Umeå University's logo

umu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Machine Learning-Assisted Log Analysis for Uncovering Anomalies
Umeå University, Faculty of Science and Technology, Department of Computing Science.
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

Logs, which are semi-structured records of system runtime information, contain a lot of valuable insights. By looking at the logs, developers and operators can analyse their system’s behavior. This is especially necessary when something in the system goes wrong, as nonconforming logs may indicate a root cause. With the growing complexity and size of IT systems however, millions of logs are generated hourly. Reviewing them manually can therefore become an all consuming task. A potential solution to aid in log analysis is machine learning. By leveraging their ability to automatically learn from experience, machine learning algorithms can be modeled to automatically analyse logs. In this thesis, machine learning is used to perform anomaly detection, which is the discovery of so called nonconforming logs. An experiment is created in which four feature extraction methods - that is four ways of creating data representations from the logs - are tested in combination with three machine learning models. These models are: LogCluster, PCA and SVM. Additionally, a neural network architecture called an LSTM network is explored as well, a network that can craft its own features and analyse them. The results show that the LSTM performed the best, in terms of precision, recall and f1-score, followed by SVM, LogCluster and PCA, in combination with a feature extraction method using word embeddings.

Place, publisher, year, edition, pages
2024. , p. 51
Series
UMNAD ; 1471
Keywords [en]
machine learning, log analysis, anomaly detection, deep learning
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:umu:diva-227113OAI: oai:DiVA.org:umu-227113DiVA, id: diva2:1877010
External cooperation
ITS vid Umeå Universitet
Educational program
Master's Programme in Computing Science
Supervisors
Examiners
Available from: 2024-06-26 Created: 2024-06-25 Last updated: 2024-06-26Bibliographically approved

Open Access in DiVA

fulltext(1217 kB)142 downloads
File information
File name FULLTEXT01.pdfFile size 1217 kBChecksum SHA-512
6081df282ee75ad953858d5505194c9d67f4a2c107f3d0bc6e73fe50d8b45befd81de062a1c2a69460b2ac38f2f49b8894f937b847f247c6a06ecc45d5b77dae
Type fulltextMimetype application/pdf

By organisation
Department of Computing Science
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 142 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 287 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf