Skip to main content

AMULOG (A Manager for Unstructured LOGs)

PyPI release Python support BSD 3-Clause License Test Documentation

Amulog is a tool to support system log management. The main function is to classify log messages with automatically generated log templates (formats and variable locations), and to store the data in a database. This system works on python3.

Main features

  • Support multiple databases: sqlite and mysql

  • Smart log segmentation with log2seq

  • Multiple template generation algorithms such as: Drain, SHISO, LenMa, FT-tree, Dlog, etc.

  • Support Online (incremental) and Offline (hindsight) use

  • Suspend and resume the template generation process

  • Import and Export log templates if you need

  • Edit log templates manually if you need

  • Search API with datetime, hostname and log template IDs

  • Ready-to-run examples for loghub open datasets (see example/loghub_*)

Tutorial

Install

$ pip install amulog

Generate config

For the first step, save following config as test.conf on an empty directory.

[general]
src_path = logfile.txt
src_recur = false
logging = auto.log

[database]
database = sqlite3
sqlite3_filename = log.db

[log_template]
lt_methods = drain
indata_filename = ltgen.dump

Then modify general.src_path option to a logfile you want to load. (If you want to use multiple files, change general.src_recur into true and specify directory name to general.src_path.)

Generate database

Try following command to generate database:

$ python -m amulog db-make -c test.conf

Check database

$ python -m amulog show-db-info -c test.conf

shows status of the generated database.

$ python -m amulog show-lt -c test.conf

shows all generated log templates in the given logfile.

$ python -m amulog show-log -c test.conf ltid=2

shows all log messages corresponding to log template ID 2.

Resume generating database

Try following command to resume generating database:

$ python -m amulog db-add -c test.conf logfile2.txt

Export and Import templates

Following command exports all log templates in the database:

$ python3 -m amulog show-lt-import -c test.conf > exported_tpl.txt

You can modify the exported templates manually. Note that some special letters (\\, @, *) are escaped in the exported templates.

To import the templates, save following config as test2.conf.

[general]
src_path = logfile.txt
src_recur = false
logging = new_auto.log

[database]
database = sqlite3
sqlite3_filename = new_log.db

[log_template]
lt_methods = import
indata_filename = new_ltgen.dump

[log_template_import]
def_path = exported_tpl.txt

Then, try generating database again:

python -m amulog db-make -c test2.conf

Using your data

Parsing your data

Amulog uses log2seq to parse input log messages in DB generation. If your data is not a default syslog output format, you need to specify an appropriate log2seq parser script. The log2seq parser script is specified in manager.parser_script in amulog config file.

[manager]
parser_script = test_parser.py
fail_output = fail.log

If the parser fails to parse some of the input log messages, they are stored in manager.fail_output file. You can check this file to test whether the parser is working appropriately or not.

There are example parser scripts in log2seq repository.

Further usage

see help with following command:

python -m amulog -h

Reference

This tool is demonstrated at International Journal of Network Management and CNSM2020.

If you use this code, please consider citing:

@article{Kobayashi_IJNM2022,
  author = {Kobayashi, Satoru and Yamashiro, Yuya and Otomo, Kazuki and Fukuda, Kensuke},
  title = {amulog: A general log analysis framework for comparison and combination of diverse template generation methods*},
  journal = {International Journal of Network Management},
  volume = {32},
  number = {4},
  pages = {e2195},
  doi = {https://doi.org/10.1002/nem.2195},
  year = {2022}
}

@inproceedings{Kobayashi_CNSM2020,
  author = {Kobayashi, Satoru and Yamashiro, Yuya and Otomo, Kazuki and Fukuda, Kensuke},
  booktitle = {Proceedings of the 16th International Conference on Network and Service Management (CNSM'20)},
  title = {amulog: A General Log Analysis Framework for Diverse Template Generation Methods},
  pages={1-5},
  year = {2020}
}

Metadata

Release files for amulog 0.5.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for amulog 0.5.2
File Size Uploaded
amulog-0.5.2.tar.gz 111.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for amulog 0.5.2
File Interpreter ABI Platform
amulog-0.5.2-py3-none-any.whl Python 3 none any Details

Total release size: 242.9 kB

Release files / amulog-0.5.2.tar.gz

Download URL amulog-0.5.2.tar.gz
Size 111.9 kB
Tags Source
SHA-256 checksum
How to use checksums
5d4c392dffa6898797d89e93eaf17f47b15512e4d40497c7035acb476060649b
BLAKE2b-256 checksum
How to use checksums
b0e8de4f6fb17f39559a8e6564ba5b80c7702f6802493484a096ccb349d4a0ab
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release files / amulog-0.5.2-py3-none-any.whl

Download URL amulog-0.5.2-py3-none-any.whl
Size 131.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
931d6c8a6c6c6e8d94176c90b7adafa6bdc0621d44c69cf466ab09f78d1ac38e
BLAKE2b-256 checksum
How to use checksums
cfa59aa44f0dcf1c4c7161e66be1884458c9c5b33312500cd64c4e6aa27ecf99
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.5.2 This release

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.14

2 release files

0.3.10

1 release file

0.3.9

1 release file

0.3.8

1 release file

0.3.7

1 release file

0.3.6

1 release file

0.3.5

1 release file

0.3.4

1 release file

0.3.3

1 release file

0.3.2

1 release file

0.3.1

1 release file

0.3.0

1 release file

0.2.12

1 release file

0.2.11

1 release file

0.2.9

1 release file

0.2.8

1 release file

0.2.7

1 release file

0.2.6

1 release file

0.2.5

1 release file

0.2.4

1 release file

0.2.3

1 release file

0.2.2

1 release file

0.2.1

1 release file

0.1.14

1 release file

0.1.13

1 release file

0.1.12

1 release file

0.1.11

1 release file

0.1.10

1 release file

0.1.9

1 release file

0.1.8

1 release file

0.1.7

1 release file

0.1.6

1 release file

0.1.5

1 release file

0.1.4

1 release file

0.1.3

1 release file

0.1.2

1 release file

0.0.8

1 release file

0.0.7

1 release file

0.0.6

1 release file

0.0.5

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page