CN1670708A - Management method for computer log - Google Patents

Management method for computer log Download PDF

Info

Publication number
CN1670708A
CN1670708A CN 200410029426 CN200410029426A CN1670708A CN 1670708 A CN1670708 A CN 1670708A CN 200410029426 CN200410029426 CN 200410029426 CN 200410029426 A CN200410029426 A CN 200410029426A CN 1670708 A CN1670708 A CN 1670708A
Authority
CN
China
Prior art keywords
log
record
daily record
computing machine
search rule
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN 200410029426
Other languages
Chinese (zh)
Other versions
CN100375047C (en
Inventor
许正华
黄平
姜晓东
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Lenovo Beijing Ltd
Original Assignee
Lenovo Beijing Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Lenovo Beijing Ltd filed Critical Lenovo Beijing Ltd
Priority to CNB2004100294266A priority Critical patent/CN100375047C/en
Publication of CN1670708A publication Critical patent/CN1670708A/en
Application granted granted Critical
Publication of CN100375047C publication Critical patent/CN100375047C/en
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Images

Landscapes

  • Debugging And Monitoring (AREA)

Abstract

This invention discloses one computer log management method, which comprises the following steps: forming the computer log file in the computer; analyzing the log record of different forms into one with united form of log record; then managing the log records with united form; and filtering and displaying the log records with united form.

