Supercharge Your Innovation With Domain-Expert AI Agents!

Log anomaly detection method and device

An anomaly detection and log technology, applied in the field of log anomaly detection, can solve problems such as unbalanced log data, achieve rich semantic information understanding ability, high detection accuracy, and solve adverse effects

Active Publication Date: 2021-06-01
ZHENGZHOU TOBACCO RES INST OF CNTC
View PDF4 Cites 1 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0006] The present invention provides a log anomaly detection method and device, which are used to solve the problem that the methods in the prior art cannot solve the adverse effects caused by the unbalanced log data

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Log anomaly detection method and device
  • Log anomaly detection method and device
  • Log anomaly detection method and device

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0032] Method example:

[0033] An embodiment of a log anomaly detection method of the present invention, its overall flow is as follows figure 1 As shown, this embodiment performs anomaly detection on logs in the tobacco big data cloud platform, that is, implements a Context-aware-based tobacco big data cloud platform log anomaly detection method.

[0034] Step 1, collect logs.

[0035] Deploy the FileBeat log collection system on all tobacco big data processing nodes (DataNodes), read the logs at the corresponding locations according to the configuration, and output the collected raw logs (Raw log) to Kafka's fixed topic; by subscribing to Kafka's topic, you can Read the collected log sequence (Log sequence) in real time.

[0036] Step 2, use the log parser Drain to parse each log into a log event.

[0037] The log generally has a fixed structure, records key information when the system is running, and is an unstructured free text. figure 2 It is a log of the hadoop big...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention belongs to the technical field of log anomaly detection, and particularly relates to a log anomaly detection method and device. The method comprises the steps: analyzing a log into a log event; and inputting the log event into the log detection model to obtain an anomaly detection result of the log, wherein the log detection model comprises a log vector conversion module and a result classification module, and the log vector conversion module is used for converting log events to obtain vector representation. The conversion processing comprises the following steps: converting each word in the log event into a word vector to obtain a vector sequence of the log event, and generating a region matrix of each word; inputting the vector sequence into a convolutional layer to obtain an adaptive context unit; multiplying the region matrix of all words in the log event by each element in the self-adaptive context to obtain mapping embedding; and performing maximum pooling operation and summation on the mapping embedding to obtain vector representation of the log event. According to the method, the log can be understood more easily, the adverse effect caused by log data imbalance can be effectively solved, and the detection precision is high.

Description

technical field [0001] The invention belongs to the technical field of log anomaly detection, and in particular relates to a log anomaly detection method and device. Background technique [0002] In recent years, logs have been used to detect anomalies in systems. According to statistics, in Microsoft's two open source projects, one code out of every 58 lines of source code is used to record logs. Once errors occur, reviewing logs is a routine operation. Therefore, logs play an important role in abnormal detection of software service systems, but as the system scale expands, the speed at which logs are generated by the system increases, and manual review of logs becomes impossible, and it is very time-consuming and costly. Error-prone, so it is very important to automate log-based anomaly detection. [0003] Tobacco big data cloud platform includes Openstack-based cloud platform management system and cloud-based big data processing system hadoop, hdfs and other business sy...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): G06F11/30G06F16/33G06F16/35G06K9/62G06N3/04G06N3/08
CPCG06F11/3006G06F11/3055G06F11/3072G06F16/3344G06F16/35G06N3/08G06N3/044G06F18/2415G06F18/241Y02D10/00
Inventor 王迪冯伟华陈瑞宗国浩王锐王峙王永胜郑新章
Owner ZHENGZHOU TOBACCO RES INST OF CNTC
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More