Back to results

Technische Universität Berlin

A layered architecture for log analysis in complex IT systems

Abstract

dc:description.abstract

In the rapidly evolving landscape of Information Technology (IT), the stability and reliability of IT systems and services are important because they underpin numerous aspects of modern life. However, their increasing complexity poses significant challenges for DevOps teams, who are responsible for their implementation and maintenance. Log analysis, a core component of Artificial Intelligence for IT Operations (AIOps), plays an essential role by serving as a major source for investigating the complex behaviors and failures of IT systems. Therefore, this dissertation addresses the critical need for effective log analysis in complex IT systems by introducing a three-layered architecture designed to enhance the capabilities of DevOps teams in failure resolution. The first layer, Log Investigation, focuses on autonomous labeling and anomaly classification to provide the groundwork for the next layers. We developed a method that accurately labels log data autonomously, facilitating supervised model training and the precise evaluation of anomaly detection methods. In addition, we created a taxonomy to classify anomalies into three different categories, guaranteeing the selection of a suitable anomaly detection method. Within the second layer, Anomaly Detection, we identify behaviors of IT systems that deviate from the norm. Therefore, we propose a flexible anomaly detection method adaptable to various training scenarios: Unsupervised, weakly supervised, or supervised. Evaluations on public and industry data sets demonstrate that our method achieves F1-Scores ranging from 0.98 to 1.0 in different training scenarios, ensuring a reliable anomaly detection. The third layer addresses Root Cause Analysis. With our developed root cause analysis method we can identify a minimal set of log lines that describe a failure along with its origin and the sequence of events that led to it. By balancing training data and identifying the primary services involved, our root cause analysis method consistently identifies 90-98 % of root cause log lines within the top 10 candidates, providing precise and actionable insights for failure mitigation. Our research answers the overarching question of how log analysis methods can be designed and optimized to help DevOps teams resolve failures efficiently. By integrating these three layers, our architecture equips DevOps teams with the necessary methods to enhance IT system reliability.

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Wittkopp, Thorsten
Advisor dc:contributor.advisor
  • Kao, Odej

Rights

Language dc:language.iso
en

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:depositonce.tu-berlin.de:11303/23198

Chain of custody

source
Harvested from
Technische Universität Berlin
Base URL
api-depositonce.tu-berlin.de/server/oai/request
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
related terms
citation

Wittkopp, Thorsten. A layered architecture for log analysis in complex IT systems. 2024. https://depositonce.tu-berlin.de/handle/11303/23198