Description

A kind of management method of computing machine daily record
Technical field
The present invention relates to computer management technology, be specifically related to a kind of management method of computing machine daily record.
Background technology
The computing machine daily record be in the computer system operational process, produce by system self or by this system is monitored watchdog routine produced through the descriptor of refinement highly, these descriptors have mainly been described mistake that the key operation that system carried out and system taken place and unusual etc. in operational process.Generally speaking, independently computer system all has the daily record of oneself, and the computer system here can be a computer operating system, also can be application program, or the system of other levels of computing machine.By analysis to system journal, the problem that can the understanding system be in operation and often occurs, thus can improve operation maintenance targetedly to system, and then the safety and the efficient of the operation of raising system.
User's management that daily record is carried out to computing machine mainly is a log searching.This is because along with the increase of system operation time, journal file is also more and more huger thereupon, even partial log has certain limitation to himself size, but the descriptor amount of its containing also is very large.So, for daily record is effectively managed, just be necessary to filter out the unconcerned content of user, and keep the small amounts of content of user's real concern, for example warning message or error message etc.This filtration is undertaken by search rule being set and according to search rule daily record being retrieved.
At present, in computer cluster system, generally be the management of concentrating to be carried out in the daily record of other All hosts in this Network of Workstation by a main frame with management function, but because the operating system of different main frames all may be different with application program, and each operating system and application program all have the daily record of own unique form, that is to say that the form of various system journals is skimble-scamble, so just need carry out different management respectively the different system daily record.In management host, different management tools need be set at different system journals, and then use different management tools to manage corresponding system journal respectively, thereby make whole management process very complicated, increased the difficulty of operation maintenance.
In addition, when the system manager retrieves journal file, all need to set in advance search rule.Being provided with of search rule needs to consider many-sided factor, for example, if rule is too simple, can't filter out the unconcerned information of user so; If rule is too complicated, increased the difficulty of bookkeeping again.Therefore concerning the system manager, search rule is set pays a lot of time and efforts.And, search rule need be set respectively, thereby further increased the complicacy of management for the daily record of different-format.
At present, generally be to be arrived management host by the log transmission of management host, to carry out the setting of search rule and carry out corresponding search operaqtion, can avoid issuing of search rule like this by management host.If but numerous by management host in the computer cluster system, these are all needed the daily record of oneself is sent to management host by management host, need take a large amount of network bandwidth of computer group like this.And management host needs the serial execution that each is retrieved by the journal file of management host, has therefore greatly reduced the work efficiency of management host.
Summary of the invention
In view of this, an object of the present invention is to provide a kind of management method of computing machine daily record, can unify the form of different journal files, thereby improve the convenience of system's operation maintenance, and the efficient that improves log management.
Above-mentioned purpose of the present invention is achieved by the following technical solutions:
A kind of management method of computing machine daily record comprises the steps: at least
A. preserve formed computing machine journal file on computers;
B. the log record of the different-format that various computing machine journal file is comprised resolves to and has log records with united form;
C. log records with united form is managed.
In said method, the management among the step c comprises the step that shows log records with united form on computers.And may further include the step of screening log records with united form.
Wherein screening step comprises:
Judge whether to have defined search rule, if carry out next step; Otherwise definition is also preserved search rule, carries out next step then;
Create the result for retrieval buffer zone, and create the daily record data source object that comprises log records with united form;
Order reads a log record from the daily record data source object, and the log record that uses the search rule coupling to read is filled into the result for retrieval buffer zone with the log record that obtains after the coupling, and sequential read is taken off a log record then;
After having mated all log records, discharge the daily record data source object, show on computers to discharge the result for retrieval buffer zone by the log record that obtains after the coupling.
The search rule here can be the forward search rule, and the log record that obtains after the coupling is the log record that satisfies the forward search rule like this; Perhaps, search rule can be reverse search rule, and the log record that obtains after the coupling is all log records except the log record that satisfies reverse search rule.
Computing machine blog management method of the present invention can be applied to unit, also can be applied to computer group.When being applied to computer group, the step of definition search rule is carried out on management host, preserve the computing machine journal file, resolve log record, create and release result for retrieval buffer zone, create and discharge the daily record data source object and read and the step of mating log record is carried out on by management host, after management host has defined search rule the present invention further comprise will definition search rule or the be used to identification information that identifies search rule be handed down to by the step of management host, further comprised that by management host the log record that will obtain after the coupling sends to the step of management host after having mated all log records, show that the log record that obtains after the coupling carries out on management host.
At this moment, after management host has been preserved search rule, further be included as the search rule of being preserved an identification information is set, and search rule and corresponding identification information sent to by management host by being preserved by management host, the identification information that will be used to identify search rule is handed down to by management host.
In the present invention, define corresponding search rule respectively for different types of journal file.
Analyzing step of the present invention comprises:
B1. be the unified journal format of log record definition of different-format;
B2. foundation is used to preserve the current log record buffer zone that has log records with united form after the parsing, and for each journal file corresponding analytic method is set respectively;
B3. open journal file, read the log record in the journal file and use the analytic method among the step b2 respectively each bar log record to be resolved to the log record with the described unified journal format of step b1;
B4. having log records with united form after will resolving is kept in the described current log record buffer zone.
In said method, reading log record among the step b3 can be to read a log record each journal file on being kept at computer disk.
In said method, reading log record and resolving among the step b3 can comprise the steps:
That b31. creates a sky reads buffer zone in advance;
B32. once read and read in advance the buffer zone surge capability the journal file on being kept at computer disk accordingly more than or equal to 1 log record and be filled into and read buffer zone in advance;
B33. read a log record the buffer zone and resolve from reading in advance, the result after resolving is saved in the current log record buffer zone, then from reading to read next bar log record the buffer zone in advance;
B34. after reading and resolved current all log records of reading in advance in the buffer zone, repeated execution of steps b32, and use the log record that newly reads to substitute and read original log record in the buffer zone in advance, repeated execution of steps b33 then, all log records in having read and resolved this journal file;
B35. discharge and read buffer zone in advance.
Before step b31, may further include the step of reading buffer zone in advance that judges whether to create a sky, if, direct execution in step b32, otherwise order execution in step b31 and b32.In addition, before step b32, further comprise and judge the step that whether comprises log record in the journal file, if, execution in step b32, otherwise process ends.
In said method, the form by the dynamic load function in step b2 is provided with analytic method.
