Efficient structured log storage

  • Authors:
  • Pavel Kácha

  • Affiliations:
  • CESNET, CERTS, Prague, Czech Republic

  • Venue:
  • ICCOMP'10 Proceedings of the 14th WSEAS international conference on Computers: part of the 14th WSEAS CSCC multiconference - Volume I
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

The paper describes working prototypes of several possible structured audit trail (logs) storages and compares their characteristics and performance parameters. The storage receives information about the format of data generated by daemons and its API enables queries according to individual attributes obtained by analyzing log rows. Such a system enables for creating applications, currently too difficult because of the text nature of the audit trail, such as looking for security anomalies, their correlation and statistical analysis.