EventBrowser: A Flexible Tool for Scalable Analysis of Event Data

  • Authors:
  • Sheng Ma;Joseph L. Hellerstein

  • Affiliations:
  • -;-

  • Venue:
  • DSOM '99 Proceedings of the 10th IFIP/IEEE International Workshop on Distributed Systems: Operations and Management: Active Technologies for Network and Service Management
  • Year:
  • 1999

Quantified Score

Hi-index 0.00

Visualization

Abstract

Event management is fundamental to network and systems management. To date, this discipline has focused on reporting alerts in real time. This paper describes a tool, EventBrowser, intended for ad hoc analysis of historical logs, especially for problem determination and validating the benefits of configuration changes. EventBrowser addresses: (a) irregularities in the structure of event messages, (b) problems with visualizing patterns in large volumes of categorical data, and (c) difficulties with providing multiple views at different levels of detail. In particular for item (c), EventBrowser provides summary statistics (e.g., by host name), relationships between events (e.g., via scatter plots), and full message details. We have applied EventBrowser to analyze data from a production network. Our visualizations reveal a number of abnormalities that are not detected readily by conventional tools.