As businesses evolve rapidly and digital transformation deepens, the scale, stability, and standardization of information systems have become increasingly critical. IT systems are trending toward massive scale and heterogeneity, with enterprises operating a large number of internal systems and applications. By collecting, monitoring, and analyzing system log data, organizations can promptly identify and resolve potential faults, optimize system performance, predict possible issues, and take preventive measures. At the same time, a log management platform delivers significant value in scenarios such as information recording, operational auditing, and problem troubleshooting.
Based on the needs and pain points outlined above, a provincial-level city commercial bank built a unified, enterprise-wide log management center using the CanWay BlueWhale Log Management Platform (hereinafter referred to as the "Log Management Platform"), and implemented a professional business monitoring system based on log content to meet the enterprise's monitoring requirements for log data and business observability.
01 Business Scenario
The enterprise operates several hundred business systems internally, generating approximately 6 TB of log data daily, with peak-day volumes reaching around 10 TB. These systems also support over a hundred business scenarios for external-facing services.
Prior to the product deployment, the enterprise lacked professional tools — technical staff spent significant time reviewing logs and troubleshooting faults on a daily basis, resulting in low response and processing efficiency and making it difficult to ensure business stability. Additionally, the inadequacy of business operation monitoring tools made it challenging for internal staff to observe business operations in real time and promptly identify and address business faults.
02 Pain Points & Requirements
Log format inconsistency creates cleansing and parsing challenges. Different systems and applications produce logs in varying formats, making it difficult to uniformly cleanse and parse log data.
Lack of unified management prevents closed-loop IT O&M. The bank's log data was scattered across servers in different data centers, tenants, and availability zones. Query and retrieval were inefficient, correlation analysis was impossible, and IT O&M workflows could not close the "last mile."
Siloed business monitoring systems prevent multi-module joint fault analysis. The existing business monitoring systems operated independently, unable to achieve linked fault analysis across multiple modules.
03 Solution
Log Format Standardization to Improve Business System Maintainability
Drawing on CanWay's years of project experience in the IT O&M domain and the bank's specific circumstances, the project team helped the client establish a bank-wide log output standard. The standard covers log levels, log storage, file naming conventions, log formats, and Log Auditing. This standard enables the CanWay observability system to parse and store log content more easily and implement Monitoring and Alerting at the business-scenario level through log data.
Building a Unified Log Center for Centralized Management of Massive, Heterogeneous Logs
Centralize the storage and management of heterogeneous, distributed logs from the physical layer, system layer, and application layer — including logs from asset types such as applications, service components, operating systems, containers, and hardware devices. Through the Log Management Platform's high-speed, stable log search and analysis capabilities combined with Monitoring and Alerting, the operational value of log data and IT O&M troubleshooting efficiency are comprehensively enhanced.
Extracting Business Operation Call Relationships from Log Data to Generate Golden Monitoring Metrics
From standardized logs, extract key fields and map the operational topology of each system within business scenarios to intuitively display actual business operation status. Aggregate and compute the four golden metrics: transaction volume, transaction duration, response rate, and success rate.
04 Results
Multiple Monitoring Methods for Multi-Scenario Business Monitoring
The Log Management Platform achieves multi-scenario monitoring of the bank's production business through log keyword detection, log metric data detection, and no-data anomaly detection, combined with 8 anomaly detection algorithms, ensuring business stability. For example, the securities market opens trading during specific time windows, and certain logs are output at specific times accordingly. In such cases, log monitoring detection needs to be configured using year-over-year comparison strategies.

Log Search: Enhancing Log Data Efficiency for Rapid Problem Localization
As the bank's business systems continue to grow in number and complexity, real-world business scenarios involve cross-system or cross-business-line transactions that require the coordinated operation of multiple different systems. If a fault occurs at any point, it may impact the entire transaction flow, necessitating the retrieval of logs from multiple business systems for troubleshooting. The Log Management Platform's joint search functionality enables correlated searches across multiple business system logs. Combined with real-time log streaming, log context views, and other log search features, it helps IT O&M and development teams rapidly locate complex issues.

Business Monitoring: Real-Time Observation of Business Operations
Through standardized log cleansing and analysis, call relationships between systems are aggregated in real time, displaying the actual operational logic of each business scenario. Simultaneously, metric data is extracted to present a comprehensive business operations dashboard. Business operations are monitored from two dimensions — scenarios and systems — with support for drill-down analysis from scenario to system to interface to individual request, enabling layered analysis of business operation data.



05 Benefits
Unified collection and management of logs from 200+ business systems, achieving full-volume log management;
Compared to the previous approach of manually retrieving business logs from servers, IT O&M troubleshooting efficiency improved by 60% after deploying the Log Management Platform;
Standardized internal business system log specifications, improving system stability, security, and maintainability;
Real-time monitoring of business system operations, providing robust assurance for business continuity;
Layered drill-down analysis capability from the business level down to the microservice interface level, leaving no operational risks hidden.
06 Applicable Scenarios
The Log Management Platform is suitable for enterprises with the following business scenario requirements:
Massive, heterogeneous business logs requiring centralized collection and management;
A need for monitoring key metrics within log content;
A need for high-performance, user-friendly log search by business system to support business log troubleshooting;
A need for business-scenario-level monitoring systems that provide real-time observation of business operations;
A need for log-level fault analysis and root cause localization capabilities.

















