Automatically Acquiring Rules for Event Correlation from Event Logs

  • Authors:
  • T. Oates;D. Jensen;P. R. Cohen

  • Affiliations:
  • -;-;-

  • Venue:
  • Automatically Acquiring Rules for Event Correlation from Event Logs
  • Year:
  • 1997

Quantified Score

Hi-index 0.00

Visualization

Abstract

A single fault in a complex network can generate a cascade of events, potentially overloading a manager''s console with information. One way to reduce the number of events is event correlation, a process that groups several related events into a single composite event. We have developed Multi-Event Dependency Detection (MEDD), an algorithm that automatically constructs event correlation rules. MEDD is a prototype for a component of NASA''s EOSDIS Core System. The algorithm efficiently searches the space of possible dependencies between events and selects the most useful rules. Preliminary results indicate that MEDD identifies useful rules for event correlation, and could reduce the information burden on network managers. This research was supported by DARPA under contract F30602-91-C-0076 and DoD Fellowship F30602-93-C-0100.