Pith. sign in

REVIEW 5 cited by

Experience Report: Deep Learning-based System Log Analysis for Anomaly Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2107.05908 v2 pith:VDEPWCCQ submitted 2021-07-13 cs.SE cs.LG

classification cs.SEcs.LG
keywords anomalymethodslearning-basedsystemsdeepdetectiondetectorslog-based
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Logs have been an imperative resource to ensure the reliability and continuity of many software systems, especially large-scale distributed systems. They faithfully record runtime information to facilitate system troubleshooting and behavior understanding. Due to the large scale and complexity of modern software systems, the volume of logs has reached an unprecedented level. Consequently, for log-based anomaly detection, conventional manual inspection methods or even traditional machine learning-based methods become impractical, which serve as a catalyst for the rapid development of deep learning-based solutions. However, there is currently a lack of rigorous comparison among the representative log-based anomaly detectors that resort to neural networks. Moreover, the re-implementation process demands non-trivial efforts, and bias can be easily introduced. To better understand the characteristics of different anomaly detectors, in this paper, we provide a comprehensive review and evaluation of five popular neural networks used by six state-of-the-art methods. Particularly, four of the selected methods are unsupervised, and the remaining two are supervised. These methods are evaluated with two publicly available log datasets, which contain nearly 16 million log messages and 0.4 million anomaly instances in total. We believe our work can serve as a basis in this field and contribute to future academic research and industrial applications.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Tracezip: Efficient Distributed Tracing via Trace Compression

    cs.SE 2025-02 conditional novelty 7.0 of 10

    Tracezip is an online trace compression system using a Span Retrieval Tree to remove redundant data across spans, improving trace collection efficiency in OpenTelemetry.

  2. AL-Bench: A Benchmark for Automatic Logging

    cs.SE 2025-02 conditional novelty 7.0 of 10

    A new benchmark with static and runtime evaluation shows state-of-the-art automatic logging tools produce many uncompilable or semantically misaligned log statements.

  3. LogNLQ: Natural-Language Log Querying with Parser-Induced and Semantically Grounded Schemas

    cs.SE 2026-07 conditional novelty 6.0 of 10

    Parser-induced, semantically grounded schemas let LLMs generate executable SQL over raw logs, beating text-QA, LogQL, and schema-free Text-to-SQL baselines on an 8,895-query execution-verified benchmark.

  4. Explaining GitHub Actions Failures with Large Language Models: Challenges, Insights, and Limitations

    cs.SE 2025-01 conditional novelty 5.0 of 10

    A 31-developer survey found that LLM-generated explanations of GitHub Actions failures are perceived as correct and clear for simple logs, but less useful for complex CI/CD failures.

  5. RANGAN: GAN-empowered Anomaly Detection in 5G Cloud RAN

    cs.NI 2025-08 conditional novelty 4.0 of 10

    A GAN-transformer model with sliding windows detects network contention in 5G RAN KPI time series, reaching 83% F1 on the SpotLight dataset.

Pith tools