Attention-based BiGRU-CNN for system log anomaly detection
Kailong Wang · 2024
Logs record events, state changes and error information during system operation, and log anomaly detection can quickly and accurately locate the source of the problem and provide powerful help for further problem solving. However, there are often multiple modules in the system, and their logs have very different output styles and complex dependencies. To this end, this paper proposes a CNN-BiGRU system log anomaly detection method based on the attention mechanism, which utilizes TimeBERT, a time-sensitive pre-trained language model, to extract the log message features, obtain the contextual and temporal correlations of the log sequences, and use the CNN-BiGRU model based on the attention mechanism for further log sequence anomaly detection. The method fully utilizes the temporal, keyword, and semantic information in the logs, and the experimental results on three public datasets show that the proposed method achieves better detection results compared to the four benchmark methods.