In said method, the journal format that step b1 is unified comprises the Log Desinations of the description object that is used to identify journal file, the generation time that is used to identify the log record rise time, the daily record rank that is used to identify the log record significance level, the log content of detailed description information that is used to identify the daily record object and the out of Memory that is used to identify the other guide that does not belong to above-mentioned four.Wherein, the description of Log Desinations and the mutual relationship between the Log Desinations are pre-defined before system's operation, and are kept in the independent configuration file.And the mutual relationship between the Log Desinations is by the formal definition of extendible Log Desinations tree.The daily record rank defines by the nonnegative integer of expression log record significance level and one two tuple that the character express of this significance level is formed.
By technical scheme of the present invention as can be seen, for the log record of preserving on computers that different journal file comprised with different-format, has log records with united form by taking different analytic methods to resolve to, thereby make the present invention on a management host, be carried out centralized and unified management by all journal files on the management host to all, greatly improved the convenience of log management, reduce the difficulty of bookkeeping, improved the efficiency of management.
Simultaneously, the present invention can also screen at different user's requests having log records with united form, then the log record that filters out is shown to the user, makes the user can promptly determine the information of being concerned about, has further improved the efficiency of management.When screening, can be undertaken, thereby improve breakneck acceleration, and therefore improve the efficiency of management of management host by being walked abreast in the computer cluster system by management host.
In addition, except carrying out the unified management numerous different types of journal files, the present invention has good extendability, does not need the active computer Network of Workstation is carried out wholesale revision, just can greatly improve the efficiency of management of Network of Workstation.In addition, for the journal file of newly-increased kind, only needing to add corresponding analytic method can manage, and therefore is very easy to expansion.
Description of drawings
Fig. 1 is the overview flow chart according to computing machine blog management method of the present invention.
Fig. 2 is the operation model synoptic diagram according to computing machine blog management method of the present invention.
Fig. 3 is the synoptic diagram of the Log Desinations tree of an operating system daily record.
Fig. 4 is the synoptic diagram of Fig. 3 through the Log Desinations tree after expanding.
Fig. 5 is the process flow diagram according to unified journal format of the present invention.
Fig. 6 is according to analytic method dynamic load process synoptic diagram of the present invention.
Fig. 7 reads buffer technology according to use of the present invention to carry out the process flow diagram that log record reads in advance.
Fig. 8 is the method synoptic diagram that visit according to the present invention has the log record of reading buffer memory in advance.
Fig. 9 is according to Log Filter layer processing flow chart of the present invention.
Embodiment
The present invention is described in detail below in conjunction with the drawings and specific embodiments.
The present invention mainly uses corresponding analytic method to resolve to by the log record to the different different-formats that journal file comprised to have identical log records with united form, and then carries out respective handling.Fig. 1 shows overall procedure of the present invention, and as can be seen from Figure 1, method of the present invention mainly comprises the steps:
Step 101: computer group by management host in preserve this by journal file that management host had.
Step 102: resolve by the journal file that management host had, the log record of the different-format that comprised in the different journal files is converted to has log records with united form.
Step 103: log records with united form is screened, filter log record useless concerning the user, pick out the log record that the user is concerned about.
Step 104: the information of picking out that log record comprised is shown to the user.
In order to realize overall procedure of the present invention, the present invention logically is divided into the log management model four levels as shown in Figure 2, upwards is respectively log store layer, daily record analytic sheaf, Log Filter layer and daily record presentation layer from bottom.In these four levels, the log store layer is used for preserving and safeguarding various journal files, and it represents is the journal file of various different-formats to the upper strata; The daily record analytic sheaf is responsible for the journal file of various forms is mapped as the daily record data source with consolidation form, and the daily record data source here will describe in detail in the back; The Log Filter layer is responsible for traveling through each the bar log record in the daily record data source, and removes useless log information according to the filtering rule that sets in advance, and picks out the log information of user's real concern, then the log information of picking out is sent to the daily record presentation layer; The daily record presentation layer is responsible for the essential information and the aforementioned filtering rule that sets in advance of configuration log file, sends the log query order downwards, and the log information that lower floor uploads is shown to the user.
In a preferred embodiment of the invention, log store layer, daily record analytic sheaf and Log Filter layer are positioned at by management host, and the daily record presentation layer is positioned at management host.That is to say that operating in that log store layer, daily record analytic sheaf and Log Filter layer are responsible for carried out on the management host, operating on the management host that the daily record presentation layer is responsible for carried out.Certainly, the present invention is not limited to this a kind of situation, except log store layer and daily record presentation layer lay respectively at by management host and the management host, daily record analytic sheaf and Log Filter layer can be positioned on the management host simultaneously, perhaps the daily record analytic sheaf is positioned at by on the management host, and the Log Filter layer is positioned on the management host.Can be communicated by communication protocols such as TCP/IP between management host and the management host.
Below in conjunction with aforementioned four levels overall procedure of the present invention is further illustrated.
The front illustrates, in a computer group, generally comprises a management host and a plurality of by management host, and this management host manages a plurality of journal files by management host.All may preserve a plurality of journal files at each in by management host, these journal files may be corresponding to computer operating system, may be corresponding to application program, and also may be corresponding to the system of other levels of computing machine.And these computing machine daily records generally have different forms.Therefore in the present invention, at first preserve these and have the dissimilar computing machine journal file of different-format in step 101.
When the system manager need check the information that comprises in some concrete computing machine journal files, can send corresponding instruction by the operation interface of management host, management host sends to this instruction by management host, is received by management host promptly to begin after the above-mentioned instruction for the desired concrete computing machine journal file execution in step 102 of instruction.Perhaps, can be in advance on by management host or management host, set a timer, after arriving the time that this timer sets, by management host for all computing machine daily records or predefined computing machine journal file execution in step 102.These two kinds of triggering modes are identical with prior art, no longer describe in detail here.
In step 102,, at first defined a kind of unified journal format for the journal file to different-format carries out management unified, that concentrate.Specifically, any one journal file can be regarded a record set as, and each the bar log record in this record set has all been represented a log information, and this log information can be a string single file character stream, also can be a string multirow character stream.In a preferred embodiment of the present invention,, each bar log record can be decomposed into following five fields: Log Desinations, generation time, daily record rank, log content and out of Memory according to analysis to various log records.
Log Desinations may also be referred to as Log Types, and it represents the object that is described of journal file, just is in the object of certain running status, for example is computer operating system itself, or an ingredient of operating system.Each journal file may comprise a plurality of Log Desinations, the for example system journal of Windows, it has a daily record and has described certain hardware damage, also has a daily record to describe certain system service and is stopped, and hardware here and system service all are Log Desinations.Certainly, a journal file also may only comprise a Log Desinations.Comprising under the situation of a plurality of Log Desinations, these Log Desinations have been formed a tree structure as shown in Figure 3.As shown in Figure 3, the daily record of Windows operating system comprises three Log Desinations: system journal, application daily record and security log, they have formed a Log Desinations tree that comprises three leaf nodes.The description of Log Desinations and the mutual relationship between them need be pre-defined before system's operation, and are kept in the configuration file that is provided with separately.
Here why will set up Log Desinations, be to wish to come log content is classified by distinguishing different Log Desinations, with convenient inquiry in the future.Therefore, the user can be on the basis of original log file layout, defines Log Desinations neatly in conjunction with oneself regulatory requirement.The above-mentioned system that is meant on the basis of original log file layout can determine that this writes down described object by the analysis of the significant information in the log record, this basis has been arranged, the user just can be according to the demand existing configuration of expansion on breadth and depth at any time of oneself, and definition is Log Desinations more in detail accurately.
For example, can further determine the daily record of application 1 and the daily record of application 2 by the analysis of Windows shown in Figure 3 being used log record, then Log Desinations tree shown in Figure 3 can be expanded to Log Desinations tree shown in Figure 4, just under the leaf node of using daily record, set up two next stage nodes again: use 1 daily record and use 2 daily records.
Time to be compared in order retrieving, to have defined the generation time of daily record in system.The generation time of daily record is a numeric character string that shows the daily record generation time with consolidation form, and its form for example can be<year〉<month<day<time<minute<second.Wherein use 4 character representation times, for example " 2003 " expression is 2003; With 2 character representation months, for example " 12 " represent Dec; With 2 character representations specifically is which day, and for example " 31 " expression is 31; With 2 character representations hour, " 12 " expression 12 points for example; With 2 character representations minute, " 00 " expression zero for example; With 2 character representation seconds, 38 seconds of " 38 " expression for example.Whole like this numeric character string " 20031231120038 " represents that the generation time of this daily record is 12: 0: 38 on the 31st Dec in 2003.
Every kind of journal file may have different time precisions, and in the present invention, for unification, system need be unified into above-mentioned precision to different time precisions.For example, can the original log format conversion during for unified journal format for the position zero padding of inaccessiable time of precision, then directly remove more more accurate numerical for what original precision surpassed above-mentioned precision.For example, the raw readings generation time of a certain log record is 12 o'clock on the 31st Dec in 2003, and then with its minute and position zero padding in second, amended generation time then becomes 12: 0: 0 on the 31st Dec in 2003.And if the raw readings generation time of a certain log record is 30 milliseconds of 12: 0: 38 on the 31st Dec in 2003, then directly removes a millisecond information, amended generation time then becomes 2003 on Dec 31,12: 0: 38.
The daily record rank shows the significance level of log record, can (level_id level_desc) defines the daily record rank with one two tuple.Wherein, level_id is a nonnegative integer that shows significance level, and numerical value is more for a short time to show that the significance level of daily record is high more.Level_desc is to other text description of level.In the present invention, can be every kind of different daily record rank of journal file definition.
Log content is the detailed description information to the daily record object.Out of Memory has then comprised in the journal file and has not belonged to other above-mentioned four content.
After as above having defined unified journal format, just the concrete log record of journal file can be converted to and have log records with united form.Specifically, comprise following steps shown in Figure 5.
In step 501, set up current log record buffer zone in advance, and set up a kind of analytic method for each journal file in advance.The current log record buffer zone here is used to preserve the log information that have unified journal format of back through resolving, and this point will have further explanation in the back.In addition, because the front is mentioned, each journal file all has different-format, resolve to the journal file of consolidation form to the journal file of different-format, just need set up corresponding analytic method respectively to the journal file of each different-format.In practical operation, can utilize the mode of dynamic load function to set up analytic method, just each method is formed a dynamic load function (parse function), and be kept in the system.For different operating system platforms, use different kinematic function loading techniques, for example for windows platform, use dynamic link libraries technology (.dll), and, then use dynamic base technology (.so) for the Linux platform.
The process of analytic method dynamic load as shown in Figure 6.Every kind of journal file all has the own special-purpose dynamic base that has comprised an analytical function, and with the library file name of journal file name as dynamic base, thereby can realize " by a name loading ".The dynamic load process of analytical function is to finish in the process of the constructed fuction of object.
In step 502, when needs carry out uniform format, at first open a concrete journal file.In the present invention, can a pre-defined daily record data source object, can keep synchronous this moment with the establishment and the deletion of the opening and closing of journal file and daily record data source object, that is to say, when creating object, open file close file when the deletion object.These document manipulations are transparent for the user.The input parameter that the journal file name can be used as the object constructed fuction is used to open file, and the filec descriptor that obtains can be kept at and be used for follow-up operation to file in the member variable.The data source here is the data access interface that bottom data encapsulation back is formed.
In step 503, journal file to be resolved by calling the dynamic load function, the log information after will resolving then is saved in the current log record buffer zone.
Wherein for step 503, because the log management operation only need be carried out from the beginning to the end sequential access to daily record, so the daily record data source only provides the member method that reads log record in proper order, just next method.Whenever call the next method one time, the current log record buffer zone of daily record data source object is refreshed.The next method is the encapsulation to the parse function, can hide the details of operation like this.Because the next method once can only record of flush buffers, so the parse function also only needs to read a pairing data field of log record at every turn from journal file and gets final product.That is to say, read a log record each journal file on being kept at disk, the process of resolving then, the log information that will this time resolve back formation then is kept in the current log buffer recording areas.This process need is visited disk file continually, has reduced operating efficiency, and for this reason, the present invention also provides another one embodiment, just uses " reading buffer zone in advance " technology, will describe in detail this below.
Read buffer zone in advance and be meant and open up an enough big buffer zone, be used for reading data as much as possible from journal file once.During each next method call parse function, the parse function only need get final product from reading the buffer zone reading of data in advance and resolve accordingly, only the parse function just carries out the file read operation once more when buffer zone is sky, can significantly reduce the access times to disk file like this.Here, all operations to buffer zone all are encapsulated in the parse function.
Use is read buffer technology in advance and is comprised four basic steps: bufcreate, fill buffer zone, read buffer zone and buffer release district.In the single job process, when needs read the data of journal file, at first create a buffer zone, then from journal file according to size many data of disposable filling in buffer zone of buffer zone, and then reading of data from buffer zone is item by item resolved each bar data simultaneously, after having read and resolved many data of disposable filling, fill once more and read operation, till reading and resolved all data, buffer release district then.Specifically, whole process comprises following steps as shown in Figure 7.
Step 701 at first judges whether to have created and reads buffer zone in advance.If, execution in step 705, otherwise execution in step 702.Here judge whether at first to have created that to read buffer zone in advance be for the reliability consideration of system.
Step 702, confirming do not have establishment to read in advance under the situation of buffer zone, further judge whether to have read end-of-file, that is to say, judge whether this journal file is an empty file without any data content, if read end-of-file, that is to say if an empty file process ends; Otherwise execution in step 703.
Step 703,704, that creates a sky reads buffer zone in advance, and will be used to represent that the static read pointer of Data Position points to the buffer empty afterbody, and execution in step 707 then.
Step 705 judges whether static read pointer points to the buffer zone afterbody.If static read pointer points to the buffer zone afterbody, show that then this buffer zone is sky, carries out the step of padding data, just step 706,707 and 708 this moment.Otherwise showing has data in the buffer zone, directly carry out the step of reading of data, just step 709 and subsequent step thereof.
