Log Anomaly Detection Method Based On Multi-Feature Graph Embedding
Jizhao Liu, Le Li · 2024
Modern software systems generate a large amount of logs during runtime, which reflect the system's operational status. The reliability of system services relies on automatic log anomaly detection. Researchers have proposed anomaly detection methods based on log features and sequence structures. However, existing methods, while utilizing various log features and structured information, still do not exploit the implicit feature information of logs and fail to fully capture the structural information of log sequences when fusing contextual event features of logs. Therefore, we propose an anomaly detection method based on multi-feature graph embedding, LogMFG, which fully extracts explicit, implicit, parameter, and semantic features of logs using a defined multi-feature extraction method for log messages. Log messages are represented as graph nodes with multiple feature attributes. Finally, GTN (Graph Transformer Network) is utilized to effectively fuse multi-feature information of log events with the global structure of log sequences for anomaly detection in log sequences. Experimental results on public datasets HDFS and BGL show that LogMFG outperforms eight log anomaly detection methods, with an anomaly log detection F1 score higher than 0.9992, and surpasses the state-of-the-art LogGT algorithm in offline log anomaly detection.