Log Analysis and Event Correlation Using Variable Temporal Event Correlator (VTEC)
نویسنده
چکیده
System administrators have utilized log analysis for decades to monitor and automate their environments. As compute environments grow, and the scope and volume of the logs increase, it becomes more difficult to get timely, useful data and appropriate triggers for enabling automation using traditional tools like Swatch. Cloud computing is intensifying this problem as the number of systems in datacenters increases dramatically. To address these problems at AMD, we developed a tool we call the Variable Temporal Event Correlator, or VTEC. VTEC has unique design features, such as inherent multi-threaded/multi-process design, a flexible and extensible programming interface, built-in job queuing, and a novel method for storing and describing temporal information about events, that well suit it for quickly and efficiently handling a broad range of event correlation tasks in realtime. These features also enable VTEC to scale to tens of gigabytes of log data processed per day. This paper describes the architecture, use, and efficacy of this tool, which has been in production at AMD for more than four years. Tags: security, case study, syslog, log analysis, event correlation, temporal variables
منابع مشابه
Real-time Log File Analysis Using the Simple Event Correlator (SEC)
Log analysis is an important way to keep track of computers and networks. The use of automated analysis always results in false reports, however these can be minimized by proper specification of recognition criteria. Current analysis approaches fail to provide sufficient support for the recognizing the temporal component of log analysis. Temporal recognition of event sequences fall into distinc...
متن کاملSimple Event Correlator for real-time security log monitoring
When it comes to the security of the IT system, event logs play a crucial role. Today, many applications, operating systems, network devices and other system components are capable of writing security related event messages to log files. The BSD syslog protocol is an event logging standard supported by majority of OS and network equipment vendors, which allows one to set up a central log server...
متن کاملAll optical three dimensional spatio-temporal correlator for automatic event recognition using a multiphoton atomic system
We describe an automatic event recognition (AER) system based on a three-dimensional spatio-temporal correlator (STC) that combines the techniques of holographic correlation and photon echo based temporal pattern recognition. The STC is shift invariant in space and time. It can be used to recognize rapidly an event (e.g., a short video clip) that may be present in a large video file, and determ...
متن کاملComposite Events for Network Event Correlation
With the increasing complexity of enterprise networks and the Internet, event correlation is playing an increasingly important role in network as well as integrated system management systems. Even though the timing of events often reveals important diagnostic information about event relationships and should therefore be represented in event correlation rules or models, most extant approaches la...
متن کاملA New Approach for Event Correlation based on Dependency Graphs
Today's fault management is characterized by ineecient event management. The events delivered by the managed system frequently descibe symptoms of a problem instead of its cause. If a problem in the managed system occurs, e.g. a network failure or misconngured software, the administrator often is ooded by a burst of more or less meaningless events indicating symptoms of the problem. The aim of ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010