DocumentCode :
1831661
Title :
System State Discovery Via Information Content Clustering of System Logs
Author :
Makanju, Adetokunbo ; Zincir-Heywood, A. Nur ; Milios, Evangelos E.
Author_Institution :
Fac. of Comput. Sci., Dalhousie Univ., Halifax, NS, Canada
fYear :
2011
fDate :
22-26 Aug. 2011
Firstpage :
301
Lastpage :
306
Abstract :
Self-awareness is an important attribute for any system to have before it is capable of self-management. A system needs to have a continuous stream of real-time data to analyze to allow it be aware of its internal state. To this end, previous approaches have utilized system performance metrics and system log data to characterize system internal state. In using system logs to characterize system internal state, the computation of strongly correlated message types is necessary. In this work, we show that strongly correlated message types can be easily discovered without much computation. Our work explores a natural behaviour of system logs where system log data partitioned using source and time information contain correlated message types. We demonstrate how the groups of partitions, which contain correlated message types, can be found by clustering the partitions based on their entropy-based information content. We evaluate our method using cluster cohesion, cluster separation and cluster conceptual purity as metrics. The results show that our proposed method not only produces well-formed clusters but also clusters that can be mapped to different alert states with a high degree of confidence.
Keywords :
entropy; pattern clustering; software fault tolerance; system monitoring; autonomic computer system; cluster cohesion; cluster conceptual purity; cluster separation; entropy-based information content clustering; self-awareness; self-management; system internal state; system log data; system performance metrics; system state discovery; Clustering algorithms; Clustering methods; Computers; Entropy; Measurement; Monitoring; System performance; Algorithms; Autonomic Computing; Modeling and Assessment; Networked Systems; System Management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
Conference_Location :
Vienna
Print_ISBN :
978-1-4577-0979-1
Electronic_ISBN :
978-0-7695-4485-4
Type :
conf
DOI :
10.1109/ARES.2011.51
Filename :
6045954
Link To Document :
بازگشت