Log Analysis and Event Correlation Using Variable Temporal Event Correlator (VTEC).

LISA'10: Proceedings of the 24th international conference on Large installation system administration(2010)

引用 9|浏览301
暂无评分
摘要
System administrators have utilized log analysis for decades to monitor and automate their environments. As compute environments grow, and the scope and volume of the logs increase, it becomes more difficult to get timely, useful data and appropriate triggers for enabling automation using traditional tools like Swatch. Cloud computing is intensifying this problem as the number of systems in datacenters increases dramatically. To address these problems at AMD, we developed a tool we call the Variable Temporal Event Correlator, or VTEC. VTEC has unique design features, such as inherent multi-threaded/multi-process design, a flexible and extensible programming interface, built-in job queuing, and a novel method for storing and describing temporal information about events, that well suit it for quickly and efficiently handling a broad range of event correlation tasks in real-time. These features also enable VTEC to scale to tens of gigabytes of log data processed per day. This paper describes the architecture, use, and efficacy of this tool, which has been in production at AMD for more than four years.
更多
查看译文
关键词
log data,multi-process design,traditional tool,unique design feature,useful data,utilized log analysis,Variable Temporal Event Correlator,broad range,built-in job,cloud computing,event correlation,variable temporal event correlator
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要