Abnormality analysis of streamed log data

Ashot N. Harutyunyan, Arnak Poghosyan, Naira Grigoryan, Mazda A. Marvasti · 2014

We examine the determination of abnormality of streamed data using the statistical structure of the meta-data associated with it. The vital need for such a subject within a heterogeneous log based environment in real-time comes from the fact that most cloud based applications will use text-based logging as a means of reporting application behavior. The sheer volume of such logs makes retrospective analysis infeasible due to large processing and storage requirements. Our approach is based on conversion of the original data stream into meta-data (graph) and revealing the dominating (normal) statistical patterns within it. Real-time analysis of the stream compared with the meta-data model determines the degree of anomaly of the current data. The resulting graph also reveals the fundamental structure (“behavioral footprint”) of the data beyond the sources (physical or virtual devices) and processes.

Read the paper · More papers on PaperTik