Spatio-temporal factorization of log data for understanding network events

Tatsuaki Kimura, Keisuke Ishibashi, Tatsuya Mori, Hiroshi Sawada, Tsuyoshi Toyono, Ken Nishimatsu, Akio Watanabe, Akihiro Shimoda, Kohei Shiomoto

研究成果: Conference contribution

65 被引用数 (Scopus)

抄録

Understanding the impacts and patterns of network events such as link flaps or hardware errors is crucial for diagnosing network anomalies. In large production networks, analyzing the log messages that record network events has become a challenging task due to the following two reasons. First, the log messages are composed of unstructured text messages generated by vendor-specific rules. Second, network equipment such as routers, switches, and RADIUS severs generate various log messages induced by network events that span across several geographical locations, network layers, protocols, and services. In this paper, we have tackled these obstacles by building two novel techniques: statistical template extraction (STE) and log tensor factorization (LTF). STE leverages a statistical clustering technique to automatically extract primary templates from unstructured log messages. LTF aims to build a statistical model that captures spatial-temporal patterns of log messages. Such spatial-temporal patterns provide useful insights into understanding the impacts and root cause of hidden network events. This paper first formulates our problem in a mathematical way. We then validate our techniques using massive amount of network log messages collected from a large operating network. We also demonstrate several case studies that validate the usefulness of our technique.

本文言語English
ホスト出版物のタイトルIEEE INFOCOM 2014 - IEEE Conference on Computer Communications
出版社Institute of Electrical and Electronics Engineers Inc.
ページ610-618
ページ数9
ISBN(印刷版)9781479933600
DOI
出版ステータスPublished - 2014
イベント33rd IEEE Conference on Computer Communications, IEEE INFOCOM 2014 - Toronto, ON, Canada
継続期間: 2014 4月 272014 5月 2

出版物シリーズ

名前Proceedings - IEEE INFOCOM
ISSN(印刷版)0743-166X

Conference

Conference33rd IEEE Conference on Computer Communications, IEEE INFOCOM 2014
国/地域Canada
CityToronto, ON
Period14/4/2714/5/2

ASJC Scopus subject areas

  • コンピュータ サイエンス(全般)
  • 電子工学および電気工学

フィンガープリント

「Spatio-temporal factorization of log data for understanding network events」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル