event summarization for system management

13
Event Summarization for System Management Wei Peng†, Chang-shing Perng§, Tao Li†, Haixun Wang§ †Florida International University §IBM T.J.Waston Research Center -presented by: Wei Peng

Upload: charis

Post on 05-Jan-2016

25 views

Category:

Documents


0 download

DESCRIPTION

Event Summarization for System Management. Wei Peng†, Chang-shing Perng§, Tao Li†, Haixun Wang§ †Florida International University §IBM T.J.Waston Research Center -presented by: Wei Peng. Introduction. Why Event Summarization? - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Event Summarization for System Management

Event Summarization for System Management

Wei Peng†, Chang-shing Perng§, Tao Li†, Haixun Wang§†Florida International University

§IBM T.J.Waston Research Center

-presented by: Wei Peng

Page 2: Event Summarization for System Management

Introduction

• Why Event Summarization?– traditional approaches are cumbersome, labor

intensive, and error prone– focus on discovering frequent or interesting

patterns, scalability , and efficiency– understanding and interpreting patterns

• A divide-and-conquer method

Page 3: Event Summarization for System Management

A Motivating Example

Page 4: Event Summarization for System Management

Steps for Event Summarization

• Preprocess log data and generate events

• Discover temporal correlation between events (dependency)

• Rank dependencies

• Construct Event Relationship Networks (ERNs)

• Derive Action Rules from Event Summary

Page 5: Event Summarization for System Management

Preprocess Log Data and Generate events

• Preprocess the brief log messages

• Categorize it into common situations/states– Incorporate time information

• An event is a pair <e, t> that e is the situation/state, t is the time stamp of e

Page 6: Event Summarization for System Management

Discover Temporal Correlation between Events (Dependency)

• b depends on a– If the occurrence of b is predictable by the occurrence of a,

then the conditional distribution which models the waiting time of event type b given event type a’s presence would be different from the unconditional one

• Estimate two distributions• Dependency test

Independent Dependent

Page 7: Event Summarization for System Management

Rank Dependencies

• Forward Entropy

• Backward Entropy

Page 8: Event Summarization for System Management

Event Relationship Networks (ERNs)

Page 9: Event Summarization for System Management

Derive Action Rules from EventSummary

• If condition is true, take action– Event reduction rules– Event correlation rules– Problem avoidance rules

Page 10: Event Summarization for System Management

A Case Study

State: start, stop, dependency, create, connection, report, request, configuration, other

Page 11: Event Summarization for System Management

Decomposition Process in the Case Study

Page 12: Event Summarization for System Management

ERN in the Case Study

Page 13: Event Summarization for System Management

Thank You !