LogParser-LLM: Advancing Efficient Log Parsing with Large Language Models

LogParser-LLM: повышение эффективности анализа журналов с помощью больших языковых моделей
Aoxiao Zhong, Dengyao Mo, Guiyang Liu, Jinbu Liu, Qingda Lu, Qi Zhou, Jiesheng Wu, Quanzheng Li, Qingsong Wen
2024-08-24

Large Language Models (LLMs)LogPub benchmarklog parsingonline parsingparsing granularity
Logs are ubiquitous digital footprints, playing an indispensable role in system diagnostics, security analysis, and performance optimization. The extraction of actionable insights from logs is critically dependent on the log parsing process, which converts raw logs into structured formats for downstream analysis. Yet, the complexities of contemporary systems and the dynamic nature of logs pose significant challenges to existing automatic parsing techniques. The emergence of Large Language Models (LLM) offers new horizons. With their expansive knowledge and contextual prowess, LLMs have been transformative across diverse applications. Building on this, we introduce LogParser-LLM, a novel log parser integrated with LLM capabilities. This union seamlessly blends semantic insights with statistical nuances, obviating the need for hyper-parameter tuning and labeled training data, while ensuring rapid adaptability through online parsing. Further deepening our exploration, we address the intricate challenge of parsing granularity, proposing a new metric and integrating human interactions to allow users to calibrate granularity to their specific needs. Our method's efficacy is empirically demonstrated through evaluations on the Loghub-2k and the large-scale LogPub benchmark. In evaluations on the LogPub benchmark, involving an average of 3.6 million logs per dataset across 14 datasets, our LogParser-LLM requires only 272.5 LLM invocations on average, achieving a 90.6% F1 score for grouping accuracy and an 81.1% for parsing accuracy. These results demonstrate the method's high efficiency and accuracy, outperforming current state-of-the-art log parsers, including pattern-based, neural network-based, and existing LLM-enhanced approaches.
1
A new parsing-granularity metric and human interaction mechanism allow users to calibrate output granularity according to their specific requirements.
2
Across 14 LogPub datasets averaging 3.6 million logs each, LogParser-LLM used only 272.5 LLM invocations on average while achieving 90.6% grouping F1 and 81.1% parsing F1.
3
Evaluations on Loghub-2k and LogPub show that LogParser-LLM outperforms pattern-based, neural-network-based, and existing LLM-enhanced log parsers.
4
LogParser-LLM combines large-language-model semantic understanding with statistical analysis for automatic log parsing without hyperparameter tuning or labeled training data.
5
The parser supports online parsing, enabling rapid adaptation to the dynamic nature of contemporary system logs.

raw system logs from contemporary computing systems

efficient, accurate, and adaptable conversion of raw logs into structured log groups and templates, including controllable parsing granularity

Publication Details
Publication Date
2024-08-24
Journal
Publisher
ISSN
Cited by
57
Access Type
Author Information
Authors
Aoxiao Zhong
Dengyao Mo
Guiyang Liu
Jinbu Liu
Qingda Lu
Qi Zhou
Jiesheng Wu
Quanzheng Li
Qingsong Wen
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%