Step 706 further judges whether to have read end-of-file.The same with step 702, this step also is in order to judge whether data recording is arranged in this journal file.If an empty file, process ends; Otherwise execution in step 707.
Step 707,708 reads and the corresponding data of buffer size, then static read pointer is pointed to the buffer zone head.The corresponding data of the buffer size here are the data that buffer zone can hold just, and for example the buffer zone of being set up can hold 10 records, read 10 logdata records with regard to disposable so here, then read pointer are pointed to article one record.
Step 709,710 reads the record that current read pointer is pointed to, and according to aforementioned analytic method this record is resolved then, and the result after will resolving is kept in the current record log buffer district.
Step 711 is pointed to the next record that need read with read pointer.
Step 712 judges whether current reading in advance also has record in the buffer zone.If re-execute step 709; Otherwise execution in step 713.
Step 713 further judges whether to read tail of file.If read tail of file, show and read all data, then carry out the step that buffer zone is read in release in advance, just step 714; Otherwise show and also have data not to be read and to resolve in the journal file, then carry out the step of filling buffer zone once more, just step 707 and subsequent step, this moment, that newly reads directly substituted data in the original buffer zone with the corresponding data of buffer size in step 707.
Step 714 discharges and reads buffer zone in advance.So far this flow process finishes.
Fig. 8 is the method synoptic diagram that visit according to the present invention has the log record of reading buffer memory in advance.Can a more intuitive explanation be arranged to above-mentioned flow process by Fig. 8.As shown in Figure 8, after having created buffer empty, call the next method, the disposable N bar data recording that reads from journal file by N time, read and resolve by what write down one by one then, the analysis result that this N bar is write down is kept in the current log record buffer zone.Then, since calling the next method above-mentioned steps that circulates for the N+1 time, till reading and resolved all data recording.
Through after the aforementioned resolving, the daily record data to consolidation form in step 103 screens, and filters log information useless concerning the user, picks out the log information that the user is concerned about.The screening operation is here finished by the Log Filter layer.
The front is mentioned, and in a preferred embodiment of the invention, the Log Filter layer is positioned at by management host, and the daily record presentation layer is positioned at management host, communicates by network communication protocols such as TCP/IP between Log Filter layer and the daily record presentation layer.In this case, the processing of screening daily record data of the present invention comprises following steps as shown in Figure 9.
Step 901 at first judges whether defined search rule on the management host.If also do not define search rule, then execution in step 902, and execution in step 903 then, otherwise direct execution in step 903.
The search rule here always journal file with concrete is relevant, and each journal file all has the cover predefine rule of oneself, and this is because the information of being concerned about for different journal file users is different.Forward search rule and reverse search rule can be set here.The forward search rule is exactly that the log record of this search rule of coupling is put into result buffer, and oppositely search rule is exactly to ignore the log record that mates this search rule.In other words, adopting the forward search rule is exactly to search satisfactory record from all log records, is exactly to remove the record that does not meet the demands from all log records and adopt reverse search rule, thus remaining satisfactory record.To adopt which kind of search rule is that the user considers based on recall precision as for concrete, with goal of the invention of the present invention much relations not, therefore no longer describes in detail.
Search rule can be goal rule, time rule, level rule or context string matched rule, just screens log record according to the front through Log Desinations, generation time, daily record rank and the log content of resolving the log record that obtains respectively.Certainly, also can retrieve by these search rules of integrated use.As for specifically how retrieving is those skilled in the art's common practise, repeats no more here.
Step 902 if there is not pre-defined search rule, then defines search rule temporarily, and then preserves this search rule on the management host.
Generally speaking, search rule is relatively-stationary, therefore do not need all to go to formulate at every turn, after having formulated search rule for the first time, it can be kept on the management host, when carrying out for the second time the processing of retrieve log record by the time, just can directly use all or part search rule of having preserved.
Step 903, management host is issued to all by management host with search rule.Preserved the search rule that is received from management host by management host.
If certain search rule can be reused, the user can be on management host saves as it fixing predefine search rule, and distributes convenient the quoting in the future of unique sign information for it.In step 903, only need get final product like this, and not need to resend rule itself, therefore improve the efficient that issues of rule to the sign information that is issued this search rule by management host.
Log management order and search rule can be handed down to all by management host concomitantly from management host, can make each by management host execution journal management concomitantly like this, thereby improve efficiency of managing.
Step 904~906 are received retrieval command by management host, create the result for retrieval buffer zone then, and create the daily record data source object.
Step 907, order reads a log record.
Whether step 908, judgement read log record successful.If, the log record that reads is carried out the coupling of search rule in step 909, judge in step 910 then whether this log record satisfies search rule, here be example with the forward search rule, if satisfy, execution in step 911, otherwise re-execute step 907.Successfully do not read log record if in step 908, judge, show then that log record has read and finish execution in step 912.
Step 911 is filled into buffer zone with the log record that satisfies the forward search rule.Re-execute step 907 then, just read next bar log record.
Step 912~914 finish if all log records have all read and mated, and discharge the daily record data source object, and matching result is returned to management host, discharge the result for retrieval buffer zone then.
In the embodiment shown in fig. 9, when management host sent a management operation request, system claimed to create corresponding daily record data source object according to requested file names, after this bookkeeping is finished, discharges this daily record data source object.That is to say that what the daily record data source object here adopted is temporary object.Certainly can understand, the daily record data source object can adopt the persistence object, just this object is created by system when starting or receiving first operation requests, does not discharge object after finishing this operation requests immediately, just discharges this object but wait when system stops.Compare with the persistence object, the present invention adopts temporary object more favourable, and this is because the reason of three aspects.One, from the access module of data, each log management operation can be regarded as once the complete traversal of journal file, and this is a kind of stateless operation, and just bookkeeping next time and last bookkeeping have nothing to do.Its two, from access frequency, log management operation is all triggered from the interface by the user, therefore this bookkeeping can be very not frequent.They are three years old, from consistency maintenance,, just must increase corresponding logic and safeguard consistance between memory object and the journal file if use the persistence object, and the content of journal file is constantly to change, and therefore will certainly greatly increase the workload of system maintenance.Based on the reason of above-mentioned three aspects, the present invention preferably uses the temporary object mode to create and discharges the daily record data source object.
After having finished above-mentioned steps,, the log information of picking out is shown to the user in step 104.The display mode here is common practise to those skilled in the art, repeats no more here.
Pass through said process, the present invention resolves the journal file of different-format by adopting different analytic methods as can be seen, form the daily record data of unified journal format, then daily record data is carried out the coupling of search rule, obtain the information that the user is concerned about, then it is shown to the user.Therefore, the present invention not only can carry out unified operation to all journal files on same management host, improved the convenience of log management greatly, simultaneously, the present invention has reduced the difficulty of bookkeeping by unified journal format, has improved the efficiency of management.
The present invention can be applied to aforementioned calculation machine cluster management system, also can be applied to independent computing machine, by the present invention the journal file of the different-format that forms on this computing machine is carried out unified management.Therefore being appreciated that above-mentioned only is the displaying of spirit of the present invention, rather than restriction.

