Storage and retrieval of system log events using a structured schema based on message type transformation

  • Authors:
  • Adetokunbo Makanju;A. Nur Zincir-Heywood;Evangelos E. Milios

  • Affiliations:
  • Dalhousie University, Halifax, Nova Scotia, Canada;Dalhousie University, Halifax, Nova Scotia, Canada;Dalhousie University, Halifax, Nova Scotia, Canada

  • Venue:
  • Proceedings of the 2011 ACM Symposium on Applied Computing
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Message types are semantic groupings of the free form messages in system log events. The message types that exist in a log file, if known, can be used in several log management and analysis tasks. In this work, we explore the use of message types as a schema definition for the storage and retrieval of messages in event logs. We show how message types can be used to impose structure on the unstructured content of event logs and how this structured representation can provide a usable index for searching the contents of the log file. As a side benefit, the structured representation that message types impose also leads to the removal of redundant information in the event logs that leads to space savings on disk.