Poikkeavuuksien löytäminen Linux System Logista syväoppimisen avulla
Mäkinen, Minttu · Aaltodoc (Aalto University) · 2019
In software development and testing, reading the system logs to find causes for errors is a common activity. When developing large, complex and concurrent systems such as Linux distributions, the amount of log files can grow very large and finding the relevant log entries is laborious. A deep learning based model, DeepLog, has been previously proposed for automatizing system log anomaly detection. The DeepLog method begins with tokenizing the log entries and then feeds the tokenized entries to an LSTM neural network. This thesis compares alternatives for LSTM network structure for log anomaly detection. LSTM is compared to three other networks: Gated Recurrent Unit (GRU), Temporal Convolutional Network (TCN) and Transformer. The results of the comparison show that Transformer performs clearly the best, reaching accuracy of 98.9 % on the test data.