponding to determination.The cumbersome of a large amount of system journals of analysis is avoided using the log analysis method of automation, analysis difficulty is reduced, improves analysis efficiency, shortens analysis time.

Description

A kind of log analysis method and system
Technical field
The present invention relates to areas of information technology, more particularly to a kind of log analysis method and system.
Background technology
With the development of modern medicine, (X is penetrated for the more and more inspections for relying on medical image of diagnosis and treatment work of medical institutions Line, CT, MR, ultrasound, endoscope, angiogram etc.), computer and the communication technology develop into digitized image and transmission is established Basis.PACK can use multiple work stations (image department work station, Clinical workstations etc.), and multiple services Device realizes its function.The complexity of PACK structure is had some idea of, once wherein a certain system breaks down, it is overhauled Need to expend substantial amounts of manpower and time.
Because user is when using PACK, system can produce corresponding journal file with recording user operation row For journal file can be used for the running situation for reflecting system, therefore technical staff can be detected by analysis system daily record The failure that PACK occurs.In existing log analysis technology, the service that generally requires there are rich experiences or grind The engineer working condition of each controlling unit in traceability system, analysis in substantial amounts of daily record is sent out to have reported between error event Logical relation etc., to complete fault location.However, when an error occurs, the mistake that the phenomenon or system that user sees initially are quoted It may not be by mistake basic reason, and multiple mistakes while the possibility reported be present.System typically uses multilayer or multimode The reason for control, controlling link also considerably complicated, additionally resulting in a failure generally has many factors, and these can all give technology Personnel bring puzzlement in maintenance process.
The content of the invention
Relied on for prior art in PACK log analysis special messenger's experience, take considerable time with energy with And easily there is the problem of analysis is omitted, it is an object of the invention to provide a kind of automated analysis method based on system journal And system, during fault location, performance test, researching and developing debugging etc., reduce analysis difficulty, improve analysis efficiency, shortening point Analyse the time.
To achieve the above object of the invention, technical scheme provided by the invention is as follows:
On the one hand, the embodiments of the invention provide a kind of log analysis method, methods described to include:
The journal file of measurement equipment to be checked is obtained, event information and data characteristic information are included in the journal file;
Event information and corresponding data characteristic information in the journal file, are collected in the journal file Phenomenon information, the phenomenon information are the combinations that event information and corresponding data characteristic information are formed;And
Analyze the phenomenon information, and conclusion corresponding to determination.
In the present invention, the phenomenon information collected in the journal file includes collecting records in the journal file Event and extract the data characteristic information of the event.
In the present invention, the method for the analysis phenomenon information includes:According to the phenomenon information being collected into, look into Conclusion storehouse is ask, there is phenomenon information and the corresponding relation of conclusion in the conclusion storehouse;If exist in the conclusion storehouse described existing Conclusion corresponding to image information, then obtain the conclusion;If knot corresponding with the phenomenon information is not present in the conclusion storehouse By then phenomenon information described in manual analysis.
In the present invention, the conclusion that methods described also includes obtaining manual analysis is updated to the conclusion storehouse.
In the present invention, the method for the analysis phenomenon information includes:According to the phenomenon information being collected into, look into Conclusion storehouse is ask, there is phenomenon information and the corresponding relation of conclusion in the conclusion storehouse;If exist in the conclusion storehouse described existing Conclusion corresponding to image information, then obtain the conclusion;If conclusion corresponding to the phenomenon information is not present in the conclusion storehouse, Then query analysis map, the analytical map record analysis path corresponding to different phenomenon informations;If exist in analytical map Analysis path corresponding to the phenomenon information, then analyze the phenomenon information using the analysis path;If in analytical map In the absence of analysis path corresponding to the phenomenon information, then phenomenon information described in manual analysis.
In the present invention, methods described also includes:The analysis path of the manual analysis is added into analytical map, makes analysis The conclusion that map is updated and/or obtains the manual analysis is updated to the conclusion storehouse.
In the present invention, the analysis path is the operation performed successively during log analysis.
In the present invention, the method for the analysis phenomenon information includes:According to the phenomenon information being collected into, look into Analytical map is ask, the analytical map records analysis path corresponding to different phenomenon informations;If exist in analytical map described Analysis path corresponding to phenomenon information, then analyze the phenomenon information using the analysis path;If do not deposited in analytical map In analysis path corresponding to the phenomenon information, then phenomenon information described in manual analysis.
In the present invention, the conclusion includes fault location result, the performance test results and/or research and development debugging result.
On the other hand, the embodiments of the invention provide a kind of Log Analysis System, the system to collect including phenomenon information Unit, phenomenon information analytic unit and conclusion determining unit;The phenomenon information collector unit is used in collector journal file Phenomenon information, the phenomenon information are the combinations that event information and corresponding data characteristic information are formed;The phenomenon information point Analysis unit is used to analyze the phenomenon information in the journal file, to obtain analysis result;And the conclusion determining unit is used The conclusion corresponding to determine the phenomenon information according to the analysis result.
In the present invention, the phenomenon information analytic unit is used for:According to the phenomenon information being collected into, conclusion is inquired about Storehouse, there is phenomenon information and the corresponding relation of conclusion in the conclusion storehouse;And if in the conclusion storehouse exist with it is described existing Conclusion corresponding to image information, then obtain the conclusion.
In the present invention, the phenomenon information analytic unit is used for:According to the phenomenon information being collected into, conclusion is inquired about Storehouse, there is phenomenon information and the corresponding relation of conclusion in the conclusion storehouse;If the phenomenon information be present in the conclusion storehouse Corresponding conclusion, then obtain the conclusion;If conclusion corresponding to the phenomenon information is not present in the conclusion storehouse, inquire about Analytical map, the analytical map record analysis path corresponding to different phenomenon informations;If institute in the analytical map be present Analysis path corresponding to phenomenon information is stated, then analyzes the phenomenon information using the analysis path, and obtain the conclusion.
Compared with prior art, beneficial effects of the present invention performance is as follows:
First, for the logic complexity, dependence special messenger experience, consuming time of PACK log analysis, easily occur The problem of omitting analysis, using the log analysis method of automation, during fault location, performance test, research and development debugging etc., Analysis difficulty is reduced, analysis efficiency is improved, shortens analysis time.
2nd, the conclusion storehouse on daily record phenomenon information is created, is easy to service or researches and develops engineer and consult historical phenomenon letter Conclusion corresponding to breath, it is possible to achieve the quick analysis to phenomenon information.
3rd, the concept of analytical map is introduced, is easy to service or researches and develops engineer and analyze the event that makes a mistake or event comprehensively The basic reason of barrier.
Brief description of the drawings
Fig. 1 is the structural representation of the log analysis platform of the present invention;
Fig. 2 is one embodiment flow chart in the renewal conclusion storehouse of the present invention;
Fig. 3 is one embodiment flow chart of the replacement analysis map of the present invention;
Fig. 4 is a flow example figure of the log analysis method of the present invention;
Fig. 5 is one embodiment flow chart of the log analysis method of the present invention;
Fig. 1 is marked:100 be PACK, and 110 be image documentation equipment, and 120 be server, and 130 be work station, and 140 are Network, 150 be log analysis platform, and 160 be phenomenon information collector unit, and 170 be phenomenon information analytic unit, and 180 be conclusion Determining unit.
Embodiment
It is understandable to enable the above objects, features and advantages of the present invention to become apparent, with reference to the accompanying drawings and examples The embodiment of the present invention is described in detail.