Claims (18)

1. the management method of a computing machine daily record comprises the steps: at least
A. preserve formed computing machine journal file on computers;
B. the log record of the different-format that various computing machine journal file is comprised resolves to and has log records with united form;
C. log records with united form is managed.
2. the management method of computing machine daily record according to claim 1 is characterized in that, the management among the step c comprises the step that shows log records with united form on computers.
3. the management method of computing machine daily record according to claim 2 is characterized in that, further comprises the step of screening log records with united form before showing log records with united form.
4. the management method of computing machine daily record according to claim 3 is characterized in that, described screening step comprises:
Judge whether to have defined search rule, if carry out next step; Otherwise definition is also preserved search rule, carries out next step then;
Create the result for retrieval buffer zone, and create the daily record data source object that comprises log records with united form;
Order reads a log record from the daily record data source object, and the log record that uses the search rule coupling to read is filled into the result for retrieval buffer zone with the log record that obtains after the coupling, and sequential read is taken off a log record then;
After having mated all log records, discharge the daily record data source object, show on computers to discharge the result for retrieval buffer zone by the log record that obtains after the coupling.
5. the management method of computing machine daily record according to claim 4 is characterized in that, described search rule is the forward search rule, and the log record that obtains after the described coupling is the log record that satisfies described forward search rule;
Perhaps, described search rule is reverse search rule, and the log record that obtains after the described coupling is all log records except the log record that satisfies reverse search rule.
6. the management method of computing machine daily record according to claim 4, it is characterized in that, described computing machine blog management method is applied to computer group, the step of described definition search rule is carried out on management host, described preservation computing machine journal file, resolve log record, create and release result for retrieval buffer zone, create and discharge the daily record data source object and read and the step of mating log record is carried out on by management host, after management host has defined search rule the present invention further comprise will definition search rule or the be used to identification information that identifies search rule be handed down to by the step of management host, further comprised that by management host the log record that will obtain after the coupling sends to the step of management host after having mated all log records, the log record that obtains after the described demonstration coupling carries out on management host.
7. the management method of computing machine daily record according to claim 6, it is characterized in that, after management host has been preserved search rule, further be included as the search rule of being preserved an identification information is set, and described search rule and corresponding identification information sent to by management host by being preserved by management host, it is to issue identification information that the identification information that described search rule or be used to definition identifies search rule is handed down to by management host.
8. according to the management method of any described computing machine daily record in the claim 4 to 7, it is characterized in that, in the step of definition search rule, define corresponding search rule respectively for different types of journal file.
9. the management method of computing machine daily record according to claim 1 is characterized in that, the described analyzing step of step b comprises:
B1. be the unified journal format of log record definition of different-format;
B2. foundation is used to preserve the current log record buffer zone that has log records with united form after the parsing, and for each journal file corresponding analytic method is set respectively;
B3. open journal file, read the log record in the journal file and use the analytic method among the step b2 respectively each bar log record to be resolved to the log record with the described unified journal format of step b1;
B4. having log records with united form after will resolving is kept in the described current log record buffer zone.
10. the management method of computing machine daily record according to claim 9 is characterized in that, reading log record among the step b3 is to read a log record each journal file on being kept at computer disk.
11. the management method of computing machine daily record according to claim 9 is characterized in that, reads log record among the step b3 and resolving comprises the steps:
That b31. creates a sky reads buffer zone in advance;
B32. once read and read in advance the buffer zone surge capability the journal file on being kept at computer disk accordingly more than or equal to 1 log record and be filled into and read buffer zone in advance;
B33. read a log record the buffer zone and resolve from reading in advance, the result after resolving is saved in the current log record buffer zone, then from reading to read next bar log record the buffer zone in advance;
B34. after reading and resolved current all log records of reading in advance in the buffer zone, repeated execution of steps b32, and use the log record that newly reads to substitute and read original log record in the buffer zone in advance, repeated execution of steps b33 then, all log records in having read and resolved this journal file;
B35. discharge and read buffer zone in advance.
12. the management method of computing machine daily record according to claim 11, it is characterized in that, before step b31, further comprise the step of reading buffer zone in advance that judges whether to create a sky, if, direct execution in step b32, otherwise order execution in step b31 and b32.
13. the management method of computing machine daily record according to claim 11 is characterized in that, before step b32, further comprises judging the step that whether comprises log record in the described journal file, if, execution in step b32, otherwise process ends.
14. the management method of computing machine daily record according to claim 9 is characterized in that, the form by the dynamic load function in step b2 is provided with analytic method.
15. the management method of computing machine daily record according to claim 9, it is characterized in that the described unified journal format of step b1 comprises the Log Desinations of the description object that is used to identify journal file, the generation time that is used to identify the log record rise time, the daily record rank that is used to identify the log record significance level, the log content of detailed description information that is used to identify the daily record object and the out of Memory that is used to identify the other guide that does not belong to above-mentioned four.
16. the management method of computing machine daily record according to claim 15 is characterized in that, the description of described Log Desinations and the mutual relationship between the Log Desinations are pre-defined before system's operation, and are kept in the independent configuration file.
17. the management method of computing machine daily record according to claim 16 is characterized in that, the mutual relationship between the described Log Desinations is by the formal definition of extendible Log Desinations tree.
18. the management method of computing machine daily record according to claim 15 is characterized in that, described daily record rank defines by the nonnegative integer of expression log record significance level and one two tuple that the character express of this significance level is formed.
CNB2004100294266A 2004-03-17 2004-03-17 Management method for computer log Expired - Fee Related CN100375047C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB2004100294266A CN100375047C (en) 2004-03-17 2004-03-17 Management method for computer log

