The log as evidence sources is selected for extracting evidence on the illegal computer invasion.Because the capacity of the log is usually larger,so combined with data mining and fuzzy mathematical,log analysis algorithm based on the clustering of Chameleon is discussed and studied.And then,according to the characteristics of Linux system log files,specific log feature extraction algorithm is presented,and performance from log collection simulated test and analysis of the invasion are put forward.