Mining Causality of Network Events in Log Data

被引:39
|
作者
Kobayashi, Satoru [1 ]
Otomo, Kazuki [1 ]
Fukuda, Kensuke [2 ]
Esaki, Hiroshi [1 ]
机构
[1] Univ Tokyo, Grad Sch Informat Sci & Technol, Tokyo 1138654, Japan
[2] Natl Inst Informat & Sokendai, Tokyo 1018430, Japan
关键词
Causal inference; log data; network management; PC algorithm; root cause analysis;
D O I
10.1109/TNSM.2017.2778096
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network log messages (e.g., syslog) are expected to be valuable and useful information to detect unexpected or anomalous behavior in large scale networks. However, because of the huge amount of system log data collected in daily operation, it is not easy to extract pinpoint system failures or to identify their causes. In this paper, we propose a method for extracting the pinpoint failures and identifying their causes from network syslog data. The methodology proposed in this paper relies on causal inference that reconstructs causality of network events from a set of time series of events. Causal inference can filter out accidentally correlated events, thus it outputs more plausible causal events than traditional cross-correlation-based approaches can. We apply our method to 15 months' worth of network syslog data obtained from a nationwide academic network in Japan. The proposed method significantly reduces the number of pseudo correlated events compared with the traditional methods. Also, through three case studies and comparison with trouble ticket data, we demonstrate the effectiveness of the proposed method for practical network operation.
引用
收藏
页码:53 / 67
页数:15
相关论文
共 50 条
  • [1] Network log mining by Bayesian network
    Chen, Jiamin
    Lu, Qiang
    2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 3, 2008, : 239 - 242
  • [2] Spatio-temporal Factorization of Log Data for Understanding Network Events
    Kimura, Tatsuaki
    Ishibashi, Keisuke
    Mori, Tatsuya
    Sawada, Hiroshi
    Toyono, Tsuyoshi
    Nishimatsu, Ken
    Watanabe, Akio
    Shimoda, Akihiro
    Shiomoto, Kohei
    2014 PROCEEDINGS IEEE INFOCOM, 2014, : 610 - 618
  • [3] Mining Delay Propagation Causality within an Airport Network from Historical Data
    Zhu, Dan
    Wang, Huawei
    Tan, Xianghua
    AEROSPACE, 2024, 11 (07)
  • [4] Mining causality from imperfect data
    Mazlack, LJ
    APPLIED COMPUTATIONAL INTELLIGENCE, 2004, : 155 - 160
  • [5] Web Log Data Analysis and Mining
    Grace, L. K. Joshila
    Maheswari, V.
    Nagamalai, Dhinaharan
    ADVANCED COMPUTING, PT III, 2011, 133 : 459 - 469
  • [6] Visual data mining of log files
    Francia, Guillermo, III
    Trifas, Monica
    Brown, Dorothy
    Francia, Rahjima
    Scott, Chrissy
    INNOVATIONS AND ADVANCED TECHNIQUES IN COMPUTER AND INFORMATION SCIENCES AND ENGINEERING, 2007, : 531 - 535
  • [7] Data preparation in web log mining
    Lu, Lina
    Yang, Yiling
    Guan, Xudong
    Wei, Hengyi
    Jisuanji Gongcheng/Computer Engineering, 2000, 26 (04): : 66 - 67
  • [8] Web log data mining analysis
    Lu Ansheng
    2012 INTERNATIONAL CONFERENCE ON INTELLIGENCE SCIENCE AND INFORMATION ENGINEERING, 2012, 20 : 213 - 215
  • [9] Mining Online Training Log Data
    Mehringer, Susan
    Myers, Christopher R.
    Houchins, Jennifer
    Rivera, Lorna
    PEARC '19: PROCEEDINGS OF THE PRACTICE AND EXPERIENCE IN ADVANCED RESEARCH COMPUTING ON RISE OF THE MACHINES (LEARNING), 2019,
  • [10] Mining causality knowledge from textual data
    Pechsiri, C
    Kawtrakul, A
    Piriyakul, R
    PROCEEDINGS OF THE IASTED INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND APPLICATIONS, 2006, : 85 - +