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB2004100294266A CN100375047C (en) 2004-03-17 2004-03-17 Management method for computer log

Publications (2)

Publication Number Publication Date
CN1670708A true CN1670708A (en) 2005-09-21
CN100375047C CN100375047C (en) 2008-03-12

Family

ID=35041981

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB2004100294266A Expired - Fee Related CN100375047C (en) 2004-03-17 2004-03-17 Management method for computer log

Country Status (1)

Country Link
CN (1) CN100375047C (en)

Cited By (36)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2008064593A1 (en) * 2006-11-30 2008-06-05 Alibaba Group Holding Limited A log analyzing method and system based on distributed compute network
CN100412807C (en) * 2005-12-22 2008-08-20 国际商业机器公司 Method and apparatus for managing event logs for processes in a digital data processing system
CN100461710C (en) * 2007-03-15 2009-02-11 华为技术有限公司 Distributed system journal collecting method and system
CN100465965C (en) * 2006-01-05 2009-03-04 三星电子株式会社 System and method for managing log information
US7746341B2 (en) 2006-05-05 2010-06-29 Hong Fu Jin Precision Industry (Shenzhen) Co., Ltd. System and method for parsing point-cloud data
CN1863325B (en) * 2006-01-18 2010-07-07 华为技术有限公司 Exchanger in communication system and method for processing exchanger running information
CN101216800B (en) * 2008-01-02 2010-12-29 中兴通讯股份有限公司 LINUX log controller and method
CN101958837A (en) * 2010-09-30 2011-01-26 北京世纪互联工程技术服务有限公司 Log processing system, log processing method, node server and center server
CN101964795A (en) * 2010-09-30 2011-02-02 北京世纪互联工程技术服务有限公司 Log collecting system, log collection method and log recycling server
CN1972352B (en) * 2005-11-25 2011-06-22 富士施乐株式会社 Document processing apparatus and document processing method
CN102147811A (en) * 2011-03-22 2011-08-10 杭州华三通信技术有限公司 System performance analyzing method based on logs and device
CN101237326B (en) * 2008-02-29 2011-09-14 成都市华为赛门铁克科技有限公司 Method, device and system for real time parsing of device log
CN102929789A (en) * 2012-09-21 2013-02-13 曙光信息产业(北京)有限公司 Record organizational method and record organizational structure
CN103324563A (en) * 2012-03-19 2013-09-25 宇龙计算机通信科技(深圳)有限公司 Method for checking terminal event of communication terminal and communication terminal thereof
CN103412893A (en) * 2013-07-24 2013-11-27 广东电子工业研究院有限公司 Collecting system and collecting method of logs
CN103425750A (en) * 2013-07-23 2013-12-04 国云科技股份有限公司 Cross-platform and cross-application log collecting system and collecting managing method thereof
CN103544298A (en) * 2013-10-30 2014-01-29 曙光信息产业(北京)有限公司 Log analysis method and analysis device for component
CN103577443A (en) * 2012-07-30 2014-02-12 中国银联股份有限公司 Log processing system
CN103593277A (en) * 2012-08-15 2014-02-19 深圳市世纪光速信息技术有限公司 Log processing method and system
CN103793297A (en) * 2014-01-14 2014-05-14 上海上讯信息技术股份有限公司 Log protecting method based on distribution modes
CN103812676A (en) * 2012-11-08 2014-05-21 深圳中兴网信科技有限公司 Apparatus and method for realizing log data real-time association
CN103823811A (en) * 2012-11-19 2014-05-28 北京百度网讯科技有限公司 Method and system for processing journals
CN104571958A (en) * 2014-12-27 2015-04-29 北京奇虎科技有限公司 Task execution method and task execution device
CN104765775A (en) * 2015-03-17 2015-07-08 新浪网技术(中国)有限公司 Log saving method and device
CN104978256A (en) * 2014-04-10 2015-10-14 阿里巴巴集团控股有限公司 Log output method and equipment
CN105335434A (en) * 2014-08-11 2016-02-17 腾讯科技(北京)有限公司 Log management method and device, and electronic equipment
CN105550265A (en) * 2015-12-09 2016-05-04 苏州天平先进数字科技有限公司 Quasi-real-time user log collecting and processing method
CN105550264A (en) * 2015-12-09 2016-05-04 苏州天平先进数字科技有限公司 User journal collecting and processing system and method
CN106681998A (en) * 2015-11-05 2017-05-17 北京国双科技有限公司 Method and device for remotely storing logs
CN106682061A (en) * 2016-10-17 2017-05-17 暨南大学 Distributed system for collection and storage of origin data
CN107729506A (en) * 2017-10-23 2018-02-23 郑州云海信息技术有限公司 A kind of storage medium and the other dynamic adjusting method of journal stage, apparatus and system
CN108235069A (en) * 2016-12-22 2018-06-29 北京国双科技有限公司 The processing method and processing device of Web TV daily record
CN109271356A (en) * 2018-09-03 2019-01-25 中国平安人寿保险股份有限公司 Log file formats processing method, device, computer equipment and storage medium
CN109359014A (en) * 2018-09-04 2019-02-19 武汉华信联创技术工程有限公司 A kind of computer operation condition monitoring method, system and storage medium
CN109739606A (en) * 2018-12-29 2019-05-10 联想(北京)有限公司 A kind of information display method and electronic equipment
CN110427282A (en) * 2019-07-17 2019-11-08 厦门市美亚柏科信息股份有限公司 The method, apparatus and computer-readable medium restored for log fragment

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2361081A (en) * 2000-04-07 2001-10-10 Digitalsecu Co Ltd Apparatus and method for storing log files on a once only recordable medium
KR100390853B1 (en) * 2000-06-07 2003-07-10 차상균 A Logging Method and System for Highly Parallel Recovery Operation in Main-Memory Transaction Processing Systems
JP2002099326A (en) * 2000-09-22 2002-04-05 Yokogawa Electric Corp Method and apparatus for managing history of equipment
CN1150717C (en) * 2001-06-21 2004-05-19 华为技术有限公司 Journal management system of integrated network manager

