Check out the new USENIX Web site.

USENIX Home . About USENIX . Events . membership . Publications . Students
18th Large Installation System Administration Conference — Abstract

Pp. 133–150 of the Proceedings

Real-time Log File Analysis Using the Simple Event Correlator (SEC)

John P. Rouillard , University of Massachusetts at Boston

Abstract

Log analysis is an important way to keep track of computers and networks. The use of automated analysis always results in false reports, however these can be minimized by proper specification of recognition criteria. Current analysis approaches fail to provide sufficient support for the recognizing the temporal component of log analysis. Temporal recognition of event sequences fall into distinct patterns that can be used to reduce false alerts and improve the efficiency of response to problems. This paper discusses these patterns while describing the rationale behind and implementation of a ruleset created at the CS department of the University of Massachusetts at Boston for SEC - the Simple Event Correlation program.

  • View the full text of this paper in HTML and PDF.
    Click here if you have forgotten your password Until November 2005, you will need your USENIX membership identification in order to access the full papers. The Proceedings are published as a collective work, © 2004 by the USENIX Association. All Rights Reserved. Rights to individual papers remain with the author or the author's employer. Permission is granted for the noncommercial reproduction of the complete work for educational or research purposes. USENIX acknowledges all trademarks within this paper.

  • If you need the latest Adobe Acrobat Reader, you can download it from Adobe's site.
To become a USENIX Member, please see our Membership Information.

 

?Need help? Use our Contacts page.

Last changed: 16 Nov. 2004 aw
Technical Program
LISA '04 Home
USENIX home