You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从杀毒软件日志中提取指定杀毒操作字段并补全缺失值

解决杀毒软件日志操作信息提取问题

问题核心

需要从杀毒软件日志的indicators列表中,提取field为actResult的字典里的value(仅匹配File cleaned/File deleted/File quarantined),要求每条日志对应一个结果,缺失时用“-”填充,最终列表长度必须和日志ID数量一致。

现有脚本的问题

  1. 嵌套循环遍历每个indicator,导致单条日志若包含多个indicator,会生成多个结果,破坏和日志ID的对应关系
  2. 仅判断value是否在目标列表,未校验field为actResult,容易误提取无关的value字段

修正后的代码

target_actions = ['File cleaned', 'File deleted', 'File quarantined']
action_results = []

# 提取日志ID列表(用于验证长度匹配)
log_ids = [log['id'] for log in logs]
print("日志ID列表:", log_ids)

for log in logs:
    # 初始化当前日志的操作结果为默认值
    current_action = '-'
    # 遍历当前日志的所有indicators,无此字段时用空列表容错
    for indicator in log.get('indicators', []):
        # 只筛选field为actResult且value在目标列表中的条目
        if indicator.get('field') == 'actResult' and indicator.get('value') in target_actions:
            current_action = indicator['value']
            # 找到匹配项后直接跳出循环,避免重复处理
            break
    # 将当前日志的结果加入列表
    action_results.append(current_action)

print("操作结果列表:", action_results)
print("长度匹配验证:", len(action_results) == len(log_ids))

关键改进点

  • 单条日志对应单个结果:外层循环仅遍历日志条目,每条日志初始化一个默认值,确保最终列表长度和日志数量一致
  • 精准筛选目标字段:增加field == 'actResult'的判断,避免误提取其他value字段
  • 容错处理:用log.get('indicators', [])避免日志缺失indicators键时抛出异常
  • 效率优化:找到匹配的actResult后立即break,无需遍历剩余indicator

内容的提问来源于stack exchange,提问作者OverflowStack

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 21:15:00