Cited By (47)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1972352B (en) * 2005-11-25 2011-06-22 富士施乐株式会社 Document processing apparatus and document processing method
CN100412807C (en) * 2005-12-22 2008-08-20 国际商业机器公司 Method and apparatus for managing event logs for processes in a digital data processing system
CN100465965C (en) * 2006-01-05 2009-03-04 三星电子株式会社 System and method for managing log information
CN1863325B (en) * 2006-01-18 2010-07-07 华为技术有限公司 Exchanger in communication system and method for processing exchanger running information
US7746341B2 (en) 2006-05-05 2010-06-29 Hong Fu Jin Precision Industry (Shenzhen) Co., Ltd. System and method for parsing point-cloud data
WO2008064593A1 (en) * 2006-11-30 2008-06-05 Alibaba Group Holding Limited A log analyzing method and system based on distributed compute network
US8671097B2 (en) 2006-11-30 2014-03-11 Alibaba Group Holdings Limited Method and system for log file analysis based on distributed computing network
CN100461710C (en) * 2007-03-15 2009-02-11 华为技术有限公司 Distributed system journal collecting method and system
CN101216800B (en) * 2008-01-02 2010-12-29 中兴通讯股份有限公司 LINUX log controller and method
CN101237326B (en) * 2008-02-29 2011-09-14 成都市华为赛门铁克科技有限公司 Method, device and system for real time parsing of device log
CN101958837A (en) * 2010-09-30 2011-01-26 北京世纪互联工程技术服务有限公司 Log processing system, log processing method, node server and center server
CN101964795A (en) * 2010-09-30 2011-02-02 北京世纪互联工程技术服务有限公司 Log collecting system, log collection method and log recycling server
CN102147811A (en) * 2011-03-22 2011-08-10 杭州华三通信技术有限公司 System performance analyzing method based on logs and device
CN102147811B (en) * 2011-03-22 2014-04-16 杭州华三通信技术有限公司 System performance analyzing method based on logs and device
CN103324563A (en) * 2012-03-19 2013-09-25 宇龙计算机通信科技(深圳)有限公司 Method for checking terminal event of communication terminal and communication terminal thereof
CN103324563B (en) * 2012-03-19 2016-08-24 宇龙计算机通信科技(深圳)有限公司 Check method and the communication terminal thereof of the terminal affair of communication terminal
CN103577443B (en) * 2012-07-30 2017-05-31 中国银联股份有限公司 A kind of log processing system
CN103577443A (en) * 2012-07-30 2014-02-12 中国银联股份有限公司 Log processing system
CN103593277A (en) * 2012-08-15 2014-02-19 深圳市世纪光速信息技术有限公司 Log processing method and system
CN102929789A (en) * 2012-09-21 2013-02-13 曙光信息产业(北京)有限公司 Record organizational method and record organizational structure
CN103812676A (en) * 2012-11-08 2014-05-21 深圳中兴网信科技有限公司 Apparatus and method for realizing log data real-time association
CN103823811A (en) * 2012-11-19 2014-05-28 北京百度网讯科技有限公司 Method and system for processing journals
CN103425750A (en) * 2013-07-23 2013-12-04 国云科技股份有限公司 Cross-platform and cross-application log collecting system and collecting managing method thereof
CN103412893A (en) * 2013-07-24 2013-11-27 广东电子工业研究院有限公司 Collecting system and collecting method of logs
CN103544298A (en) * 2013-10-30 2014-01-29 曙光信息产业(北京)有限公司 Log analysis method and analysis device for component
CN103544298B (en) * 2013-10-30 2017-09-08 曙光信息产业(北京)有限公司 The log analysis method and analytical equipment of component
CN103793297A (en) * 2014-01-14 2014-05-14 上海上讯信息技术股份有限公司 Log protecting method based on distribution modes
CN103793297B (en) * 2014-01-14 2017-10-20 上海上讯信息技术股份有限公司 Daily record guard method based on distribution mode
CN104978256A (en) * 2014-04-10 2015-10-14 阿里巴巴集团控股有限公司 Log output method and equipment
CN105335434A (en) * 2014-08-11 2016-02-17 腾讯科技(北京)有限公司 Log management method and device, and electronic equipment
CN105335434B (en) * 2014-08-11 2020-08-25 腾讯科技(北京)有限公司 Log management method and device and electronic equipment
CN104571958B (en) * 2014-12-27 2019-06-07 北京奇虎科技有限公司 A kind of task executing method and device
CN104571958A (en) * 2014-12-27 2015-04-29 北京奇虎科技有限公司 Task execution method and task execution device
CN104765775A (en) * 2015-03-17 2015-07-08 新浪网技术(中国)有限公司 Log saving method and device
CN106681998A (en) * 2015-11-05 2017-05-17 北京国双科技有限公司 Method and device for remotely storing logs
CN105550264A (en) * 2015-12-09 2016-05-04 苏州天平先进数字科技有限公司 User journal collecting and processing system and method
CN105550265A (en) * 2015-12-09 2016-05-04 苏州天平先进数字科技有限公司 Quasi-real-time user log collecting and processing method
CN106682061A (en) * 2016-10-17 2017-05-17 暨南大学 Distributed system for collection and storage of origin data
CN106682061B (en) * 2016-10-17 2019-09-17 暨南大学 It is a kind of distribution origination data collect and storage system
CN108235069A (en) * 2016-12-22 2018-06-29 北京国双科技有限公司 The processing method and processing device of Web TV daily record
CN107729506A (en) * 2017-10-23 2018-02-23 郑州云海信息技术有限公司 A kind of storage medium and the other dynamic adjusting method of journal stage, apparatus and system
CN109271356A (en) * 2018-09-03 2019-01-25 中国平安人寿保险股份有限公司 Log file formats processing method, device, computer equipment and storage medium
CN109271356B (en) * 2018-09-03 2024-05-24 中国平安人寿保险股份有限公司 Log file format processing method, device, computer equipment and storage medium
CN109359014A (en) * 2018-09-04 2019-02-19 武汉华信联创技术工程有限公司 A kind of computer operation condition monitoring method, system and storage medium
CN109739606A (en) * 2018-12-29 2019-05-10 联想(北京)有限公司 A kind of information display method and electronic equipment
CN110427282A (en) * 2019-07-17 2019-11-08 厦门市美亚柏科信息股份有限公司 The method, apparatus and computer-readable medium restored for log fragment
CN110427282B (en) * 2019-07-17 2022-05-27 厦门市美亚柏科信息股份有限公司 Method, apparatus and computer readable medium for log fragment recovery

Also Published As

Publication number Publication date
CN100375047C (en) 2008-03-12

Similar Documents

Publication Publication Date Title
CN1670708A (en) Management method for computer log
CN1303523C (en) Figure user interface revising method and recording medium
JP4129819B2 (en) Database search system, search method thereof, and program
US8645905B2 (en) Development artifact searching in an integrated development environment
US11568013B2 (en) Methods and systems for providing a search service application
CN1713179A (en) Impact analysis in an object model
US8108373B2 (en) Selecting an author of missing content in a content management system
CN101840432B (en) Data mining device based on Deep Web deep dynamic data and method thereof
US20080243897A1 (en) Autonomic updating of templates in a content management system
CN1755720A (en) Methods and systems for caching and synchronizing project data
CN101454779A (en) Search-based application development framework
US12086194B2 (en) Methods and systems for building search service application
US8458215B2 (en) Dynamic functional module availability
US20120054636A1 (en) Document management framework
CN1766876A (en) System and method for managing structured document
US9373093B2 (en) Gateway service manager for business object applications
US7844976B2 (en) Processing data across a distributed network
US9397976B2 (en) Tuning LDAP server and directory database
US9135251B2 (en) Generating simulated containment reports of dynamically assembled components in a content management system
CN1698057A (en) System and method for automatically starting a document on a workflow process
CN1604043A (en) Method for autonomic self-learning in selecting resources for dynamic provisioning
WO2016206395A1 (en) Weekly report information processing method and device
CN109446263A (en) A kind of data relationship correlating method and device
US20120259847A1 (en) Collaborative Data Appliance
US8136121B2 (en) Graphical message format builder

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20080312

Termination date: 20210317

CF01 Termination of patent right due to non-payment of annual fee