A Comprehensive Linux Log Dataset with Root Cause and Remediation for Security Analysis

Ananya S Shastry, M P Shreyas, Raghavendhar Karthik, B N Chinmaya, H. T. Chethana, Shek Diya Sarkar · 2025

Linux security monitoring is built on system logs that capture events ranging from process executions to kernel failures to its authentication attempts. These records are bulky and redundant, making it cumbersome to analyse manually. To overcome this, a dataset comprising of 12,685 Linux logs generated from Ubuntu virtual machines configured to mimic real-time scenarios were collected. Five threat levels classification (0–Emergency to 4-Warning) is applied to logs according to severity, ensuring a structured security analysis. Security management and process control represent essential components among the multiple critical aspects they handle. Redundancy was eliminated through pre-processing. Referring to Linux and Red Hat manuals to compare logs to causes and repair methods. Through this dataset, organizations can automate log file threat detection with real-time processing capabilities and exact threat classification and issue recognition functions. The efficiency of security monitoring improves through this dataset because it allows proactive along with reactive threat mitigation and response measures.

Read the paper · More papers on PaperTik