Thesis of Nabil Hammoud


Subject:
Detection of correlation events in large and heterogeneous logs

Defense date: 01/11/2009

Advisor: Jean-Marc Petit

Summary:

In our rapidly evolving societies, every corporate is trying to improve its competitiveness by refactoring and improving some - if not all - of its industrial software infrastructure. This goes from mainframe applications that actually handle the company’s profit generating material, to the internal desktop applications used to manage those application servers.
Activity logging is the mechanism that consists of collecting information about activities that the system or the administrator can use to characterize the behavior activity of information systems by generating events to log files. By extending activity logging features, applications are being able to notify administrators of every event encountered at runtime.
While applications are being developed by people with different backgrounds and development skills, every application may generate its own log messages and log structures. Consequently we find out in any information system distributed and heterogeneous logs that are not structured in the same way. Such situation would drastically increase the complexity of managing and maintaining the log files.
Since log files are excellent sources for determining the health status of a system, our Phd subject will study log analysis. Consequently it will move toward log event management systems with the aim to integrate, interrogate and correlate log events from different logs entries.