Decentralized log event correlation architecture

  • Authors:
  • Nabil Hammoud

  • Affiliations:
  • AMD Consulting, Paris, France and LIRIS-INSA de lyon, Villeurbanne cedex, France

  • Venue:
  • Proceedings of the International Conference on Management of Emergent Digital EcoSystems
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

In our rapidly evolving societies, every corporate is trying to improve its competitiveness by refactoring and improving some - if not all - of its industrial software infrastructure. This goes from mainframe applications that actually handle the company's profit generating material, to the internal desktop applications used to manage those application servers. These applications often have extended activity logging features that notify the administrators of events those programs encounter at runtime. Unfortunately, the standalone nature of the event logging sources renders difficult the correlation of log events. In this setting, "continuous queries" developed in the database area offer a deal of opportunity to query such evolving logs. This paper describe an approach that "adapt and employ continues queries" for distributed log event correlation. Our aims cope with problems facing the present log event management systems.