In order to intactly understand the present invention, refer to Fig. 1, represent the present invention in a preferred embodiment thereof be used for medical image The structural representation of the log analysis platform of system.PACK 100 includes but is not limited to image documentation equipment 110, server 120th, work station 130 and network 140.Log analysis platform 150 includes phenomenon information collector unit 160, phenomenon information analysis list Member 170 and conclusion determining unit 180.It should be noted that the present invention only illustrates that log analysis is put down by taking PACK as an example The structure of platform and application, it is not intended that the log analysis platform of the present invention can be only applied to PACK.The present invention's The other systems that log analysis platform can apply to outside PACK, for example, information management system, Distributed Calculation System, Internet of things system etc., especially form or control the more complication system of link.
Image documentation equipment 110 is the medical image acquisition system for obtaining image, and it includes but is not limited at least one number Word imaging device.For example, digitalized image equipment can be calculate X-ray photographic instrument (CR), Digital X-ray Radiotive instrument (DR), Computed tomographic scanner (CT), Positron emission computed tomography instrument (PET), Magnetic resonance imaging scanner (MRI), One or more in digital subtraction angiography scanner (DSA), Prostate specific antigen instrument (ECT), or other Similar imaging device.Image documentation equipment 110 can be communicated by network 140 and server 120, the image number obtained According to being stored in server 120.Image documentation equipment 110 can also be communicated by network 140 and work station 130, be obtained Image data is transferred to work station 130, so that user carries out review and analysis.Alternatively, image documentation equipment 110 can also be with daily record Analysis platform 150 carries out Direct Communication, and log analysis platform 150 can access the journal file of image documentation equipment 110, for inspection Survey and analyze the working condition of image documentation equipment 110.
Server 120 is for storing the management and image storage management system with processing data.Server 120 passes through network 140 Carry out data transmission with image documentation equipment 110, work station 130, log analysis platform 150, can both store image documentation equipment 110 and work Data caused by making station 130, can also store data caused by log analysis platform 150.
Work station 130, is properly termed as image workstation again, is the important component of PACK 100, main negative Duty provides the interface of medical imaging diagnosis process and operation.Work station 130 includes one or more type of work stations, such as image Section reports station 130-1, Clinical workstations 130-2, mobile workstation 130-3, tele-medicine work station 130-4 etc..Work Stand 130 can directly or indirectly be led to by network 140 and image documentation equipment 110, server 120, log analysis platform 150 News.Alternatively, log analysis platform 150 can access the journal file of work station 130, for detecting and analyzing work station 130 working condition.
Log analysis platform 150 can be used for reading and analyze measurement equipment to be checked in PACK 100 or system Journal file, fault location, performance are realized by analyzing event data characteristics corresponding with its of the journal file record Test, and/or research and development debugging etc..In certain embodiments, such as fault location, the log analysis platform 150 can be analyzed The event of log recording data characteristics corresponding with its realizes fault location.In certain embodiments, such as performance is surveyed Examination, the log analysis platform 150 collected obtained phenomenon information can be analyzed using analysis path (for example, with The parameter of normal operating conditions is compared), and then analysis result is obtained, the analysis result can include PACK Whether the service behaviour of one or more of 100 parts is abnormal, so as to realize the performance test of PACK 100. In some embodiments, such as research and development debugging, the log analysis platform 150 can utilize the analysis path to newest daily record File is (for example, the journal file have recorded in tuning parameter, adjustment method, debug time, and/or PACK 100 One or more parts working parameters) analyzed, and then analysis result is obtained, and according to analysis result to medical science Image system 100 is debugged.Alternatively, log analysis platform 150 includes phenomenon information collector unit 160, phenomenon information point Analyse unit 170, conclusion determining unit 180.Log analysis platform 150 can both access to be checked in PACK 100 automatically Journal file in measurement equipment or system (such as image documentation equipment 110, server 120, work station 130), can also pass through user The a certain measurement equipment to be checked of manual loading or the journal file of system are to the analysis platform 150.
