Efficient structured log storage
Pavel Kácha · Annual Conference on Computers · 2010
The paper describes working prototypes of several possible structured audit trail (logs) storages and compares their characteristics and performance parameters. The storage receives information about the format of data generated by daemons and its API enables queries according to individual attributes obtained by analyzing log rows. Such a system enables for creating applications, currently too difficult because of the text nature of the audit trail, such as looking for security anomalies, their correlation and statistical analysis.