Oracle Corporation
Anomaly detection based on events composed through unsupervised clustering of log messages
Last updated:
Abstract:
The disclosed embodiments provide a system that detects an anomaly in a computer system based on log messages. During operation, the system receives log messages generated by the computer system during operation of the computer system. Next, the system maps each received log message to a cluster in a set of clusters of log messages, wherein each cluster is associated with a specific event. The system then forms events for consecutive log messages into sequences of events. Finally, the system performs anomaly detection based on the sequences of events, wherein if an anomaly is detected, the system triggers an alert.
Status:
Grant
Type:
Utility
Filling date:
21 May 2018
Issue date:
21 Jul 2020