Management of Very Large Security Event Logs.
Balasubramanian Ramaiah, Myungsook Klassen · International Conference on Internet Computing · 2007
Modern computing systems generate huge amounts of system event log data which are used to address a wide range of important issues such as auditing network status. The traditional method of analyzing event log data is labor intensive and error-prone. In this paper, we will describe our efforts on architecting an integrated log data mining system for automatic management. The system includes a SQL server as a central log server to store historic event log data from other monitored computers. The relational database offers many features desirable for conducting network management: indexes, query optimizer, and powerful query language. We evaluate SQL server hardware performance and query execution speeds with two different sizes of real data.