Mid Sweden University

miun.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Machine Learning Based Anomaly Detection of Log Files Using Ensemble Learning and Self-Attention
Mid Sweden University, Faculty of Science, Technology and Media, Department of Information Systems and Technology. Försäkringkassan, ITPBM Systems Management, Sundsvall, Sweden.ORCID iD: 0000-0001-6535-0624
Mid Sweden University, Faculty of Science, Technology and Media, Department of Information Systems and Technology.ORCID iD: 0000-0002-1797-1095
Mid Sweden University, Faculty of Science, Technology and Media, Department of Information Systems and Technology.
2021 (English)In: 5th International Conference on System Reliability and Science, Palermo, Italy, 24-26 Nov. 2021, 2021, p. 209-215Conference paper, Published paper (Refereed)
Abstract [en]

Modern enterprise IT systems generate large amounts of log data to record system state, potential errors, and performance metrics. Manual analysis of log data is becoming more difficult as these systems become more complex. Therefore, machine learning based anomaly detection of system logs is a vital component for the future of system management. Existing log anomaly detection models commonly rely on learning the general normal behavior of the target systems to accurately detect anomalies. They are however limited by the often sparse existing system knowledge. Therefore, this paper proposes a general anomaly detection method which requires little or no knowledge of the target system. This is done by assuming there are semantic similarities in different systems’ log data. Labeled log data from other systems can then be used for training the anomaly detection model. The model uses self-attention transformers and ensemble learning techniques to learn the semantic representation of normal and abnormal log messages. The proposed method achieves a performance comparable to other log anomaly detection methods while requiring little knowledge of the target system.

Place, publisher, year, edition, pages
2021. p. 209-215
Keywords [en]
log, anomaly detection, AIOps, attention, ensemble learning, machine learning
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:miun:diva-44038DOI: 10.1109/ICSRS53853.2021.9660694ISI: 000850133700031Scopus ID: 2-s2.0-85124992999OAI: oai:DiVA.org:miun-44038DiVA, id: diva2:1626167
Conference
International Conference on System Reliability and Science (ICSRS), Palermo, Italy, November 24-26, 2021
Available from: 2022-01-10 Created: 2022-01-10 Last updated: 2022-09-16Bibliographically approved

Open Access in DiVA

fulltext(395 kB)2494 downloads
File information
File name FULLTEXT01.pdfFile size 395 kBChecksum SHA-512
7d63b77d109503c7355f2314ff17e34169418bcb8f061e0024c0d9df4dc46c7c0989dc0f914400409b77ddbf2ca949514e9b10bf44dfcad24320cd273b5c7fac
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Authority records

Fält, MarkusForsström, StefanZhang, Tingting

Search in DiVA

By author/editor
Fält, MarkusForsström, StefanZhang, Tingting
By organisation
Department of Information Systems and Technology
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 2494 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 403 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf