• DocumentCode
    3040180
  • Title

    LogView: Visualizing Event Log Clusters

  • Author

    Makanju, Adetokunbo ; Brooks, Stephen ; Zincir-Heywood, A. Nur ; Milios, Evangelos E.

  • Author_Institution
    Fac. of Comput. Sci., Dalhousie Univ., Halifax, NS
  • fYear
    2008
  • fDate
    1-3 Oct. 2008
  • Firstpage
    99
  • Lastpage
    108
  • Abstract
    Event logs or log files form an essential part of any network management and administration setup. While log files are invaluable to a network administrator, the vast amount of data they sometimes contain can be overwhelming and can sometimes hinder rather than facilitate the tasks of a network administrator. For this reason several event clustering algorithms for log files have been proposed, one of which is the event clustering algorithm proposed by Risto Vaarandi, on which his simple log file clustering tool (SLCT) is based. The aim of this work is to develop a visualization tool that can be used to view log files based on the clusters produced by SLCT. The proposed visualization tool, which is called LogView, utilizes treemaps to visualize the hierarchical structure of the clusters produced by SLCT. Our results based on different application log files show that LogView can ease the summarization of vast amount of data contained in the log files. This in turn can help to speed up the analysis of event data in order to detect any security issues on a given application.
  • Keywords
    computer network management; data visualisation; file organisation; security of data; system monitoring; LogView; administration setup; event clustering algorithm; event log cluster visualization; hierarchical structure; log files; network administrator; network management; security issues; simple log file clustering tool; visualization tool; Clustering algorithms; Computer science; Computer security; Data analysis; Data security; Data visualization; Event detection; Fault detection; Monitoring; Privacy; Clustering; Event Logs; SLCT; Treemaps; Visualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy, Security and Trust, 2008. PST '08. Sixth Annual Conference on
  • Conference_Location
    Fredericton, NB
  • Print_ISBN
    978-0-7695-3390-2
  • Type

    conf

  • DOI
    10.1109/PST.2008.17
  • Filename
    4641277