Phenomenon information collector unit 160 can be with the phenomenon information recorded in collector journal file.In certain embodiments, Phenomenon information refers to the combination of the event and corresponding data characteristics recorded in daily record.Data characteristics refers to what event was included Correlation attribute information.Data can refer to the feedback data of at least one part, PACK in PACK 100 100 issue data etc..Data characteristics can be with the relation between index evidence and reference data or condition of garbled data etc..Example Such as, when a certain device fails to be detected can not start, system will report this error event of user, while described Journal file in device systems to be detected can record above-mentioned error event and the data characteristics (example corresponding to the error event Such as, mistake application name, error module title, abnormality code, mistake offset, mistake process ID, mistake application program Path etc.).It should be noted that the error event can be the error event relevant with hardware.Herein only with error event Exemplified by illustrate, be not offered as the event recorded in daily record and only include error event.Event recorded in daily record can be with Produced including PACK 100 or relative any event, such as, if print some daily record etc..Phenomenon information Collector unit 160 is by accessing the journal file of measurement equipment to be checked come Collection Events, extraction data characteristics.
Phenomenon information analytic unit 170 can be used for analyzing the phenomenon collected by above-mentioned phenomenon information collector unit 160 Information.In certain embodiments, phenomenon information analytic unit 170 can be according to collected by phenomenon information collector unit 160 Phenomenon information whether there is conclusion corresponding with the phenomenon information to inquire about in conclusion storehouse, phenomenon is have recorded in the conclusion storehouse The corresponding relation of information and conclusion.In certain embodiments, exemplary flow as shown in Figure 2, by servicing or researching and developing engineering Teacher obtains corresponding conclusion after being investigated at the scene to phenomenon, phenomenon information and corresponding conclusion are inputted into conclusion storehouse (see step It is rapid 220) so as to updating conclusion storehouse (see step 230).For example, the conclusion storehouse have recorded history error event phenomenon information and The corresponding relation of fault location result.When error event C, phenomenon information analytic unit 170 occurs in part B in device A to be detected Inquired about according to phenomenon information corresponding to error event C in conclusion storehouse, if it is concluded that having recorded showing for error event C in storehouse Corresponding relation between image information and corresponding fault location result D, then phenomenon information analytic unit 170 is by inquiring about conclusion storehouse Fault location result D can be obtained, service can be reduced in this way or technician positions the time of failure, so as to Quickly and accurately fix a breakdown.If it is concluded that conclusion corresponding with the phenomenon information is not present in storehouse, then this is existing for manual analysis Image information, obtain corresponding conclusion.In certain embodiments, the conclusion that can be obtained manual analysis is updated to the conclusion Storehouse.Such as obtain the fault location result of a certain error event, the phenomenon information corresponding to the error event using manual analysis The conclusion storehouse is updated to corresponding fault location result.It should be noted that this illustrates in event exemplified by sentencing error event The renewal process in conclusion storehouse, is not offered as conclusion storehouse and only updates fault location result in barrier positioning.Similarly, performance test or grind Conclusion storehouse can also be updated with conclusion according to the flow shown in Fig. 2 by sending out caused event in debugging process.
In certain embodiments, when conclusion corresponding to the phenomenon information is not present in above-mentioned conclusion storehouse, phenomenon information Analytic unit 170 can be used for judging whether analytical map.Above-mentioned analytical map is to be collected to form by analysis path, that is, is divided Analysis map records analysis path corresponding to different phenomenon informations.In certain embodiments, analysis path refers in log analysis mistake Performed operation in journey, such as user A is in the morning 10:00 has searched a certain keyword, user A has searched the moment 11:00 institute Event of generation etc..In certain embodiments, the analytical map can be updated by recording manual analysis path.One In a little embodiments, exemplary flow as shown in Figure 3, the phenomenon information analytic unit 170 can obtain system construction drawing with And system architecture and the corresponding relation of daily record are (see step 320), and according to system construction drawing and system architecture and pair of daily record Analytical map described in relation pair is answered to be updated (see step 330).The system construction drawing have recorded system architecture, and the system There is corresponding relation between system structure and daily record, therefore, analytical map can be updated according to system construction drawing.Work as phenomenon When storage unit 170 determines to have the analytical map, the analytical map is inquired about, if existed and institute in analytical map When stating analysis path corresponding to phenomenon information, the phenomenon information can be analyzed using the analysis path, and show analysis result. If including conclusion in analysis result, phenomenon information analytic unit 170 determines conclusion corresponding to the phenomenon information.If point When not including conclusion in analysis result, service or research and development engineer are further analyzed above-mentioned analysis result, while phenomenon information point Analysis unit 170 can record above-mentioned manual analysis path automatically, and by above-mentioned analysis path added to analytical map to update point Analyse map.In certain embodiments, if manual analysis obtains corresponding conclusion, phenomenon information analytic unit 170 can incite somebody to action The new conclusion that manual analysis obtains is updated into conclusion storehouse.In certain embodiments, same phenomenon information also likely to be present more Individual analysis path, then phenomenon information analytic unit 170 analyzes each analysis path one by one, until conclusion corresponding to obtaining or each point Analysis path analysis finishes.
Conclusion determining unit 180 can show conclusion corresponding to the phenomenon information to user.In certain embodiments, institute It can be the positioning to a certain error event or failure to state conclusion.Event or failure B for example, certain device A to be checked makes a mistake, warp Cross phenomenon analysis unit 170 and analyze phenomenon information recorded in the equipment journal file, conclusion determining unit 180 receives existing The analysis result of picture analysis unit 170 shows that the basic reason that the error event or failure B occur is due to user to user In the morning 10:00, which has carried out a faulty operation, causes system failure C occur.In certain embodiments, conclusion determining unit 180 can be based on analysis result, perform judgment rule and analysis result is judged.
Alternatively, if finding still to be not enough to according to after analyzing the phenomenon information by phenomenon analysis unit 170 Phenomenon information obtains corresponding conclusion, and conclusion determining unit 180 can record the possible cause that the phenomenon information occurs, and unite Count the generation scene and/or frequency of the phenomenon information.
Fig. 4 is the example flow diagram of the log analysis method for PACK of the present invention.
In step 410, log analysis platform 150 obtains the journal file of measurement equipment to be checked.Alternatively, log analysis platform 150 can directly or indirectly communicate with measurement equipment to be checked, can read the journal file of the measurement equipment to be checked automatically.It is optional Ground, user can manually load the journal file of the measurement equipment to be checked or system to log analysis platform 150, can read Take the journal file of the measurement equipment to be checked.
In step 420, phenomenon information collector unit 160 collects institute according to the journal file of the measurement equipment to be checked of reading State the phenomenon information of journal file record.
In step 430, phenomenon information analytic unit 170 analyzes showing collected by above-mentioned phenomenon information collector unit 160 Image information.Alternatively, phenomenon information analytic unit 170 can inquire about conclusion storehouse according to above-mentioned phenomenon information, in judgement conclusion storehouse With the presence or absence of conclusion corresponding to above-mentioned phenomenon information, such as exist, then can obtain and above-mentioned phenomenon information by inquiring about conclusion storehouse Corresponding conclusion.Alternatively, if it is concluded that conclusion corresponding to above-mentioned phenomenon information is not present in storehouse, then phenomenon information analytic unit 170 may determine that and whether there is analysis path corresponding with above-mentioned phenomenon information in analytical map.If analysis path be present, phenomenon Storage unit 170 can analyze the phenomenon information using analysis path.Alternatively, phenomenon information analytic unit 170 can be with Phenomenon information is analyzed under human assistance.Such as conclusion or analysis corresponding to above-mentioned phenomenon information are not present in conclusion storehouse When analysis path corresponding with above-mentioned phenomenon information being not present in map, then phenomenon analysis unit 170 can be under human assistance Analyze the phenomenon information.Alternatively, used by phenomenon information analytic unit 170 can record during manual analysis automatically Analysis path, and by the renewal of above-mentioned analysis path into analytical map.Alternatively, phenomenon information analytic unit 170 can be by people The conclusion of work point analysis is updated to above-mentioned conclusion storehouse.
In step 440, conclusion determining unit 180 determines and/or shown conclusion corresponding to the phenomenon.For example, the knot By the positioning that can be a certain error event or failure.In another example the conclusion can be the illegal operation of user, such as illegally step on Land, virus attack etc..In another example the conclusion can be caused event and the performance test results during performance test.Again For example, the conclusion can be caused event and debugging result in research and development debugging process.Alternatively, the conclusion can be with source The history conclusion included in conclusion storehouse.Alternatively, the conclusion can derive from the analytical conclusions obtained according to analysis path. Alternatively, the conclusion can derive from the conclusion that manual analysis obtains.Alternatively, the conclusion can derive from above-mentioned one kind Or the combination of a variety of conclusions.
Fig. 5 is one embodiment flow chart of the log analysis method for PACK of the present invention.The day Will analysis method can apply the malfunction elimination (or fault location) in measurement equipment to be checked, performance test, and/or research and development debugging In.
In step 502, the journal file that user can load measurement equipment to be checked is used for subsequently to being collected into from daily record Phenomenon information is analyzed.
In step 504, phenomenon information collector unit 160 collects institute according to the journal file of the measurement equipment to be checked of reading State the phenomenon information of journal file record.In certain embodiments, the phenomenon information collector unit 160 can use syslog Agreement collects the phenomenon information recorded in the journal file.In certain embodiments, the phenomenon information collector unit 160 The phenomenon information recorded in the journal file can be collected using sftp agreements.It is understood that for this area For those of ordinary skill, suitable for collector journal file method within protection scope of the present invention.
In certain embodiments, when the log analysis method is used for the malfunction elimination of measurement equipment to be checked, into step 506, inquire about conclusion storehouse using phenomenon information analytic unit 170.
In step 508, phenomenon information analytic unit 170 judges whether conclusion corresponding with the phenomenon information.If Conclusion be present, into step 510, conclusion determining unit 180 can directly obtain the conclusion and be shown, can so save Save service or research and development engineer carries out positioning spent plenty of time and energy to error event or failure.If it is not present and institute Conclusion corresponding to phenomenon information is stated, into step 512, phenomenon information analytic unit 170 judges whether analysis path.If deposit In analysis path, into step 514, analyze the phenomenon according to the one or more analysis paths included in analytical map and believe Breath, and each analysis result is shown in step 516, the analysis result can be used for subsequent artefacts to analyze the phenomenon information to be tied By.In certain embodiments, can be updated directly into conclusion storehouse after judgement of the analysis result Jing Guo 522 steps, i.e. Step 522 directly can be connected with step 516.If analysis path is not present, into step 518, service or research and development engineer can To carry out manual analysis, while the automatic record analysis path of the meeting of phenomenon information analytic unit 170 to the phenomenon information, such as look into Look for certain keyword, search the operation such as time point.It should be noted that a plurality of phenomenon information can correspond to an analysis path, one Bar phenomenon information can also correspond to a plurality of analysis path.
In step 520, manual analysis path is added in analytical map, and analytical map is updated.
In step 522, conclusion determining unit 180 judges whether to draw a conclusion by above-mentioned analysis result.If drawing a conclusion, Into step 524 and 526, conclusion determining unit 180 shows the conclusion, and by conclusion renewal into conclusion storehouse, so as to after There are similar events, can quickly obtain conclusion.If not drawing a conclusion, flow terminates.In certain embodiments, conclusion is true Order member 180 can be based on analysis result, perform judgment rule and analysis result is judged.
In certain embodiments, when the log analysis method is used to treat detection device progress performance test and/or grinds During hair debugging, after step 504, into step 505, phenomenon analysis unit 170 can be direct according to collected phenomenon information Query analysis map, and in step 512, judge in the analytical map with the presence or absence of analysis road corresponding to the phenomenon information Footpath.If analysis path be present, into step 514, the phenomenon is analyzed according to the analysis path, and display is each in step 516 Analysis result.For example, a certain mistake (bug) that the analysis result, which can be measurement equipment to be checked, to be occurred, service or research and development engineering Teacher and then debugged (debug) according to the bug.In certain embodiments, the analysis result includes conclusion, will can tie By being updated directly into conclusion storehouse.Analysis path is such as not present, its subsequent processes is similar to the processing procedure of malfunction elimination, It will not be repeated here.
Being preferable to carry out for the present invention is the foregoing is only, is not intended to limit the invention, for the technology of this area For personnel, the present invention can have various modifications and variations.Within the spirit and principles of the invention, that is made any repaiies Change, equivalent substitution, improvement etc., should be included in the scope of the protection.

Claims (10)

1. a kind of log analysis method, it is characterised in that methods described includes:
The journal file of measurement equipment to be checked is obtained, event information and data characteristic information are included in the journal file;
Event information and corresponding data characteristic information in the journal file, collect the phenomenon in the journal file Information, the phenomenon information are the combinations that event information and corresponding data characteristic information are formed;And
Analyze the phenomenon information, and conclusion corresponding to determination.
2. log analysis method as claimed in claim 1, it is characterised in that the phenomenon letter collected in the journal file Breath includes the data characteristic information collected the event recorded in the journal file and extract the event.
3. log analysis method as claimed in claim 1, it is characterised in that the method bag of the analysis phenomenon information Include:
According to the phenomenon information being collected into, conclusion storehouse is inquired about, the correspondence in the conclusion storehouse with phenomenon information and conclusion Relation;
If conclusion corresponding with the phenomenon information in the conclusion storehouse be present, the conclusion is obtained;
If conclusion corresponding with the phenomenon information, phenomenon information described in manual analysis are not present in the conclusion storehouse.
4. log analysis method as claimed in claim 3, it is characterised in that the conclusion for also including obtaining manual analysis updates To the conclusion storehouse.
5. log analysis method as claimed in claim 1, it is characterised in that the method bag of the analysis phenomenon information Include:
According to the phenomenon information being collected into, conclusion storehouse is inquired about, the correspondence in the conclusion storehouse with phenomenon information and conclusion Relation;
If conclusion corresponding to the phenomenon information being present in the conclusion storehouse, obtains the conclusion;
If conclusion corresponding to the phenomenon information, query analysis map, the analytical map are not present in the conclusion storehouse Record analysis path corresponding to different phenomenon informations;
If analysis path corresponding to the phenomenon information in analytical map be present, analyzed using the analysis path described existing Image information;
If analysis path corresponding to the phenomenon information, phenomenon information described in manual analysis are not present in analytical map.
6. log analysis method as claimed in claim 5, it is characterised in that also include:
The analysis path of the manual analysis is added into analytical map, analytical map is updated and/or by people's work point Analyse obtained conclusion and be updated to the conclusion storehouse.
7. log analysis method as claimed in claim 5, it is characterised in that the analysis path is during log analysis The operation performed successively.
8. log analysis method as claimed in claim 1, it is characterised in that the method bag of the analysis phenomenon information Include:
Recorded according to the phenomenon information being collected into, query analysis map, the analytical map corresponding to different phenomenon informations Analysis path;
If analysis path corresponding to the phenomenon information in analytical map be present, analyzed using the analysis path described existing Image information;
If analysis path corresponding to the phenomenon information, phenomenon information described in manual analysis are not present in analytical map.
9. log analysis method as claimed in claim 1, it is characterised in that the conclusion includes fault location result, performance Test result and/or research and development debugging result.
10. a kind of Log Analysis System, it is characterised in that the system includes phenomenon information collector unit, phenomenon information is analyzed Unit and conclusion determining unit;
The phenomenon information collector unit be used for collector journal file in phenomenon information, the phenomenon information be event information and The combination that corresponding data characteristic information is formed;
The phenomenon information analytic unit is used to analyze the phenomenon information in the journal file, to obtain analysis result;And
The conclusion determining unit is used for the conclusion according to corresponding to the analysis result determines the phenomenon information.
CN201710857751.9A 2017-09-20 2017-09-20 A kind of log analysis method and system Pending CN107564584A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710857751.9A CN107564584A (en) 2017-09-20 2017-09-20 A kind of log analysis method and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710857751.9A CN107564584A (en) 2017-09-20 2017-09-20 A kind of log analysis method and system

