Deep unsupervised system log monitoring - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Deep unsupervised system log monitoring

Résumé

This work proposes a new unsupervised deep generative model for system logs. It is designed to be generic and may be used in various downstream anomaly detection tasks, such as system failure or intrusion detection. It is based on the (reasonable) assumption that most log lines follow rather fixed syntactic structures, which enables us to replace the costly traditional convolutional and recurrent architectures by a much faster component: a deep averaging network. Our model still exploits a standard recurrent model with attention to capture the dependencies between successive log lines. We experimentally validate the proposed generative model on a real dataset obtained from a state-of-the-art High Performance Computing cluster and show the effectiveness of the proposed approach in modeling the "normal" behaviour of the system.
Fichier principal
Vignette du fichier
paper.pdf (318.73 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02295951 , version 1 (24-09-2019)

Identifiants

  • HAL Id : hal-02295951 , version 1

Citer

Hubert Nourtel, Christophe Cerisara, Samuel Cruz-Lara. Deep unsupervised system log monitoring. PROFES 2019 - 20th International Conference on Product-Focused Software Process Improvement, Nov 2019, Barcelona, Spain. ⟨hal-02295951⟩
213 Consultations
886 Téléchargements

Partager

Gmail Facebook X LinkedIn More