LogInsight: A Tool for Log Analysis and Threat Detection

Yashashwi Patil, Sharwari S Solpaure, Shravani Umare, Swarada Bhosale · 2025

As organizations grow, the amount of log data from systems such as firewalls, servers, and applications increases, making it difficult to detect cyber security threats manually. Real-world cases, such as brute-force attacks on Microsoft Exchange Servers highlight the need for efficient log analysis. In these attacks, the authentication logs showed repeated failed attempts to log in from unusual IP addresses, and other types of logs, such as system logs, firewall logs, are also playing a crucial role. However, many organizations struggled to detect and respond to the threat quickly due to the overwhelming volume of log data and lack of effective analysis tools. Existing tools like Splunk, ELK Stack, and Graylog help in managing and visualizing logs but often lack advanced features using machine learning to detect threats. They can also be complex to set up and use, and may not adapt easily to new types of logs or attacks. To address these issues, LogInsight is a tool developed for real-time log analysis and threat detection. LogInsight uses machine learning models specifically designed for system, network, and cloud logs to find unusual activity and alert users for the same. Proposed solution focuses on ease of use, provides support for multiple log formats, and uses advanced models for better accuracy. LogInsight also ensures scalability with technologies like MongoDB, Docker, and AWS, allowing it to handle large amounts of log data. Tests show LogInsight accurately detects threats and provides actionable insights, making it a reliable tool to enhance security and respond faster to threats.

Read the paper · More papers on PaperTik