Publications (1)

Publication Number Publication Date
CN107564584A true CN107564584A (en) 2018-01-09

Family

ID=60982319

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710857751.9A Pending CN107564584A (en) 2017-09-20 2017-09-20 A kind of log analysis method and system

Country Status (1)

Country Link
CN (1) CN107564584A (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101060436A (en) * 2007-06-05 2007-10-24 杭州华三通信技术有限公司 A fault analyzing method and device for communication equipment
CN103246735A (en) * 2013-05-13 2013-08-14 中国工商银行股份有限公司 Abnormal data processing method and abnormal data processing system
CN105812177A (en) * 2016-03-08 2016-07-27 华为技术有限公司 Network fault processing method and processing apparatus

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101060436A (en) * 2007-06-05 2007-10-24 杭州华三通信技术有限公司 A fault analyzing method and device for communication equipment
CN103246735A (en) * 2013-05-13 2013-08-14 中国工商银行股份有限公司 Abnormal data processing method and abnormal data processing system
CN105812177A (en) * 2016-03-08 2016-07-27 华为技术有限公司 Network fault processing method and processing apparatus

Similar Documents

Publication Publication Date Title
US10796181B2 (en) Machine learning based method and system for analyzing image artifacts and imaging system failure
US8401259B2 (en) Image diagnosis support system
US6442542B1 (en) Diagnostic system with learning capabilities
US20080221834A1 (en) Method and system for enhanced fault detection workflow
CN109805932A (en) Automatic fault detection in MR device
US20160110510A1 (en) Medical Workflow Determination And Optimization
CN107018023A (en) A kind of server diagnostic method, apparatus and system
CN108257111A (en) Automated image in x-ray imaging is examined
CN107424105B (en) Medical imaging equipment fee-missing intelligent management system and method
CN113396395A (en) Method for effectively evaluating log mode
US20100260399A1 (en) Scanner data collection
KR20170028931A (en) Systems and methods for managing adverse reactions in contrast media-based medical procedures
JP5732015B2 (en) Graph creating apparatus, graph creating method, and graph creating program
US20130267842A1 (en) Method for operating an imaging diagnostic device and medical imaging system
US20020143575A1 (en) Interpretation system and method for multi-threaded event logs
CN109288531A (en) Method for the workflow that detection and analysis is executed using image mode
US20100042434A1 (en) System and method for discovering information in medical image database
CN107993707A (en) The maintaining method and device of a kind of error code information
US20120290312A1 (en) Charging management apparatus, charging management system, and charging management program
CN111448615A (en) System and method for processing patient-related medical data
CN107564584A (en) A kind of log analysis method and system
JP4991128B2 (en) Image management system, image display device, management server, and image data management method
JP4599148B2 (en) Image quality management system
KR101403685B1 (en) System and method for relating between failed component and performance criteria of manintenance rule by using component database of functional importance determination of nuclear power plant
JP6827925B2 (en) Efficiency analysis by extracting precise timing information

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
CB02 Change of applicant information

Address after: 201807 Shanghai City, north of the city of Jiading District Road No. 2258

Applicant after: Shanghai Lianying Medical Technology Co., Ltd

Address before: 201807 Shanghai City, north of the city of Jiading District Road No. 2258

Applicant before: SHANGHAI UNITED IMAGING HEALTHCARE Co.,Ltd.

CB02 Change of applicant information